Page MenuHomeVyOS Platform

AWS SupportInfrastructure
ActivePublic

Details

Description

This all about AWS support related tasks and questions

Recent Activity

Jul 12 2023

syncer closed T425: AWS CloudWatch monitoring scripts as Resolved.
Jul 12 2023, 3:26 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Apr 13 2023

fernando added a comment to T425: AWS CloudWatch monitoring scripts.

Thanks for clarifying. Yes , I also saw the possibility of extending role based IAM to add on-premise image (that could be interesting for VyOS).

Apr 13 2023, 7:35 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
unity added a comment to T425: AWS CloudWatch monitoring scripts.

@fernando

  1. In order to apply SSM auto-configuration of the CloudWatch agent, an SSM agent must be installed that installs the CloudWatch agent with the necessary configuration. Currently, there is no SSM agent inside VyOS AWS images, and I haven't heard anything about willingness to include it.
  2. The amazon-cloudwatch-agent package has only one dependency, libc6. Therefore, it does not need the aws-cli to be configured or set up at all.
  3. Granting access to the CloudWatch service from an EC2 instance is done by applying the corresponding IAM role to the instance. While it is possible to do this via manual credential input, it is an unwanted practice inside AWS.
  4. The possible scenario of sending data to CloudWatch out of AWS is unique and requires another Phorge task, I think.
Apr 13 2023, 3:58 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
fernando added a comment to T425: AWS CloudWatch monitoring scripts.

@unity when you need AWS credential , will they be automatically deployed from SSM or will we have to add those credentials in the virtual machine? ? shouldn't aws-cli be integrated?

Apr 13 2023, 3:30 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Apr 12 2023

unity added a comment to T425: AWS CloudWatch monitoring scripts.

I've created the PR https://github.com/vyos/vyos-documentation/pull/987 as a temporary explanation for users on how to preserve CloudWatch Agent configuration in a semi-automated way, using the SSM Parameter Store.

Apr 12 2023, 5:09 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Apr 10 2023

unity added a comment to T425: AWS CloudWatch monitoring scripts.

Notice. Initially this task was about monitoring scripts but they were deprecated. Then aws-cloudwatch-agent emerged.
aws-cloudwatch-agent was successfully added to vyos-build:equuleus. But cloudwatch configuration preservation between image updates is not.
This task was closed mistakenly prematurely thus should be reopen.

Apr 10 2023, 7:11 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
syncer reopened T425: AWS CloudWatch monitoring scripts as "Open".

Requires some additional work
we need to preserve configuration between upgrade
alternatively, we need to investigate if default config can be used with VM role

Apr 10 2023, 11:08 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Apr 5 2023

c-po closed T425: AWS CloudWatch monitoring scripts as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Mar 31 2023

c-po moved T425: AWS CloudWatch monitoring scripts from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Mar 31 2023, 11:33 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support
c-po added a comment to T425: AWS CloudWatch monitoring scripts.

PR for VyOS 1.3 https://github.com/vyos/vyos-build/pull/330

Mar 31 2023, 11:32 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support
c-po added a comment to T425: AWS CloudWatch monitoring scripts.

https://dev.packages.vyos.net/repositories/current/pool/main/a/amazon-cloudwatch-agent/amazon-cloudwatch-agent_1.247358.0b252413-1_amd64.deb
https://dev.packages.vyos.net/repositories/equuleus/pool/main/a/amazon-cloudwatch-agent/amazon-cloudwatch-agent_1.247358.0b252413-1_amd64.deb

Mar 31 2023, 10:42 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support
c-po added a comment to T425: AWS CloudWatch monitoring scripts.

Building from source always results in:

Mar 31 2023, 8:28 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Mar 30 2023

c-po added a parent task for T425: AWS CloudWatch monitoring scripts: T5129: Add AWS build flavour.
Mar 30 2023, 2:20 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
c-po changed the status of T425: AWS CloudWatch monitoring scripts from Open to In progress.
Mar 30 2023, 2:17 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Aug 29 2022

syncer edited projects for T425: AWS CloudWatch monitoring scripts, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.0).
Aug 29 2022, 7:15 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Nov 6 2021

syncer edited projects for T425: AWS CloudWatch monitoring scripts, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus.
Nov 6 2021, 11:33 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Sep 10 2021

dmbaturin edited projects for T1062: Cannot connect to a newly created Amazon EC2 instance via SSH, added: Invalid; removed VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 10 2021, 6:29 AM · Invalid, build-ami, AWS Support
dmbaturin renamed T1062: Cannot connect to a newly created Amazon EC2 instance via SSH from SSH connection to AWS AMI not possible for newly created image to Cannot connect to a newly created Amazon EC2 instance via SSH.
Sep 10 2021, 6:29 AM · Invalid, build-ami, AWS Support

Sep 4 2021

syncer removed a member for AWS Support: syncer.
Sep 4 2021, 9:08 AM

Sep 3 2021

dmbaturin set Issue type to feature on T425: AWS CloudWatch monitoring scripts.
Sep 3 2021, 7:25 AM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Aug 31 2021

erkin set Is it a breaking change? to none on T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.
Aug 31 2021, 7:15 PM · Invalid, build-ami, AWS Support

Jan 27 2021

dmbaturin changed Difficulty level from unknown to normal on T425: AWS CloudWatch monitoring scripts.
Jan 27 2021, 6:41 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support

Apr 30 2020

syncer added a member for AWS Support: syncer.
Apr 30 2020, 5:37 PM

Nov 12 2019

c-po moved T1062: Cannot connect to a newly created Amazon EC2 instance via SSH from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 12 2019, 9:19 PM · Invalid, build-ami, AWS Support

Oct 19 2019

syncer closed T1062: Cannot connect to a newly created Amazon EC2 instance via SSH as Wontfix.

This works as expected

Oct 19 2019, 1:57 AM · Invalid, build-ami, AWS Support
spectre3500 added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I'm still having an issue with using build-ami to create an AMI in us-gov-west-1.

Oct 19 2019, 1:50 AM · Invalid, build-ami, AWS Support

Jun 4 2019

altmind added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

All you need for ssh keys to work for AMI is to add cloud-init package in configure step:

Jun 4 2019, 10:00 PM · Invalid, build-ami, AWS Support

May 30 2019

spectre3500 added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

build-ami is working for me if I remove disable-password-authentication from the config template and add in a password into the config template. I have come across another issue though. I was able to get it to work in us-east-1 and us-east-2, but I can't deploy into us-gov-west-1. First problem was it couldn't find a debian-jessie image but that was solved by changing the owner from 379101102735 to 256493402735. Now it's throwing an 401 when attempting to list all subnets. I'm guessing that the python code pulled from ansible is configured for a specific region or the cli command used in GovCloud is slightly different. Either way it's not working.

May 30 2019, 10:22 PM · Invalid, build-ami, AWS Support

Apr 20 2019

spectre3500 added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I wasn't aware that there was an aws target for the vyos-build scripts.

Apr 20 2019, 2:48 PM · Invalid, build-ami, AWS Support
dmbaturin added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

@spectre3500 Now that I think of it, did you build it with build-ami or the AWS target of the vyos-build scripts?

Apr 20 2019, 12:46 PM · Invalid, build-ami, AWS Support
dmbaturin added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

...oh, and remove "disable-password-authentication" from the SSH settings of course.

Apr 20 2019, 12:00 PM · Invalid, build-ami, AWS Support
dmbaturin updated subscribers of T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I wonder if this issue will ever stop re-occuring. Every time it happens, it's for some new reason. I think this time it may be related to ongoing work of @Unicron.

Apr 20 2019, 11:45 AM · Invalid, build-ami, AWS Support

Apr 19 2019

spectre3500 added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I'm also experiencing the same issue with vyos-1.2.0-rolling-201904190439. I was able to create the ami using the build-ami playbooks, but when launched I could not login using the keypair. Is there a fix for this or a workaround?

Apr 19 2019, 2:00 PM · Invalid, build-ami, AWS Support

Dec 21 2018

syncer moved T1033: build-ami: Enable support for ENA from Needs Triage to Finished on the VyOS 1.2 Crux ( VyOS 1.2.0-rc11) board.
Dec 21 2018, 10:10 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11), build-ami, AWS Support

Dec 14 2018

UnicronNL closed T1033: build-ami: Enable support for ENA as Resolved.

added the patch! thanks

Dec 14 2018, 10:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11), build-ami, AWS Support

Dec 10 2018

iceblade added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I found an AMI I had built from 1.1.8 back on July 7th. I can create functional 1.1.8 instances from that, so it looks to be something unique to 1.2.0, but I can't say for sure because I don't have a working way to build 1.1.8 AMIs currently. The 1.1.8 playbooks rely on modules that have been removed from Ansible, so I would have to rewrite them or downgrade my ansible install.

Dec 10 2018, 4:03 PM · Invalid, build-ami, AWS Support

Dec 8 2018

iceblade added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

Also tried 1.2.0-rolling-201812080337. My best guess is that its not copying the SSH key into the system properly to allow the vyos user to login, as the system responds, accepts the username, rejects the key then disconnects with no further auth method.

Dec 8 2018, 6:15 AM · Invalid, build-ami, AWS Support
iceblade added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I tried the build with 1.2.0-rc9 and rc10 with the same results. The instance boots up without issue, but rejects any login attempts with the SSH key the instance was launched with. The error it gets back suggests its not configured for key or password login, or any other method for some reason.

Dec 8 2018, 5:07 AM · Invalid, build-ami, AWS Support

Dec 5 2018

syncer edited projects for T1033: build-ami: Enable support for ENA, added: VyOS 1.2 Crux ( VyOS 1.2.0-rc11); removed VyOS 1.2 Crux (VyOS 1.2.0-rc10).
Dec 5 2018, 11:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11), build-ami, AWS Support

Dec 3 2018

begetan added a comment to T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.

I forgot to fetch commits for the latest build-ami version when submitted report.
Now I confirms that problem exists in the latest version with the last commit:

Dec 3 2018, 9:58 AM · Invalid, build-ami, AWS Support

Dec 1 2018

syncer assigned T1062: Cannot connect to a newly created Amazon EC2 instance via SSH to UnicronNL.

@UnicronNL can you explain right way to create 1.2 ami

Dec 1 2018, 6:24 PM · Invalid, build-ami, AWS Support
syncer assigned T1033: build-ami: Enable support for ENA to UnicronNL.
Dec 1 2018, 6:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11), build-ami, AWS Support

Nov 30 2018

begetan created T1062: Cannot connect to a newly created Amazon EC2 instance via SSH.
Nov 30 2018, 1:16 PM · Invalid, build-ami, AWS Support
begetan added a comment to T1033: build-ami: Enable support for ENA.

This is great an very important feature for AWS since they introduced very cheap and advanced t3 instances.

Nov 30 2018, 1:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11), build-ami, AWS Support

Nov 27 2018

syncer moved T1032: Install awscli package by default on AWS images from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc9) board.
Nov 27 2018, 12:06 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support
syncer moved T1003: AWS: Login via SSH key does no longer work from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc9) board.
Nov 27 2018, 12:06 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support

Nov 23 2018

m.tremer added a comment to T1003: AWS: Login via SSH key does no longer work.

Thank you!

Nov 23 2018, 10:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support
UnicronNL closed T1003: AWS: Login via SSH key does no longer work as Resolved.

@m.tremer added the patch, thanks... was under the impression cloud-init added the user as it is stated as default user, but clearly it does not.

Nov 23 2018, 9:01 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support
m.tremer added a comment to T1032: Install awscli package by default on AWS images.

Isn't that how Open Source is supposed to work? :)

Nov 23 2018, 11:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support

Nov 22 2018

dmbaturin closed T1032: Install awscli package by default on AWS images as Resolved.

Good idea, thanks! I've applied the patch and will push it shortly.

Nov 22 2018, 9:18 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), AWS Support