Hacker News new | past | comments | ask | show | jobs | submit login

Cripes - that's a lot of machinery - we simply use security groups as roles, no iptables at all.

The only groups/roles that allow external access are:

  - proxy (80,443 /0)
  - extranet (80,443 office-ips/32)
  - admin (22 office-ips/32)
The rest of the security groups are set up appropriate to the roles eg: db allows 3306 to app,extranet,...

instances can do discovery thru' the ec2 api - looke for a machine wit the role they require.

Once an instance is booted and the packages are installed, it is maybe a minute or less to availability.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: