A DevOps team manages a critical application that processes sensitive customer data, running on EC2 instances. They need to ensure that all changes to the operating system, including package installations and configuration modifications, are immutable and auditable. If an unauthorized change occurs, the instance should be automatically terminated and replaced with a known good state. Which strategy should the team implement?
- ARegularly take snapshots of EC2 instance volumes and restore them if unauthorized changes are detected.
- BUse AWS Systems Manager State Manager to define and enforce desired state configurations on EC2 instances.
- CUse Amazon Machine Images (AMIs) built with all required software and configurations, and deploy instances from these AMIs using an Auto Scaling Group.
- DImplement a configuration management tool like Ansible or Chef to apply desired state configurations to running instances periodically.
Show answer & explanationAnswer & explanation
Correct answer: C. Use Amazon Machine Images (AMIs) built with all required software and configurations, and deploy instances from these AMIs using an Auto Scaling Group.
This approach embodies the 'immutable infrastructure' principle. By baking all software and configurations into an AMI, any deployed instance starts from a known, verified state. If an unauthorized change occurs, the instance is considered compromised and can be terminated, relying on an Auto Scaling Group to launch a fresh, compliant instance from the golden AMI. This ensures auditability and guarantees a consistent, immutable environment.
Why the other options are wrong
- A. Regular snapshots are good for backup and recovery, but detecting unauthorized changes, restoring a snapshot, and integrating this into an automated remediation workflow for immutability is complex and not as efficient as simply replacing an instance from a golden AMI.
- B. Systems Manager State Manager enforces desired state on *running* instances, making them mutable and not fully immutable. It attempts to correct drift rather than replace the entire instance with a known good image.
- D. Configuration management tools apply changes to *running* instances, making them mutable. While auditable, they don't guarantee immutability or automatic replacement with a pristine state upon unauthorized change.
Immutable Infrastructure
Immutable infrastructure is an approach where servers are never modified after they are deployed. If changes are needed, a new server image is built with the changes, and existing servers are replaced by new ones.
- Increases consistency and reliability.
- Simplifies rollbacks and deployments.
- Enhances security by preventing configuration drift on running instances.
Memory trick: Build once, deploy many, never change a single one; if it drifts, replace it, and the problem's gone.