Use this CDK stack to create a redis cluster and allow bastion host to access it.
Use this CDK stack to create a redis cluster and allow bastion host to access it.
Amazon ElastiCache allows you to seamlessly set up, run, and scale popular open-Source compatible in-memory data stores in the cloud.
You will need the following before utilize this CDK stack:
Define project-name, env and profile context variables in cdk.json
{
"context": {
"project-name": "container",
"env": "dev",
"profile": "devopsrepo"
}
}
Setup standard VPC with public, private, and isolated subnets.
const vpc = new ec2.Vpc(this, 'Vpc', {
maxAzs: 3,
natGateways: 1,
cidr: '10.0.0.0/16',
subnetConfiguration: [
{
cidrMask: 24,
name: 'ingress',
subnetType: ec2.SubnetType.PUBLIC,
},
{
cidrMask: 24,
name: 'application',
subnetType: ec2.SubnetType.PRIVATE,
},
{
cidrMask: 28,
name: 'rds',
subnetType: ec2.SubnetType.ISOLATED,
}
]
});
Create flowlog and log the vpc traffic into cloudwatch
vpc.addFlowLog('FlowLog');
Get vpc create from vpc stack
const { vpc } = props;
Create security group for bastion host
const bastionSecurityGroup = new ec2.SecurityGroup(this, 'BastionSecurityGroup', {
vpc: vpc,
allowAllOutbound: true,
description: 'Security group for bastion host',
securityGroupName: 'BastionSecurityGroup'
});
Allow ssh access to bastion host
bastionSecurityGroup.addIngressRule(ec2.Peer.anyIpv4(), ec2.Port.tcp(22), 'SSH access');
Create security group for redis
const redisSecurityGroup = new ec2.SecurityGroup(this, 'RedisSecurityGroup', {
vpc: vpc,
allowAllOutbound: true,
description: 'Security group for Redis Cluster',
securityGroupName: 'RedisSecurityGroup'
});
Allow access from bastion host
redisSecurityGroup.addIngressRule(bastionSecurityGroup, ec2.Port.tcp(6379), 'Access from bastion host');
Get the vpc and bastionSecurityGroup from vpc and security stacks.
const { vpc, bastionSecurityGroup } = props;
Get profile from context variables
const profile = this.node.tryGetContext('profile');
Create bastion host instance in public subnet
const bastionHostLinux = new ec2.BastionHostLinux(this, 'BastionHostLinux', {
vpc: vpc,
securityGroup: bastionSecurityGroup,
subnetSelection: {
subnetType: ec2.SubnetType.PUBLIC
}
});
Display commands for connect bastion host using ec2 instance connect
const createSshKeyCommand = 'ssh-keygen -t rsa -f my_rsa_key';
const pushSshKeyCommand = `aws ec2-instance-connect send-ssh-public-key --region ${cdk.Aws.REGION} --instance-id ${bastionHostLinux.instanceId} --availability-zone ${bastionHostLinux.instanceAvailabilityZone} --instance-os-user ec2-user --ssh-public-key file://my_rsa_key.pub ${profile ? `--profile ${profile}` : ''}`;
const sshCommand = `ssh -o "IdentitiesOnly=yes" -i my_rsa_key ec2-user@${bastionHostLinux.instancePublicDnsName}`;
new cdk.CfnOutput(this, 'CreateSshKeyCommand', { value: createSshKeyCommand });
new cdk.CfnOutput(this, 'PushSshKeyCommand', { value: pushSshKeyCommand });
new cdk.CfnOutput(this, 'SshCommand', { value: sshCommand});
Get the vpc and redisSecurityGroup from vpc and security stack
const { vpc, redisSecurityGroup } = props;
Get projectName and env from context variables
const projectName = this.node.tryGetContext('project-name');
const env = this.node.tryGetContext('env');
Get all private subnet ids
const privateSubnets = vpc.privateSubnets.map((subnet) => {
return subnet.subnetId
});
Create redis subnet group from private subnet ids
const redisSubnetGroup = new redis.CfnSubnetGroup(this, 'RedisSubnetGroup', {
subnetIds: privateSubnets,
description: "Subnet group for redis"
});
Create Redis Cluster
const redisCluster = new redis.CfnCacheCluster(this, 'RedisCluster', {
autoMinorVersionUpgrade: true,
cacheNodeType: 'cache.t2.small',
engine: 'redis',
numCacheNodes: 1,
cacheSubnetGroupName: redisSubnetGroup.ref,
clusterName: `${projectName}${env}`,
vpcSecurityGroupIds: [redisSecurityGroup.securityGroupId]
});
Define this redis cluster is depends on redis subnet group created first
redisCluster.addDependsOn(redisSubnetGroup);
Deploy all the stacks to your aws account.
cdk deploy '*'
or
cdk deploy '*' --profile your_profile_name
npm run build
compile typescript to jsnpm run watch
watch for changes and compilenpm run test
perform the jest unit testscdk list (ls)
Lists the stacks in the appcdk synthesize (synth)
Synthesizes and prints the CloudFormation template for the specified stack(s)cdk bootstrap
Deploys the CDK Toolkit stack, required to deploy stacks containing assetscdk deploy
Deploys the specified stack(s)cdk deploy '*'
Deploys all stacks at oncecdk destroy
Destroys the specified stack(s)cdk destroy '*'
Destroys all stacks at oncecdk diff
Compares the specified stack with the deployed stack or a local CloudFormation templatecdk metadata
Displays metadata about the specified stackcdk init
Creates a new CDK project in the current directory from a specified templatecdk context
Manages cached context valuescdk docs (doc)
Opens the CDK API reference in your browsercdk doctor
Checks your CDK project for potential problemsAs this cdk stack will create aws elasticache service, please refer the following link for pricing