Amazon Elastic Block Store (EBS) Volumes are highly available and reliable storage volumes that can be attached to any running EC2 instance that is in the same Availability Zone. When we attach the EBS volumes to EC2 instances they act as physical drive disks that we can format and use to install our operating system, our files and so on.
EBS Snapshot is one of the most useful tools offered by Amazon to make a copy of your volume. There are several reasons to do snapshots:
- Point-in-time recovery of your volumes when you delete the data or volumes accidentally
- Create an identical Volume in another Zone or Region
- Create a Disaster Recovery environment in another Region
- Remove the unused volumes for cost saving, but data needs to preserved for future use
- Using the same kind of volumes for Dev and Staging environments
- When AWS Zones or Regions are down
Amazon is providing various interfaces to create a snapshot of a Volume like Amazon AWS console, Command-line, APIs and SDKs. From AWS Console, you can create snapshots for any volume from either Volumes tab or from the Snapshots tab.
Unfortunately, AWS doesn’t have the scheduling feature with already set times like daily, hourly, weekly and etc.
You need to automate snapshots of volumes by yourself, using either command-line or APIs or SDKs. Here I am showing a script where you can automate the snapshot operations of volumes on regular intervals using AWS command-line tools.
A script to automate your Snapshots with EBS (Elastic Block Storage)
This script needs mainly 3 parameters:
- Volumes-list: Get all the volumes list in a file called “volumes-list” line by line as VolumeID: VolumeName
- Retention Period: How many latest snapshots you want to keep for a volume. Beyond that, you can purge the volumes.
- AWS Keys/ IAM Role: Use IAM role of EC2 Instance or AWS Keys. It would be good, if you use the IAM role for your EC2 instances to avoid the specifying keys, if not use the AWS Keys with EBS privileges and update them in the script.
Let’s see how it works:
- Creation of the snapshot for each Volume reading it from the volume-list file.
aws ec2 create-snapshot –volume-id $VOL_ID –description “$DESCRIPTION” –region $REGION &>> $SNAP_CREATION
- Describe the list of completed snapshots for each Volume by excluding AMI snapshots.
aws ec2 describe-snapshots –query Snapshots[*].[SnapshotId,VolumeId,Description,StartTime] –output text –filters “Name=status,Values=completed” “Name=volume-id,Values=$VOL_ID” | grep -v “CreateImage” > $SNAPSHOT_INFO
- Delete the snapshots of a Volume which exceeds the Retention period time.
When you take the snapshots of your volumes, it would be a good idea to ignore the Auto Scaling instances volumes, because those instances are stateless. Remember that auto-scaling machines will have an AMI to store their required config and data.
The sample script is to give you an idea of we can do the snapshots management, but you can always extend it to meet your needs.
AWS Security: Bastion Host, NAT instances and VPC Peering
Effective security requires close control over your data and resources. Bastion hosts, NAT instances, and VPC peering can help you secure your AWS infrastructure. Welcome to part four of my AWS Security overview. In part three, we looked at network security at the subnet level. This ti...
Top 13 Amazon Virtual Private Cloud (VPC) Best Practices
Amazon Virtual Private Cloud (VPC) brings a host of advantages to the table, including static private IP addresses, Elastic Network Interfaces, secure bastion host setup, DHCP options, Advanced Network Access Control, predictable internal IP ranges, VPN connectivity, movement of interna...
Big Changes to the AWS Certification Exams
With AWS re:Invent 2019 just around the corner, we can expect some early announcements to trickle through with upcoming features and services. However, AWS has just announced some big changes to their certification exams. So what’s changing and what’s new? There is a brand NEW ...
New on Cloud Academy: ITIL® 4, Microsoft 365 Tenant, Jenkins, TOGAF® 9.1, and more
At Cloud Academy, we're always striving to make improvements to our training platform. Based on your feedback, we released some new features to help make it easier for you to continue studying. These new features allow you to: Remove content from “Continue Studying” section Disc...
AWS Security Groups: Instance Level Security
Instance security requires that you fully understand AWS security groups, along with patching responsibility, key pairs, and various tenancy options. As a precursor to this post, you should have a thorough understanding of the AWS Shared Responsibility Model before moving onto discussi...
Cloud Migration Risks & Benefits
If you’re like most businesses, you already have at least one workload running in the cloud. However, that doesn’t mean that cloud migration is right for everyone. While cloud environments are generally scalable, reliable, and highly available, those won’t be the only considerations dri...
Real-Time Application Monitoring with Amazon Kinesis
Amazon Kinesis is a real-time data streaming service that makes it easy to collect, process, and analyze data so you can get quick insights and react as fast as possible to new information. With Amazon Kinesis you can ingest real-time data such as application logs, website clickstre...
Google Cloud Functions vs. AWS Lambda: The Fight for Serverless Cloud Domination
Serverless computing: What is it and why is it important? A quick background The general concept of serverless computing was introduced to the market by Amazon Web Services (AWS) around 2014 with the release of AWS Lambda. As we know, cloud computing has made it possible for users to ...
Google Vision vs. Amazon Rekognition: A Vendor-Neutral Comparison
Google Cloud Vision and Amazon Rekognition offer a broad spectrum of solutions, some of which are comparable in terms of functional details, quality, performance, and costs. This post is a fact-based comparative analysis on Google Vision vs. Amazon Rekognition and will focus on the tech...
New on Cloud Academy: CISSP, AWS, Azure, & DevOps Labs, Python for Beginners, and more…
As Hurricane Dorian intensifies, it looks like Floridians across the entire state might have to hunker down for another big one. If you've gone through a hurricane, you know that preparing for one is no joke. You'll need a survival kit with plenty of water, flashlights, batteries, and n...
Amazon Route 53: Why You Should Consider DNS Migration
What Amazon Route 53 brings to the DNS table Amazon Route 53 is a highly available and scalable Domain Name System (DNS) service offered by AWS. It is named by the TCP or UDP port 53, which is where DNS server requests are addressed. Like any DNS service, Route 53 handles domain regist...
How to Unlock Complimentary Access to Cloud Academy
Are you looking to get trained or certified on AWS, Azure, Google Cloud Platform, DevOps, Cloud Security, Python, Java, or another technical skill? Then you'll want to mark your calendars for August 23, 2019. Starting Friday at 12:00 a.m. PDT (3:00 a.m. EDT), Cloud Academy is offering c...