I blanked when an interviewer asked me "Can you describe a three-tier architecture?"
So I decided to solve that problem. After looking at several infrastructures, I found one to copy using Terraform -- but the more I looked, the more questions I had.
First up: Why is there an empty public subnet?
I first asked people on this post. Then, I asked Chat GPT (CGPT) and Google Gemini without sharing the code.
Using publicly available and free to use SVGs for AWS diagramming, diagram this infrastructure.
My mindset on AI is this:
I do not want to see AI generated images that were trained on unsuspecting and non-consenting people's artwork.
I personally am fine with it in a technical department (Though I think making it consumer - and even business - grade was a mistake). A public set of images for free use? Okay.
Here is the first iteration of the diagram ChatGPT's output;
CGPT didn't initially understand that the IGW was attached to the VPC. The explanation included suggestions for other resources, including an application load balancer and a second private subnet - Neither of which was in my initial diagram.
Here is the first iteration of the diagram Gemini's output; It inserted a route table in Pub2;
They both did not include a NAT gateway or Application Load Balancer at this point, and confirmed this was a Bastion setup - a setup where an EC2 is the primary access point for someone to access private resources.
The Priv 1 instance in both diagrams is an instance that connects to the database.
There should be a simple webpage in Public Subnet 1 for the Presentation layer. The original repo uses a webserver. Speaking of subnets --
The AI said I could remove the empty public subnet -- but best (production) practice is to leave it intact. It appears to me to cost no money besides ingress/egress traffic to Pub2 and Priv machines, and could be used in the future.
I asked people if an Application Load Balancer would be fitting to install for something, and was recommended not to.
Second Question: Did I need an Elastic IP?
The Elastic IP is also unnecessary for a small test, so I'll be using an ephemeral IP that changes each time the instance is re-upped.
Let's see what happens;
Terraform Apply 1:
3 Errors that boiled down to -- There's no default VPC or default subnet in the regions of choice. So Terraform couldn't place the resources anywhere!
I recreated the default VPC and subnets for Ohio using AWS Command Line Interface (CLI).
Posting weekly videos has been very helpful; Cory Kelly reminded me about CloudFormation -- which I have used -- is also an option. It deletes cleanly when an entire stack isn't operable!
I needed to insall the AWS Toolkid to VS Code.
This post by AWS Fundamentals showed up in my inbox; They also mention how a NAT Gateway isn't always necessary.
So overall, that's how it works, simplified, and with less cost.


Comments
Post a Comment