[AWS] Elastic BeanstalkのAutoscalingデプロイポリシー

バッチサイズやデプロイ中のヘルスチェックの動作を設定するオプション

[All at once]、[Rolling]、[Rolling with additional batch]、[Immutable]
・一度に全てのインスタンスへデプロイを反映させる時は”All at once”を選択する。
・デプロイ時にサービスに対しダウンタイムを発生させないようにするためには、”Rolling”を選択し1台ずつデプロイを行わせるようにする。
・全てのインスタンスを新しく構築し直す変更不可なデプロイは、”Immutable”を選択する。

例: Elastic Beanstalk config

ApplicationName: xxx
DateUpdated: 2017-08-18 05:22:49+00:00
EnvironmentName: dev
PlatformArn: arn:aws:elasticbeanstalk:ap-northeast-1::platform/Tomcat 7 with Java
  7 running on 64bit Amazon Linux/2.6.1
settings:
  AWSEBAutoScalingScaleDownPolicy.aws:autoscaling:trigger:
    LowerBreachScaleIncrement: '-1'
  AWSEBAutoScalingScaleUpPolicy.aws:autoscaling:trigger:
    UpperBreachScaleIncrement: '1'
  AWSEBCloudwatchAlarmHigh.aws:autoscaling:trigger:
    UpperThreshold: '90'
  AWSEBCloudwatchAlarmLow.aws:autoscaling:trigger:
    BreachDuration: '10'
    EvaluationPeriods: '1'
    LowerThreshold: '10'
    MeasureName: CPUUtilization
    Period: '10'
    Statistic: Average
    Unit: Percent
  AWSEBLoadBalancerSecurityGroup.aws:ec2:vpc:
    VPCId: null
  aws:autoscaling:asg:
    Availability Zones: Any
    Cooldown: '360'
    Custom Availability Zones: ap-northeast-1a
    MaxSize: '2'
    MinSize: '1'
  aws:autoscaling:launchconfiguration:
    BlockDeviceMappings: null
    EC2KeyName: xxx
    IamInstanceProfile: aws-elasticbeanstalk-ec2-role
    ImageId: ami-xxx
    InstanceType: t2.small
    MonitoringInterval: 5 minute
    RootVolumeIOPS: null
    RootVolumeSize: null
    RootVolumeType: null
    SSHSourceRestriction: tcp,xx,xx,xxx.xxx.xxx.xx/xx
    SecurityGroups: xxx
  aws:autoscaling:updatepolicy:rollingupdate:
    MaxBatchSize: '2'
    MinInstancesInService: '1'
    PauseTime: null
    RollingUpdateEnabled: 'true'
    RollingUpdateType: Health
    Timeout: PT30M
  aws:ec2:vpc:
    AssociatePublicIpAddress: null
    ELBScheme: public
    ELBSubnets: null
    Subnets: null
  aws:elasticbeanstalk:application:
    Application Healthcheck URL: /_health_check.html
  aws:elasticbeanstalk:cloudwatch:logs:
    DeleteOnTerminate: 'false'
    RetentionInDays: '7'
    StreamLogs: 'false'
  aws:elasticbeanstalk:container:tomcat:jvmoptions:
    JVM Options: -Duser.timezone="Asia/Tokyo" -Dhttps.protocols=TLSv1.1,TLSv1.2
    XX:MaxPermSize: 128m
    Xms: 512m
    Xmx: 1024m
  aws:elasticbeanstalk:control:
    DefaultSSHPort: '22'
    LaunchTimeout: '0'
    LaunchType: Migration
    RollbackLaunchOnFailure: 'false'
  aws:elasticbeanstalk:environment:
    EnvironmentType: LoadBalanced
    ExternalExtensionsS3Bucket: null
    ExternalExtensionsS3Key: null
    LoadBalancerType: classic
    ServiceRole: null
  aws:elasticbeanstalk:environment:proxy:
    GzipCompression: 'true'
    ProxyServer: apache
  aws:elasticbeanstalk:healthreporting:system:
    ConfigDocument: '{"Version":1,"CloudWatchMetrics":{"Instance":{"CPUIrq":null,"LoadAverage5min":null,"ApplicationRequests5xx":null,"ApplicationRequests4xx":null,"CPUUser":null,"LoadAverage1min":n...
    HealthCheckSuccessThreshold: Ok
    SystemType: basic
  aws:elasticbeanstalk:hostmanager:
    LogPublicationControl: 'false'
  aws:elasticbeanstalk:managedactions:
    ManagedActionsEnabled: 'false'
    PreferredStartTime: null
  aws:elasticbeanstalk:managedactions:platformupdate:
    InstanceRefreshEnabled: 'false'
    UpdateLevel: null
  aws:elasticbeanstalk:monitoring:
    Automatically Terminate Unhealthy Instances: 'true'
  aws:elasticbeanstalk:sns:topics:
    Notification Endpoint: xxx@xxx.com
    Notification Protocol: email
    Notification Topic ARN: arn:aws:sns:ap-northeast-1:xxx:ElasticBeanstalkNotifications-Environment-dev
    Notification Topic Name: null
  aws:elasticbeanstalk:xray:
    XRayEnabled: 'false'
  aws:elb:healthcheck:
    HealthyThreshold: '5'
    Interval: '10'
    Target: HTTP:80/_health_check.html
    Timeout: '5'
    UnhealthyThreshold: '5'
  aws:elb:listener:443:
    InstancePort: '80'
    InstanceProtocol: HTTPS
    ListenerEnabled: 'true'
    ListenerProtocol: HTTPS
    PolicyNames: null
    SSLCertificateId: arn:aws:acm:ap-northeast-1:xxx:certificate/xxx
  aws:elb:listener:80:
    InstancePort: '80'
    InstanceProtocol: HTTP
    ListenerEnabled: 'true'
    ListenerProtocol: HTTP
    PolicyNames: null
    SSLCertificateId: null
  aws:elb:loadbalancer:
    CrossZone: 'false'
    LoadBalancerHTTPPort: '80'
    LoadBalancerHTTPSPort: '443'
    LoadBalancerPortProtocol: HTTP
    LoadBalancerSSLPortProtocol: HTTPS
    SSLCertificateId: arn:aws:acm:ap-northeast-1:xxx:certificate/xxx
    SecurityGroups: sg-xxx
  aws:elb:policies:
    ConnectionDrainingEnabled: 'false'
    ConnectionDrainingTimeout: '20'
    ConnectionSettingIdleTimeout: '60'

トリガーのしきい値例

・MeasureName: CPU利用率
・UpperThreshold: CPU平均利用率 < 90% -> インスタンス増加
・LowerThreshold: CPU平均利用率 > 10% -> インスタンス減少
・Unit: 単位=%
・BreachDuration: 上記が10分継続した場合、Autoscalingが起動
・IgnoreHealthCheck: デプロイ時にHealthCheckは無視する

Rollingを指定したデプロイ時ダウンタイムを発生させない設定例

1. しきい値等変更作業

Autoscalingの設定、インスタンス台数の設定を変更する。
ダウンタイムを避けるためインスタンスを1台追加し、計2台で一時的に稼働させる。

・実行時間: 2分30秒
・ダウンタイム: 無

AWSEBCloudwatchAlarmHigh.aws:autoscaling:trigger:
  UpperThreshold: '90'
AWSEBCloudwatchAlarmLow.aws:autoscaling:trigger:
  BreachDuration: '10'
  LowerThreshold: '10'
  MeasureName: CPUUtilization
  Statistic: Average
  Unit: Percent
aws:autoscaling:asg:
  MaxSize: '4'
  MinSize: '2'
aws:autoscaling:updatepolicy:rollingupdate:
  MaxBatchSize: '2'
  MinInstancesInService: '2'
aws:elasticbeanstalk:command:
  BatchSizeType: Percentage
  IgnoreHealthCheck: 'true'

2. 新しいアプリケーションのデプロイ

2台のインスタンスへ対して、1つずつ順にデプロイされる。
その間、サイトが遅くなる可能性はあるものの、サービスのダウンタイムは発生しない。

・実行時間: 約6分30秒
・ダウンタイム: 無

3. インスタンス数を戻す

デプロイの為に追加したインスタンスの台数を減らす。
実行時間: 約2分

aws:autoscaling:asg:
  MaxSize: '4'
  MinSize: '1'
aws:autoscaling:updatepolicy:rollingupdate:
  MaxBatchSize: '2'
  MinInstancesInService: '2'

参考site

デプロイポリシーと設定
Elastic Beanstalk 環境設定のローリング更新
すべての環境に対する汎用オプション

[AWS][Beanstalk][Shell Script] デプロイスクリプト

AWS Elastic Beanstalk へのデプロイ

殴り書きです。

  • Gitからリポジトリを取得
  • 環境毎に設定を上書き
  • コンパイル
  • EB CLIでデプロイ

シェルスクリプト

sedで環境設定ファイルを書き換えている部分は引数渡しへ変更下さい。

#!/bin/bash
## Example of Beanstalk deploy
##
set -Ceu
PATH=/root/.local/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/opt/aws/bin:/root/bin

# Path
doc_path=/var/www/vhosts/
deploy_path=/var/www/vhosts/xxx
branch=develop

# Beanstalk Environment
prod_env=prod-xxx
stg_env=stg-xxx
dev_env=dev-xxx

# Beanstalk application
prod_app=xxx
stg_app=xxx
dev_app=xxx

# Beanstalk Keyname
prod_key=xxx
stg_key=xxx
dev_key=xxx

# AWS profile
prod_profile=prod
stg_profile=stg
dev_profile=dev

# Domain
prod_domain=xxx.com
stg_domain=xxx.com
dev_domain=xxx.com

# Internal ELB
prod_elb=internal-prod-xxx.com
sgc_elb=internal-stg-xxx.com
dev_elb=internal-dev-xxx.com

# Confirm Git CLI
if ! type 'git' > /dev/null 2>&1; then
  echo 'Git CLI not found.'
  exit 1
fi

cd ${doc_path}

# Confirm Deploy PATH
if [ -e "${deploy_path}" ]; then
  echo 'Remove existing Working copy.'
  rm -rf {woking copy}
fi

git clone https://github.com/xxx.git
cd ${deploy_path}

git checkout ${branch}

cd ${deploy_path}

git status

echo '~~~~~~~~~~~~ Overwrite conf file ~~~~~~~~~~~~'

# 00_application.conf
sed -i -e "s@${prod_elb}@${dev_elb}@g" ./src/main/ebextensions/httpd/conf.d/elasticbeanstalk/00_application.conf

# config.yml
sed -i -e "s@${prod_env}@${dev_env}@g" ./.elasticbeanstalk/config.yml
sed -i -e "s@${stg_env}@${dev_env}@g" ./.elasticbeanstalk/config.yml
sed -i -e "s@application_name: ${prod_app}@application_name: ${dev_app}@g" ./.elasticbeanstalk/config.yml
sed -i -e "s@default_ec2_keyname: ${prod_key}@default_ec2_keyname: ${dev_key}@g" ./.elasticbeanstalk/config.yml
sed -i -e "s@profile: ${prod_profile}@profile: ${dev_profile}@g" ./.elasticbeanstalk/config.yml

# httpd.conf ServerName
sed -i -e "s@${prod_domain}@${dev_domain}@g" ./src/main/ebextensions/httpd/conf/httpd.conf

# 00-basic-setting.config HOSTNAME
sed -i -e "s@${prod_domain}@${dev_domain}@g" ./src/main/ebextensions/00-basic-setting.config

if grep "${prod_elb}" "./src/main/ebextensions/httpd/conf.d/elasticbeanstalk/00_application.conf" >/dev/null; then
  echo 'failed to overwrite in 00_application.conf.'
  exit 1
elif grep "${prod_profile}" "./.elasticbeanstalk/config.yml" >/dev/null; then
  echo 'failed to overwrite in config.yml.'
  exit 1
elif grep "${prod_domain}" "./src/main/ebextensions/httpd/conf/httpd.conf" >/dev/null; then
  echo 'failed to overwrite in httpd.conf.'
  exit 1
else
  echo 'overwrite ok'
fi

echo '~~~~~~~~~~~~ Compile ~~~~~~~~~~~~'
mvn clean package

# Confirm EB CLI
if ! type 'eb' > /dev/null 2>&1; then
  echo 'EB CLI not found...'
  exit 1
fi

echo '~~~~~~~~~~~~ eb status ~~~~~~~~~~~~'
eb status ${dev_env}

echo '~~~~~~~~~~~~ Start deploy ~~~~~~~~~~~~'
eb deploy ${dev_env} --process --timeout 10

sleep 60s

echo '~~~~~~~~~~~~ eb logs ~~~~~~~~~~~~'
eb logs ${dev_env}

echo '~~~~~~~~~~~~ Deployment success ! ~~~~~~~~~~~~'

exit 0

関連記事