Италианско сърце с гръцка душа или защо кафето на остров Корфу е различно

Post Syndicated from Йовко Ламбрев original https://yovko.net/coffee-culture-at-corfu/

Италианско сърце с гръцка душа или защо кафето на остров Корфу е различно

Попаднах на Корфу съвсем в началото на месец октомври 2024 година. Планирано нарочно, когато активният сезон поприключваше. Заради онова чудно есенно време, в което жегата вече не те притиска, но островът все още е пълен с позакъснели туристи, опитващи се да откраднат още малко от лятото.

Корфу не е типичен гръцки остров с бели къщи и сини прозорци. Тук историята е напластена на слоеве, с които се сблъскваш на всяка крачка. Владян е от римляните и Византия, минал през ръцете на Неапол, Франция, Австрия и Англия. Всеки завоевател е оставил по нещо след себе си там, но нищо не е оформило Корфу така, както управлението на Венецианската република. Тази връзка е и причината в главния град на острова Керкира човек да се чувства по-скоро в Италия. Докато останалата част от Гърция попада под османска власт, венецианците превръщат Корфу в своя стратегическа крепост. Това дълго присъствие е попило в самата тъкан на града – от плътно прилепените една до друга сгради в пастелни цветове, до местния диалект и, разбира се, кухнята.

Прекарах седмица там, но не можах да изям толкова sofrito, колкото ми се искаше. Със същото име има поне няколко разпознаваеми ястия от най-различни кулинарни географии, при това без някакви задължителни прилики помежду им. Но корфуанското софрито от бавно готвено телешко във винено-оцетен сос, в който чесънът и подправките доминират без дори намек за извинение, завинаги зае специално място в сърцето и душата ми. На български нямаме добър превод на т.нар. comfort food, но затова пък изразът храна за душата пасва идеално за светата троица ястия на корфуанската кухня pastitsada, sofrito и bourdeto.

Йонийските вина никак не са лоши, но и местната крафт бира не е за пропускане. Без претенцията да съм опитал всичко, много ми допадна един чуден плътен червен ейл с леко карамелизиран малцов вкус.

Иначе, разбира се, никой който е стигнал до тук не трябва да пропуска местните архитектурни и исторически забележителности като Старата крепост, историята на която започва още от византийски времена. А гледките отгоре към морето и града си заслужават всяко издрапано стъпало.

На десетина километра на юг от града, дворецът Ахилион пък напомня за австрийското влияние. Построен за лятна резиденция на Елизабет Баварска (Сиси) – императрица на Австрия и кралица на Унгария – Ахилион днес е музей и своеобразен паметник на личната ѝ меланхолия, обграден от впечатляващи градини с още по-приказни гледки към Йонийско море.

Едва ли пък изобщо е възможно да се пропуснат площад Спианада и улица Листон. Тук архитектурата рязко сменя стила си на френска – елегантна, подредена, с високи тавани и широки сводове, под които са се приютили кафенета с бели покривки.

И понеже започнах тази публикация с идеята да пиша за кафе културата на остров Корфу, мисля че кулинарно-визуалното въведение е крайно време да приключи някъде тук… преди този текст да стане банален туристически пътепис.

Това, което моментално прави впечатление на всеки кафе-маниак, попаднал в Керкира е, че тук почти отсъстват популярните индустриални марки кафе. Кафенетата най-често сервират напитки от прясно изпечено кафе, което или се пече на място в самото заведение, или се доставя от някой местен пекар от Корфу. Предлагат се (макар и по-рядко) и кафета от популярни пекари от други части на Гърция като нашумелите напоследък The Underdog от Атина или Hue от Солун. Срещат се и Coffee Island – доста популярна кафе-верига в Гърция, но с фокус върху кафета с установен произход.

В Керкира за седмица успях да видя едва две места, където имаше рекламни табели на Kimbo и Illy, и разбира се, много бързо ги подминах.

Един от популярните доставчици на кафе в Корфу е Cofeco. Те едновременно дистрибутират кафе на някои по-малки пекари и предлагат свое. Изглежда, че много кафенета из острова разчитат на тях за своето кафе. Дори на някои места, където първоначално твърдяха, че предлагат собствено печено на място кафе, в последствие признаха, че всъщност кафето им е от Cofeco.

Любопитен факт е, че Cofeco и по-конкретно роденият на Корфу Янис Зоис допринасят за развитието и на българската кафе култура. Той е замесен както в създаването на дистрибутора на кафе (и други продукти) Ibeco, така и в появата и развитието на Memento, които (ако не греша) бяха първите в България, които пробваха да се заявят със собствен бленд кафе.

Янис Зоис
който предлага чудесно кафе на ъгъла на ”Гурко” и ”Дякон Игнатий”
Италианско сърце с гръцка душа или защо кафето на остров Корфу е различно

През 2018 г. в Гърция се появява и U-ROAST – шотландска компания, която се опитва да промени начина, по който малките кафенета пекат кафето си. Вместо да разчитат на доставки с готово изпечени зърна от популярните брандове, те да могат да пекат своето кафе на място, чрез компактна автоматизирана машина. А доставките зелено кафе (от около 8 региона по света) са подсигурени в точните за въпросната машина разфасовки от по 2 килограма. Така кафенетата от програмата предлагат винаги прясно изпечени зърна и имат свободата да експериментират с различни блендове и произход всеки ден.

И така, сега… на входа на доста кафенета в града Керкира и на острова се забелязва голямата черно-бяла емблема на U-ROAST.

Италианско сърце с гръцка душа или защо кафето на остров Корфу е различно
Дори в крайпътните кафенета се забелязва претенциозно оборудване и се предлага прясно печено кафе

Най-впечатляващите кафета, които опитах на Корфу обаче бяха от една местна микропекарна, наречена CafeTierra която пече кафе съвсем близо до парка в подножието на Старата крепост. Част от кафетата им могат да се опитат на място, приготвени по различни начини на филтър и еспресо. Самото местенце е притегателен център и за много чужденци, които са се озовали в Корфу по различни причини.

CafeTierra имат и още една локация – точно на живописното площадче пред църквата Св. Спиридон в центъра на стария град на Керкира.

Не си купих достатъчно пакетчета с техни кафета за България и малко съжалявах като се прибрах.

Но в крайна сметка хубавото прясно печено кафе учи точно на това – да цениш момента тук и сега, защото ароматът му не може винаги да бъде опакован в куфар.

За мен важна част от спомена за Корфу остана плътния вкус на софритото, препечения малц в местната бира и нежната киселинност на еспресото от прясно изпеченото кафе на CafeTierra. Защото островът може и да има венецианска фасада, но сърцето му е гръцко – бавно, гостоприемно и влюбено в добрия живот с вкусна храна и напитки.

Прибирайки се към България, в главата ми се загнезди идеята да си купя своя печка за кафе и… към днешна дата вече трупам втората си година стаж в този занаят. Само като хоби. Без амбиция да го превръщам в бизнес. Но и до днес ми е любопитно как така се е случило на остров Корфу за мнозинството кафенета да е важно да предлагат собствено или поне местно прясно печено кафе. И колко време е отнела тази революция, благодарение на която буквално на всеки ъгъл човек да може да се наслади на много добро кафе.

А ако някога се озовете на площадчето пред църквата Св. Спиридон в Керкира… поръчайте си любимата кафеена напитка от CafeTierra, оставете телефона настрани и се насладете на факта, че сте на място, където историята се пие на малки глътки, а храната наистина е за душата.

И си купете поне два пакета кафе повече, отколкото мислите, че са ви нужни. Ще ми благодарите някой друг път.

Complexity is a choice. SASE migrations shouldn’t take years.

Post Syndicated from Warnessa Weaver original https://blog.cloudflare.com/complexity-is-a-choice-sase-migrations-shouldnt-take-years/

For years, the cybersecurity industry has accepted a grim reality: migrating to a zero trust architecture is a marathon of misery. CIOs have been conditioned to expect multi-year deployment timelines, characterized by turning screws, manual configurations, and the relentless care and feeding of legacy SASE vendors.

But at Cloudflare, we believe that kind of complexity is a choice, not a requirement. Today, we are highlighting how our partners are proving that what used to take years now takes weeks. By leveraging Cloudflare One, our agile SASE platform, partners like TachTech and Adapture are showing that the path to safe AI and Zero Trust adoption is faster, more seamless, and more programmable than ever before.

Slashing timelines from 18 months to 6 weeks

The traditional migration path for legacy SASE products—specifically the deployment of Secure Web Gateway (SWG) and Zero Trust Network Access (ZTNA)—often stretches to 18 months for large organizations. For a CIO, that represents a year and a half of technical debt and persistent security gaps.

By contrast, partners like TachTech and Adapture are proving that this marathon of misery is not a technical necessity. By using a unified connectivity cloud, they have compressed these timelines from 18 months down to just six weeks.

Kyle Jerome Thompson, a solutions architect at TachTech with 30 years of experience, says Cloudflare One fundamentally changes this calculus. By replacing legacy tools with Cloudflare’s robust telemetry and global network, TachTech has slashed deployment times for large organizations down to just four to six weeks.

“Cloudflare has taken the ‘wizardry’ out of zero trust,” says Thompson. “Unlike legacy solutions that require continual care and feeding, Cloudflare Access is lightweight and ‘no-touch’ after deployment. It commoditizes security in the same way you think about plumbing or electricity—it just works, it’s cost-effective, and it lets our customers get back to their real day jobs.”

Why legacy migrations stall

Legacy migrations typically fail when they are treated as a series of hardware replacements rather than a software transformation. Traditional vendors often require complex service chaining where traffic is passed from one inspection cluster to another. This creates a “trombone effect,” adding latency and making troubleshooting nearly impossible.

When you decouple the security policy from the physical network, the migration speed changes. Our partners focus on three pillars to accelerate this transition:

  1. Identity-first on-ramps: Instead of rebuilding network segments, they use existing identity provider (IdP) groups to define access.

  2. Consolidated policy engines: By using a single pass for both SWG and ZTNA, administrators avoid the need to “sync” different products.

  3. Cloud-native connectors: Using lightweight daemons like cloudflared allows for instant connectivity without opening inbound firewall ports.

Scaling at the speed of business

The story is similar at Adapture, where they have a simple mission: improve IT performance and mitigate risk for clients. For one client, what started as a small contractor-focused footprint quickly exploded from 600 seats to a 5,000-seat deployment of Cloudflare Access.

This rapid elasticity proved that Cloudflare’s easy-to-use SASE platform bypasses legacy deployment hurdles—a transition Adapture characterized as “seamless.” 

“Organizations can’t afford an implementation that stretches across months,” says Greg O’Connor, VP of Strategic Alliances at Adapture. “Cloudflare is creating a new standard when it comes to SASE implementation, bringing our clients to the cutting edge of SASE.” 

The power of an extensible edge

In global infrastructure, unique environments and highly specialized workflows are the reality. A hallmark of the Cloudflare One architecture is that it is software-defined and extensible, allowing partners to unblock specific requirements without compromising the organization’s overall security posture.

Cloudflare One is a truly composable and programmable platform, allowing proactive partners to move away from static GUIs and build without bounds.

For example, when Thompson at TachTech encountered a developer team utilizing Arch Linux, they didn’t have to sacrifice visibility or create a security exception. They were able to extend the Cloudflare One Client to support the specific requirements of that environment.

By extracting the binaries from the Ubuntu .deb package and creating a custom PKGBUILD, the team ensured the client could run as a native service on Arch. This ensured the organization maintained consistent device posture checks—verifying disk encryption and firewall status—even on non-standard developer workstations.

Beyond connectivity: the fast path to safe AI

As organizations move toward agentic workflows, O’Connor notes “both threats and security measures are moving faster than ever.” Across the industry, the role of the SWG is evolving. It is no longer just about blocking malicious URLs; it’s about controlling the flow of data into Large Language Models (LLMs). Cloudflare One serves as the fast path to safe AI adoption by integrating security directly into the user’s path to the Internet.

Our goal is to set our partners up for success across a wide variety of customer challenges. Rather than managing disparate security tools, our partners deploy the Cloudflare AI Security Suite to provide a unified defense across the entire AI lifecycle. This native set of controls allows organizations to:

Secure your workforce as they use AI. For employees leveraging public LLMs, Cloudflare One provides a “safe harbor” that balances innovation with strict data governance.

  • Shadow AI visibility: Instantly discover and categorize which unapproved third-party AI tools are being used across your network via the Shadow AI dashboard.

  • AI confidence scores: Move beyond “block-all” policies by grading models on their compliance posture (SOC 2, ISO 42001) and data handling reliability before sanctioning them.

  • DLP AI prompt protection: Secure your intellectual property by using AI-powered Cloudflare Data Loss Prevention (DLP) to block sensitive source code, PII, or financials from being submitted into public training sets.

Secure your AI-powered apps. For the AI-powered applications your team builds and hosts, we provide a dedicated Firewall for AI to protect the integrity of your models.

  • LLM discovery: Automatically discover and label every LLM endpoint exposed to the internet, providing immediate visibility into your AI attack surface.

  • Request validation: Prevent “AI-jacking” by blocking prompt injections and malicious inputs designed to coerce your model into producing wrong or embarrassing outputs.

  • Response scrubbing: Ensure your model doesn’t accidentally “hallucinate” sensitive internal data back to a customer by scrubbing the response for PII or toxic topics before it crosses the wire.

Secure agentic AI. As we move toward autonomous agents, MCP server portals provide a central registry and least-privilege control over how AI interacts with corporate resources like Slack or Confluence. This prevents the autonomous horror stories of data heists and rogue actions by returning visibility and control to IT admins.


The Cloudflare AI Security Suite acts as a secure intermediary between users and AI ecosystems, providing visibility, data protection, and governance for public, private, and agentic AI applications. 

Accelerate your migration

If you are a CIO still tethered to a multi-year migration roadmap, you are operating at a competitive disadvantage. Cloudflare One integrates your network and security into a single fabric that is fast, safe, and infinitely more programmable than the legacy solution in your current stack.

Don’t let the fear of a difficult migration keep you trapped in a legacy mindset. Our partners are proving every day that the move to SASE can be fast, effective, and—dare we say—easy.

Connect with a Cloudflare One expert to start mapping your migration.

Huston: Revisiting time

Post Syndicated from corbet original https://lwn.net/Articles/1061930/

Geoff Huston looks at the network
time protocol
, and efforts to secure it, in detail.

NTP operates in the clear, and it is often the case that the
servers used by a client are not local. This provides an
opportunity for an adversary to disrupt an NTP session, by
masquerading as a NTP server, or altering NTP payloads in an effort
to disrupt a client’s time-of-day clock. Many application-level
protocols are time sensitive, including TLS, HTTPS, DNSSEC and
NFS. Most Cloud applications rely on a coordinated time to
determine the most recent version of a data object. Disrupting time
can cause significant chaos in distributed network environments.

While it can be relatively straightforward to secure a TCP-based
protocol by adding an initial TLS handshake and operating a TLS
shim between TCP and the application traffic, it’s not so
straightforward to use TLS in place of a UDP-based protocol for
NTP. TLS can add significant jitter to the packet exchange. Where
the privacy of the UDP payload is essential, then DTLS might
conceivably be considered, but in the case of NTP the privacy of
the timestamps is not essential, but the veracity and authenticity
of the server is important.

NTS, a secured version of NTP, is designed to address this
requirement relating to the veracity and authenticity of packets
passed from a NTS server to an NTS client. The protocol adds a NTS
Key Establishment protocol (NTS-KE) in additional to a conventional
NTPv4 UDP packet exchange (RFC 8915).

Седмицата (2–7 март)

Post Syndicated from Боряна Телбис original https://www.toest.bg/sedmitsata-2-7-mart/

Седмицата (2–7 март)

Тази седмица ресторантьорите и хотелиерите в Северна Гърция бяха доволни, защото България имаше национален празник. Което означава едно – гуляй на Офриньо (или подобно северногръцко крайбрежно курортче, неизвестно никому с нищо, преди да го налазят българите с панамерите).

В същото време ресторантьорите и хотелиерите в Банско пък никак не са доволни, понеже всички резервации от туристи от Израел и Близкия изток са отменени заради войната. Толкова ли няма българи, които карат ски? Има, разбира се, но предпочитат да ходят в Алпите, защото им излиза по-евтино от Банско. По тази причина от туристическия бранш настояват за дотация от държавата.

За помощ от държавата настояват и блокираните в Близкия и Далечния изток наши сънародници екскурзианти, които не могат да се приберат (да си бяха стояли на Банско!), понеже няма полети. А полети няма, защото не е добра идея да се движат пътнически самолети, докато летят ракети и дронове, не за друго.

А аз настоявам (защото явно всеки има право на това) да се проведе общ тест за функционална грамотност на нацията. Който не го издържи дори с минимален положителен резултат, да бъде ритуално изхвърлян от моста „Чавдар“, от Аспаруховия мост, от Витиня или от някакво друго сравнително високо място. Така както се твърди, че в зората на човечеството са правили храбрите спартанци с болните деца, вследствие на което са се превърнали в нация от хора с плочки и нито един освободен от физическо (справка – филмът „300“). 

Защо ни е такъв общодържавен тест? Защото е крайно време да си признаем, че нещо не е наред с народ, който отива на екскурзия в Дубай или на Малдивите, при положение че от месеци – а в последния особено интензивно – се говори, снима, показва и коментира, че напрежението в Близкия изток се покачва и всеки момент ще прерасне в активен военен конфликт.

Изумителна е тази наша способност да се изненадваме всеки път като малки деца от неща, за които сме били предупредени месеци или даже години по-рано. Както ще стане и с Радевата „Прогресивна България“ – предупреждава се, че на поредния спасител е даден много сериозен начален тласък от създателите на спасители, ама няма кой да чуе.

Поход към прогреса. И още банани
Коалиция без партия, лозунги без програма и лидер, който стои „над“ собствената си конструкция. Походът на Румен Радев към властта започва с познат модел и много въпроси какво всъщност стои зад обещанията. От Емилия Милчева.
Седмицата (2–7 март)

По тази причина ще си вземе едни 32–33% на предстоящите избори. И после какво? Не е ясно. Няма и да стане. Лозунги има, яснота – не. В текста си „Поход към прогреса. И още банани“ Емилия Милчева обобщава тази липса на отговори така:

Онова, което мерят социолозите, за да го позиционират като победител във всички проучвания от началото на януари 2026-та досега, е не потенциалът на партия, а президентско-спасителският рейтинг на Румен Радев. Защото партия няма, програми (още) не са обявени и лицата в кандидатдепутатските листи не са известни. Основният политически капитал произтича от един лидер. Така както през 2001 г. дойде от невидимата корона на Царя, през 2009 г. – от мускулите и черната кожена тужурка на Бат’ Бойко, а сега идва от генералските пагони и ореола на „силната президентска ръка“, обещаваща нов ред и държавност.

И понеже споменах за създателите на спасители, съвсем естествено ми идва тъкмо ей тук да влезе вторият текст на Полковник А. – любимата ми тоестка мистификация. Този път Полковника ни разказва за една малка кафява книжка, която са притежавали всички офицери от Държавна сигурност. Нещо като наръчник, нещо като ръководство, нещо като упътване за употреба на държава и на хора. 

Кафявата книжка
Какво е общото между Карибската криза, пандемията от COVID-19 и една тънка кафява книжка, с която са разполагали офицерите от Държавна сигурност по времето на социализма? Полковник А. разказва.
Седмицата (2–7 март)

Кафявата книжка не се появи случайно. Тя беше дете на страха.

Най-вече на онзи страх, който преживяхме по време на Карибската криза. Най-големият ми кошмар. Днес хората, които не помнят онези времена, когато СССР и САЩ бяха на ръба на ядрена война, нямат ни най-малка представа колко близо бяхме до края на всичко.

В перспектива „краят на всичко“ никак не звучи зле, но преди това ще трябва още да се помъчим със собствените си дефицити.

Един такъв е дефицитът на мечта. Коя е „българската мечта“? Защото си имаме „българския Лувър“, даже „българската Анджелина Джоли“, но мечта си нямаме. Защо днес изглежда толкова трудно да я формулираме пустата му и мечта, проследява Искрен Иванов в новия си текст „НАТО, ЕС и „българската мечта“. Но кое по-напред?“. 

НАТО, ЕС и „българската мечта“. Но кое по-напред?
Представите за „българската мечта“ често се люшкат между исторически митове и заемки от чужди модели. Но как изобщо се ражда тази идея и защо днес изглежда толкова трудно да я формулираме? Нейните корени, трансформации и рискове в съвременния геополитически контекст проследява Искрен Иванов.
Седмицата (2–7 март)

От националните мечти отиваме към позорния стълб. Те крачките от едното към другото са няколко, така че си е съвсем в реда на нещата. „На позорния стълб“ всъщност е заглавието на материала на Светла Енчева, посветен на отварянето за обществото на част от т.нар. регистър на педофилите. Предпазва ли това децата, или просто превръща страха в удобен политически инструмент, пита Светла и даже и отговаря, което не е особено присъщо в контекста на темата „педофилия“, защото по нея обикновено се мълчи единодушно. Като политиците в парламента.

На позорния стълб
Темата „педофилия“ е достатъчно токсична, за да накара политиците да изглеждат единодушни. Така без особени колебания парламентът направи част от „регистъра на педофилите“ публична. Но предпазва ли това децата, или просто превръща страха в удобен политически инструмент? От Светла Енчева.
Седмицата (2–7 март)

Менопаузата – още една тема, по която мълчим, или ако говорим, го правим предимно с клишета. Някои от тях са верни. Някои от тях са най-голямата глупост на света. При всички положения сериозният преход, който променя тялото, паметта, съня и въобще цялостното усещане за собственото аз на всяка жена в този период, не е просто „от възрастта“. Надежда Цекулова разказва за менопаузата в последния текст от поредицата си „Анатомия на пола: Жена“. 

Менопаузата и глупавите клишета, които понякога се оказват верни
Менопаузата още се разказва през топли вълни, лошо настроение и „така е на тази възраст“. Само че зад тях стои сериозен преход, който променя тялото, паметта, съня и въобще цялостното усещане за собственото аз. И който често започва по-рано, отколкото предполагаме. От Надежда Цекулова.
Седмицата (2–7 март)

Цялата рубрика на Надежда е създадена с идеята да промени някои закостенели обществени нагласи относно женското здраве. С промяната на нагласи се занимава и героят на Ина Иванова в поредицата „Тези хора“. Теодор Караколев, създател на платформата „Български архитектурен модернизъм“, която повиши социалната чувствителност към опазването на ценни сгради, е сред най-разпознаваемите изследователи на българската архитектура между двете световни войни. Ето малка част от разговора му с Ина:

В началото много мислех върху това колко голяма част от архитектурната история акцентираше върху сградите. Хората ги нямаше – какви са били, какво са правили, каква е връзката между човека и сградата. А интериорите също са част от ежедневието ни. На връщане към къщи може да избереш четири-пет маршрута. Но влезеш ли, имаш само едно стълбище, понякога го ползваш през целия си живот. Ако си израснал в някоя сграда, ще ти е трудно да я видиш с нови очи. Тя е тривиална част от теб, несъзнавано усещане, което те формира. Затова за мен е важно да покажем на хората, че това, което обитават, е всъщност красиво, достойно.

Теодор Караколев: Човек може да влияе силно, макар и върху малък кръг хора
Понякога една неголяма общност може съществено да промени обществените нагласи. Такъв е случаят с платформата „Български архитектурен модернизъм“, която повиши социалната чувствителност към опазването на ценни сгради. Тази седмица Ина Иванова разговаря с човека зад всичко това – Теодор Караколев.
Седмицата (2–7 март)

В броя имаме още една редовна рубрика – „По буквите“. Зорница Христова ни насочва към историята на всекидневието и мемоарния жанр с „Музеят на моето време“ от Слава Янакиева и „Цени и заплати през Възраждането (1750–1878 г.)“ от Мартин Иванов. 

По буквите: Янакиева, Иванов
В епохата на постистината, когато т.нар. факти губят тежест и ни заслепяват като сажди след опустошителен пожар, Зорница Христова ни насочва към историята на всекидневието и мемоарния жанр. Шанс да възвърнем вярата си, че миналото ни все още успява да намери легитимни разказвачи.
Седмицата (2–7 март)

Малък откъс от обосновката на Зорница защо ни представя точно тези две книги: 

Едната е субективен, личен опит, другата е неутралният глас на статистиката. Страници след страници списъци с цени на основни стоки през Възраждането и само в началото на главите – обзор и анализ. Видимо предназначено за учени, както и подобава на книга на университетско издателство.

Защо тогава ви говоря за нея? Защото е друга стратегия към истината в постистинния свят: този път не през гаранцията на личното свидетелство, а през гаранцията на изчерпателността. 

В „Тоест“ гаранции за изчерпателност не даваме. Както впрочем и всякакви други гаранции, защото сме наясно, че нищо на този свят не ни е гарантирано. Може би само фактът, че ще става по-зле. Последното все едно не съм го казала.

Оставям ви с 42-рия епизод на „Т.Е. от Е.Т.“, в който не са окей нещата, както казва героят на нашето време Благо Джизъса, и ви благодаря, че сме заедно, което сигурно също е казвал Благо Джизъса някога, но съм убедена, че поводът е бил друг. (Ако искате да ни подкрепите, под видеото на Е.Т. сме ви оставили един любезен червен бутон. Натиснете го и вижте какво ще стане.)

Enabling high availability of Amazon EC2 instances on AWS Outposts servers (Part 3)

Post Syndicated from Brianna Rosentrater original https://aws.amazon.com/blogs/compute/enabling-high-availability-of-amazon-ec2-instances-on-aws-outposts-servers-part-3/

This post is part 3 of the three-part series ‘Enabling high availability of Amazon EC2 instances on AWS Outposts servers’. We provide you with code samples and considerations for implementing custom logic to automate Amazon Elastic Compute Cloud (EC2) relaunch on Outposts servers. This post focuses on guidance for using Outposts servers with third party storage for boot and data volumes, whereas part 1 and part 2 focus on automating EC2 relaunch between standalone servers. Outposts servers support integration with Dell PowerStore, HPE Alletra Storage MP B10000 systems, NetApp on-premises enterprise storage arrays, and Pure Storage FlashArray.

Outposts servers provide compute and networking services that are designed for low-latency, local data processing needs for on-premises locations such as retail stores, branch offices, healthcare provider locations, or environments that are space-constrained. Outposts servers use EC2 instance store storage to provide non-durable block-level storage to the instances running stateless workloads. For applications that require persistent storage, you can create a three-tier architecture by connecting your Outposts servers to a third-party storage appliance. In this post, you will learn how to implement custom logic to provide high availability (HA) for your applications running on Outposts servers using two or more servers for N+1 fault tolerance. The code provided is meant to help you get started, and can be modified further for your unique workload needs.

Overview

In the following sections we will show how custom logic can be used to automate EC2 instance relaunch between two or more Outposts servers using boot and data volumes on third party storage. If your EC2 instance fails while using this solution, an Amazon CloudWatch alarm monitoring the EC2 StatusCheckFailed_Instance metric of your source EC2 instance will be triggered, and you will receive an Amazon Simple Notification Service (Amazon SNS) notification. An AWS Lambda function will then relaunch your EC2 instance onto the destination Outposts server that you’ve set up for resiliency. This is done using a launch template created during setup, and the script will connect your relaunched instance to the existing boot and data volumes on your third party storage appliance. This storage device provides shared storage for your Outposts servers. If a single server fails, new instances can connect to existing volumes on the array. This allows for a zero data loss Recovery Point Objective (RPO) and a Recovery Time Objective (RTO) equaling the time it takes to launch your EC2 instance. Take advantage of the features on your storage appliance for configuring data durability and resiliency to hardware failures, and make sure that you are regularly backing up your SAN volumes.

Figure 1 – Solution Architecture for automated EC2 Relaunch

Prerequisites

The following prerequisites are required to complete the walkthrough:

  • Two Outposts servers that can be set up as an active-active or active-passive resilient pair.
  • For workloads with a low threshold for downtime, ensure that your secondary Outpost server that’s used for recovery has a unique service link connection.
  • Outposts servers must be colocated within the same Layer 2 (L2) network.
  • Network latency between the Outposts servers must not exceed 5ms round trip time (RTT).
  • A storage appliance that supports the iSCSI protocol. Credentials to manage the storage appliance initiator/target mappings. See Simplifying the use of third-party block storage with AWS Outposts for more information.
  • If you’re setting this up from an Outposts consumer account, you must configure Amazon CloudWatch cross-account observability between the consumer account and the Outposts owning account to view Outposts metrics in your consumer account.
  • Create launch templates for the EC2 instances that you want to protect, the launch wizard will help you create these.
  • Credentials with permissions for AWS CloudFormation, Amazon EC2, and (optional) AWS Secrets Manager if authentication is required. IAM Permission Examples.md is provided in the repository.
  • A Windows or Linux host that can access the storage appliance and your AWS account (management computer).
  • AWS Outposts iPXE Amazon Machine Image (AMI) from the AWS Marketplace.
  • Python 3.8 or later (recommended) is used to run the init.py script that dynamically creates a CloudFormation stack in the account specified as an input parameter.
  • AWS SDK for Python (Boto3) version 1.26.0 or later recommended.
  • Operating system with iSCSI boot support (Windows Server 2022 and Red Hat Enterprise Linux 9 AMIs are provided).
  • Internet access to AWS service endpoints for the private subnet hosting the recovery Lambda function.
  • Download the repository sample-outposts-third-party-storage-integration.

Walkthrough

The first step is to deploy an EC2 instance configured to boot from a volume on the third-party storage that is prepared with an OS boot image. This step uses the launch wizard portion of the solution.

  1. Download and extract the OutpostServer_Recovery_3Pstorage repository to the management computer that has the AWS SDK for Python (Boto3) and Python installed.
  2. Run launch_wizard from the sample-outposts-third-party-storage-integration directory. You can run interactively or provide arguments for region, subnet, iPXE AMI, storage vendor, storage management ip, and credentials.

Figure 2 – Running launch wizard

  1. When prompted for a feature name, enter sanboot.
  2. For Guest OS type, enter in Linux or Windows.
  3. When prompted “Do you want to continue with this unverified AMI?”, select Y.
  4. The launch wizard will provide a list of instance types available on the Outpost server associated with the subnet you specified. Enter the instance type that you want to use.
  5. The launch wizard will now prompt you for optional EC2 Key Pair, Security Group, and Instance Profile settings for the EC2 instance that you are launching.
  6. Next, the launch wizard prompts you to specify an instance name. Note that specifying an instance name is required to set up automated instance recovery because the instance name is used as part of the recovery process.

Figure 3 – Taking user input for variable values

  1. The launch wizard prompts for root volume size. This is the root volume that the iPXE AMI boots from. The default is a 1GB volume on the Outpost server instance storage.
  2. Next, the launch wizard prompts you to select which third party storage controller you want to use based on the management ip that you specified. In this example, we are using NetApp, so I select a NetApp Storage Virtual Machine (SVM) named outpost_iscsi.
  3. If the connection to the storage array is successful and the protocol is available (iSCSI or NVMe over TCP) you are provided additional storage options for initiator group and logical unit number (LUN).
  4. In this example, we are using NetApp with iSCSI, so I can select an existing initiator group or create a new one.
  5. You can specify an existing initiator qualified name (IQN), or the launch wizard can generate a new one. IMPORTANT: Make sure that IQNs are unique to each instance because duplicates can cause data corruption.
  6. Next the launch wizard prompts which LUN’s you want to connect to this instance. For this example, I am going to use a Windows Server 2022 boot volume that I already created on the NetApp storage array.
  7. You are now asked which storage array target interface you want to use for connecting to these LUNs.
  8. The launch wizard provides the capability to specify guest OS scripts to customize the OS after sanboot. Combining this capability with storage array cloning provides a streamlined process for deploying new instances.
  9. The launch wizard now displays the EC2 user data template that it generated for use with the iPXE AMI and asks if you want to proceed with launching the instance.
  10. After the EC2 instance is launched, select yes to proceed with automated instance recovery setup.

Figure 4 – Running launch template creation script

Generating EC2 launch templates for recovery and failback

In the second step, we are generating EC2 launch templates for the EC2 instance launched in step 1. Launch templates can be generated for the primary and secondary Outpost servers. The launch template for the secondary Outpost server can be used for automated or manual recovery of the EC2 instance. Failback to the primary Outpost server is manual using the primary launch template.

  1. Select the instance that you want automated recovery for and select the subnet that you launched the instance in. This subnet represents the primary Outpost server that the instance is running on.

Figure 5 – Selecting subnets for EC2 instance relaunch

  1. When prompted to create a second launch template for Outpost server recovery, select yes, and then select to use the same instance (for recovery on different Outpost server).
  2. When you get a list of available subnets, select the subnet that’s associated with your secondary Outpost server. This is the server that the EC2 instance will be launched on in the event of the EC2 StatusCheckFailed_Instance metric triggers the CloudWatch alarm.
  3. You will see both launch templates created successfully.

Deploying automated EC2 instance recovery

The third step creates a CloudFormation template for monitoring, notifications, and automated recovery of the EC2 instance deployed in step 1. The CloudFormation template automatically captures the instance and secondary launch template information necessary for automatic recovery.

  1. Select Y to set up automated recovery. This will create a CloudFormation stack.
  2. Provide a name and description for the CloudFormation stack.
  3. Select whether you want automated recovery or notification only. This provides flexibility to choose manual or automatic recovery based on whether you want to verify the primary Outpost server is down before initiating recovery.
  4. In the AWS CloudFormation console, monitor the CloudFormation stack creation process.

Figure 6 – CloudFormation stack creation in progress

  1. After the CloudFormation Stack is complete, you have successfully deployed an EC2 instance using third party storage for boot and data volumes on a primary Outpost server. You also created instance recovery capabilities by using the Amazon Outpost server automated recovery solution for third party storage.
  2. You can verify whether the EC2 StatusCheckFailed_Instance is healthy under the Alarms section in the Amazon CloudWatch console.

Considerations

The logic discussed in this post relies on the secondary destination Outposts server having a connected service link. For more information about how to create a highly available service link connection for your Outpost servers, see the Networking section of AWS Outposts High Availability Design and Architecture Considerations whitepaper.

Clean up

Confirm whether it is safe to terminate the Amazon EC2 instance that you launched with this walkthrough. The operating system and data volumes are on the third party storage, so EC2 instance termination only removes the iPXE AMI from the Outposts server instance storage. To clean up, complete the following steps.

  1. Terminate the Amazon EC2 instance. Then, verify that the Instance state is Terminated to ensure that the instance is not using Outposts server resources.
  2. Delete the Amazon EC2 Launch Templates associated with the Amazon EC2 instance that you terminated. The names of the launch templates that were automatically generated will start with ‘lt-‘, followed by the instance name and the instance id. If you generated a recovery launch template, it will have a ‘-recovery’ suffix in the name.
  3. Delete the AWS CloudFormation Stack. The Stack name will start with ‘autorestart-‘ followed by the Amazon EC2 instance name.
  4. Clean up your initiators, initiator group, and LUNs on the third party storage array.

Conclusion

With the use of custom logic through AWS tools such as CloudFormation, CloudWatch, Amazon SNS, and AWS Lambda, you can architect for HA for stateful workloads on Outposts server. By implementing the custom logic in this post, you can automatically relaunch EC2 instances running on a source Outposts server to a secondary destination Outposts server if an instance fails, and connect to existing volumes on a shared storage appliance for recovery. This also reduces the downtime of your applications in the event of a hardware or service link failure. The code provided in this post can be further expanded upon to meet the unique needs of your workload.

While the use of infrastructure-as-code (IaC) can improve your application’s availability and be used to standardize deployments across multiple Outposts servers, it’s crucial to do regular failure drills to test the custom logic in place. This is to make sure that you understand your application’s expected behavior on relaunch in the event of a failure. To learn more about Outposts servers, visit the Outposts servers User Guide. Reach out to your AWS account team, or fill out this form to learn more about Outposts servers.

The collective thoughts of the interwebz