Closed
Bug 1476717
Opened 7 years ago
Closed 7 years ago
Request to shutdown kai-engert-mozilla AWS account (315031162935)
Categories
(NSS :: Tools, enhancement)
NSS
Tools
Tracking
(Not tracked)
RESOLVED
WONTFIX
People
(Reporter: gene, Unassigned)
References
Details
The kai-engert-mozilla AWS account (315031162935) has one user (:kaie:), who hasn't logged in in a year. The account contains a single host, (nssbbdeb) running since 2014.
Can we either take this host down and close this AWS account or can we migrate this host to an IT managed AWS account and close this AWS account?
| Reporter | ||
Updated•7 years ago
|
Flags: needinfo?(kaie)
Comment 1•7 years ago
|
||
Hello Gene, the host is used. I haven't logged in to AWS, because there was no need to perform any changes. However, the host is still in use, and operates the following NSS test site:
https://bot.nss-crypto.org:8011/waterfall?reload=180
Are you just trying to identify unused services? Or does Mozilla no longer want to pay for this host?
Flags: needinfo?(kaie)
Comment 2•7 years ago
|
||
We didn't use a Mozilla AWS account in the past, because Mozilla IT isn't involved in maintaining this host. I'm the administrator.
| Reporter | ||
Comment 3•7 years ago
|
||
> Are you just trying to identify unused services?
I'm trying to see if there's any way to reduce the management overhead of having this AWS account with this server in it.
> We didn't use a Mozilla AWS account in the past
Is this current AWS account not a Mozilla AWS account?
Would it make sense to move this instance to an IT maintained AWS account and grant you administrative rights over the instance? This would keep the service up and running but allow us to leverage the administrative efforts already being done for things like security. I'm only thinking that might be possible since the host has been running since 2014 so there's probably not a lot of AWS specific tasks that are done to it?
Also, thanks so much for getting back to me so quickly =)
Flags: needinfo?(kaie)
Comment 4•7 years ago
|
||
(In reply to Gene Wood [:gene] from comment #3)
> > Are you just trying to identify unused services?
>
> I'm trying to see if there's any way to reduce the management overhead of
> having this AWS account with this server in it.
I'm sorry that this is causing overhead for you. When we created this in the past, this was the only solution that we were able to figure out: On hand side, don't require IT staff to be responsible, on the other hand, have Mozilla to sponsor it.
> > We didn't use a Mozilla AWS account in the past
>
> Is this current AWS account not a Mozilla AWS account?
It's a Mozilla sponsored account, but not operated by Mozilla IT. It's for operating a kind of community service. It helps with QA for the NSS project.
> Would it make sense to move this instance to an IT maintained AWS account
> and grant you administrative rights over the instance?
I don't know what this means in practice from my perspective of a user and administrator of that host.
> This would keep the
> service up and running but allow us to leverage the administrative efforts
> already being done for things like security.
The system is isolated from everything else at Mozilla. It only reads public information, it obtains a few status results from contributing build machines, and makes that status available on a web page. (Using the "buildbot" software.)
I have been upgrading this machine every once in a while, and I also install new TLS certificates from let's Encrypt on it every 3 months.
I don't see a reason to be worried about it's security. Is there something specific?
> I'm only thinking that might be
> possible since the host has been running since 2014 so there's probably not
> a lot of AWS specific tasks that are done to it?
I don't know what "AWS specific tasks" means. Mozilla IT never interacts with this machine.
Also, I just saw that we have stopped instances on that account which we don't require any longer. I am about to terminate those and the associated storage, this should further reduce the bill related to this account.
Flags: needinfo?(kaie)
| Reporter | ||
Comment 5•7 years ago
|
||
> I'm sorry that this is causing overhead for you
No no, no need to be sorry. Running AWS workloads is part of doing business.
> It's a Mozilla sponsored account, but not operated by Mozilla IT
Got it. Ya most Mozilla AWS accounts are not operated by IT.
> I don't know what this means in practice from my perspective of a user and administrator of that host.
What I'm imagining is :
* spinning up an instance in a different AWS account (e.g. the mozilla-infra account)
* migrating the content from the existing instance to the new one
* granting you root on the box
* optionally if the box is provisioned through config management or something, setting up autoscaling so that if/when it dies a new one comes up
* tearing down the existing AWS account
> I don't see a reason to be worried about it's security. Is there something specific?
Right, I have no concerns about the system security, I was referring to the security of the AWS account. The reason this came up is that CloudTrail logs aren't being processed by our security event information management system, I was going to go ask you to fix it, then noticed that there was one server and thought it would be easier/better to not maintain an entire distinct AWS account just for the one server.
> I don't know what "AWS specific tasks" means. Mozilla IT never interacts with this machine.
No, I meant that it was unlikely that *you* would need to do AWS specific tasks. For example, creating new RDS databases, creating IAM roles, changing security groups, that kind of stuff.
> this should further reduce the bill related to this account.
Cool. Ya I have no concerns about the AWS spend, not my department (and for 1 server, I can't imagine anyone cares about the cost)
So if that clarification above made this sound like a great idea, cool. If not, I'm getting the sense from you that this is me rocking the boat and I'll just take that as a "No, I need this server in it's own account" and I'll close this and open a different ticket on fixing CloudTrail
Flags: needinfo?(kaie)
| Reporter | ||
Comment 6•7 years ago
|
||
Kai, do you think we should move towards moving this ec2 instance to an IT managed account or towards leaving this account as is and fixing CloudTrail?
Comment 7•7 years ago
|
||
Hi Gene, sorry for the delay. I'm not sure what CloudTrail is and how to fix it. I probably don't need to understand. You had asked me a few years ago to make some adjustments in the AWS interface to add some roles for you. I don't mind doing this again, whenever it's necessary.
The existing server has a manual configuration. Following your plan will require me/us to shut down the service and have a few days of downtime (no big deal), and manually re-produce the existing configuration on the new replacement machine, then fix DNS etc. This might be around a half day of work. I will lose some history data, or I will have to spend time on moving data from the old to the new machine.
This is all doable, and if this is a significant simplification for you, I'm willing to do it.
However, if the simplification on your side would be very small, I'd prefer to avoid this work and keep things as they are now, and do the occassional adjustments to AWS configuration whenever you require them.
Flags: needinfo?(kaie)
| Reporter | ||
Comment 8•7 years ago
|
||
Ok, sounds good. I'll open a new ticket requesting the changes within the account.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WONTFIX
You need to log in
before you can comment on or make changes to this bug.
Description
•