AWS mirroring - Terraform
The topic explains deploying Traceable’s platform agent using Terraform in AWS. The template also sets up traffic mirroring. Traffic mirroring can be used to capture a copy of the original data from the source network interface without disrupting your existing infrastructure and without adding any latency to your requests. For example, this mirrored data can be used for telemetry, attack detection, and so on.
Before you begin
Make a note of the following before you proceed with the deployment:
Make sure that you have Terraform 1.2 and later.
Keep Traceable's access token handy. It will be used when you configure the variables in the
*.tfvarsfile. You can copy the access token by logging into your Traceable platform and then navigate to Settings (
) → Account → Agent Token.Make sure that Terraform is already installed. For more information on installing Terraform, see Download Terraform.
Configure AWS in the shell you are using. Enter the following command to set up your AWS CLI installation:
aws configureThe following example shows sample values. Replace them with your values to configure the credentials correctly.
$ aws configure AWS Access Key ID [None]: AKIAIOSFODNN7EXAMPLE AWS Secret Access Key [None]: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY Default region name [None]: us-west-2 Default output format [None]: jsonFor more information on the
credentialsfile, see Configuration and credential file settings.If you have configured named AWS profiles, export the environment variable
AWS_PROFILE=myprofilewhere the profile namedmyprofilehas the credentials which you wish to use in deploying the Traceable mirroring resources.Finally, run the following command and verify that the AWS region is set to the region where you wish to install Traceable:
aws configure get regionFor more information on configuration, see AWS documentation.
Download
Enter the following command to download the AWS traffic mirroring tarball:
Untar the tarball. Enter the following command:
Installation
To install, create a file terraform.tfvars with terraform variables as shown below.
Configure terraform variables
The following tables describe the various terraform variables.
Name
Type
Default value
Description
vpc_id
string
""
VPC where you wish to deploy Traceable.
subnet_ids
string
""
Provide a comma-separated list of subnets where Traceable will be deployed. Provide one subnet for each availability zone across which the mirror sources exist.
assign_public_ip
bool
false
Assign public IP to Traceable instance/ECS service.
traceable_refresh_token
string
""
Traceable Platform token.
traceable_environment
string
"traffic-mirroring"
Environment under which mirrored traffic will be seen on Traceable platform.
traceable_service_name
string
"traffic-mirroring-service"
Service name for the mirrored traffic.
traceable_api_endpoint
string
"api.traceable.ai"
Traceable API Endpoint.
deploy_traceable_agent_in_ecs
bool
false
Deploy Traceable in an ECS cluster.
mirror_source
object
—
See the next section.
instance_group_configuration
object
—
See the next section.
autoscaling_configuration
object
—
See the autoscaling configuration section.
tags
map(string)
{}
Additional tags to be applied on all the Traceable resources.
install_packages
bool
true
Install Traceable and mirroring packages on the Traceable instances. This variable will be ignored if custom_ami_id is not provided.
custom_ami_id
string
""
Custom AMI ID to be used for Traceable instances.
mirroring_session_lambda
object
—
See the mirroring session lambda section.
You can deploy the Traceable agent either in an instance-group or in an ECS cluster. If deploy_traceable_agent_in_ecs=true then Traceable is deployed in an ECS cluster. In such a case, instance_group_configuration is ignored. If deploy_traceable_agent_in_ecs=false then Traceable is deployed in an Instance group. Refer below for the attributes which should be passed as part of the
instance_group_configuration.
mirror_source
The mirror_source object has the following values:
Name
Type
Default value
Description
type
string
"MANUAL"
Type of mirror source. Possible values are LOAD_BALANCER, LOAD_BALANCER_TAGS, TARGET_GROUP, ECS_CLUSTER, MANUAL, and FARGATE.
value
string
""
Depending on the type, the possible values could be:
LOAD_BALANCER- Provide a comma-separated list of load balancers.LOAD_BALANCER_TAGS- Provide a comma-separated list of load balancer tags. See the LOAD_BALANCER_TAGS section for more information.TARGET_GROUP- Provide a comma-separated list of target groups.ECS_CLUSTER- Provide the name of an ECS cluster, for example,value = "MY_CLUSTER"MANUALandFARGATE- This must be empty, that is,value = ""
vpc_id
string
""
comma-separated list of VPC IDs where mirrored sources exist, for example, vpc_id = "MY_VPC"
LOAD_BALANCER_TAGS
You can use mirror_source type if you wish to choose load balancers based on tags. All load balancers that match at least one of the tags provided in the mirror_source value are mirrored. The Tag can be either in the form of key=value or key.
Example: For the following input:
All load balancers in the VPC MY_VPC_ID satisfying at least one of the following conditions will be mirrored:
The load balancer has a tag with key
appand valuedevelopment.The load balancer has a tag with key
traceable-mirrorand valuetrue.The load balancer has a tag with a key
traceable-appand any value.
instance_group_configuration
The instance_group_configuration has the following values:
Name
Type
Default value
Description
key_name
string
""
SSH key name that should be attached to Traceable EC2 instances.
instance_type
string
"m4.xlarge"
Instance type name of Traceable instances. Make sure that the VM instance where Traceable Platform agent will be installed has at least 4 vCPUs and 8 GB RAM.
traceable_refresh_token_secret_arn
string
""
ARN of secret where Traceable Platform token is stored. If you provide this, then traceable_refresh_token will be ignored.
autoscaling_configuration
The autoscaling_configuration has the following values:
max_size
number
20
Maximum number of EC2 instances in the Traceable autoscaling group or ECS tasks in the Traceable ECS cluster.
target_value
number
80
Target threshold value in percentage for average CPU and memory utilization in the autoscaling policy of Traceable Instance group or ECS service.
mirroring_session_lambda
The mirroring_session_lambda has the following values:
timeout
number
600 seconds
Mirroring session lambda timeout in seconds.
interval
number
15 minutes
Mirroring session lambda interval in minutes. Lambda runs at the configured interval to update mirror sessions and filter rules for any changes in the mirror sources.
mirror_unhealthy_targets
bool
false
If you set this value to true, Traceable creates traffic mirroring sessions and filter rules for targets even if their health status is not healthy.
route53_configuration
This variable is used only when you set mirror_source.type = FARGATE. The route53_configuration object has the following values:
name
string
private.traceable.ai
Defines the zone name for Traceable route53 private zone.
id
string
""
Zone ID for existing route53 private zone. If this configuration is empty, a new private hosted zone is created for the Traceable NLB. Otherwise, Traceable uses the zone represented by this zone ID for the Traceable NLB.
subdomain
string
mirroring-fargate
Subdomain for route53 alias record created for the Traceable NLB.
associate_traceable_vpc
bool
true
Defines whether Traceable VPC should be associated with the Traceable route53 zone.
Apply terraform
Run the following commands to apply the terraform changes:
Mirroring in peered VPC
what is peered VPC?
A peered VPC (Virtual Private Cloud) is a networking configuration in which two or more VPCs are connected to each other through a VPC peering connection. This allows resources in one VPC to communicate with resources in the other VPC as if they were on the same network. When VPCs are peered, their CIDR blocks become part of the same IP address range, which allows resources to communicate with each other using private IP addresses. This eliminates the need to use public IP addresses or a VPN connection to connect the VPCs.
AWS provides the capability to create VPC peering connections between VPCs in the same region, or across different regions, or across different accounts, using the VPC peering connection feature in the AWS Management Console.
Traceable traffic-mirroring in peered VPC
If you want to deploy Traceable in a VPC which is different from the VPC where your mirror source(s) reside, it can be done as follows:
Under the mirror_source configuration, provide the source VPC where the mirror sources reside.
Under the
vpc_idconfiguration, provide the destination VPC where you wish to deploy Traceable.Make sure that an active peering connection exists between the source and destination VPC provided above. For more information, see VPC Peering.
In the main route table of source VPC, add a new route with target as the peering connection and destination as the VPC CIDR of the destination VPC. This allows the mirrored traffic to go from the source VPC to destination VPC.
Example
Let us assume that the mirror sources are in
vpc_A while you wish to deploy Traceable in
vpc_B. If the subnets used to deploy Traceable are
subnet_1
,
subnet_2, and so on, with CIDRs as
cidr_1,
cidr_2, and so on, then follow these two steps:
Establish a peering connection pcx_AB between vpc_A and vpc_B.
Add new routes in the main route table of vpc_A with target as pcx_AB and destination as cidr_1, cidr_2 , and so on. By doing this, we are trying to make sure that all the subnets where Traceable is deployed receive mirrored traffic from the source VPC vpc_A.
Once done, you can use the following configuration to deploy Traceable. Rest of the configuration options can be used as described in Configure terraform variables:
Note that if the mirror sources are across more than one VPC (say
vpc_A2
, vpc_A3, and so on) then you need to repeat the above two steps for vpc_A2
, vpc_A3, and so on, and finally add these VPCs to the
vpc_id
variable in
mirror_source in the above configuration.
Verification
Log into Traceable Platform to and navigate to API Catalog > Services to view the service name that you configured earlier.
Uninstall
Run the following command from the same directory to destroy all the resources created in the installation step:
Last updated
Was this helpful?