{"id":2371,"date":"2018-03-26T16:57:50","date_gmt":"2018-03-26T20:57:50","guid":{"rendered":"http:\/\/blog.domb.net\/?p=2371"},"modified":"2018-03-27T11:01:37","modified_gmt":"2018-03-27T15:01:37","slug":"aws-multi-az-ansible-tower-cluster-backed-by-rds-and-fronted-by-alb","status":"publish","type":"post","link":"https:\/\/blog.domb.net\/?p=2371","title":{"rendered":"AWS Multi &#8211; AZ Ansible Tower Cluster backed by RDS and fronted by ALB"},"content":{"rendered":"<p>Ever wondered how you could run ansible tower in clustered mode across\u00a0multiple AZ in AWS?\u00a0 This post will describe how you can build the following architecture:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2393\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/toweraws4.jpg\" alt=\"\" width=\"962\" height=\"603\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/toweraws4.jpg 962w, https:\/\/blog.domb.net\/wp-content\/uploads\/toweraws4-300x188.jpg 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/toweraws4-768x481.jpg 768w\" sizes=\"auto, (max-width: 962px) 100vw, 962px\" \/><\/p>\n<p>First, build 3 ec2 instances each in a different AZ&#8217;s. You should be more than ok with t2.large instance sizes. The subnets in the VPC can be private. If you have a private VPC make sure you have a nat gateway so that the instance can talk to the internet.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2382\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/ec2inst.png\" alt=\"\" width=\"684\" height=\"96\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/ec2inst.png 684w, https:\/\/blog.domb.net\/wp-content\/uploads\/ec2inst-300x42.png 300w\" sizes=\"auto, (max-width: 684px) 100vw, 684px\" \/><\/p>\n<p>Then make sure you are adding the correct security group (sg) settings to the instances<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2383\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/secgroup.png\" alt=\"\" width=\"1147\" height=\"395\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/secgroup.png 1147w, https:\/\/blog.domb.net\/wp-content\/uploads\/secgroup-300x103.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/secgroup-768x264.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/secgroup-1024x353.png 1024w\" sizes=\"auto, (max-width: 1147px) 100vw, 1147px\" \/><\/p>\n<p>Once you have the security groups attached to the ec2 instances you can go ahead to the RDS tab and create the postrges\u00a09.4 database. Choose production and multi-az. If you filled out everything correctly you should see something like<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2389\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/db.png\" alt=\"\" width=\"1034\" height=\"194\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/db.png 1034w, https:\/\/blog.domb.net\/wp-content\/uploads\/db-300x56.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/db-768x144.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/db-1024x192.png 1024w\" sizes=\"auto, (max-width: 1034px) 100vw, 1034px\" \/><\/p>\n<p>The connection string can be found all the way on the bottom of the page<\/p>\n<p><strong>tower.cqdtdsqmastk.us-east-1.rds.amazonaws.com<\/strong><\/p>\n<p>Also, make sure that your instance has the RDS SG attached so it can talk to the database.<\/p>\n<p>Next login into your main ansible tower node and download the latest tower<\/p>\n<pre class=\"lang:default decode:true\">[ec2-user@ip-10-0-1-247 ~]$ wget http:\/\/releases.ansible.com\/ansible-tower\/setup-bundle\/ansible-tower-setup-bundle-latest.el7.tar.gz\r\n<\/pre>\n<p>Untar the directory and\u00a0cd into it<\/p>\n<div class=\"\">\n<div class=\"\">\n<pre class=\"lang:default decode:true \">[ec2-user@ip-10-0-1-247 ~]$ tar -xzvf ansible-tower-setup-bundle-latest.el7.tar.gz &amp;&amp; cd ~\/ansible-tower-setup-bundle-3.2.3-1.el7<\/pre>\n<p>Next, edit the inventory file<\/p>\n<div class=\"\">\n<div class=\"\">\n<pre class=\"lang:default decode:true\">[ec2-user@ip-10-0-1-247 ~]$ cat inventory\r\n\r\n[tower]\r\nip-10-0-1-247.ec2.internal ansible_user=ec2-user ansible_ssh_private_key_file=\/home\/ec2-user\/ansible-tower-setup-bundle-3.2.3-1.el7\/ansible.pem\r\nip-10-0-2-222.ec2.internal ansible_user=ec2-user ansible_ssh_private_key_file=\/home\/ec2-user\/ansible-tower-setup-bundle-3.2.3-1.el7\/ansible.pem\r\nip-10-0-3-210.ec2.internal ansible_user=ec2-user ansible_ssh_private_key_file=\/home\/ec2-user\/ansible-tower-setup-bundle-3.2.3-1.el7\/ansible.pem\r\n\r\n\r\n[instance_group_east_b_c]\r\n\r\nip-10-0-2-222.ec2.internal\r\nip-10-0-3-210.ec2.internal\r\n\r\n[instance_group_east_a_c]\r\nip-10-0-1-247.ec2.internal\r\nip-10-0-3-210.ec2.internal\r\n\r\n[database] \r\n[all:vars]\r\n\r\nadmin_password='opensource2018'\r\npg_host='tower.cqdtdsqmastk.us-east-1.rds.amazonaws.com'\r\npg_port='5432'\r\npg_database='awx'\r\npg_username='awx'\r\npg_password='opensource2018'\r\n\r\nrabbitmq_port=5672\r\nrabbitmq_vhost=tower\r\nrabbitmq_username=tower\r\nrabbitmq_password='opensource2018'\r\nrabbitmq_cookie=cookiemonster\r\n# Needs to be true for fqdns and ip addresses\r\n\r\nrabbitmq_use_long_name=true # IMPORTANT\r\n# Isolated Tower nodes automatically generate an RSA key for authentication;\r\n# To disable this behavior, set this value to false\r\n# isolated_key_generation=true\r\n\r\n<\/pre>\n<p>As you are in AWS you will need to enable the following 2 repos<\/p>\n<div class=\"\">\n<div class=\"\">\n<pre class=\"lang:default decode:true \">[ec2-user@ip-10-0-1-247 ~]$ yum-config-manager --enable rhui-REGION-rhel-server-extras &amp;&amp;yum-config-manager --enable rhui-REGION-rhel-server-optional<\/pre>\n<p>Install ansible<\/p>\n<pre class=\"lang:default decode:true \">[ec2-user@ip-10-0-1-247 ~]$ yum install ansible -y<\/pre>\n<p>Once finished launch the installation<\/p>\n<div class=\"\">\n<div class=\"\">\n<pre class=\"lang:default decode:true \">[ec2-user@ip-10-0-1-247 ~]$ ANSIBLE_BECOME=True .\/setup.sh<\/pre>\n<p>If the installation is successful you should no be able to login\u00a0to one of the tower\u00a0hosts via its public fqdn assigned by AWS.<\/p>\n<p>As we want to have a single entry point to the cluster we front end it with an ALB ( you will also need to have Route53 setup correctly for this to work) Go ahead and create the ELB. The cert and key for SSL can be found in \/etc\/tower. Make sure you upload the cert when creating the ALB. You also see that it spans across the 3 AZ&#8217;s.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2375\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/elbtower-1.jpg\" alt=\"\" width=\"1141\" height=\"525\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/elbtower-1.jpg 1141w, https:\/\/blog.domb.net\/wp-content\/uploads\/elbtower-1-300x138.jpg 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/elbtower-1-768x353.jpg 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/elbtower-1-1024x471.jpg 1024w\" sizes=\"auto, (max-width: 1141px) 100vw, 1141px\" \/><\/p>\n<p>Lastly, create an alias in route53 pointing to the ALB.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2376\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/alias.jpg\" alt=\"\" width=\"1135\" height=\"314\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/alias.jpg 1135w, https:\/\/blog.domb.net\/wp-content\/uploads\/alias-300x83.jpg 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/alias-768x212.jpg 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/alias-1024x283.jpg 1024w\" sizes=\"auto, (max-width: 1135px) 100vw, 1135px\" \/><\/p>\n<p>It will take a few minutes until the alias is available. Log in into your Tower instance<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2377\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2018-03-26-at-3.53.23-PM.png\" alt=\"\" width=\"555\" height=\"346\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2018-03-26-at-3.53.23-PM.png 555w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2018-03-26-at-3.53.23-PM-300x187.png 300w\" sizes=\"auto, (max-width: 555px) 100vw, 555px\" \/><\/p>\n<p>You can then go to configuration instance groups to validate your config<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2385\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/cluster1.png\" alt=\"\" width=\"1261\" height=\"332\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/cluster1.png 1261w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster1-300x79.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster1-768x202.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster1-1024x270.png 1024w\" sizes=\"auto, (max-width: 1261px) 100vw, 1261px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2386\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/cluster2.png\" alt=\"\" width=\"1348\" height=\"611\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/cluster2.png 1348w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster2-300x136.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster2-768x348.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster2-1024x464.png 1024w\" sizes=\"auto, (max-width: 1348px) 100vw, 1348px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2387\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/cluster3.png\" alt=\"\" width=\"1357\" height=\"614\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/cluster3.png 1357w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster3-300x136.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster3-768x347.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/cluster3-1024x463.png 1024w\" sizes=\"auto, (max-width: 1357px) 100vw, 1357px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Congratulations if you read until here. You now have a fully HA Tower installation with AWS managed ELB and RDS.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<div><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ever wondered how you could run ansible tower in clustered mode across\u00a0multiple AZ in AWS?\u00a0 This post will describe how you can build the following architecture: &nbsp; First, build 3 ec2 instances each in a different AZ&#8217;s. You should be more than ok with t2.large instance sizes. The subnets in the VPC can be private&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[64],"tags":[71,108,142,141,34],"class_list":["post-2371","post","type-post","status-publish","format-standard","hentry","category-ansible","tag-ansible-tower","tag-aws","tag-multi-az","tag-rds","tag-redhat"],"_links":{"self":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2371"}],"version-history":[{"count":9,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2371\/revisions"}],"predecessor-version":[{"id":2395,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2371\/revisions\/2395"}],"wp:attachment":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}