{"id":2707,"date":"2022-12-16T17:35:57","date_gmt":"2022-12-16T22:35:57","guid":{"rendered":"http:\/\/blog.domb.net\/?p=2707"},"modified":"2023-11-23T18:05:34","modified_gmt":"2023-11-23T23:05:34","slug":"fault-injection-simulator-cross-account-experiments","status":"publish","type":"post","link":"https:\/\/blog.domb.net\/?p=2707","title":{"rendered":"AWS Fault Injection Simulator Cross Account Experiments via AWS StepFunctions"},"content":{"rendered":"<p>Many AWS customers run their workloads across multiple AWS accounts. Therefore they want to be able to run chaos experiments across accounts to understand how their workload behaves during a cascading or correlated failure. Today, AWS Fault Injection Simulator does not yet support targets in different accounts, but this doesn&#8217;t hinder us to run experiments via AWS StepFunctions which has great integrations with AWS Fault Injection Simulator.<\/p>\n<p>AWS StepFunctions allows us to create states with the following actions: <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.21.11-PM-300x228.png\" alt=\"\" width=\"300\" height=\"228\" class=\"alignnone size-medium wp-image-2708\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.21.11-PM-300x228.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.21.11-PM.png 311w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/> <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.22.03-PM-300x235.png\" alt=\"\" width=\"300\" height=\"235\" class=\"alignnone size-medium wp-image-2709\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.22.03-PM-300x235.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.22.03-PM.png 305w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/> <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.22.49-PM.png\" alt=\"\" width=\"296\" height=\"238\" class=\"alignnone size-full wp-image-2711\" \/> <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.23.56-PM-300x236.png\" alt=\"\" width=\"300\" height=\"236\" class=\"alignnone size-medium wp-image-2713\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.23.56-PM-300x236.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.23.56-PM.png 304w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>If you are interested in having a central place where you create experiments and fan out experiments to the various accounts via service catalog, you can read up on it <a href=\"https:\/\/aws.amazon.com\/blogs\/mt\/chaos-engineering-leveraging-aws-fault-injection-simulator-in-a-multi-account-aws-environment\/?nc1=b_rp\" rel=\"noopener\" target=\"_blank\">here<\/a>. In the case of this blog post, I&#8217;ve created an experiment that only executes a chaos-mesh experiment via FIS in account A and reboots an EC2 instances via FIS in account B. You will point the execution steps to your own FIS Experiment Templates. <\/p>\n<p>Please keep in mind that when running chaos experiments in your environment you&#8217;d want to follow the following workflow before the execution of the experiment. As the goal of this blog post is to provide you with insights on how to built a StepFunction that can run experiments cross accounts, I will therefore skip much of this workflow and only focus on the FIS execution via StepFunction. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-1024x575.png\" alt=\"\" width=\"1024\" height=\"575\" class=\"alignnone size-large wp-image-2720\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-1024x575.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-300x168.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-768x431.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-1536x862.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.37.44-PM-2048x1150.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>For our workload, that is comprised of an EKS Cluster in account A, and a Database on EC2 in account B, I will build the following state machine<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.44.52-PM.png\" alt=\"\" width=\"547\" height=\"556\" class=\"aligncenter size-full wp-image-2724\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.44.52-PM.png 547w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.44.52-PM-295x300.png 295w\" sizes=\"auto, (max-width: 547px) 100vw, 547px\" \/><\/p>\n<p>Before we can start, you will need to create a IAM role in account <strong>B<\/strong> that you will use to allow account A to assume the FIS-Execution role. <\/p>\n<p>[cc lang=&#8221;bash&#8221;]<\/p>\n<p>{<br \/>\n    &#8220;Version&#8221;: &#8220;2012-10-17&#8221;,<br \/>\n    &#8220;Statement&#8221;: [<br \/>\n        {<br \/>\n            &#8220;Sid&#8221;: &#8220;FisExecutionRole&#8221;,<br \/>\n            &#8220;Effect&#8221;: &#8220;Allow&#8221;,<br \/>\n            &#8220;Action&#8221;: [<br \/>\n                &#8220;fis:StartExperiment&#8221;,<br \/>\n                &#8220;fis:TagResource&#8221;<br \/>\n            ],<br \/>\n            &#8220;Resource&#8221;: &#8220;*&#8221;<br \/>\n        }<br \/>\n    ]<br \/>\n}<\/p>\n<p>[\/cc]<\/p>\n<p>You will also have to define a trust policy for this role so that account A is authorized to assume the role in account B<\/p>\n<p>[cc lang=&#8221;bash&#8221;]<\/p>\n<p>{<br \/>\n    &#8220;Version&#8221;: &#8220;2012-10-17&#8221;,<br \/>\n    &#8220;Statement&#8221;: [<br \/>\n        {<br \/>\n            &#8220;Effect&#8221;: &#8220;Allow&#8221;,<br \/>\n            &#8220;Principal&#8221;: {<br \/>\n                &#8220;AWS&#8221;: &#8220;arn:aws:iam::YourAccountID:root&#8221;<br \/>\n            },<br \/>\n            &#8220;Action&#8221;: &#8220;sts:AssumeRole&#8221;,<br \/>\n            &#8220;Condition&#8221;: {}<br \/>\n        }<br \/>\n    ]<br \/>\n}<br \/>\n[\/cc]<\/p>\n<p><strong>Note the ARN of the role in account B<\/strong> as you will need it in the Step Function Step in account <strong>A<\/strong>!<\/p>\n<p>Let&#8217;s create a state machine in <strong>account A<\/strong> and click next. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-1024x387.png\" alt=\"\" width=\"1024\" height=\"387\" class=\"aligncenter size-large wp-image-2726\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-1024x387.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-300x113.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-768x290.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-1536x581.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-4.47.13-PM-2048x774.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>In the search field on the top left enter FIS <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.04.55-PM.png\" alt=\"\" width=\"513\" height=\"384\" class=\"aligncenter size-full wp-image-2731\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.04.55-PM.png 513w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.04.55-PM-300x225.png 300w\" sizes=\"auto, (max-width: 513px) 100vw, 513px\" \/><\/p>\n<p>and drag the StartExperiment tab into your State Machine workflow. Rename it as you like. You should see something like this<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM-1024x521.png\" alt=\"\" width=\"1024\" height=\"521\" class=\"aligncenter size-large wp-image-2732\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM-1024x521.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM-300x153.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM-768x391.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM-1536x781.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.09.48-PM.png 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Click <img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.10.50-PM.png\" alt=\"\" width=\"132\" height=\"58\" class=\"aligncenter size-full wp-image-2733\" \/> twice and notice the banner on the bottom of the page! We will add the permissions once the role is created.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-1024x193.png\" alt=\"\" width=\"1024\" height=\"193\" class=\"aligncenter size-large wp-image-2734\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-1024x193.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-300x57.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-768x145.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-1536x290.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.11.36-PM-2048x386.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Give the StateMachine a name and click<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.12.26-PM.png\" alt=\"\" width=\"295\" height=\"61\" class=\"aligncenter size-full wp-image-2735\" \/><\/p>\n<p>This will get you to the following page. Click on <strong>Edit Role in IAM<\/strong> to Add the missing permissions.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-1024x170.png\" alt=\"\" width=\"1024\" height=\"170\" class=\"aligncenter size-large wp-image-2736\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-1024x170.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-300x50.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-768x128.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-1536x255.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.14.17-PM-2048x340.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Keep in mind that our role does also need assume role permissions for the cross account access. We are therefore adding the following permissions<\/p>\n<p>Allow the role to assume all resources<\/p>\n<p>[cc lang=&#8221;bash&#8221;]<br \/>\n{<br \/>\n    &#8220;Version&#8221;: &#8220;2012-10-17&#8221;,<br \/>\n    &#8220;Statement&#8221;: [<br \/>\n        {<br \/>\n            &#8220;Sid&#8221;: &#8220;AllowAssumeRole&#8221;,<br \/>\n            &#8220;Effect&#8221;: &#8220;Allow&#8221;,<br \/>\n            &#8220;Action&#8221;: &#8220;sts:AssumeRole&#8221;,<br \/>\n            &#8220;Resource&#8221;: &#8220;*&#8221;<br \/>\n        }<br \/>\n    ]<br \/>\n}<br \/>\n[\/cc]<\/p>\n<p>as well as execute the experiment. <\/p>\n<p>[cc lang=&#8221;bash&#8221;]<\/p>\n<p>{<br \/>\n    &#8220;Version&#8221;: &#8220;2012-10-17&#8221;,<br \/>\n    &#8220;Statement&#8221;: [<br \/>\n        {<br \/>\n            &#8220;Sid&#8221;: &#8220;FisExecutionRole&#8221;,<br \/>\n            &#8220;Effect&#8221;: &#8220;Allow&#8221;,<br \/>\n            &#8220;Action&#8221;: [<br \/>\n                &#8220;fis:StartExperiment&#8221;,<br \/>\n                &#8220;fis:TagResource&#8221;<br \/>\n            ],<br \/>\n            &#8220;Resource&#8221;: &#8220;*&#8221;<br \/>\n        }<br \/>\n    ]<br \/>\n}<\/p>\n<p>[\/cc]<\/p>\n<p>Now go back to your state machine and add a second step as follows<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.29.32-PM-1024x562.png\" alt=\"\" width=\"1024\" height=\"562\" class=\"aligncenter size-large wp-image-2739\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.29.32-PM-1024x562.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.29.32-PM-300x165.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.29.32-PM-768x422.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.29.32-PM.png 1519w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Make sure that for the IAM role for cross-account access &#8211; optional you chose <\/p>\n<p>Provide IAM role ARN and choose the role ARN in <strong>account B<\/strong> that you&#8217;ve created before! arn:aws:iam::<strong>AccountNumberB:role<\/strong>\/fisfullaccess<\/p>\n<p>Click apply the changes. You are now ready to execute the State Machine. <\/p>\n<p>You should see both states turning green<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-1024x535.png\" alt=\"\" width=\"1024\" height=\"535\" class=\"aligncenter size-large wp-image-2743\" srcset=\"https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-1024x535.png 1024w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-300x157.png 300w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-768x401.png 768w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-1536x802.png 1536w, https:\/\/blog.domb.net\/wp-content\/uploads\/Screen-Shot-2022-12-16-at-5.32.49-PM-2-2048x1070.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>You can now go verify on both accounts in your FIS console that both experiments were executed with the Tag names defined in your step functions step!<\/p>\n<p>For a comprehensive workflow in a single account please review <a href=\"https:\/\/aws.amazon.com\/blogs\/compute\/chaos-experiments-using-aws-step-functions-and-aws-fault-injection-simulator\/\">Chaos experiments using AWS Step Functions and AWS Fault Injection Simulator<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many AWS customers run their workloads across multiple AWS accounts. Therefore they want to be able to run chaos experiments across accounts to understand how their workload behaves during a cascading or correlated failure. Today, AWS Fault Injection Simulator does not yet support targets in different accounts, but this doesn&#8217;t hinder us to run experiments&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2847,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[173],"tags":[177,178,179,176,180,181],"class_list":["post-2707","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-chaos-engineering","tag-cross-account","tag-crossaccount","tag-fault-injection-simulator","tag-fis","tag-step-functions","tag-stepfunctions"],"_links":{"self":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2707"}],"version-history":[{"count":32,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2707\/revisions"}],"predecessor-version":[{"id":2768,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/posts\/2707\/revisions\/2768"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=\/wp\/v2\/media\/2847"}],"wp:attachment":[{"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.domb.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}