A company has 20 service teams. Each service team is responsible for its own microservice. Each service team uses a separate AWS account for its microservice and a VPC with the 192.168.0.0/22 CIDR block. The company manages the AWS accounts with AWS Organizations. Each service team hosts its microservice on multiple Amazon EC2 instances behind an Application Load Balancer. The microservices communicate with each other across the public internet. The company’s security team has issued a new guideline that all communication between microservices must use HTTPS over private network connections and cannot traverse the public internet. A DevOps engineer must implement a solution that fulfills these obligations and minimizes the number of changes for each service team. Which solution will meet these requirements?
一位开发人员编写了一个应用程序,将数据写入AmazonDynamoDB。DynamoDB表已配置为使用条件写入。在使用高峰期间,由于ConditionalCheckFailedException错误,写入操作失败。当多个客户端试图写入同一记录时,开发人员如何提高应用程序的可靠性?
一家公司使用AmazonS3来存储专有信息。开发团队每天为新项目创建bucket。安全团队希望确保所有现有和未来的存储桶都启用了加密、日志记录和版本控制。此外,任何存储桶都不应该是可公开读取或写入的。DevOps工程师应该做些什么来满足这些要求?
一家公司已经将其所有内部质量控制应用程序打包。该公司正在亚马逊EC2实例上运行Jenkins,这些实例需要修补和升级。合规官要求DevOps工程师开始加密构建工件,因为它们包含公司知识产权。DevOps工程师应该做些什么才能以最可维护的方式实现这一点?
一家总部位于美国的在线零售公司计划在未来六个月内将业务扩展到欧洲和亚洲。其产品目前在应用程序负载均衡器后面的AmazonEC2实例上运行。这些实例在多个可用性区域的AmazonEC2自动缩放组中运行。所有数据都存储在AmazonAurora数据库实例中。当产品部署在多个地区时,公司希望在所有地区都有一个单一的产品目录,但出于法规遵从性的目的,其客户信息和购买必须保留在每个地区。公司应该如何在应用程序更改数量最少的情况下满足这些要求?