developmentseed / developmentseed/eoapi-cdk

Add docs with networking scenarios

Open
#116 2 comments 2 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
29
Forks
6
Avg merge
1d 2h
Merged PRs (30d)
7

Description

While working on #114 I have experimented with different networking arrangements and have been reminded that it is easy to create a configuration that does not work! It could be helpful for users to see a few example configurations while they consider their own deployment.

Here are a few that do work:

## Scenario 1: Higher security, higher cost
* RDS Instance in a `PRIVATE_ISOLATED` subnet
* [optional] `pgbouncer` instance in a `PRIVATE_WITH_EGRESS` subnet
* `pgstac_secret` host value is the private IP address for pgbouncer or the RDS hostname
* Lambdas added to the `vpc` in a `PRIVATE_WITH_EGRESS` subnet (adds a NAT Gateway which costs $)
* granted connect access to either the RDS instance or the pgbouncer instance
* **important**: add an S3 Endpoint to the `vpc` to make it possible to read data from S3 buckets in the same region as the VPC for free even within the vpc instead of paying the NAT Gateway tax

## Scenario 2: Lower security, lower cost
* RDS Instance in a `PUBLIC` subnet
* [optional]`pgbouncer` instance in a `PUBLIC` subnet with a public IP address assigned
* `pgstac_secret` host value is the public IP address for the `pgbouncer` instance or the RDS hostname
* **important**: RDS Instance (or pgbouncer instance) allow all traffic (any Ipv4) on port 5432
* Lambdas in `PUBLIC` subnet
* Makes it possible to connect to the database from any client with the credentials
* convenient for loading STAC items without the ingestor infrastructure

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.