Q: Your team has deployed a new microservice that needs to talk to a legacy SOAP API hosted in a partner's data center. The partner has an IP whitelisting firewall. Since your microservices run on auto-scaling EC2 instances that constantly change IPs, how do you manage the whitelist?
To provide a static IP to a dynamically scaling fleet of instances, you must use a NAT Gateway.
#General DevOps #General DevOps — Scenario-Based Interview Questions #L2 #DevOps #SRE #Architecture
🎙️ Candidate Opening & Architectural Context
""In our engineering organization, DevOps culture meant aligning developer speed with site reliability. The interviewer is testing: NAT Gateways, Egress design, static IPs.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
To provide a static IP to a dynamically scaling fleet of instances, you must use a NAT Gateway.
- Place all the dynamic EC2 Auto Scaling instances in a Private Subnet.
- Deploy a NAT Gateway in a Public Subnet.
- Attach an AWS Elastic IP (EIP) to the NAT Gateway.
2️⃣
Remediation & Permanent Safeguards
All outbound HTTP requests from hundreds of dynamic EC2 instances will now appear to the partner's firewall as originating from the single, static Elastic IP of the NAT Gateway, which they can comfortably whitelist.
- Route all outbound internet traffic (
0.0.0.0/0) from the private subnet through the NAT Gateway.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Place all the dynamic EC2 Auto Scaling instances in a Private Subnet.."
⚡ 60-Second Elevator Pitch Talking Points
- Place all the dynamic EC2 Auto Scaling instances in a Private Subnet.
- Deploy a NAT Gateway in a Public Subnet.
- Attach an AWS Elastic IP (EIP) to the NAT Gateway.
Advertisement