Lesson 1: Immutable Infrastructure & Packer
🧠 The Concept (Explain Like I'm 5)
- Mutable (Bad): You have a pet dog. If it gets sick, you take it to the vet and give it medicine (SSHing into a server to run
apt-get upgrade).
- Immutable (Good): You have cattle. If a cow is sick, you replace it (Terminating the EC2 instance and spinning up a brand new one with the latest patched image).
🏢 The Enterprise Context
- Configuration Drift: When engineers manually patch running servers, no two servers are identical anymore.
- Golden AMIs: HashiCorp Packer builds a standardized Virtual Machine image containing your OS, security agents (CrowdStrike), and CIS hardening rules. Every 30 days, you build a new Golden AMI, roll it out via ASG Instance Refresh, and terminate the old ones.
🗺️ Visual Architecture: The Golden Image Factory
flowchart LR
Packer["HashiCorp Packer"] -->|Boots temporary EC2| EC2["Raw Ubuntu AMI"]
EC2 --> Ansible["Ansible Provisioner"]
subgraph Hardening ["CIS Hardening"]
Ansible --> P1["Install CloudWatch/SSM"]
Ansible --> P2["Disable Root SSH"]
Ansible --> P3["Apply Security Patches"]
end
Hardening --> Snapshot["Take EBS Snapshot"]
Snapshot --> AMI[("Golden AMI<br/>(Encrypted)")]
AMI --> ASG["Auto Scaling Group<br/>(Rolling Update)"]