Skip to content

Lesson 1: Immutable Infrastructure & Packer

🧠 The Concept (Explain Like I'm 5)

  • Mutable (Bad): You have a pet dog. If it gets sick, you take it to the vet and give it medicine (SSHing into a server to run apt-get upgrade).
  • Immutable (Good): You have cattle. If a cow is sick, you replace it (Terminating the EC2 instance and spinning up a brand new one with the latest patched image).

🏢 The Enterprise Context

  • Configuration Drift: When engineers manually patch running servers, no two servers are identical anymore.
  • Golden AMIs: HashiCorp Packer builds a standardized Virtual Machine image containing your OS, security agents (CrowdStrike), and CIS hardening rules. Every 30 days, you build a new Golden AMI, roll it out via ASG Instance Refresh, and terminate the old ones.

🗺️ Visual Architecture: The Golden Image Factory

flowchart LR
    Packer["HashiCorp Packer"] -->|Boots temporary EC2| EC2["Raw Ubuntu AMI"]
    EC2 --> Ansible["Ansible Provisioner"]

    subgraph Hardening ["CIS Hardening"]
        Ansible --> P1["Install CloudWatch/SSM"]
        Ansible --> P2["Disable Root SSH"]
        Ansible --> P3["Apply Security Patches"]
    end

    Hardening --> Snapshot["Take EBS Snapshot"]
    Snapshot --> AMI[("Golden AMI<br/>(Encrypted)")]

    AMI --> ASG["Auto Scaling Group<br/>(Rolling Update)"]