Create ECS IAM Permissions for hosting the container application
1. In the IAM Console select Roles and create a new role.data:image/s3,"s3://crabby-images/00b8f/00b8f947b91916a68989a44af5fce89d9adc1bca" alt=""
2. Select AWS service from the trusted entity type section. Under the use case section select Elastic Container Service. Select Elastic Container Service task from the list. Select next.data:image/s3,"s3://crabby-images/373a6/373a620ba747f43a21b72f942701b7c56e8ddc2e" alt=""
3. Add the policies AmazonSQSFullAccess, SecretsManagerReadWrite, and AmazonECSTaskExecutionRolePolicy. Select next when the three polcies have been checked. data:image/s3,"s3://crabby-images/1a634/1a6340327643710c253b67a662af898f0ec9a09a" alt=""
data:image/s3,"s3://crabby-images/27c07/27c07062fda5cd1bc69463c8620685396f8407b3" alt=""
data:image/s3,"s3://crabby-images/adf9b/adf9be72de4ae6c44501e2bfa690ee434d8c2fe5" alt=""
4. Name the role that holds the ECS Permissions. Select create role on the bottom of the page.data:image/s3,"s3://crabby-images/f6166/f6166971b311ee84e4b2a0e5aa661a7f3c238ff1" alt=""
Create the ECS Resource to host the python application
Create the ECS Cluster
1. Select create cluster on the Elastic Container Services Page.data:image/s3,"s3://crabby-images/bf170/bf170e22fd89942fe0ac72c1a8058a81655a8499" alt=""
2. Enter name fore the cluster. Select AWS Fargate under the Infrastructure heading. Select create at the bottom of the page once finished.data:image/s3,"s3://crabby-images/bb7f0/bb7f03ca267635149a91b6bf81386df1079131c7" alt=""
Create the task definition
1. Select task definition from the left menu and select the create new task definition button. On the drop down menu select create new task definition. data:image/s3,"s3://crabby-images/dd229/dd229e40c01fc8c8dae7405b57c6ce581558db7f" alt=""
2. Create a name for the task definition under task definition family. Select launch type as AWS Fargate. OS will be Linux/x86_64. Select cpu and memory size for the container.data:image/s3,"s3://crabby-images/1962f/1962fd9a52e27f433788b2ec9add6fc16c111637" alt=""
3. In the task role and task execution role section select the ecs IAM role created earlier. Under the contaienr section, Name the container image and supply the repository image url for the container. Repository for the application in this example is zacaryfettig/signupapplication:latestdata:image/s3,"s3://crabby-images/3acb0/3acb046700be853ae43586c8b13f52f59cc91fe4" alt=""
4. Under port mappings for this application, the container port will be 5000, protocol TCP, and also enter a name to identify the port. Scrolling down to environment variables, select add environment variable that will be used to select the region that the the Sign Up Application will reference to access the secrets manager resource. The key will be REGION, value type will be set as value, and the value will be the region that you created secrets manager in.data:image/s3,"s3://crabby-images/8cdc3/8cdc3f9b2dac7c749461f521a899e15ee6719ec7" alt=""
5. Leave the rest of the settings as default and select create at the bottom of the page.data:image/s3,"s3://crabby-images/e663a/e663a0ee63a5e33ee35725ca9f852c10bb6822f8" alt=""
Create the task
1. Go back to the clusters tab and select the cluster that was created in the previous steps.
data:image/s3,"s3://crabby-images/2acd3/2acd31e06918c83a3e1caf08f75090506026899d" alt=""
2. On the tasks tab, select run new task.data:image/s3,"s3://crabby-images/61a56/61a56ef755de7da9d304b45d8f57c5d5d605280c" alt=""
3. Under compute configuration select Launch Type. Scroll down to task and add the task definition family to the task. Leave the rest as default and select create at the bottom of the page.
data:image/s3,"s3://crabby-images/bab26/bab266d582af073d2d3f5c0242e4d4f9f1c036c3" alt=""
data:image/s3,"s3://crabby-images/90adb/90adb195adad67c86987c89d1d8c9cae1b997bd2" alt=""
data:image/s3,"s3://crabby-images/e01b6/e01b65d5708217b87cc36bee0e16f342997a94ed" alt=""
Connecting to the application
1. Select the newly created task. On the network bindings tab of the configuration, the external link to the application is show with port 5000. Select open address or copy the link to connect to the application.data:image/s3,"s3://crabby-images/bc47a/bc47a7b19236ea8dfc05662a8c32ad6a9b039ae5" alt=""
Creating the AWS SQS Queue
1. Go the sqs resource page and select create queue.data:image/s3,"s3://crabby-images/69ce7/69ce7bdb764702209ea95f75fcd877983650de34" alt=""
2. Select the type as standard. The more premium tier will give exact message processing order, but that is not needed in this case with the sign up confirmation email. Name the Queue and select create queue at the bottom of the page. data:image/s3,"s3://crabby-images/04ecb/04ecb32bc6bed4de3349e65a4510cd22d72df3aa" alt=""
3. AWS will show a confirmation message when the queue creation is successful.
data:image/s3,"s3://crabby-images/1a8ad/1a8ad06e740f6757fb8caa82c86a3f711fbf9a06" alt=""
Adding SQS URL Secret to AWS Secrets Manager
1. Select the queue that was created earlier and copy the SQS URL from the queue configuration page.data:image/s3,"s3://crabby-images/c932d/c932df2107f56f0ca531d1f7d7ef04e71dc8e1e8" alt=""
2. Go to AWS Secrets Manager and select store a new secret.data:image/s3,"s3://crabby-images/b700e/b700ece72f6f11cc7abcdb997ca7046047f65afe" alt=""
3. Select other type of secret from the secret type menu. Enter sqsurl as the key and paste the url from the SQS Page into the values field. Select next.data:image/s3,"s3://crabby-images/8e00e/8e00e9af478c47170952807e153087b805e40e29" alt=""
4. On the next page, enter sqsurl into the secret name field. Select next.data:image/s3,"s3://crabby-images/07bca/07bca86cadc94cc634637f7d74a9e87e0150d392" alt=""
5. Toggle automatic rotation for scheduled rotation of secrets and select next.data:image/s3,"s3://crabby-images/c7b22/c7b22e09dc32b367198fff2c7f389bc6aef930c2" alt=""
6. On the review page, the bottom of the page shows a sample of the Python Code used to get the secrets. This has been built into the code of the Sign Up Page Python Application. Select store on the bottom of the review page to finish the secret creation process.data:image/s3,"s3://crabby-images/c4ede/c4edefe22fddfa06409b58881d1794beeb816357" alt=""
Setting Up SES Email Service
1. Search for the SES Service and select get started.data:image/s3,"s3://crabby-images/4ef31/4ef31471ca5b2e77ac85dd07e5f3971d54c32049" alt=""
2. Add email address used to verify ownershipdata:image/s3,"s3://crabby-images/72408/7240872adf8364d292faaf35618eb5df329afd9c" alt=""
3. Enter sending domain that will be used for sending emails with SES. Domain record verification is required for the domain in next steps. Select Next.data:image/s3,"s3://crabby-images/0b91d/0b91d2006b77be60eb55215058ffbe4bdee251d8" alt=""
4. Select Turn on Virtual Deliverability Manager for more insight into sending statistics in production. Select next to continue.data:image/s3,"s3://crabby-images/ed8c3/ed8c37a92a6e21b670ffd54b17661c24ee6646f2" alt=""
5. Select Get Starteddata:image/s3,"s3://crabby-images/234cb/234cbbdc6e4d6b26a633bbaf620775473b7ec27d" alt=""
6. After completing the wizard, it will take you to the get set up page. A verification email has been sent to the verification email selected during setup. Go to our email and click the verification link to complete email verification.data:image/s3,"s3://crabby-images/4e82b/4e82bf0225dd982872acf6c61016151f5d39fc78" alt=""
7. Select Get DNS Records to view the dns records that will be inputted into the domains registrar to verify the domain.data:image/s3,"s3://crabby-images/8f85a/8f85a7280d89acae32a438cc02c9da4269dd4146" alt=""
8. Add the records to your domain registrar. Note that depending on your registrar, it may already append the domain name to the end of the record name during creation and the copied name entry for the record may need modified as such.data:image/s3,"s3://crabby-images/2abc8/2abc80fdb90966d954466736d26d7f88e891d31c" alt=""
9. Once the records have been propagated and AWS recognizes those changes, the domain will show as verified in the completed tasks section.
10. The last step is to request production access, so that the email recipients don't need to go through the verification process to receive the sign up conformation emails from the application.data:image/s3,"s3://crabby-images/4b99d/4b99ddf103fbd3ce27b31cbd2e046280d4819cf1" alt=""
data:image/s3,"s3://crabby-images/0eb53/0eb53c294361693007ff64bcfc4a03909c07f725" alt=""
Create Lambda IAM Permissions
1. Add a new role
2. Select AWS Service. Under use case, select the Lambda Service. Select Next.data:image/s3,"s3://crabby-images/f20b2/f20b2941839ca9493f46c1702b6ec2def93c1707" alt=""
3. Add the policies AWSLambda_FullAccess, AWSLambdaSQSQueueExecutionRole, AmazonSESFullAccessdata:image/s3,"s3://crabby-images/0162d/0162d895c1e56e3ab0e6180f7fd8f9b5ebe53af7" alt=""
data:image/s3,"s3://crabby-images/423df/423df251f41c139e8bb8cb4e70eeb523ba7e9e90" alt=""
data:image/s3,"s3://crabby-images/f1946/f1946a92602f6f370476508fbdcba573eabc6743" alt=""
4. Name the Role that holds the policies for Lambda. Select create role at the bottom of the page.data:image/s3,"s3://crabby-images/da976/da976e33032890fb54bb4d94d27843b5135307cd" alt=""
data:image/s3,"s3://crabby-images/de60f/de60f3c372685a2c2717811618d89dbbbb4e2ae9" alt=""
Create AWS Lambda Resource
1. Search for Lambda in AWS and select create a functiondata:image/s3,"s3://crabby-images/d2840/d2840998df614bab53c1e2d4ae0b478dca006f98" alt=""
2. Name the Function and use existing role created in previous steps. Select create function.data:image/s3,"s3://crabby-images/87e79/87e799f1427594db4b58e77c1c85d602eba4f503" alt=""
3. On the function editing page, scroll down to the code source section. Add the following code to the Lambda function.data:image/s3,"s3://crabby-images/beb09/beb09f4bc37ccd6ac4aeb1535a21d2c0b3b29f34" alt=""
data:image/s3,"s3://crabby-images/f6321/f632106b1dbc1cbc5c08f74187415614d8a0c5e8" alt=""
4. Select deploy which will save the code.
5. Set SQS Trigger in Lambda so that Lambda will execute the python script when a new SQS Message comes in. Select add trigger.data:image/s3,"s3://crabby-images/c09b6/c09b6ff66eb22a9f2ae89913e45d0bfd28469107" alt=""
6. Search for and select SQS for the source.data:image/s3,"s3://crabby-images/43e43/43e43f751810ba16e2beedabf7bf0c97c05071f1" alt=""
7. Select the SQS queue created from before and select activate trigger. Keep the rest as default and select the add button at the bottom of the page.data:image/s3,"s3://crabby-images/64561/64561b3583005f8fa84dd821024c9c944204af35" alt=""
data:image/s3,"s3://crabby-images/7c90e/7c90e6d704fbc28b4026ded7c37b9a953536dcc4" alt=""
Testing the Sign Up Confirmation Application
1. Connect to the application. Copy the url or open the address from the ECS Cluster Task.data:image/s3,"s3://crabby-images/06b82/06b82177b92ec9805ecac5b38429a605a29497dc" alt=""
2. Register for an account at the sign in page.data:image/s3,"s3://crabby-images/cb7c7/cb7c7c8d3910901ceaedd0a20c2b3aab2977ef88" alt=""
3. With successful login the successful login page and the email confirmation message process will have kicked off.data:image/s3,"s3://crabby-images/8315e/8315edab490f0edd99baa92b739b2164ae9f056d" alt=""
2. The python application will send off a message to SQS, the message will be passed off to Lambda, which will initiate SES to send an email with the SQS Message Details. The sign up confirmation message will show up in the registered users mailbox.data:image/s3,"s3://crabby-images/73031/73031734f291a6e9bd4eb28053d79702f004dce0" alt=""