Amazon Web Services EC2 Linux Out Of Box Catalog items

  • Release version: Xanadu
  • Updated August 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Amazon Web Services EC2 Linux Out Of Box Catalog items

    The Amazon Web Services EC2 Linux Out Of Box Catalog items provide a streamlined process for requesting Linux virtual machines (VMs) on EC2. The catalog includes a fully functional sample item for ordering Linux instances of various types, essential for deploying production environments with Agent Client Collector (ACC) capabilities.

    Show full answer Show less

    Key Features

    • Order Linux VMs: Users can request a Linux VM on EC2 with ACC installation, which is mandatory for production instances.
    • Approval Requirements: Requests for VM sizes other than t2.nano or t2.micro require administrator approval. Up to two additional disks can be added without approval, while more than two require administrator approval.
    • Compliance Checks: A Cloud Configuration scan is conducted to ensure compliance with organizational policies post-deployment.
    • Enhanced Security: Users can assign a Network Security Group to enhance security for the VM, restricting network access effectively.
    • Tagging Resources: All deployed resources receive a key-value tag for identification, although updates to public cloud tags are planned for future releases.

    Key Outcomes

    By utilizing these catalog items, ServiceNow customers can efficiently provision Linux VMs that comply with security and operational policies, ensuring a robust deployment process. The built-in approval workflows and compliance checks help maintain governance and best practices in cloud resource management.

    Cloud Services Catalog Linux VM with agent client collector (ACC), up to 10 additional disks on EC2 or with security groups.

    This is a fully functional sample catalog item that can be used to request a Linux instance of any instance type from Amazon EC2.

    The video demonstrates how to order an Amazon Web Services EC2 Linux virtual machine.

    Linux VM orders and features:

    Order Features

    Order a Linux virtual machine on EC2, that allows installation of agent client collector. ACC is compulsory for production instances. VM sizes other than t2.nano, t2.micro require approval. Cloud configuration scan is run for compliance checking.

    For instance types other than t2.nano and t2.micro, approval is needed from administrator, by policy. The catalog item has built in client rules to drive an ACC (Agent Client Collector) installation when the deployment environment is marked for production.

    To select the credential alias key for ACC deployment from mid, the appropriate ACC admin role permissions are required to be bestowed to the user. For prerequisites check “Deploy ACC-* in post provisioning” below. The work-flow automation runs a CCG scan on the deployed Linux instance and checks the policy rule with the configuration of the VM. If there is any violation, the stack will be set with 'Follow up required' state to notify that the stack deployment is not as per norms.

    Order a Linux virtual machine on EC2 and specify up to 10 additional disk. For up to two disks, no approval is necessary. Seek approval for anything beyond that.

    This catalog item form allows ordering up to 10 additional disks (volumes) attached to the VM of varying sizes and types. If more than two additional disks are added to the request, seek approval from administrator, by policy.

    Order a secure Linux virtual machine with enhanced security by assigning a Network Security Group for highest level of security.

    This catalog item form allows capability to assign one Network Security Group to the compute instance so that the network access to the VM is restricted. Security groups are listed for the selected VPC and subnets.

    Note:

    Tag (key-value) is assigned to all deployed resources. Example: VM, network, storage as present in the stack.

    The key-value is updated only in the cmdb_key_value table, not in public cloud at this time. This will be fixed in future releases to update the tags in cloud.