Hello everyone. I was recently hired at an established company that is in the process of migrating to AWS from Heroku. I am the second devops/SRE like employee, the other person has more of an IT background. He,…

5 points•pigradish•13 days ago•9 comments•
Hello everyone. I was recently hired at an established company that is in the process of migrating to AWS from Heroku. I am the second devops/SRE like employee, the other person has more of an IT background. He, along with the 20ish person dev team, have no experience with anything cloud or IaC. Our workloads are almost entirely stateless web services, with some data pipeline work that has already been moved to AWS lambda.

My gut is telling me ECS is the better choice for this team - simpler, no operational maintenance, almost no additional abstractions beyond the AWS primitives people will need to learn anyway. A consulting team hired before I was brought in are pushing EKS, but I’m not convinced that the improved devex is worth the increase in complexity and operational burden for our team. Their argument is that developers can be effectively quarantined within k8s, so the increase in maintenance on the cluster itself is offset by the reduction in work around custom IAM permissioning, multiple AWS accounts (we’d just use namespaces within the cluster), etc.

Any thoughts or input would be greatly appreciated.

9 comments

niklasmtj13 days ago
ECS Fargate. We used it for a lot of stateless containers, similar as you mention. I tried to migrate from ECS Fargate onto EKS, but moved back after a while. The reason was the "management" overhead of babysitting the cluster and it's non-app deployment like cilium, fluxcd etc. - Since those were part needed and part QoL features we came to the conclusion that ECS Fargate was the better and less 'head ache' solution. I would do it again. Especially not thinking about provision new nodes etc.

Sure you pay for that comfortable solution, but it was worth in my opinion

roryirvine13 days ago
If you don't need anything beyond the feature set of ECS and are happy to stick with AWS for the foreseeable future, then I'd advise you to listen to your gut - EKS is more complex, and needs a bit more looking after.

Personally, I'd disagree with your consultants on being able to avoid multiple AWS accounts as a selling point. When you need to isolate workloads or implement hard security boundaries, accounts are generally the simplest and most reliable way of doing that. Following the Well Architected Framework is a good standard practice and there are plenty of guides and examples to help you.

If things do change in the future, it's not actually that big a deal to deploy to EKS instead (or as well) - but for your needs, I think ECS would make a better starting point.

(And I agree with other posters that ECS Fargate is likely the best fit for you)

flybayer12 days ago
Agreed with the others. Also, shameless plug, you might like Ravion[1] for more quickly setting up your AWS infra and more easily monitoring and maintaining it over time.

[1] https://www.ravion.com

shameemkhd13 days ago
Go with ECS if you don’t need Helm and significant operational overhead. Having used both ECS and EKS for the past few years, I’ve found that ECS requires negligible maintenance.

BTW: Checkout ecs fargate too. if workload is small this will do the most.

kypro12 days ago
> My gut is telling me ECS is the better choice for this team - simpler, no operational maintenance, almost no additional abstractions beyond the AWS primitives people will need to learn anyway. A consulting team hired before I was brought in are pushing EKS, but I’m not convinced that the improved devex is worth the increase in complexity and operational burden for our team.

Yes, I'd say 100% ECS given what you've said here. Don't add complexity until you need it. When you have a larger and more mature devops team you can always reassess if it's time to consider EKS.

Also, definitely have multiple AWS accounts either way. This is very standard and arguably best practice. AWS have management accounts specifically for this reason. Keep developers off prod and on a AWS separate account where you (and they) can be 100% certain they can't do any harm.

But at the end of the day, neither are strictly wrong and what you're asking here is largely a question of corporate politics. If you don't feel you have a strong voice yet, then just try to have a good sense of the pros and cons of the different options you're considering and present a well reasoned opinion. If you're told you're wrong or you're overruled, then that's okay! Ultimately either will work, and right now it's probably better that you focus on building trust before being too opinionated.

Read the full thread on Hacker News →

Related stories