
एक AWS AMI के EBS डिस्क्स को प्राप्त करता है जिसे आप लॉन्च कर सकते हैं, EBS direct APIs के माध्यम से snapshots को sha256 manifests और वैकल्पिक raw image unpacking के साथ एक private S3 bucket में स्ट्रीम करता है।
एक AMI की डिस्क्स को एक private S3 bucket में acquire करें, जिसे आप पहले से ही launch कर सकते हैं। कोई catalog नहीं, कोई product list नहीं, कोई baked-in AMI ids नहीं। आप AMI id पास करते हैं।
S3 store है। Boot, snapshot, compress, और upload सब AWS के अंदर चलते हैं। Local bandwidth का उपयोग केवल तब होता है जब आप बाद में कोई specific object pull करते हैं।
graph LR
A[AMI you supply] -->|run-instances| B[boot instance]
B -->|every EBS disk| C[snapshots you own]
C --> D[terminate boot instance]
C -->|ListSnapshotBlocks / GetSnapshotBlock| E[helper]
E -->|raw then zstd| F[(S3 golden store)]
F -->|optional pull| G[local artifacts]
DeleteOnTermination set करती हैं।raw | zstd | aws s3 cp - stream करता है। कोई volume create या attach नहीं होता।manifest.json में record करें।region में मौजूद होनी चाहिए।OptInRequired एक console step है।केवल उन्हीं images को dump करें जिन्हें चलाने का आपको अधिकार है। Artifacts को private रखें। एक Marketplace software fee, यदि listing में है, तो केवल तब तक accrues होती है जब तक boot instance चल रहा हो।
AWS buyers को Marketplace AMI के पीछे का snapshot नहीं देता। उस snapshot के विरुद्ध copy-image
और create-volume fail होते हैं। AMI को boot करने से एक
volume बनता है जो इस account के स्वामित्व में है, और उस volume का snapshot लिया जा सकता है।
जिस volume पर अभी भी Marketplace product code हो, उसे केवल एक stopped instance के
root device के रूप में attach किया जा सकता है, इसलिए इसे helper पर data
disk के रूप में attach करना काम नहीं करता। ListSnapshotBlocks + GetSnapshotBlock bytes को
HTTPS पर बिना attach के return करते हैं। Unallocated blocks को zeros के रूप में emit किया जाता है ताकि offsets
सही रहें।
Direct API CBOR को PascalCase members के साथ बोलती है। Checksum raw digest का base64 है, hex नहीं।
ebs_snapshot_read.py दोनों को handle करता है।
jq, flock, और ऐसे credentials जो stack apply कर सकें और नीचे दिए गए
instance/snapshot/SSM/S3 calls चला सकेंzstd केवल unpack.sh के लिएScripts द्वारा उपयोग की जाने वाली Operator permissions (helper role अलग है, और Terraform द्वारा create किया जाता है):
ec2:DescribeImages, DescribeInstances, DescribeSnapshots, RunInstances,
TerminateInstances, CreateSnapshot, DeleteSnapshot, CreateTags,
RegisterImageiam:PassRolessm:GetParameter, SendCommand, GetCommandInvocation,
DescribeInstanceInformations3:* (get/put/list/delete/head)sts:GetCallerIdentitycd terraform && cp terraform.tfvars.example terraform.tfvars
# edit region / name_prefix if needed — still no AMI ids
cd ..
make init && make apply && make configure
make probe AMI=ami-0123456789abcdef0
make dump LABEL=my-image AMI=ami-0123456789abcdef0
make ls
ami-0123456789abcdef0 एक placeholder है। इसे उस AMI id से replace करें जिसे यह
account launch कर सकता है।
make apply एक VPC, एक egress-only security group, एक S3 bucket, और
helper IAM role create करता है। यह billable compute start नहीं करता जब तक
helper_enabled = true न हो। VPC में कोई NAT gateway नहीं है, इसलिए idle cost केवल bucket है
(और वह खाली है जब तक आप कुछ dump नहीं करते)।
scripts/dump.sh --ami ami-0123456789abcdef0 --label my-image
scripts/dump.sh --ami ami-0123456789abcdef0 --label my-image --boot-type m5.2xlarge --dwell 60
scripts/dump.sh --ami ami-0123456789abcdef0 --label my-image --dry-run
scripts/dump.sh --ami ami-0123456789abcdef0 --label my-image --snapshot-id snap-0123456789abcdef0
--dry-run AMI describe करता है और plan print करता है। यह launch नहीं करता।
Defaults:
| Flag | Default | Notes |
|---|---|---|
--boot-type | m5.xlarge, या m6g.xlarge यदि AMI arm64 है | Listings अक्सर अन्य types reject करती हैं। AWS error उन्हें name करता है जिन्हें वे allow करती हैं। |
--dwell | 180 | Snapshot से पहले guest कितने seconds चलता है। 0 instance के running होते ही snapshot लेता है। |
--workers | 32 | प्रति disk concurrent GetSnapshotBlock calls। |
Labels को ^[A-Za-z0-9][A-Za-z0-9._-]{0,62}$ से match करना चाहिए। वे S3 keys बन जाते हैं।
एक re-run उस label को skip करता है जिसका object पहले से S3 में है और जिसका sha256
manifest में है। --force फिर से fetch करता है।
images.tsv, प्रति line एक image। Blank lines और # comments ignore किए जाते हैं।
तीसरा field एक optional instance type है।
# LABEL AMI BOOT_TYPE
my-image ami-0123456789abcdef0
other-image ami-0123456789abcdef0 m5.2xlarge
make dump-batch BATCH=images.tsv JOBS=2
--jobs N प्रत्येक worker को उसका अपना helper slot देता है। Manifest updates
flock के साथ locked हैं। दो अलग driver processes manifest.json share कर सकते हैं; उन्हें
अलग DUMP_STATE_DIR values दें यदि उन्हें helper slot file share नहीं करनी है।
make probe AMI=ami-0123456789abcdef0
run-instances --dry-run free है। DryRunOperation का मतलब है कि account इसे
launch कर सकता है। OptInRequired का मतलब है कि AWS console में उस listing को accept करें, फिर
दोबारा probe करें। यह repo आपके लिए terms accept नहीं करेगा।
--snapshot-id boot skip करता है और एक existing snapshot पढ़ता है। केवल single image।--register-ami अभी लिए गए snapshots से इस account में एक launchable AMI register करता है,
और उन snapshots को रखता है। उनका बिल per GB-month होता है।--keep-snapshot snapshots को बिना AMI register किए रखता है। Cleanup
Keep=true tagged snapshots को skip करता है जब तक आप --force पास न करें।make ls # keys + manifest, no download
make watch # in-flight helper log, multipart upload size
make pull LABELS="my-image"
make pull LABELS="my-image" RAW=1 # also write a sparse .raw
scripts/unpack.sh my-image # partition metadata next to the raw
pull label को downloaded record करने से पहले compressed object का sha256 check करता है।
unpack artifacts/raw/ के अंतर्गत एक sparse raw image और एक
.diskmeta.txt (file, sfdisk, blkid, parted) लिखता है। Mount करें
losetup -Pf --show artifacts/raw/<label>.raw के साथ।
s3://<bucket>/
golden/<label>/<label>.raw.zst
golden/<label>/<label>.raw.zst.sha256 # checksum of the compressed stream
golden/<label>/<label>.stats.json
golden/<label>/<label>.<device>.raw.zst # extra disks, root is the unsuffixed object
_scripts/snapshot_to_s3.sh
_scripts/ebs_snapshot_read.py
_status/<label>.json # expires after 7 days
_logs/<label>.log # expires
golden/ में कोई lifecycle expiry नहीं है। Incomplete multipart uploads 3 दिन बाद
abort कर दिए जाते हैं। terraform destroy bucket delete करता है (force_destroy = true),
golden/ सहित।
manifest.json (local, gitignored) index है: AMI id, name, owner,
architecture, product codes, per-disk keys, sha256, sizes, fetch time।