Advanced cloud provider configurations
Adding a new cloud provider via Settings
- Log into your Cloud 66 dashboard and go to Account Settings → Cloud Keys.
- Click the green + and then select your cloud provider
- Follow the instructions to connect your accounts
Update an existing cloud provider
- Log into Cloud 66 as account owner
- Open the Cloud Keys page under Settings.
- Click on the “edit cloud” button next to your Linode cloud key
- Enter the new personal access token and click Save
Using IAM instance profiles with your servers
Instance profiles are a way to set specific roles on new servers that you spin up with AWS. You can read more about creating your own instance profiles in the AWS docs.
You can use your instance profiles via Cloud 66 by calling them in the manifest file of your application. You can set a different profile for each component of an application (e.g. MySQL or Redis). We will then use that profile whenever we provision a server for that component.
Required AWS permissions
Attaching an instance profile requires three permissions on the IAM user behind your cloud key:
iam:PassRoleec2:AssociateIamInstanceProfileec2:ReplaceIamInstanceProfileAssociation
All three are already granted by our recommended minimum policy, where the two EC2 actions are covered by ec2:*. If you have narrowed that policy to suit your own security requirements, check that these survived. Instance profiles are the only feature that needs iam:PassRole, so it is an easy one to drop.
If any of these are absent, the server fails to provision rather than launching without the profile. Your manifest is not checked against your AWS permissions beforehand, so the error appears during deployment.
Profiles are applied when a server is created
An instance profile is attached at the moment a server is created, not during later deployments. Adding iam_instance_profile_name to your manifest will therefore have no effect on servers that already exist, and redeploying will not apply it.
This also applies to a scale-up that fails partway. If the server was created but the operation did not finish, retrying reuses that existing server, so the profile is never attached to it.
To apply a profile to a server that is already running, either:
- Attach the role directly in the AWS console. Select the instance under EC2, then Actions → Security → Modify IAM role, and choose your profile. This takes effect immediately and does not require a restart.
- Remove the server and scale up again. Any new server is created with the profile attached.
The second option replaces a running server, so we recommend trying it on a staging environment first, or scheduling it outside business hours if the server is serving live traffic.
Cloud 66 Security Groups on AWS
Whenever we provision servers for a new application on AWS, we configure separate AWS Security Groups for each type of server (e.g. application servers or database servers).
This requires Cloud 66 to have IAM permissions on your AWS account, so please be sure to set them up as explained in our Deploying Your First App guide.
If new servers are added to a group on Cloud 66 (e.g. scaling up your web servers), then they are added to the corresponding Security Group on AWS. If servers are removed from Cloud 66, they are also removed from their Security Group on AWS.
AWS Reserved instances
AWS reserved instances enable users to reserve instances for one to three years, which has pricing benefits when compared to on-demand instances. To use Cloud 66 with AWS reserved instances:
- Reserve an instance with your size/region requirements.
- Use Cloud 66 to deploy to a server of that size in the same region, and we’ll use your reserved instance.
AWS EC2-Classic
EC2 Classic is now completely deprecated.
Using GCE service accounts with Cloud 66
A service account is a GCE identity that Google Cloud can use to run API requests on your behalf. If you’ve never used a GCE service account before, please read Google’s documentation before starting.
To use a GCE service account with a Cloud 66 application, you must add the name of the account to your manifest using the format configuration/instance_service_account_name. For example, this would configure MySQL to use the GCE service account named mysql-user@my-project-name.iam.gserviceaccount.com:
Cloud 66 will now associate any MySQL instances created with the GCE service account you specified.
Using multiple keys with OVH
If you need your servers to be separated for different applications, you should create a separate Project in your OVHcloud account, and then add it to Cloud 66 as a separate cloud key. Be sure to name your keys to make them easy to recognise and differentiate (use the Project name, for example).
You will be able to choose between cloud keys (and therefore between your OVH Projects) whenever you create a new application. However you cannot use a cloud key from a different Project once an application has been created. It will always use the Project that it was assigned to during initial setup.