AWS mgn: Reorganized MGN launch FAQ; removed encryption/VPC entries
Summary
Reorders and renames FAQ sections, removes Q&As about EBS encryption, VPC endpoints/PrivateLink, monitoring dashboards, and conversion/replication servers, and adds guidance on EBS volume hydration/initialization rate.
Security assessment
The diff is an editorial FAQ reorganization that removes security-adjacent content such as the EBS encryption question rather than documenting a new security feature or addressing a specific vulnerability. No CVE, incident, or security control change is referenced.
Evidence
- * How can we encrypt an unencrypted AWS Transform MGN base snapshot?
Diff
diff --git a/mgn/latest/ug/AWS-Related-FAQ.md b/mgn/latest/ug/AWS-Related-FAQ.md index 65debbced..a832bd20d 100644 --- a//mgn/latest/ug/AWS-Related-FAQ.md +++ b//mgn/latest/ug/AWS-Related-FAQ.md @@ -7 +7 @@ -What does the AWS Transform MGN Machine Conversion Server do?What boot modes are supported by the AWS Transform MGN?How can we encrypt an unencrypted AWS Transform MGN base snapshot?How do I change the server AMI on AWS after Migration?Which AWS services are automatically installed when launching a test or cutover instance?How long does it take to copy a disk from the AWS Transform MGN staging area to production?What are the differences between conversion servers and replication servers?Can I prevent AWS Transform MGN from cleaning up test instance resources in AWS?Why are my Windows server disks read-only after launching the test or cutover instance?What impacts the conversion and boot time of test and cutover instances?Why do I observe EBS volume performance issues while using test or cutover instances?What are the Amazon EBS volume limits for AWS Transform MGN?How is the AWS Licensing Model Tenancy chosen for AWS Transform MGN?How does AWS Transform MGN interact with Interface VPC Endpoints?How do I use MGN with CloudWatch and EventBridge dashboards? +What does the AWS Transform MGN Machine Conversion Server do?What boot modes are supported by the AWS Transform MGN?What impacts the conversion and boot time of test and cutover instances?How long does it take to copy a disk from the AWS Transform MGN staging area to production?Which AWS services are automatically installed when launching a test or cutover instance?Why are my Windows server disks read-only after launching the test or cutover instance?How do I change the server AMI on AWS after Migration?Can I prevent AWS Transform MGN from cleaning up test instance resources in AWS?Why do I observe EBS volume performance issues while using test or cutover instances?Which Amazon EBS attributes can I use to optimize EBS volume hydration when launching instances?What are the Amazon EBS volume limits for AWS Transform MGN?How is the AWS Licensing Model Tenancy chosen for AWS Transform MGN? @@ -11 +11 @@ NEW - You can now accelerate your migration and modernization with AWS Transform -# AWS related FAQs +# Launch questions @@ -13 +13 @@ NEW - You can now accelerate your migration and modernization with AWS Transform -This section contains answers to questions about AWS and AWS Transform MGN. +This section contains answers to questions about launching test and cutover instances with AWS Transform MGN. @@ -21 +21 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * How can we encrypt an unencrypted AWS Transform MGN base snapshot? + * What impacts the conversion and boot time of test and cutover instances? @@ -23 +23 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * How do I change the server AMI on AWS after Migration? + * How long does it take to copy a disk from the AWS Transform MGN staging area to production? @@ -27 +27 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * How long does it take to copy a disk from the AWS Transform MGN staging area to production? + * Why are my Windows server disks read-only after launching the test or cutover instance? @@ -29 +29 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * What are the differences between conversion servers and replication servers? + * How do I change the server AMI on AWS after Migration? @@ -33,4 +32,0 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * Why are my Windows server disks read-only after launching the test or cutover instance? - - * What impacts the conversion and boot time of test and cutover instances? - @@ -38,0 +35,2 @@ This section contains answers to questions about AWS and AWS Transform MGN. + * Which Amazon EBS attributes can I use to optimize EBS volume hydration when launching instances? + @@ -43,4 +40,0 @@ This section contains answers to questions about AWS and AWS Transform MGN. - * How does AWS Transform MGN interact with Interface VPC Endpoints? - - * How do I use MGN with CloudWatch and EventBridge dashboards? - @@ -58,9 +52 @@ Specifically, the machine conversion server makes bootloader changes, injects hy -The agent supports systems using either BIOS (Basic Input/Output System) or UEFI (Unified Extensible Firmware Interface) boot modes. BIOS is the traditional boot mode that initializes hardware and bootstraps the operating system. UEFI is a more modern boot firmware that provides additional boot configurations and security features over BIOS. Both boot modes are fully supported by the agent, giving users flexibility to choose the mode that best fits their systems and requirements. Users can install the agent on servers using either UEFI or legacy BIOS firmware. - -## How can we encrypt an unencrypted AWS Transform MGN base snapshot? - -The encryption status of AWS Transform MGN base snapshots is determined by the default EBS (Elastic Block Store) encryption setting for the respective AWS region. Encryption Scenarios: - - * Default EBS Encryption Enabled: - -If the default EBS encryption is enabled for the region, the base snapshots created by MGN will be encrypted. +The agent supports systems that use either BIOS (Basic Input/Output System) or UEFI (Unified Extensible Firmware Interface) boot modes. BIOS is the traditional boot mode that initializes hardware and starts the operating system. UEFI is a more modern boot firmware that provides additional boot configurations and security features. You can install the agent on servers that use either UEFI or legacy BIOS firmware. @@ -68,3 +54 @@ If the default EBS encryption is enabled for the region, the base snapshots crea - * Default EBS Encryption Disabled: - -If the default EBS encryption is not enabled, the base snapshots will be unencrypted. +## What impacts the conversion and boot time of test and cutover instances? @@ -72 +56 @@ If the default EBS encryption is not enabled, the base snapshots will be unencry - * Encrypting Existing Unencrypted Base Snapshots - +Before launching the test or cutover instance, AWS Transform MGN runs a machine conversion server process on the boot volume. This conversion process is quick. @@ -74 +58 @@ If the default EBS encryption is not enabled, the base snapshots will be unencry -To encrypt an existing unencrypted base snapshot, follow these steps: +The time to boot the test or cutover instance varies depending on many factors unrelated to AWS Transform MGN processes. Some of these factors are within your control and should be considered when recovery or cutover times are important. @@ -76 +60 @@ To encrypt an existing unencrypted base snapshot, follow these steps: - 1. Delete the unencrypted base snapshot from the snapshots console. + * Operating system – The amount of time required to boot the operating system is dependent on the OS itself. Although Linux servers typically boot quickly, Windows servers might take additional time, because of the nature of the Windows OS. If opportunity permits, test the boot time of the source server. If Linux OS takes a long time to boot ensure to check that dhclient (Dynamic Host Configuration Protocol Client) is installed and running on the system so it can pull an IP. @@ -78 +62 @@ To encrypt an existing unencrypted base snapshot, follow these steps: - 2. Enable default EBS encryption for the AWS region where the MGN source environment is located. + * Scheduled Windows Updates – If the Windows server has pending patches, ensure those are installed before launching the test or cutover instance. If pending patches remain, the boot time in the cloud might be severely impacted because the patch process might start upon the initial boot. @@ -80 +64 @@ To encrypt an existing unencrypted base snapshot, follow these steps: - 3. Initiate a new test or cutover migration in MGN. During this process, MGN will create a new encrypted base snapshot based on the default EBS encryption setting for the region. + * Boot volume type – Depending on services/applications, boot time might be impacted by disk performance. It is recommended that boot volumes be tested with a higher performance SSD and even by provisioning IOPs to ensure throughput. This might be more critical during the first initial boot of the server in the cloud, because all initial settings are applied. In many cases, the boot volume type might be scaled back after the initial boot and should be tested. @@ -87,13 +71 @@ To encrypt an existing unencrypted base snapshot, follow these steps: -Enabling default EBS encryption at the region level will encrypt all newly created EBS volumes and snapshots in that region. - -## How do I change the server AMI on AWS after Migration? - -After the machine has been launched by AWS Transform MGN switching the AMI can be done by launching a vanilla machine from the required AMI, stopping that machine, detaching all the disks (including the root) and then attaching the disks from the test or cutover instance created by AWS Transform MGN. - -## Which AWS services are automatically installed when launching a test or cutover instance? - -AWS Transform MGN automatically installs EC2Config. After installation, EC2Config automatically installs the SSM EC2 Configuration Service. - -CloudWatch, AWS PowerShell or CLI are not automatically installed. This can be done by combining the AWS Transform MGN APIs and the AWS APIs – you can use the AWS Transform MGN APIs to determine the EC2 instance IDs of the machines and then use AWS API/CLI to turn on the detailed monitoring. An alternative approach would be to do it via AWS API only based on the tags you associate with the machine. A third approach would be to do so from the post-launch script. - -AWS Transform MGN installs EC2Launch (Windows 2016 only). You will need to configure EC2Launch based on [these specific requirements](https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2launch.html#ec2launch-config). This configuration step needs to be performed post Migration using the wizard in C:\ProgramData\Amazon\EC2-Windows\Launch\Settings\Ec2LaunchSettings.exe on the test or cutover instance. +The first boot of Windows machines on AWS might take up to 45 minutes because of Windows adjusting to the AWS virtual hardware. @@ -105,13 +77 @@ AWS Transform MGN uses internal cloud provider snapshots. This process typically -## What are the differences between conversion servers and replication servers? - -Replication servers run on Linux and conversion servers (for Windows machines) run on Windows. - -The conversion is done by AWS Transform MGN automatically bringing up a vanilla Windows conversion server machines in the same subnet with the replication servers as part of the launch job. - -Both conversion and replication servers have public IPs. - -The conversion servers will use the same security groups as the Replication Server. - -The conversion server must be able to access the MGN's service manager. - -The conversion server machines, just like the Replication servers are managed automatically by AWS Transform MGN. Any attempt to disrupt their automated functionality will result in failed conversions. +## Which AWS services are automatically installed when launching a test or cutover instance? @@ -119 +79 @@ The conversion server machines, just like the Replication servers are managed au -## Can I prevent AWS Transform MGN from cleaning up test instance resources in AWS? +AWS Transform MGN automatically installs EC2Config. After installation, EC2Config automatically installs the SSM EC2 Configuration Service. @@ -121 +81 @@ The conversion server machines, just like the Replication servers are managed au -AWS Transform MGN will, by default, remove any resources created during the test process either when requested by the user or when a new Test instance is launched. +CloudWatch, AWS PowerShell or CLI are not automatically installed. This can be done by combining the AWS Transform MGN APIs and the AWS APIs – you can use the AWS Transform MGN APIs to determine the EC2 instance IDs of the machines and then use AWS API/CLI to turn on the detailed monitoring. An alternative approach would be to do it by using the AWS API only based on the tags you associate with the machine. A third approach would be to do so from the post-launch script. @@ -123 +83 @@ AWS Transform MGN will, by default, remove any resources created during the test -To prevent this in AWS, you can [activate Termination Protection](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/terminating-instances.html#Using_ChangingDisableAPITermination) for the test or cutover instance, and the resources will not be removed upon a new instance launch. +AWS Transform MGN installs EC2Launch (Windows 2016 only). You need to configure EC2Launch based on [these specific requirements](https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2launch.html#ec2launch-config). This configuration step needs to be performed post Migration using the wizard in C:\ProgramData\Amazon\EC2-Windows\Launch\Settings\Ec2LaunchSettings.exe on the test or cutover instance. @@ -131,12 +91 @@ This is a common issue that occurs when detaching and attaching data disks. This -## What impacts the conversion and boot time of test and cutover instances? - -Before launching the test or cutover instance, AWS Transform MGN goes through a machine conversion server process on the boot volume. The conversion process is fairly quick. - -While the actual conversion process itself is quick, the time to boot the test or cutover instance varies depending on many factors unrelated to any AWS Transform MGN processes. Some of these are controllable and should be taken into account when recovery or cutover times are of importance. - - * Operating system – The amount of time required to boot the operating system is dependent on the OS itself. While Linux servers typically boot quickly, Windows servers may take additional time, due to the nature of the Windows OS. If opportunity permits, test the boot time of the source server. If Linux OS takes a long time to boot ensure to check that dhclient (Dynamic Host Configuration Protocol Client) is installed and the system so it can pull an IP. - - * Scheduled Windows Updates – If the Windows server has pending patches, ensure those are installed before launching the test or cutover instance. If pending patches remain, the boot time in the cloud may be severely impacted as the patch process may start upon the initial boot. - - * Boot volume type – Depending on services/applications, boot time may be impacted by disk performance. It is recommended that boot volumes be tested with a higher performance SSD and even by provisioning IOPs to ensure throughput. This may be more critical during the first initial boot of the server in the cloud, as all initial settings are applied. In many cases, the boot volume type may be scaled back after the initial boot and should be tested. - +## How do I change the server AMI on AWS after Migration? @@ -143,0 +93 @@ While the actual conversion process itself is quick, the time to boot the test o +After AWS Transform MGN launches the machine, you can switch the AMI. Launch a new machine from the required AMI, stop that machine, detach all of its disks (including the root disk), and then attach the disks from the test or cutover instance that MGN created. @@ -144,0 +95 @@ While the actual conversion process itself is quick, the time to boot the test o +## Can I prevent AWS Transform MGN from cleaning up test instance resources in AWS? @@ -146 +97 @@ While the actual conversion process itself is quick, the time to boot the test o -###### Note +By default, AWS Transform MGN removes any resources created during the test process either when requested by the user or when a new Test instance is launched. @@ -148 +99 @@ While the actual conversion process itself is quick, the time to boot the test o -The first boot of Windows machines on AWS may take up to 45 minutes due to Windows adjusting to the AWS virtual hardware. +To prevent this in AWS, you can [activate Termination Protection](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/terminating-instances.html#Using_ChangingDisableAPITermination) for the test or cutover instance, and the resources are not removed upon a new instance launch. @@ -158,13 +109 @@ The EBS volumes attached to the test or cutover instances are created from snaps -## What are the Amazon EBS volume limits for AWS Transform MGN? - -AWS Transform MGN does not impose its own limits on Amazon EBS volume size or the number of Amazon EBS volumes per instance. The limits for maximum volume size, number of volumes per instance, and other Amazon EBS constraints are governed by Amazon EBS itself. For current limits, see [Amazon EBS service quotas](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-resource-quotas.html) and [Instance volume limits](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/volume_limits.html). - -## How is the AWS Licensing Model Tenancy chosen for AWS Transform MGN? - -AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazon.com/windows/resources/licensing/) guidelines. - -## How does AWS Transform MGN interact with Interface VPC Endpoints? - -If you use Amazon Virtual Private Cloud (Amazon VPC) to host your AWS resources, you can establish a private connection between your VPC and AWS Transform MGN. You can use this connection to allow AWS Transform MGN to communicate with your resources on your VPC without going through the public internet. - -Amazon VPC is an AWS service that you can use to launch AWS resources in a virtual network that you define. With a VPC, you have control over your network settings, such as the IP address range, subnets, route tables, and network gateways. With VPC endpoints, the routing between the VPC and AWS services is handled by the AWS network, and you can use IAM policies to control access to service resources. +## Which Amazon EBS attributes can I use to optimize EBS volume hydration when launching instances? @@ -172 +111 @@ Amazon VPC is an AWS service that you can use to launch AWS resources in a virtu -To connect your VPC to AWS Transform MGN, you define an _interface VPC endpoint_ for AWS Transform MGN. An interface endpoint is an elastic network interface with a private IP address that serves as an entry point for traffic destined to a supported AWS service. The endpoint provides reliable, scalable connectivity to AWS Transform MGN without requiring an internet gateway, network address translation (NAT) instance, or VPN connection. For more information, see [What is Amazon VPC](https://docs.aws.amazon.com/vpc/latest/userguide/) in the _Amazon VPC User Guide_. +AWS Transform MGN supports the Amazon EBS Provisioned Rate for Volume Initialization (volume initialization rate). When launching an instance, it creates Amazon EBS volumes from snapshots, and this attribute downloads the snapshot blocks at a rate you specify (100 to 300 MiB/s), so volumes reach full performance in a predictable amount of time. @@ -174 +113 @@ To connect your VPC to AWS Transform MGN, you define an _interface VPC endpoint_ -Interface VPC endpoints are powered by AWS PrivateLink, an AWS technology that allows private communication between AWS services using an elastic network interface with private IP addresses. For more information, see [AWS PrivateLink](https://aws.amazon.com/privatelink/). +AWS Transform MGN does not support Amazon EBS fast snapshot restore (FSR), as it is not well suited to migration. FSR must be enabled in advance per snapshot and Availability Zone and is billed while enabled, which better suits steady-state workloads that repeatedly create volumes from the same snapshot and require full volume performance immediately at creation. @@ -176 +115 @@ Interface VPC endpoints are powered by AWS PrivateLink, an AWS technology that a -For more information, see [Getting Started](https://docs.aws.amazon.com/vpc/latest/userguide/GetStarted.html) in the _Amazon VPC User Guide_. +For more information, see [Initialize Amazon EBS volumes](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-initialize.html) and [Amazon EBS fast snapshot restore](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-fast-snapshot-restore.html) in the _Amazon EBS User Guide_. @@ -178,9 +117 @@ For more information, see [Getting Started](https://docs.aws.amazon.com/vpc/late -## How do I use MGN with CloudWatch and EventBridge dashboards? - -You can monitor AWS Transform MGN using CloudWatch, which collects raw data and processes it into readable, near real-time metrics. AWS Transform MGN sends events to Amazon EventBridge whenever a source server launch has completed, a source server reaches the READY_FOR_TEST lifecycle state for the first time, and when the data replication state becomes stalled or when the data replication state is no longer Stalled. You can use EventBridge and these events to write rules that take actions, such as notifying you, when a relevant event occurs. - -You can see MGN in CloudWatch automatic dashboards: - - - - +## What are the Amazon EBS volume limits for AWS Transform MGN? @@ -188 +119 @@ You can see MGN in CloudWatch automatic dashboards: -MGN events can be selected when defining a rule from the EventBridge console: +AWS Transform MGN does not impose its own limits on Amazon EBS volume size or the number of Amazon EBS volumes per instance. The limits for maximum volume size, number of volumes per instance, and other Amazon EBS constraints are governed by Amazon EBS itself. For current limits, see [Amazon EBS service quotas](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-resource-quotas.html) and [Instance volume limits](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/volume_limits.html). @@ -190 +121 @@ MGN events can be selected when defining a rule from the EventBridge console: - +## How is the AWS Licensing Model Tenancy chosen for AWS Transform MGN? @@ -192 +123 @@ MGN events can be selected when defining a rule from the EventBridge console: -[Learn more about monitoring MGN](./monitoring-overview.html). +AWS Transform MGN conforms to the [Microsoft Licensing on AWS](https://aws.amazon.com/windows/resources/licensing/) guidelines. @@ -200 +131 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -Replication related +Replication questions @@ -202 +133 @@ Replication related -Does MGN work with...? +Post-launch actions questions