Can I use Private AMI to create a base image for Appstream application ?

0

Can I use Private Windows server image (AWS AMI) for creating a base image for an Appstream application? Due to company security policy I do not want to use 'standard' AWS Windows server images available in Appstream 2.0 to build the Appstream application but would like to use secure Windows server images (AMI).

Thanks
SJ

Edited by: SJ on Aug 28, 2019 4:40 AM

SJ
질문됨 5년 전950회 조회
5개 답변
0

SJ,

AppStream 2.0 images cannot be based on private AMIs. Due to the specialized nature of application streaming, AppStream 2.0 Fleets must be based on AppStream 2.0 Images. It is possible to start an Image Builder from a publicly available AppStream 2.0 base Image, apply the security settings required by company security policy, and then create a private AppStream 2.0 Image to use as the base for future Image Builders. Keep in mind that the private AppStream 2.0 Image will need to be maintained periodically to ensure adherence to patching standards outlined by the company security policy.

Thank you,

Kellie (AWS)

AWS
답변함 5년 전
0

Kellie,
Thanks for your prompt response. I have suggested Appstream 2.0 to an enterprise client.

1.Is there a security deck or an AWS presentation (security focused) that I can use ? I have been asked my a large enterprise client about the security of using Appstream 2.0. This client uses its private Windows 2012 and 2016 images as EC2 Instances.

  1. Can I connect to my Appstream 2.0 server as an Admin and apply regular patches/settings etc that the security department Admin would - Business As Usual?

Thanks Again
SJ

Edited by: SJ on Aug 28, 2019 9:43 AM

SJ
답변함 5년 전
0

SJ,

I do not have any prepared presentations around security. The AppStream 2.0 networking, access, and security documentation can be found here:
https://docs.aws.amazon.com/appstream2/latest/developerguide/update-fleets-new-image.html

AppStream 2.0 fleet instances are designed to be single use, so changes made directly to the instances would be lost after a user ends the session. To make changes to AppStream 2.0 fleet instances, such as patching, you would create a new private image, either from an existing image builder, or from an image builder created from an existing image, that contains the updates required. That image is then applied to a fleet, at which point new fleet instances will be created from that image. Unused fleet instances are replaced periodically, while in use fleet instances terminated and replace, based on scaling policies, when the active user session ends.
https://docs.aws.amazon.com/appstream2/latest/developerguide/update-fleets-new-image.html

Hopefully that helps,
Kellie (AWS)

AWS
답변함 5년 전
0

Correction, the AppStream 2.0 networking, access, and security documentation can be found here:
https://docs.aws.amazon.com/appstream2/latest/developerguide/managing-network.html

Kellie (AWS)

AWS
답변함 5년 전
0

Thanks, Kellie

I will go over the docs.

Regards
SJ

SJ
답변함 5년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠