Conversation
✅ Deploy Preview will be available once build job completes!
|
| f5-audience: operator | ||
| --- | ||
|
|
||
| This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name. |
There was a problem hiding this comment.
I don't think "Private Endpoint" needs to be bolded in this context. Bold is generally reserved for UI elements.
There was a problem hiding this comment.
| This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name. | |
| This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a Private Endpoint service frontend. To connect , you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name. |
There was a problem hiding this comment.
removing the bold and replacing starting from scratch as suggested by @kkyle-f5
|
|
||
| This guide shows how to use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that's configured with a **Private Endpoint** service frontend. Starting from scratch, you create a VPC, a subnet, a security group, and an interface VPC endpoint that targets your deployment's PrivateLink Endpoint Service Name. | ||
|
|
||
| For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. |
There was a problem hiding this comment.
For information about endpoint service connections, see the AWS document, [Connect to an endpoint service as the service consumer]
There was a problem hiding this comment.
| For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. | |
| For information about endpoint service connections, see the AWS document, [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. |
|
|
||
| - The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources. | ||
| - An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). | ||
| - The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`. |
There was a problem hiding this comment.
| - The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`. | |
| - The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's Details tab under **Cloud Settings** > **Service Frontend**, for example, `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`. |
| --region $AWS_REGION | ||
| ``` | ||
|
|
||
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. |
There was a problem hiding this comment.
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. | |
| The command's output includes a `VpcEndpointId`, for example, `vpce-0123456789abcdef0`. Record it; you'll need it to allow the connection in the next step and to test connectivity. |
| For more background on endpoint service connections, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. | ||
|
|
||
| ## Before you begin | ||
|
|
There was a problem hiding this comment.
Before you start, you must have:
There was a problem hiding this comment.
| Before you start, you must have: |
| ## Before you begin | ||
|
|
||
| - The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources. | ||
| - An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). |
There was a problem hiding this comment.
No bold for "Private Endpoint"
There was a problem hiding this comment.
| - An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). | |
| - An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). |
| Otherwise, create a new VPC. Replace `$VPC_CIDR` with a CIDR block for the VPC (for example, `10.0.0.0/16`) and `$AWS_REGION` with your deployment's region: | ||
|
|
||
| {{< call-out class="caution" title="CIDR overlap" >}} | ||
| The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open your deployment's Details tab to find its **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before choosing `$VPC_CIDR`. |
There was a problem hiding this comment.
"Open the Details tab in your deployment to find the IPv4 CIDR (and IPv6 CIDR, if applicable) before you choose $VPC_CIDR"
There was a problem hiding this comment.
| The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open your deployment's Details tab to find its **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before choosing `$VPC_CIDR`. | |
| The VPC's CIDR block must not overlap with your deployment's VPC CIDR block. Open the **Details** tab in your deployment to find the **IPv4 CIDR** (and **IPv6 CIDR**, if applicable) before you choose `$VPC_CIDR`. |
| ## Before you begin | ||
|
|
||
| - The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources. | ||
| - An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). |
There was a problem hiding this comment.
| - An F5 ADS deployment configured with a **Private Endpoint** service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). | |
| - An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). |
|
|
||
| ## Step 1: Create a VPC | ||
|
|
||
| If you already have a VPC you want to connect from, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead. |
There was a problem hiding this comment.
| If you already have a VPC you want to connect from, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead. | |
| If you already have a VPC you want to connect, skip to [Step 2](#step-2-identify-a-subnet-for-the-endpoint) and use its VPC ID instead. |
There was a problem hiding this comment.
I think here, the connection comes from a service in the VPC so saying connecting the VPC is a little misleading. This is especially because there are other mechanisms that actually "peer" VPCs.
| F5 ADS doesn't currently support cross-region PrivateLink connections. Create the interface VPC endpoint in the same region as your deployment. | ||
| {{< /call-out >}} | ||
|
|
||
| ## Step 1: Create a VPC |
There was a problem hiding this comment.
| ## Step 1: Create a VPC | |
| ## Create a VPC |
|
|
||
| Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation. | ||
|
|
||
| ## Step 2: Identify a subnet for the endpoint |
There was a problem hiding this comment.
| ## Step 2: Identify a subnet for the endpoint | |
| ## Identify a subnet for the endpoint |
| } | ||
| ``` | ||
|
|
||
| Record the `SubnetId` for use in Step 4. |
There was a problem hiding this comment.
| Record the `SubnetId` for use in Step 4. | |
| Record the `SubnetId` for when you create the interface VPC endpoint. |
|
|
||
| Record the `SubnetId` for use in Step 4. | ||
|
|
||
| ## Step 3: Create a security group for the endpoint |
There was a problem hiding this comment.
| ## Step 3: Create a security group for the endpoint | |
| ## Create a security group for the endpoint |
| Scope the ingress rule to only the CIDR ranges or security groups that need to reach the deployment. For example, use `$CLIENT_CIDR=10.0.1.0/24` to allow only clients in a specific subnet, instead of a broad range like `0.0.0.0/0`. | ||
| {{< /call-out >}} | ||
|
|
||
| ## Step 4: Create the interface VPC endpoint |
There was a problem hiding this comment.
| ## Step 4: Create the interface VPC endpoint | |
| ## Create the interface VPC endpoint |
|
|
||
| ## Step 4: Create the interface VPC endpoint | ||
|
|
||
| Create the interface VPC endpoint, targeting the deployment's PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps: |
There was a problem hiding this comment.
| Create the interface VPC endpoint, targeting the deployment's PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps: | |
| Create the interface VPC endpoint, targeting the deployment PrivateLink Endpoint Service Name from [Before you begin](#before-you-begin). Replace `$VPC_ID`, `$SERVICE_NAME`, `$SUBNET_ID`, and `$SECURITY_GROUP_ID` with the values from the previous steps: |
| --region $AWS_REGION | ||
| ``` | ||
|
|
||
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. |
There was a problem hiding this comment.
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. | |
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it to use when you allow the connection in the next step and to test connectivity. |
|
|
||
| Wait until `State` shows `available` before continuing. | ||
|
|
||
| ## Step 5: Allow the connection in F5 ADS |
There was a problem hiding this comment.
| ## Step 5: Allow the connection in F5 ADS | |
| ## Allow the connection in F5 ADS |
|
|
||
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. | ||
|
|
||
| The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`: |
There was a problem hiding this comment.
I'm unsure if there is a missing word before the comma?
"Check its state and DNS names with,"
|
|
||
| ## Step 5: Allow the connection in F5 ADS | ||
|
|
||
| Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection: |
There was a problem hiding this comment.
| Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection: | |
| Add the VPC endpoint ID to the PrivateLink Connection Allow List for your deployment so F5 ADS accepts the connection: |
| Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection: | ||
|
|
||
| 1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**. | ||
| 1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**. |
There was a problem hiding this comment.
| 1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**. | |
| 1. Under **Service Frontend**, add the `VpcEndpointId` you saved when you created the interface VPC endpoint to the **PrivateLink Connection Allow List**. |
| F5 ADS accepts the PrivateLink connection only after you add the VPC endpoint ID (or its AWS account ID) to the allow list. Removing the entry disconnects the endpoint from the deployment. | ||
| {{< /call-out >}} | ||
|
|
||
| ## Step 6: Test the connection |
There was a problem hiding this comment.
| ## Step 6: Test the connection | |
| ## Test the connection |
|
|
||
| ## Step 6: Test the connection | ||
|
|
||
| From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4: |
There was a problem hiding this comment.
| From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4: | |
| From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to the listening port for your NGINX configuration using one of the endpoint's DNS names: |
|
|
||
| This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs. | ||
|
|
||
| For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation. |
There was a problem hiding this comment.
| For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation. | |
| For more background on VPC peering, see the AWS [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation. |
|
|
||
| For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation. | ||
|
|
||
| ## Before you begin |
There was a problem hiding this comment.
| ## Before you begin | |
| ## Before you begin | |
| Before you start, you must have the following: |
|
|
||
| - The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources in your upstream AWS account. | ||
| - An F5 ADS deployment. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). | ||
| - Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab. |
There was a problem hiding this comment.
| - Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab. | |
| - Your deployment AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment **Details** tab. |
|
|
||
| Otherwise, create a new VPC. Replace `$VPC_CIDR` with a CIDR block for the VPC (for example, `10.0.0.0/16`) and `$AWS_REGION` with your deployment's region: | ||
|
|
||
| {{< call-out class="caution" title="CIDR overlap" >}} |
There was a problem hiding this comment.
Topic: colons. Line 34 ends with a colon that introduces the command, but this Caution comes between the colon and the code block. Move the Caution above "Otherwise, create a new VPC" so the colon leads straight into the command. The same layout appears on lines 34 to 40 of connect-upstream-cli.md.
| --region $AWS_REGION | ||
| ``` | ||
|
|
||
| **Example output:** |
There was a problem hiding this comment.
Topic: bold. Bold is for UI labels, not labels in running text. Use plain text for "Example output:". This applies to all four instances across both new pages.
| } | ||
| ``` | ||
|
|
||
| Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation. |
There was a problem hiding this comment.
Topic: em-dash. Use a period instead of --. The same pattern is on line 139 of this page and on lines 58, 85, and 144 of connect-upstream-cli.md. A period also works in the line 139 suggestion, which currently uses a semicolon (topic: semicolons).
| Record the `VpcId` -- you'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation. | |
| Record the `VpcId`. You'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation. |
|
|
||
| Record the `SubnetId` for use in Step 4. | ||
|
|
||
| ## Step 3: Create a security group for the endpoint |
There was a problem hiding this comment.
Topic: step-numbers-in-headings. The suggestions on lines 30 and 60 drop "Step N:" from those headings. The same change applies here and on lines 125, 152, and 164. After you rename the headings, the #step-2-identify-a-subnet-for-the-endpoint anchor on line 32 breaks. Text such as "Step 4" on lines 96, 157, and 166 also stops matching a heading. Refer to the section names instead (topic: cross-references).
| --region $AWS_REGION | ||
| ``` | ||
|
|
||
| Record the returned `GroupId`, then add an ingress rule for the port your NGINX configuration listens on (for example, `443`). Replace `$SECURITY_GROUP_ID` and `$CLIENT_CIDR` with the CIDR range of the clients that need access: |
There was a problem hiding this comment.
Topics: sentence-length, step-formatting. This sentence has 22 words and two actions. The next sentence also says to replace both placeholders with the client CIDR range. The command sets --port 443, while the text presents 443 as an example. If the port can differ, make it a placeholder.
| Record the returned `GroupId`, then add an ingress rule for the port your NGINX configuration listens on (for example, `443`). Replace `$SECURITY_GROUP_ID` and `$CLIENT_CIDR` with the CIDR range of the clients that need access: | |
| Record the returned `GroupId`. Then add an ingress rule for the port that your NGINX configuration listens on. Replace `$SECURITY_GROUP_ID` with the `GroupId`, and replace `$CLIENT_CIDR` with the CIDR range of the clients that need access: |
|
|
||
| The command's output includes a `VpcEndpointId`, for example `vpce-0123456789abcdef0`. Record it -- you'll need it to allow the connection in the next step and to test connectivity. | ||
|
|
||
| The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`: |
There was a problem hiding this comment.
Topics: pronouns, gerunds. The sentence is incomplete ("with, replacing"). Also, "its" could refer to either the output or the endpoint. The same "replacing" pattern appears on lines 95 and 149 of connect-upstream-cli.md.
| The endpoint's initial state is `pending`. Check its state and DNS names with, replacing `$VPC_ENDPOINT_ID`: | |
| The endpoint starts in the `pending` state. To check the endpoint state and DNS names, run the following command. Replace `$VPC_ENDPOINT_ID` with the `VpcEndpointId`: |
|
|
||
| Add the VPC endpoint ID to your deployment's **PrivateLink Connection Allow List** so F5 ADS accepts the connection: | ||
|
|
||
| 1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**. |
There was a problem hiding this comment.
Topics: step-formatting, ui-element-names. Give one action per step, and bold the Details tab label. The same applies to steps 1 and 2 on lines 91 and 92 of connect-upstream-cli.md. Line 92 contains three actions.
| 1. In the F5 ADS Console, open your deployment's Details tab and select **Edit**. | |
| 1. In the F5 ADS Console, open your deployment and select the **Details** tab. | |
| 1. Select **Edit**. |
| 1. Under **Service Frontend**, add the `VpcEndpointId` from Step 4 to the **PrivateLink Connection Allow List**. | ||
| 1. Select **Save Changes**. | ||
|
|
||
| {{< call-out class="important" >}} |
There was a problem hiding this comment.
Topic: admonitions. The first sentence repeats the intro on line 154. Keep only the new information, or move it into the main text: "Removing the entry disconnects the endpoint from the deployment." You could also move "or its AWS account ID" into step 2.
| From a resource inside the VPC (for example, an EC2 instance in the same subnet as the endpoint), connect to your NGINX configuration's listening port using one of the endpoint's DNS names from Step 4: | ||
|
|
||
| ```bash | ||
| curl https://vpce-0123456789abcdef0-abc12345.vpce-svc-0c0d939ca9a7ce020.us-east-1.vpce.amazonaws.com |
There was a problem hiding this comment.
Topic: sensitive-information. The service ID vpce-svc-0c0d939ca9a7ce020 in this hostname and on line 24 looks like a real identifier. Can you confirm that it's fictional, or replace it with a placeholder?
| f5-audience: operator | ||
| --- | ||
|
|
||
| This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs. |
There was a problem hiding this comment.
Topic: sentence-length. The second sentence has about 35 words, and the conceptual limit is 25. Also, reviewers asked to remove "Starting from scratch" from the matching intro on the PrivateLink page. Here's one way to split the sentence, which also spells out VPC on first use (topic: acronyms):
| This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. Starting from scratch, you create an upstream VPC, request a VPC peering connection to your deployment's VPC, accept it in F5 ADS, and update routing and security rules so traffic can flow between the two VPCs. | |
| This guide shows how to use the AWS CLI to let an F5 Application Delivery Service for AWS deployment reach applications in your upstream network. You create an upstream virtual private cloud (VPC) and request a VPC peering connection to your deployment's VPC. Then you accept the connection in F5 ADS and update routing and security rules so traffic can flow between the two VPCs. |
|
|
||
| For more background on VPC peering, see AWS's [Create a VPC peering connection](https://docs.aws.amazon.com/vpc/latest/peering/create-vpc-peering-connection.html) documentation. | ||
|
|
||
| ## Before you begin |
There was a problem hiding this comment.
Topics: lists, prerequisites. Introduce the list with a sentence that ends in a colon. To match the suggestion on the PrivateLink page, add "Before you start, you must have:" after the heading.
| - Your deployment's **AWS Account ID**, **VPC ID**, **IPv4 CIDR**, and **IPv6 CIDR** (if you plan to use IPv6), found on the deployment's Details tab. | ||
|
|
||
| {{< call-out class="caution" >}} | ||
| F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected. |
There was a problem hiding this comment.
Topics: admonitions, tense, active-voice. Start the Caution with the action. Also, use present tense and active voice instead of "will be rejected."
| F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected. | |
| Request the peering connection from the same region as your deployment. F5 ADS rejects peering connections from any other region. |
| F5 ADS doesn't currently support cross-region VPC peering connections. A peering connection from any region other than the deployment's region will be rejected. | ||
| {{< /call-out >}} | ||
|
|
||
| ## Step 1: Create your upstream VPC |
There was a problem hiding this comment.
Topic: step-numbers-in-headings. Drop "Step N:" from the six task headings on this page, as reviewers suggested on the PrivateLink page. After you rename them, update the #step-2-request-a-vpc-peering-connection anchor on line 32. Also replace "Step 2" on line 92 with the section name (topic: cross-references).
| Otherwise, create a new VPC in the same AWS Region as your deployment. Replace `$UPSTREAM_VPC_CIDR` with a CIDR block for the VPC and `$AWS_REGION` with your deployment's region: | ||
|
|
||
| {{< call-out class="caution" title="CIDR overlap" >}} | ||
| Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs, or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering will fail. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information. |
There was a problem hiding this comment.
Topic: tense. Use "fails" instead of "will fail." Also, remove the comma before "or."
| Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs, or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering will fail. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information. | |
| Your upstream VPC's CIDR block must not overlap with the deployment's VPC CIDRs or the CIDRs of other peered upstream VPCs. If CIDRs overlap, VPC peering fails. See [Upstream network]({{< ref "/f5ads/aws/overview.md#upstream-network" >}}) for more information. |
|
|
||
| ## Step 2: Request a VPC peering connection | ||
|
|
||
| From your upstream AWS account, request a peering connection targeting your deployment's VPC. Replace `$UPSTREAM_VPC_ID` with your upstream VPC ID, `$DEPLOYMENT_VPC_ID` and `$DEPLOYMENT_AWS_ACCOUNT_ID` with the values from your deployment's Details tab, and `$AWS_REGION` with your deployment's region: |
There was a problem hiding this comment.
Topic: sentence-length. The second sentence has about 25 words, and the task limit is 20. A short list of placeholders is easier to scan: "Replace the following values:", then one item for each placeholder.
|
|
||
| ## Step 3: Accept the peering connection in F5 ADS | ||
|
|
||
| F5 ADS accepts the peering connection request on the deployment side; you don't accept it using the AWS CLI. |
There was a problem hiding this comment.
Topic: semicolons. Use two sentences.
| F5 ADS accepts the peering connection request on the deployment side; you don't accept it using the AWS CLI. | |
| F5 ADS accepts the peering connection request on the deployment side. You don't accept it with the AWS CLI. |
| --query "RouteTables[0].Routes" | ||
| ``` | ||
|
|
||
| Once the connection is `active` and the routes and security group rules are in place, your deployment can reach applications in your upstream VPC through the addresses your NGINX configuration is set up to proxy to. |
There was a problem hiding this comment.
Topics: word-list, sentence-length. Use "after" instead of "once," and split this 30-word sentence.
| Once the connection is `active` and the routes and security group rules are in place, your deployment can reach applications in your upstream VPC through the addresses your NGINX configuration is set up to proxy to. | |
| After the connection is `active` and the routes and security group rules are in place, your deployment can reach your upstream applications. The deployment reaches them at the addresses that your NGINX configuration proxies to. |
|
This pull request adds two AWS CLI guides for F5 Application Delivery Service for AWS: one for connecting to a private endpoint deployment and one for connecting upstream applications. It also updates Style findings are in the inline comments. The most important ones are the capitalization of "private endpoint," the placeholder format, and the "Step N:" headings along with the anchors that link to them. Each of these applies to both new pages. Technical accuracy concerns:
|
kkyle-f5
left a comment
There was a problem hiding this comment.
Remove "Step 1" etc from titles. Be sure to remove references to "Step 1, 2, etc" from text.
3c278ce to
65c93ad
Compare
…ns or upstream CLI
65c93ad to
bf1140d
Compare
|
|
||
| 1. After your deployment is created, open its Details tab and find the **PrivateLink Endpoint Service Name** under **Cloud Settings** > **Service Frontend**, for example `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`. | ||
| 1. Create an interface VPC endpoint that targets this Service Name. For step-by-step instructions, see AWS's [Connect to an endpoint service as the service consumer](https://docs.aws.amazon.com/vpc/latest/privatelink/create-endpoint-service.html#connect-to-endpoint-service) documentation. When prompted for **Service name**, enter the PrivateLink Endpoint Service Name from the previous step. | ||
| 1. Create an interface VPC endpoint that targets this Service Name. For step-by-step instructions, see [Connect to a Private Endpoint deployment using the AWS CLI]({{< ref "/f5ads/aws/deploy/create-deployment/connect-privatelink-cli.md" >}}). |
There was a problem hiding this comment.
so AWS CLI is nice but I might already be using the AWS management console to try things out.
I think you should keep the original guidance and append to it. In fact, we should make some of this more specific/inline: When I try creating a VPC endpoint, what do I select (there are 6ish options on AWS and we want users to pick a specific one), right?
| @@ -0,0 +1,175 @@ | |||
| --- | |||
| title: Connect to a private Endpoint deployment using the AWS CLI | |||
There was a problem hiding this comment.
| title: Connect to a private Endpoint deployment using the AWS CLI | |
| title: Connect to a Private Endpoint deployment using the AWS CLI |
| @@ -0,0 +1,175 @@ | |||
| --- | |||
| title: Connect to a private Endpoint deployment using the AWS CLI | |||
| description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend" | |||
There was a problem hiding this comment.
| description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend" | |
| description: "Use the AWS CLI to connect an F5 Application Delivery Service for AWS deployment to an AWS VPC Endpoint" |
mentioning the use-case is nicer^^
|
|
||
| - The [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured with credentials that can manage VPC resources. | ||
| - An F5 ADS deployment configured with a Private Endpoint service frontend. See [Create a new deployment]({{< ref "/f5ads/aws/deploy/create-deployment/deploy-console.md#create-a-new-deployment" >}}). | ||
| - The deployment's **PrivateLink Endpoint Service Name**, found on the deployment's **Details** tab under **Cloud Settings** > **Service Frontend**, for example, `com.amazonaws.vpce.us-east-1.vpce-svc-0c0d939ca9a7ce020`. |
There was a problem hiding this comment.
is that VPC endpoint service name made up or of an old/deleted deployment? Would recommend putting some made up value in it if it's not that.
| "Vpc": { | ||
| "VpcId": "vpc-0123456789abcdef0", | ||
| "CidrBlock": "10.0.0.0/16", | ||
| "State": "pending" |
There was a problem hiding this comment.
I believe this is not the final state of the VPC right? If so, let's put a terminal output, i.e., once the VPC is ready and show what that looks like.
| } | ||
| ``` | ||
|
|
||
| Record the `VpcId`. You'll need it in the following steps. For more background on VPC design, see AWS's [Create a VPC](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html) documentation. |
There was a problem hiding this comment.
nudging users to best practices is good but let's keep this document and its flow to the sequence we are trying to have the users follow. otherwise, that;s another redirection.
maybe it's something we can add under a references/more information/what's next section...
| --output table | ||
| ``` | ||
|
|
||
| Use an existing subnet, or create a new one. Replace `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region: |
There was a problem hiding this comment.
| Use an existing subnet, or create a new one. Replace `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region: | |
| Use an existing subnet, or create a new one by running the following command and replacing `<SUBNET_CIDR>` with an available CIDR block from your VPC and `<AZ>` with an Availability Zone in your region: |
| aws ec2 authorize-security-group-ingress \ | ||
| --group-id <SECURITY_GROUP_ID> \ | ||
| --protocol tcp \ | ||
| --port 443 \ |
There was a problem hiding this comment.
| --port 443 \ | |
| --port <PORT> \ |
Users tend to copy stuff^^
| --query "VpcEndpoints[0].{State:State,DNSEntries:DnsEntries}" | ||
| ``` | ||
|
|
||
| Wait until `State` shows `available` before continuing. |
There was a problem hiding this comment.
for me on the AWS Console, the status was always Pending/Awaiting until I allowed the endpoint on the deployment. Just want to make sure we can double check this.
| @@ -0,0 +1,175 @@ | |||
| --- | |||
| title: Connect to a private Endpoint deployment using the AWS CLI | |||
| description: "Use the AWS CLI to connect to an F5 Application Delivery Service for AWS deployment that uses a private endpoint service frontend" | |||
There was a problem hiding this comment.
this document has a lot of good information regardless of the tool being used to manage VPC endpoints: AWS CLI, Console (or even the plain SDK).
Can we inline this content into the connectivity page and make it collapsable?
| @@ -0,0 +1,168 @@ | |||
| --- | |||
There was a problem hiding this comment.
|
|
||
| ## Request a VPC peering connection | ||
|
|
||
| From your upstream AWS account, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region: |
There was a problem hiding this comment.
| From your upstream AWS account, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region: | |
| From your upstream VPC, request a peering connection targeting your deployment VPC. Replace `<UPSTREAM_VPC_ID>` with your upstream VPC ID, `<DEPLOYMENT_VPC_ID>` and `<DEPLOYMENT_AWS_ACCOUNT_ID>` with the values from your deployment Details tab, and `<AWS_REGION>` with your deployment region: |
|
|
||
| ## Accept the peering connection in F5 ADS | ||
|
|
||
| F5 ADS accepts the peering connection request on the deployment side. You don't accept it using the AWS CLI. |
There was a problem hiding this comment.
This sentence in noisy. I think just the steps below are good.
| 1. Go to **Cloud Details** > **Upstream Network**, select **+ Add Entry**, and add the `VpcPeeringConnectionId` you recorded when you requested the VPC peering connection. | ||
| 1. Select **Save Changes** to allow F5 ADS to accept the peering connection request. | ||
|
|
||
| Confirm the connection is active, replacing `<VPC_PEERING_CONNECTION_ID>`: |
There was a problem hiding this comment.
| Confirm the connection is active, replacing `<VPC_PEERING_CONNECTION_ID>`: | |
| Confirm that your AWS VPC peering connection is active by replacing `<VPC_PEERING_CONNECTION_ID>`: |
|
@rshyamsu Thanks for this change. I left a few comments which I feel will improve the overall information for the users. |
Proposed changes
Checklist
Before sharing this pull request, I completed the following checklist:
Footnotes
Potentially sensitive information includes personally identify information (PII), authentication credentials, and live URLs. Refer to the style guide for guidance about placeholder content. ↩