[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: AWS EC2: Jessie AMIs 20141225 and https to Cloudfront.debian.net



On 26 December 2014 at 06:57, James Bromberger <james@rcpt.to> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Hello all,

I've refreshed the Jessie AMIs in all regions as shown at https://wiki.debian.org/Cloud/AmazonEC2Image/Jessie, and hereby listed (and this message is signed):

|| '''Region''' || '''hvm x86_64 ebs''' || '''paravirtual x86_64 ebs''' ||
|| ap-northeast-1 || ami-a4272ca5 || ami-74262d75 ||
|| ap-southeast-1 || ami-332f0161 || ami-2f2f017d ||
|| ap-southeast-2 || ami-e1b9d2db || ami-d3b9d2e9 ||
|| cn-north-1 || ami-ee65f7d7 || - ||
|| eu-central-1 || ami-702c1c6d || ami-6a2c1c77 ||
|| eu-west-1 || ami-9440fbe3 || ami-7047fc07 ||
|| sa-east-1 || ami-4b5dee56 || ami-7d5dee60 ||
|| us-east-1 || ami-aae18fc2 || ami-2cfc9244 ||
|| us-gov-west-1 || ami-b39ef890 || ami-b19ef892 ||
|| us-west-1 || ami-17899452 || ami-21899464 ||
|| us-west-2 || ami-698cdf59 || ami-438cdf73 ||



The one addition is I have added in apt-transport-https. I've read through https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756535 that requests this in the default Debian install, and I think there is a use case for supporting using https for package sources in the cloud from boot (without having to grab apt-transport-https from http/ftp based sources first.

At the same time, let me also introduce https://cloudfront.debian.net/, following me purchasing a discounted SSL certificate recently.  Note that https is NOT the default in the Jessie images sources.list, but you can easily switch to it if you wish.

Together this means you can now launch Jessie instances and with this change should you chose, restrict the outbound Security Group ports to 443 in order to get to the Debian archive via Cloudfront. (You can install apt-transport-https and do similar in Wheezy now).

Happy holidays, Merry Christmas, etc.

  James

- --
/Mobile:/ +61 422 166 708, /Email:/ james_AT_rcpt.to
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)
 
iQIcBAEBAgAGBQJUnPi6AAoJEK7IKHSdhcU8U9wP/3AgAxYFSG4Funbf1H5yghpB
ySvzJ/8fG3973bicl40iawM/c7PQbuciyb8SJs4eVA+58b5Mj1mbRL11ODq61OZj
yV8ljqSFsJBqJThxx4zYaDlDRzKOvBdpDW/FdA2gRXool3vTrMi8ttbmok2uF2jC
Cgb2e1PvzC5z7OMsgaej0qk5hxkJxlgC924IB3faDDPGutvih1nCmht7JSswv3IE
fj1xSVZJJbNx9oYC/tttvifedWDF7xfpkPSTG/FvwRFXQ78rGWWhcRYL6qe/wwHU
776kabJ0gLLCt7dEbOrlSFjumauExA/rnkk1yjur1y0q2OYXQoCjqdcA7EC/dtRk
MQTfGutnX6Ir0q5nr7aQm2MW7akAEhjx/7Xbim0aPDMKnUJfSmbvHl1Inevo+3hb
qrHh6TEzy/XU8w41OthzF/bvFiGCkJfedPOuCc+O9zT00o3Wg24v2tqFRUvyxLNJ
fDlLxfZ94z/UYpI4hGzJ69xZ9AL2MS99AY30+//RoCFlqK+tfBouSHJTk0wy+wPb
omMJ+mDn0Oh4q8cOaMYw4H7vPCG7GzQgsT9GRezFxRwmQgssU9rl6erA7DyVpEtu
ruafhZSyNiXnXMPfaaeBA5g2oG4434ViyDBX+aYmyKshKt0x+uhY5yDefwYo4k/0
grNZYObJk5Um19NAyUyx
=LiQs
-----END PGP SIGNATURE-----


Nicely done! Thank you James. I think the SSL transport is a welcome and uncontroversial addition to the base images.
On a side: Something is afoot in bootstrap-vz, I have recently pushed an integration testing branch, which right now successfully tests virtualbox wheezy images (oldstable and unstable are failing atm) - it's been a long time coming and it's far from done, but I'd love to hear if anybody'd have some feedback.

Kind regards
Anders

Reply to: