Soru

Zorluk: KolayBilling, Cost Management, and Resource Sharing Strategy

A company is setting up a multi-account environment using AWS Organizations. The cloud engineering team wants to allow developers in various member accounts to launch Amazon EC2 instances into a set of pre-defined private subnets located in a central VPC. To simplify administration and maintain control over IP address allocation, the team wants to share these subnets directly without creating separate VPCs or peering connections. Which approach should the solutions architect recommend to share these subnets with the member accounts?

  1. Enable resource sharing within AWS Organizations in the AWS Resource Access Manager (RAM) settings, create a resource share for the subnets, and share them with the target member accounts or Organizational Units.Cevap
  2. B
    Create a resource share in AWS Resource Access Manager (RAM) for the subnets and share them with the member accounts directly, without enabling the setting to share with AWS Organizations.
  3. C
    Attach a Service Control Policy (SCP) to the target Organizational Units that grants access to the central subnets, allowing member accounts to launch instances directly.
  4. D
    Share the subnets using AWS Resource Access Manager (RAM), and use the default AWS-managed KMS key in the member accounts to encrypt EBS volumes launched in those subnets.

Cevap

Enable resource sharing within AWS Organizations in the AWS Resource Access Manager (RAM) settings, create a resource share for the subnets, and share them with the target member accounts or Organizational Units.
The correct strategy is to enable resource sharing within AWS Organizations in the AWS Resource Access Manager (RAM) settings, create a resource share for the subnets, and share them with the target member accounts or Organizational Units. This allows participant accounts to deploy resources like EC2 instances directly into the owner's subnets.

Adım Adım Çözüm

1
Enable sharing within AWS Organizations in the AWS Resource Access Manager (RAM) settings console.
Enables seamless sharing with accounts, Organizational Units (OUs), or the entire organization.
This is required to allow RAM to distribute resource shares across the organization without manual invitation handshakes.
2
Create a new resource share in AWS RAM, specifying VPC subnets as the resource type.
The target subnets are packaged into a reusable resource share.
AWS RAM requires grouping shareable resources into a resource share package.
3
Associate the resource share with the target Organizational Units (OUs) or member account IDs.
The subnets become available in the participant accounts' EC2 launch consoles and APIs.
This associates the target consumers with the shared resources.

Anahtar Kavram

AWS Resource Access Manager (RAM) VPC Subnet Sharing
Bu soruyu puanla