# AWS Service - RDS

**RDS:**

* Overview
    
    * RDS - Relational Database Service
        
    * It’s a managed DB service for DB use SQL as a query language.
        
    * It allows you to create databases in the cloud that are managed by AWS
        
        * MySQL, Postgres, MariaDB, Oracle, Microsoft SQL Server, Aurora
            
* RDS vs DB on EC2
    
    * RDS is a managed service:
        
        * Automated provisioning, OS patching
            
        * Continuous backups and restore to specific timestamp (Point in Time Restore)
            
        * Monitoring dashboards
            
        * Read replicas for improved read performance
            
        * Multi AZ setup for DR (Disaster Recovery)
            
        * Maintenance windows for upgrades
            
        * Scaling capability (vertical and horizontal)
            
        * Storage backed by EBS (gp2 or io1)
            
    * SSH into the underlying instance is not possible
        
* Storage Auto Scaling
    
    * Helps you increase storage on your RDS DB instance dynamically
        
    * When RDS detects you are running out of free database storage, it scales automatically
        
    * Avoid manually scaling your database storage
        
    * You have to set Maximum Storage Threshold (maximum limit for DB storage)
        
    * Automatically modify storage if:
        
        * Free storage is less than 10% of allocated storage
            
        * Low-storage lasts at least 5 minutes
            
        * 6 hours have passed since last modification
            
    * Useful for applications with unpredictable workloads
        
    * Supports all RDS database engines
        
* Read Replicas for read scalability
    
    * Up to 15 Read Replicas
        
    * Within AZ, Cross AZ or Cross Region
        
    * Replication is `Async`, so reads are eventually consistent
        
    * Replicas can be promoted to their own DB
        
    * Applications must update the connection string to leverage read replicas
        

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1725780662549/a51ff945-e778-413f-9d78-88dbb4ea8843.png align="center")

* Read Replicas - Use Cases
    
    * You have a production database that is taking on normal load
        
    * You want to run a reporting application to run some analytics
        
    * You create a Read Replica to run the new workload there
        
    * The production application is unaffected
        
    * Read replicas are used for SELECT (read) only kind of statements (not INSERT, UPDATE, DELETE)
        

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1725781034814/c01688ee-80b1-418b-8905-68ef7a486c38.png align="center")

* Read Replicas - Network Cost
    
    * In AWS there’s a network cost when data goes from one AZ to another
        
    * For RDS Read Replicas within the same region, you don’t pay that fee
        

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1725781105697/d837c9a7-35d0-4876-8b0d-4aeac9f15a76.png align="center")

* Multi AZ - for DR
    
    * SYNC replication
        
    * One DNS name - automatic app failover to standby
        
    * Increase availability
        
    * Failover in case of loss of AZ, loss of network, instance or storage failure
        
    * No manual intervention in apps
        
    * Not used for scaling
        

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1725812654199/cffb41ae-39a7-4e8a-8f97-610b4d4de4b9.png align="center")

* Single-AZ to Multi-AZ
    
    * Zero downtime operation - no need to stop the DB
        
    * Just click on “modify” for the database
        
    * The following happens internally:
        
        * A snapshot is taken
            
        * A new DB is restored from the snapshot in a new AZ
            
        * Synchronization is established between the two databases
            

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1725812899998/6f9c68fc-3081-4285-92ec-886f751954c1.png align="center")

* RDS Custom
    
    * Managed Oracle and Microsoft SQL Server Database with OS and database customization
        
    * RDS: Automates setup, operation, and scaling of database in AWS
        
    * Custom: access to the underlying database and OS so you can
        
        * Configure settings; Install patches; Enable native features;
            
        * Access the underlying EC2 Instance using SSH or SSM Session Manager
            
    * De-activate Automation Mode to perform your customization, better to take a DB snapshot before to be safe
        
    * RDS vs. RDS Custom
        
        * RDS: entire database and the OS to be managed by AWS
            
        * RDS Custom: full admin access to the underlying OS and the database
            
* RDS Backups
    
    * Automated backups:
        
        * Daily full backup of the database (during the backup window)
            
        * Transaction logs are backed-up by RDS every 5 minute
            
        * Ability to restore to any point in time (from oldest backup to 5 minutes ago)
            
        * 1 to 35 days of retention, set 0 to disable automated backups
            
    * Manual DB Snapshots
        
        * Manually triggered by the user
            
        * Retention of backup for as long as you want
            
* RDS Restore Options
    
    * Restoring a RDS backup or a snapshot creates a new database
        
    * Restoring MySQL RDS database from S3
        
        * Create a backup of your on-premises database
            
        * Store it on Amazon S3 (object storage)
            
        * Restore the backup file onto a new RDS instance running MySQL
            
* RDS Security
    
    * At-rest encryption
        
    * In-flight encryption: TLS-ready by default, use the AWS TLS root certificates client-side
        
    * IAM Authentication: IAM roles to connect to your database (instead of username/pw)
        
    * Security Groups: Control Network access to your RDS DB
        
    * No SSH available except on RDS Custom
        
    * Audit Logs can be enabled and sent to CloudWatch Logs for longer retention
        

**Relevant Doc:**

[https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html)

**Disclaimer:** This is a personal blog that might come in handy when I suffer from Dementia in future.
