Docs: System requirements
Documentation / Reference

System requirements

The AWS resources, instance types, storage, network ports and permissions an OBSESC deployment needs.

OBSESC runs as an Amazon Machine Image (AMI) from AWS Marketplace. You launch it with a CloudFormation template inside your own AWS account and VPC. This page lists what that deployment needs.

Platform

ItemRequirement
DeliveryAWS Marketplace AMI, deployed with the OBSESC CloudFormation template
Architecturex86_64
Base operating systemAmazon Linux 2023 (built into the AMI)
Instance familiesc6in (network-optimised compute)

Instance types

The template accepts these instance types for a node:

Instance typeNotes
c6in.2xlargeDefault
c6in.4xlarge
c6in.8xlarge
c6in.12xlarge
c6in.16xlarge
c6in.24xlarge

Each node serves the web console and API on its query port, and runs a local Prometheus that evaluates OBSESC’s built-in alert rules.

Storage

EBS volumes

The stack attaches three encrypted gp3 volumes to each node. All three use your KMS key.

VolumeMount pointDefault sizeAllowed sizeProvisioned performance
Write-ahead log (WAL)/var/lib/obsesc/wal100 GiB20–16,384 GiB3,000 IOPS, 250 MB/s
Summaries/var/lib/obsesc/summary500 GiB100–16,384 GiB6,000 IOPS, 500 MB/s
Anomaly data/var/lib/obsesc/anomaly100 GiB20–16,384 GiB3,000 IOPS, 250 MB/s

The AMI’s root volume is 30 GiB of gp3. OBSESC keeps data on EBS that makes the console fast; the original events stay in S3 in open formats. By default (EnableDataVolumeSnapshots=true) the stack takes a daily snapshot of every data volume and keeps 7.

If your KMS key is customer-managed and snapshots are enabled, the key policy must allow the stack’s snapshot (DLM) role to use the key. Granting access on the IAM side alone is not enough.

S3 bucket

Your raw events are stored in an S3 bucket that you own:

  • Bring your own bucket (default): pass RawBucketName. You manage its lifecycle rules. Tell OBSESC what they are under storage.lifecycle (see Configuration reference).
  • Let the stack create it: set CreateRawBucket=true. The bucket is created with SSE-KMS, public access blocked and a Retain deletion policy. It moves objects from Standard to Standard-IA (default 30 days, minimum 30) and then to Glacier Instant Retrieval (default 180 days).
  • Object Lock is available only on a bucket the stack creates (EnableObjectLock=true). S3 only allows Object Lock to be turned on when a bucket is created.
  • The bucket may live in another account or Region. Use RawBucketAccountId, S3AssumeRoleArn and S3Region. Cross-Region storage adds inter-Region data transfer to every read and write.

Use one OBSESC deployment per bucket. OBSESC keeps its Iceberg catalog and deployment metadata at the root of the bucket.

Required stack parameters

ParameterWhat to provide
AmiIdThe OBSESC AMI ID from your Marketplace subscription
RawBucketNameThe S3 bucket name for your raw events, for example my-obsesc-bucket
VpcIdThe VPC to deploy into
SubnetIdThe subnet for the first node
KmsKeyArnA customer-managed KMS key ARN, for example arn:aws:kms:us-east-1:123456789012:key/...

The stack creates named IAM resources, so deploy it with CAPABILITY_NAMED_IAM. Optional parameters are listed in the Configuration reference and in Deploying from AWS Marketplace.

Network

Inbound ports

The stack’s node security group opens these ports to AllowedIngestCidr (default 10.0.0.0/8):

PortService
4317/tcpOTLP/gRPC ingest
4318/tcpOTLP/HTTP ingest
9200/tcpElasticsearch _bulk ingest
18080/tcpWeb console, API and the /ready health check

The stack also allows 9100/tcp between members of the node security group only. It is reserved for multi-node deployments; contact us via the contact page about those.

The node also listens on these ports, but the default security group does not open them. Add ingress rules yourself for the ones you use:

PortServiceEnabled by default
8088/tcpSplunk HECYes
24224/tcpFluent ForwardYes
9000/tcpVector nativeYes
3100/tcpLoki pushNo (ingest.loki.enabled)
8555/tcpFirehose HTTP endpointNo (ingest.firehose.enabled)
12201/tcp and udpGELFNo (ingest.gelf.enabled)

Console address

The stack’s UiUrl output is the address to open the console. Without the optional load balancer, it’s the node’s private address on port 18080.

Optional internal load balancer

With EnableUiLoadBalancer=true, the stack puts an internal Application Load Balancer in front of the node’s console and API port:

  • The load balancer needs at least two subnets in different Availability Zones (UiAlbSubnetIds).
  • It accepts traffic on ports 80 and 443 from UiAllowedCidr. With UiCertificateArn set, it serves HTTPS on 443 and redirects 80 to 443.
  • It reaches the node on port 18080, and uses GET /ready as its health check.
  • Optionally, UiPrivateZoneId and UiHostname give it a name in your private Route 53 zone.

Console sign-in

With EnableUiPerUserRbac=true, people sign in to the console through your identity provider, and each user gets their own role. This option needs:

  • EnableUiLoadBalancer=true and UiCertificateArn (sign-in works only over HTTPS)
  • AuthSecretArn
  • your identity provider’s details: UiOidcIssuerUrl, UiOidcClientId and the AlbOidc* parameters
  • NodeApiOidcAdminValue, the identity that gets the admin role

Set NodeApiOidcViewerValue to * so that everyone else who signs in gets the viewer role. Otherwise they can sign in but can’t see anything. The load balancer needs outbound HTTPS to your identity provider, and the stack adds that rule for you.

If you set AuthSecretArn without console sign-in, the console still loads, but it needs an API token before it can show any data.

EnableNodeApiOidc=true adds a separate sign-in listener on port 8443 for the API. It has the same requirements as console sign-in.

Outbound access

Each node must be able to reach these AWS services, through a NAT gateway or VPC endpoints:

  • Amazon S3 (raw events and catalog)
  • AWS KMS
  • AWS STS (needed when you use S3AssumeRoleArn, or when the bucket owner is looked up at startup)
  • AWS Secrets Manager and SSM Parameter Store, if you use AuthSecretArn or the TLS parameters
  • AWS Marketplace Metering
  • Amazon EC2 instance metadata (IMDS), for instance-role credentials

With console sign-in, the load balancer must also be able to reach your identity provider over HTTPS.

To deliver OBSESC’s built-in alerts, set AlertmanagerEndpoint to an Alertmanager every node can reach.

The node role includes the AWS managed policy AmazonSSMManagedInstanceCore, so you can reach a node with Session Manager and no SSH key.

IAM

The stack creates a node role. It is scoped to:

  • read, write and delete objects in the raw bucket, and list that bucket
  • use the KMS key you supply
  • call aws-marketplace:MeterUsage
  • register itself with the stack’s load balancer, when you use one
  • optionally, read the specific Secrets Manager secret and SSM parameters you name, and assume S3AssumeRoleArn
  • launch, tag, describe and terminate EC2 instances and volumes tagged for this stack. These permissions are reserved for multi-node deployments

The template does not grant permissions for the Kinesis or SQS pull sources. If you turn either one on, attach these permissions to the node role yourself:

  • Kinesis: kinesis:ListShards, kinesis:GetShardIterator and kinesis:GetRecords.
  • SQS: sqs:ReceiveMessage and sqs:DeleteMessage, plus s3:GetObject on the bucket the notifications point to.

The Kinesis and Kafka sources record how far they have read in your raw bucket, under the ingest-checkpoints/ prefix. If you turn either one on, also grant the node role s3:GetObject and s3:PutObject on that prefix.

See IAM and permissions.

Shipper compatibility

The node accepts OTLP (HTTP with protobuf, and gRPC), Elasticsearch _bulk, Splunk HEC (there is no Splunk forwarder receiver), Fluent Forward, Vector native, Loki push, GELF, Amazon Data Firehose, Kinesis, SQS with S3 event notifications, and Kafka. OTLP over HTTP with a JSON payload is rejected with 415, so configure your exporter to send protobuf. There is no native syslog listener. rsyslog can send through its Elasticsearch output instead. See Supported sources.