System requirements
The AWS resources, instance types, storage, network ports and permissions an OBSESC deployment needs.
OBSESC runs as an Amazon Machine Image (AMI) from AWS Marketplace. You launch it with a CloudFormation template inside your own AWS account and VPC. This page lists what that deployment needs.
Platform
| Item | Requirement |
|---|---|
| Delivery | AWS Marketplace AMI, deployed with the OBSESC CloudFormation template |
| Architecture | x86_64 |
| Base operating system | Amazon Linux 2023 (built into the AMI) |
| Instance families | c6in (network-optimised compute) |
Instance types
The template accepts these instance types for a node:
| Instance type | Notes |
|---|---|
c6in.2xlarge | Default |
c6in.4xlarge | |
c6in.8xlarge | |
c6in.12xlarge | |
c6in.16xlarge | |
c6in.24xlarge |
Each node serves the web console and API on its query port, and runs a local Prometheus that evaluates OBSESC’s built-in alert rules.
Storage
EBS volumes
The stack attaches three encrypted gp3 volumes to each node. All three use your KMS key.
| Volume | Mount point | Default size | Allowed size | Provisioned performance |
|---|---|---|---|---|
| Write-ahead log (WAL) | /var/lib/obsesc/wal | 100 GiB | 20–16,384 GiB | 3,000 IOPS, 250 MB/s |
| Summaries | /var/lib/obsesc/summary | 500 GiB | 100–16,384 GiB | 6,000 IOPS, 500 MB/s |
| Anomaly data | /var/lib/obsesc/anomaly | 100 GiB | 20–16,384 GiB | 3,000 IOPS, 250 MB/s |
The AMI’s root volume is 30 GiB of gp3. OBSESC keeps data on EBS that makes the console fast; the original events stay in S3 in open formats. By default (EnableDataVolumeSnapshots=true) the stack takes a daily snapshot of every data volume and keeps 7.
If your KMS key is customer-managed and snapshots are enabled, the key policy must allow the stack’s snapshot (DLM) role to use the key. Granting access on the IAM side alone is not enough.
S3 bucket
Your raw events are stored in an S3 bucket that you own:
- Bring your own bucket (default): pass
RawBucketName. You manage its lifecycle rules. Tell OBSESC what they are understorage.lifecycle(see Configuration reference). - Let the stack create it: set
CreateRawBucket=true. The bucket is created with SSE-KMS, public access blocked and a Retain deletion policy. It moves objects from Standard to Standard-IA (default 30 days, minimum 30) and then to Glacier Instant Retrieval (default 180 days). - Object Lock is available only on a bucket the stack creates (
EnableObjectLock=true). S3 only allows Object Lock to be turned on when a bucket is created. - The bucket may live in another account or Region. Use
RawBucketAccountId,S3AssumeRoleArnandS3Region. Cross-Region storage adds inter-Region data transfer to every read and write.
Use one OBSESC deployment per bucket. OBSESC keeps its Iceberg catalog and deployment metadata at the root of the bucket.
Required stack parameters
| Parameter | What to provide |
|---|---|
AmiId | The OBSESC AMI ID from your Marketplace subscription |
RawBucketName | The S3 bucket name for your raw events, for example my-obsesc-bucket |
VpcId | The VPC to deploy into |
SubnetId | The subnet for the first node |
KmsKeyArn | A customer-managed KMS key ARN, for example arn:aws:kms:us-east-1:123456789012:key/... |
The stack creates named IAM resources, so deploy it with CAPABILITY_NAMED_IAM. Optional parameters are listed in the Configuration reference and in Deploying from AWS Marketplace.
Network
Inbound ports
The stack’s node security group opens these ports to AllowedIngestCidr (default 10.0.0.0/8):
| Port | Service |
|---|---|
| 4317/tcp | OTLP/gRPC ingest |
| 4318/tcp | OTLP/HTTP ingest |
| 9200/tcp | Elasticsearch _bulk ingest |
| 18080/tcp | Web console, API and the /ready health check |
The stack also allows 9100/tcp between members of the node security group only. It is reserved for multi-node deployments; contact us via the contact page about those.
The node also listens on these ports, but the default security group does not open them. Add ingress rules yourself for the ones you use:
| Port | Service | Enabled by default |
|---|---|---|
| 8088/tcp | Splunk HEC | Yes |
| 24224/tcp | Fluent Forward | Yes |
| 9000/tcp | Vector native | Yes |
| 3100/tcp | Loki push | No (ingest.loki.enabled) |
| 8555/tcp | Firehose HTTP endpoint | No (ingest.firehose.enabled) |
| 12201/tcp and udp | GELF | No (ingest.gelf.enabled) |
Console address
The stack’s UiUrl output is the address to open the console. Without the optional load balancer, it’s the node’s private address on port 18080.
Optional internal load balancer
With EnableUiLoadBalancer=true, the stack puts an internal Application Load Balancer in front of the node’s console and API port:
- The load balancer needs at least two subnets in different Availability Zones (
UiAlbSubnetIds). - It accepts traffic on ports 80 and 443 from
UiAllowedCidr. WithUiCertificateArnset, it serves HTTPS on 443 and redirects 80 to 443. - It reaches the node on port 18080, and uses
GET /readyas its health check. - Optionally,
UiPrivateZoneIdandUiHostnamegive it a name in your private Route 53 zone.
Console sign-in
With EnableUiPerUserRbac=true, people sign in to the console through your identity provider, and each user gets their own role. This option needs:
EnableUiLoadBalancer=trueandUiCertificateArn(sign-in works only over HTTPS)AuthSecretArn- your identity provider’s details:
UiOidcIssuerUrl,UiOidcClientIdand theAlbOidc*parameters NodeApiOidcAdminValue, the identity that gets theadminrole
Set NodeApiOidcViewerValue to * so that everyone else who signs in gets the viewer role. Otherwise they can sign in but can’t see anything. The load balancer needs outbound HTTPS to your identity provider, and the stack adds that rule for you.
If you set AuthSecretArn without console sign-in, the console still loads, but it needs an API token before it can show any data.
EnableNodeApiOidc=true adds a separate sign-in listener on port 8443 for the API. It has the same requirements as console sign-in.
Outbound access
Each node must be able to reach these AWS services, through a NAT gateway or VPC endpoints:
- Amazon S3 (raw events and catalog)
- AWS KMS
- AWS STS (needed when you use
S3AssumeRoleArn, or when the bucket owner is looked up at startup) - AWS Secrets Manager and SSM Parameter Store, if you use
AuthSecretArnor the TLS parameters - AWS Marketplace Metering
- Amazon EC2 instance metadata (IMDS), for instance-role credentials
With console sign-in, the load balancer must also be able to reach your identity provider over HTTPS.
To deliver OBSESC’s built-in alerts, set AlertmanagerEndpoint to an Alertmanager every node can reach.
The node role includes the AWS managed policy AmazonSSMManagedInstanceCore, so you can reach a node with Session Manager and no SSH key.
IAM
The stack creates a node role. It is scoped to:
- read, write and delete objects in the raw bucket, and list that bucket
- use the KMS key you supply
- call
aws-marketplace:MeterUsage - register itself with the stack’s load balancer, when you use one
- optionally, read the specific Secrets Manager secret and SSM parameters you name, and assume
S3AssumeRoleArn - launch, tag, describe and terminate EC2 instances and volumes tagged for this stack. These permissions are reserved for multi-node deployments
The template does not grant permissions for the Kinesis or SQS pull sources. If you turn either one on, attach these permissions to the node role yourself:
- Kinesis:
kinesis:ListShards,kinesis:GetShardIteratorandkinesis:GetRecords. - SQS:
sqs:ReceiveMessageandsqs:DeleteMessage, pluss3:GetObjecton the bucket the notifications point to.
The Kinesis and Kafka sources record how far they have read in your raw bucket, under the ingest-checkpoints/ prefix. If you turn either one on, also grant the node role s3:GetObject and s3:PutObject on that prefix.
See IAM and permissions.
Shipper compatibility
The node accepts OTLP (HTTP with protobuf, and gRPC), Elasticsearch _bulk, Splunk HEC (there is no Splunk forwarder receiver), Fluent Forward, Vector native, Loki push, GELF, Amazon Data Firehose, Kinesis, SQS with S3 event notifications, and Kafka. OTLP over HTTP with a JSON payload is rejected with 415, so configure your exporter to send protobuf. There is no native syslog listener. rsyslog can send through its Elasticsearch output instead. See Supported sources.