During the session we will describe common methods used to create a Hybrid Cloud with AWS. We step through successful operational models, how to get started, and tools to simplify operations. We will explore topics such as networking, directories, DNS, and security. Importantly, we will cover ongoing operational and management practices.
Speaker: Phil Barlow, Solutions Architect, Amazon Web Services
Featured Customer - AMP
4. VPC Subnet
Availability Zone
Security group
VPC subnet
Availability Zone
Security group
Connectivity
1. Most Specific Route
2. Direct Connect
3. Static VPN
4. Dynamic VPN
5. Shortest AS Path (BGP)
Your
data center
Data center router
Customer
Router
Servers
IPSec VPN
Peering Point
AWS DX routers
Virtual
Gateway
6. VPC Design Considerations
Production
• Trusted Zones
• Managed Independently
• SG will govern Ingress &
Egress based on App
• A Proxy Layer could simplify
• Be flexible with your VPC
design
Pre Production Dev & Test
Corporate
data center
7. Availability Zone
Availability Zone
Hybrid DNS Architecture
Corporate
data center
Users
On Prem DNS
Forwarders
Virtual
Gateway
AWS Directory
Service
Customer
Gateway
VPC
Provided DNS
Route 53
Private
Hosted Zone
AWS Directory
Service
8. Hybrid Access Control
AWS IAM
AWS Directory
Service
• Utilise existing IDM policies
• Provide SSO to Apps, Console
and API’s
• AD Connector
• Enterprise Federation with
SAML 2.0 compliant IdP
9. Hybrid Visibility
AWS Partner & Opensource
Metric and
Performance
Data
Security Data
Analytics
AWS
CloudTrail
Amazon
CloudWatch
Logs
Amazon
Elasticsearch
Amazon
Kinesis
VPC
Flow logs
AWS
Lambda
Amazon
CloudWatch
20. Tagline or document title20 |
Rajiv Sri Skantha Rajah,
Head of Technology Architecture, CTO Function
Hybrid
Cloud
Evolution
21. Who we are…
4000
financial advisers
5400
employees
800,000
shareholders
4 million+
customers
$226 bn
assets under mgmt
Helping people own tomorrow
Reference: 2015 annual report
22. DevOps Lifecycle
Leverage Cloud (Private and Public) services as an innovation platform which can meet the
needs for rapid experimentation using new / disruptive technologies… through high degrees of
automation
Business
Developers
(application)
IT Operations
(Technology)
Enterprise
Agility
IT
AgilityCommodity Services e.g. Compute, Hosting, Network, Storage etc…
Foundational Services e.g. Assurance, IDAM, Integration, etc…
Technology Services Application Services Platform Services
Service Interface e.g. Self Service Portal, API’s
Cloud Services
Innovation
4
3
2
1 Customer Insight Driven Design
Customers
Business
Owners
Development /
Test
Operations /
Production
GrowthValue
• Using customer insight to
evolve our solutions
• Incremental deployment with
shorter cycle times from
experimentation, prototyping
and through to production
scale
• Snap in and out technical
services to deliver business
outcomes
• Strengthen core foundational
services to provide a stable
platform to enable the
adoption of new technology
services
4
3
2
1
23. How we started our Cloud 1.0 Journey?
Cloud Program
Migration
Factory
Australian Region
opened for business
2015…
Cloud Program
Completes
Cloud
Program
Initiated
Commence build of
migration factory
Migrated a range of production
low value systems
~70%
of midrange
hosted across Private
and Public Cloud
~30%
Reduction in
Infrastructure
Costs
Focused on cost optimisation, elastic compute and
consumption based pricing…contestability was priority..
portability was important
Mode 1
moves to
BAU
Mode 2
continues
journey
2012…
Our journey
Begins
Incubator approach to test, learn
and validate solution and controls
...The question is no longer:
‘How do I move to the cloud?’
Detailed assessment
applications for
suitability
Migrated a range of production
high value systems
Define
migration
scope
Zone 2
Onshore - Virtual Private Cloud
Zone 1
Onsite - Private Cloud
Zone 0
Traditional Managed Services
Zone 3
Onshore - Virtual Private Cloud
Zone 4
Onshore - Virtual Private Cloud
Production,
Critical
Non-prod,
non-critical
Isolated Lab
Confidential
Data
Public Data
Cloud
Zones (IaaS)
Workload
Types
Data
Classification
Our implementation of a Hybrid Cloud environment comprised
of multiple zones based on service levels and technical
capabilities…workloads were assessed and placed into the most
appropriate zones
‘Now that I’m in the
cloud, how do I make
sure I’ve optimized my
investment and risk
exposure”
24. Cloud 2.0 is shifting to include opportunities relating to business agility and
developer productivity… Cloud native workloads take maximum advantage of
the benefits of cloud
Cloud 2.0….Evolution and Maturing of Cloud…
Automation
Auto Scaling
Auto Healing
Cloud Centre
of Excellence
(COE)
• Identify opportunities to
further drive efficiencies
Cloud Centre of Excellence
-Keep abreast of new cloud services
-Support the automation build factory
-Educate and train teams on cloud best practises
Cloud 2.0 first principle Migrate AEM to Mode 2 operation
One Click
Deploy
100%
Re-Architected our
integration platform
25. § Leverage cloud as an innovation
platform… shift the culture
§ Nothing hand crafted… all automated
§ Security by design…
§ Application AND Infrastructure is versioned
together
§ Consistency is key… across all
environments
§ Architect for failure… chaos engineering
Key Insights / Learnings
26.
27. A Hybrid Car uses 2 Engines.
I give one Petrol and the other Electricity.
They both deliver propulsion but the way it is delivered has
different characteristics.
I have a policy for when either is used:
Integrate the Infrastructure and Integrate the Orchestration.
Parting Thought
28. AWS Training & Certification
Intro Videos & Labs
Free videos and labs to
help you learn to work
with 30+ AWS services
– in minutes!
Training Classes
In-person and online
courses to build
technical skills –
taught by accredited
AWS instructors
Online Labs
Practice working with
AWS services in live
environment –
Learn how related
services work
together
AWS Certification
Validate technical
skills and expertise -
identify qualified IT
talent or show you
are AWS cloud ready
Learn more: aws.amazon.com/training
29. Your Training Next Steps:
ü Visit the AWS Training & Certification pod to discuss your
training plan & AWS Summit training offer
ü Register & attend AWS instructor led training
ü Get Certified
AWS Certified? Visit the AWS Summit Certification Lounge to pick up your swag
Learn more: aws.amazon.com/training