SlideShare a Scribd company logo
1 of 31
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Landing Zones
What?, Why?, and How?
Joe Healy
Principal Consultant
AWS
June 13, 2017 Zachary Kelly
AVP Enterprise Engineering
1901 Group
Migration & Transformation Track
Tuesday, June 13th - Room 201
8:45 - 9:35 AM
119706 - My CIO Says That We are Going All-In and Migrating to AWS?
Now What?
9:40 - 10:30 AM
125086 - Hybrid as a Stepping Stone: It’s Not All or Nothing for Your
Cloud Transformation Journey
2:00 - 2:50 PM
119707 - Why do I need to plan for Security, Risk, & Compliance before
migrating to AWS?
3:30 - 4:20 PM
119708 - How Can I Build a Landing Zone & Extend my Operations into
AWS to Support my Migration?
4:30 - 5:20 PM
119709 - What Organizational & Governance Changes do I Need to Make
Prior to Migrating to AWS?
Three Phase Journey
Assess
Readiness
Assessment
Readiness &
Planning
Migrations
month months months
What is a Landing Zone and do I need one?
H
- A configured secure enterprise multi-account AWS
environment based on best practices
- A foundation for your Enterprise migration journey
- An environment that allows for iteration & extension over time
Landing Zone – Account Structure
Outcomes
• Billing Visibility
• Environment Isolation
• Small Blast Radius
• Centralized Services
• Centralized Logs
Landing Zone – Identity & Access Management
Landing Zone – VPC Design
Multi-AZ
Public
vs
Private
Ingress/
Egress
Points
Landing Zone – Networking
Landing Zone – Continuous Compliance
Event
Driven
Deployment
Pipeline
Holistic
Inspection
Build Buy
VS
Implementation Paths
18
There’s an Elephant in the Room…
19
Purpose
▶ Reference architectures and best practices are often
demonstrated…
▶ …but how to successfully perform Pre-Migration Discovery and
Landing Zone Buildout is less frequently discussed
▶ This presentation focuses on a few key activities that 1901 Group
has found leads to successful cloud migration
20
Benefits
▶ CMMI ML3 Development
▶ CMMI ML3 Services
▶ ISO 9001:2008
▶ FedRAMP authorized MSP
Certifications
Differentiators
▶ Enterprise IT “as a service”
▶ Consumption-based delivery
models
▶ Integrated processes and
technology platform
▶ Pricing model includes all facility,
hardware, software and services
▶ Increased infrastructure
performance
▶ Improved situational awareness
of critical services
▶ Lower cost of operations
Infrastructure
▶ Storage management
▶ Network management
▶ Server & Virtualization management
▶ Database Administration
▶ Mobility management
▶ Unified Communications management
Security
▶ Security Information and Event
Management (SIEM)
▶ Threat Detection
▶ Vulnerability Management
Applications
▶ Agile Software Development
▶ Application O&M
▶ DevOps
▶ Private Cloud Storage
▶ Cloud Migration
▶ Cloud application monitoring and
management
Cloud
Services
1901 Group at a Glance – Booth #415
Customers
▶ Dept of Education
▶ Dept of Interior
▶ Dept of Justice
▶ Dignity Healthcare
▶ DISA
▶ FERC
▶ SBA
▶ U.S. Army
▶ USAB
▶ USDA
▶ VDOT
+ Others
1st IT Utility
▶ Established in 2009 as Managed
Service Provider
▶ 14,000 sq ft operations center in
Blacksburg, VA – combination of
talent, quality of life, and
reasonable cost of living
▶ FedRAMP-compliant with multiple
ATOs and security agreements with
federal clients
▶ Over 20 clients in public sector and
commercial
▶ 100% of CPARs are “Excellent”.
D&B Open Ratings of 94 out of 100
▶ Over 6,000 calls per month, over
10,900 Incident and Request tickets
per month
▶ Over 3,000 Incident tickets per
month proactively generated and
resolved by automated monitoring
▶ Device based GSA schedule
21
1901 Group Cloud Factory: A Repeatable Blueprint for Cloud Transformation
22
The Foundation is a Great Team
Build Multi-
Functional
Team
Learn
PartnerTool Up
• Explore Hands-On
• Use Services Internally
• Earn Certifications
• Receive Training
• Receive Mentoring
23
Pre-Migration Discovery: AWS Migration Strategy
24
Pre-Migration Discovery: Process and Documents
25
Pre-Migration Discovery: Technology Families with Migration Strategy
Decomposing Discovery
data into Technology
Families and AWS
Migration Strategies
provides a high-level view
of project complexity:
• Creates natural Best Practice
work blocks for project and
resource planning
• Visual representation clearly
communicates intended
activities to business and
technical stakeholders
• Facilitates risk identification
toward risk management
strategies
Technology Families Mapped to AWS Migration Strategy
Technology Family Migration Strategy
General AWS Environment AWS Best Practice Reference Architecture
Customer Enterprise Services and Tools Native AWS, Repurchase, Rehost, Retire
Required Local Servers and Storage Retain
"Migratable" Applications Rehost
Citrix as a Service (XenApp) Rehost
Private Storage Replatform
Solaris to Red Hat Enterprise Linux Refactor
PowerBuilder to "Generic" Platform Refactor
Public Event Website New Build
26
Risk-Based Approach to Address Issues Early and Gain Buy-in
Risk Identification and Mitigation
Risk Mitigation Approach
Heavy application dependency
entanglement
Move multiple applications in blocks, troubleshoot and update
config/code in Cloud environment
Moving off Exadata could create
data access performance issues
Add resources, refactor SQL queries and associated code, refactor
data access workflow, tune and optimize databases
Application performance issues
Add resources, optimize garbage collection, optimize session
management, destroy unreachable objects, close database
connections and statements, improve error catching
Public/Private Cloud Latency
Optimize networking, deploy local caching in Public Cloud (ex. Cloud
OnTap)
SPARC to x86 “Endian” data conversion, code refactoring, emulation (worst case)
WAN performance issues
Optimize WAN accelerators, increase circuits in case of bottlenecks,
CloudFront where applicable, code changes to reduce data transfer
load
Public Cloud Interoperability
Recommend using Azure for AD and Mobile Device Management,
do not recommend running and syncing Live/Live applications
across AWS and Azure
Oracle 12c RDBMS and Middleware
Upgrade RDBMS and Middleware software versions as needed,
make required application code changes to support upgrades
Potential for Unexpected Costs “Elasticity Engineering”
27
Landing Zone: Best Practice HA Architecture
Customer Users
Start with AWS
Reference Architecture
to enforce HA Best
Practices…
• Provides an out-of-the-box
template architecture
suitable for most HA
enterprise systems
• Minimizes “design sprawl”
by specifying proven top-
level architecture
• Provides robust “wrapper”
services for existing
applications
28
Landing Zone: Specific Implications of Migration Strategies
…then move to specific implementation details populating the reference architecture with
well-formed systems:
• Focus is on complex migration issues, not infrastructure or environment
• Decouples each Technology Family from overall environment to minimize risk and facilitate iterative rollout of services
• From here: Elasticity and automated orchestration to enforce “clean,” cost-effective environment
Technology Families Mapped to AWS Migration Strategy
Technology Family Migration Strategy Landing Zone Considerations
General AWS Environment
AWS Best Practice Reference
Architecture
AZ's, Region DR, VPC Architecture, Security
groups/access control, STIG baselines of
target OS, Secure network architecture
Customer Enterprise Services and Tools Native AWS, Repurchase, Rehost, Retire
Analyze services, Determine 1901 Group /
AWS overlap and Deploy Native AWS,
Rehost, or Retire
Required Local Servers and Storage Retain
Write data to S3/Glacier for DR and long
term storage
"Migratable" Applications Rehost
Automated cloud migration tool, EC2, EBS,
ELB
Citrix as a Service (XenApp) Rehost
Build Citrix HA environment, Deploy FIPS
compliant NetScaler in Private cloud,
Perform automated cloud migration
Private Storage Replatform
Build private storage and migrate data, AWS
DirectConnect to GovCloud
Solaris to Red Hat Enterprise Linux Refactor
Build RHEL target architecture, Middleware
and Application code updates
PowerBuilder to "Generic" Platform Refactor
Auto convert to JSF, Refactor code, Data
access changes for SQL Server
Public Event Website New Build
Lambda, S3, Rekognition, WAF, Shield,
ElastiSearch
29
Conclusions
1. Structured Pre-Migration Discovery leads to accurate and
actionable decomposition of Technology Families into AWS best
practice Migration Strategies
2. The Migration Strategy view leads to specific Landing Zone
implications and requirements, guiding detail Landing Zone design
3. When built within AWS best practice architectures, the resulting
Cloud Landing Zone reduces risk, ensures security, high
availability, performance, scalability, and above all, migration
success
30
Let’s Go!
Thank you

More Related Content

What's hot

What's hot (20)

Introduction to Microsoft Azure
Introduction to Microsoft AzureIntroduction to Microsoft Azure
Introduction to Microsoft Azure
 
Azure Migration Program Pitch Deck
Azure Migration Program Pitch DeckAzure Migration Program Pitch Deck
Azure Migration Program Pitch Deck
 
Getting started on your AWS migration journey
Getting started on your AWS migration journeyGetting started on your AWS migration journey
Getting started on your AWS migration journey
 
App Modernisation with Microsoft Azure
App Modernisation with Microsoft AzureApp Modernisation with Microsoft Azure
App Modernisation with Microsoft Azure
 
Azure Security Overview
Azure Security OverviewAzure Security Overview
Azure Security Overview
 
On-premise to Microsoft Azure Cloud Migration.
 On-premise to Microsoft Azure Cloud Migration. On-premise to Microsoft Azure Cloud Migration.
On-premise to Microsoft Azure Cloud Migration.
 
Large-Scale AWS Migrations with CSC
Large-Scale AWS Migrations with CSCLarge-Scale AWS Migrations with CSC
Large-Scale AWS Migrations with CSC
 
AWS Cloud Adoption Framework
AWS Cloud Adoption Framework AWS Cloud Adoption Framework
AWS Cloud Adoption Framework
 
CAF presentation 09 16-2020
CAF presentation 09 16-2020CAF presentation 09 16-2020
CAF presentation 09 16-2020
 
VMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPTVMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPT
 
AWS Cloud Security
AWS Cloud SecurityAWS Cloud Security
AWS Cloud Security
 
Migrating On-Premises Databases to Cloud
Migrating On-Premises Databases to CloudMigrating On-Premises Databases to Cloud
Migrating On-Premises Databases to Cloud
 
Migrate to Microsoft Azure with Confidence
Migrate to Microsoft Azure with ConfidenceMigrate to Microsoft Azure with Confidence
Migrate to Microsoft Azure with Confidence
 
Aws
AwsAws
Aws
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security Overview
 
AWS Partner Webcast - Data Center Migration to the AWS Cloud
AWS Partner Webcast - Data Center Migration to the AWS CloudAWS Partner Webcast - Data Center Migration to the AWS Cloud
AWS Partner Webcast - Data Center Migration to the AWS Cloud
 
SK Telecom - 망관리 프로젝트 TANGO의 오픈소스 데이터베이스 전환 여정 - 발표자 : 박승전, Project Manager, ...
SK Telecom - 망관리 프로젝트 TANGO의 오픈소스 데이터베이스 전환 여정 - 발표자 : 박승전, Project Manager, ...SK Telecom - 망관리 프로젝트 TANGO의 오픈소스 데이터베이스 전환 여정 - 발표자 : 박승전, Project Manager, ...
SK Telecom - 망관리 프로젝트 TANGO의 오픈소스 데이터베이스 전환 여정 - 발표자 : 박승전, Project Manager, ...
 
Azure security architecture
Azure security architectureAzure security architecture
Azure security architecture
 
Azure 101
Azure 101Azure 101
Azure 101
 
Azure cloud migration simplified
Azure cloud migration simplifiedAzure cloud migration simplified
Azure cloud migration simplified
 

Similar to How Can I Build a Landing Zone & Extend my Operations into AWS to Support my Migration? | AWS Public Sector Summit 2017

Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
Amazon Web Services
 
Aberdeen Oil & Gas Event - Cloud Adoption Framework
Aberdeen Oil & Gas Event - Cloud Adoption FrameworkAberdeen Oil & Gas Event - Cloud Adoption Framework
Aberdeen Oil & Gas Event - Cloud Adoption Framework
Amazon Web Services
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud Strategy
Amit Gatenyo
 

Similar to How Can I Build a Landing Zone & Extend my Operations into AWS to Support my Migration? | AWS Public Sector Summit 2017 (20)

Application Migrations at Scale
Application Migrations at ScaleApplication Migrations at Scale
Application Migrations at Scale
 
Application Migrations at Scale
Application Migrations at ScaleApplication Migrations at Scale
Application Migrations at Scale
 
Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017
 
(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS
 
220929-Presentation-business case for moving to the cloud.pptx
220929-Presentation-business case for moving to the cloud.pptx220929-Presentation-business case for moving to the cloud.pptx
220929-Presentation-business case for moving to the cloud.pptx
 
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
Migrating Thousands of Workloads to AWS at Enterprise Scale – Chris Wegmann, ...
 
Migrate and Manage Workloads with Apps Associates
Migrate and Manage Workloads with Apps AssociatesMigrate and Manage Workloads with Apps Associates
Migrate and Manage Workloads with Apps Associates
 
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout SessionAccenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
 
Logicalis Cloud Briefing
Logicalis Cloud BriefingLogicalis Cloud Briefing
Logicalis Cloud Briefing
 
Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
Track 3 Session 4_企業工作負載遷移至 AWS 的最佳實踐
 
ZiniosEdge Managed Cloud and DevOps
ZiniosEdge Managed Cloud and DevOpsZiniosEdge Managed Cloud and DevOps
ZiniosEdge Managed Cloud and DevOps
 
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
(ENT206) Migrating Thousands of Workloads to AWS at Enterprise Scale | AWS re...
 
Financial impact of Cloud Computing
Financial impact of Cloud ComputingFinancial impact of Cloud Computing
Financial impact of Cloud Computing
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
CSRA’s Migration to AWS GovCloud (US): An All-In Case Study | AWS Public Sect...
CSRA’s Migration to AWS GovCloud (US): An All-In Case Study | AWS Public Sect...CSRA’s Migration to AWS GovCloud (US): An All-In Case Study | AWS Public Sect...
CSRA’s Migration to AWS GovCloud (US): An All-In Case Study | AWS Public Sect...
 
Aberdeen Oil & Gas Event - Cloud Adoption Framework
Aberdeen Oil & Gas Event - Cloud Adoption FrameworkAberdeen Oil & Gas Event - Cloud Adoption Framework
Aberdeen Oil & Gas Event - Cloud Adoption Framework
 
Future of Enterprise IT
Future of Enterprise IT Future of Enterprise IT
Future of Enterprise IT
 
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud Strategy
 
Introduction to Microsoft on AWS
Introduction to Microsoft on AWS Introduction to Microsoft on AWS
Introduction to Microsoft on AWS
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 

How Can I Build a Landing Zone & Extend my Operations into AWS to Support my Migration? | AWS Public Sector Summit 2017

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Landing Zones What?, Why?, and How? Joe Healy Principal Consultant AWS June 13, 2017 Zachary Kelly AVP Enterprise Engineering 1901 Group
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8. Migration & Transformation Track Tuesday, June 13th - Room 201 8:45 - 9:35 AM 119706 - My CIO Says That We are Going All-In and Migrating to AWS? Now What? 9:40 - 10:30 AM 125086 - Hybrid as a Stepping Stone: It’s Not All or Nothing for Your Cloud Transformation Journey 2:00 - 2:50 PM 119707 - Why do I need to plan for Security, Risk, & Compliance before migrating to AWS? 3:30 - 4:20 PM 119708 - How Can I Build a Landing Zone & Extend my Operations into AWS to Support my Migration? 4:30 - 5:20 PM 119709 - What Organizational & Governance Changes do I Need to Make Prior to Migrating to AWS?
  • 9. Three Phase Journey Assess Readiness Assessment Readiness & Planning Migrations month months months
  • 10. What is a Landing Zone and do I need one? H - A configured secure enterprise multi-account AWS environment based on best practices - A foundation for your Enterprise migration journey - An environment that allows for iteration & extension over time
  • 11. Landing Zone – Account Structure Outcomes • Billing Visibility • Environment Isolation • Small Blast Radius • Centralized Services • Centralized Logs
  • 12. Landing Zone – Identity & Access Management
  • 13. Landing Zone – VPC Design Multi-AZ Public vs Private Ingress/ Egress Points
  • 14. Landing Zone – Networking
  • 15. Landing Zone – Continuous Compliance Event Driven Deployment Pipeline Holistic Inspection
  • 17.
  • 18. 18 There’s an Elephant in the Room…
  • 19. 19 Purpose ▶ Reference architectures and best practices are often demonstrated… ▶ …but how to successfully perform Pre-Migration Discovery and Landing Zone Buildout is less frequently discussed ▶ This presentation focuses on a few key activities that 1901 Group has found leads to successful cloud migration
  • 20. 20 Benefits ▶ CMMI ML3 Development ▶ CMMI ML3 Services ▶ ISO 9001:2008 ▶ FedRAMP authorized MSP Certifications Differentiators ▶ Enterprise IT “as a service” ▶ Consumption-based delivery models ▶ Integrated processes and technology platform ▶ Pricing model includes all facility, hardware, software and services ▶ Increased infrastructure performance ▶ Improved situational awareness of critical services ▶ Lower cost of operations Infrastructure ▶ Storage management ▶ Network management ▶ Server & Virtualization management ▶ Database Administration ▶ Mobility management ▶ Unified Communications management Security ▶ Security Information and Event Management (SIEM) ▶ Threat Detection ▶ Vulnerability Management Applications ▶ Agile Software Development ▶ Application O&M ▶ DevOps ▶ Private Cloud Storage ▶ Cloud Migration ▶ Cloud application monitoring and management Cloud Services 1901 Group at a Glance – Booth #415 Customers ▶ Dept of Education ▶ Dept of Interior ▶ Dept of Justice ▶ Dignity Healthcare ▶ DISA ▶ FERC ▶ SBA ▶ U.S. Army ▶ USAB ▶ USDA ▶ VDOT + Others 1st IT Utility ▶ Established in 2009 as Managed Service Provider ▶ 14,000 sq ft operations center in Blacksburg, VA – combination of talent, quality of life, and reasonable cost of living ▶ FedRAMP-compliant with multiple ATOs and security agreements with federal clients ▶ Over 20 clients in public sector and commercial ▶ 100% of CPARs are “Excellent”. D&B Open Ratings of 94 out of 100 ▶ Over 6,000 calls per month, over 10,900 Incident and Request tickets per month ▶ Over 3,000 Incident tickets per month proactively generated and resolved by automated monitoring ▶ Device based GSA schedule
  • 21. 21 1901 Group Cloud Factory: A Repeatable Blueprint for Cloud Transformation
  • 22. 22 The Foundation is a Great Team Build Multi- Functional Team Learn PartnerTool Up • Explore Hands-On • Use Services Internally • Earn Certifications • Receive Training • Receive Mentoring
  • 23. 23 Pre-Migration Discovery: AWS Migration Strategy
  • 25. 25 Pre-Migration Discovery: Technology Families with Migration Strategy Decomposing Discovery data into Technology Families and AWS Migration Strategies provides a high-level view of project complexity: • Creates natural Best Practice work blocks for project and resource planning • Visual representation clearly communicates intended activities to business and technical stakeholders • Facilitates risk identification toward risk management strategies Technology Families Mapped to AWS Migration Strategy Technology Family Migration Strategy General AWS Environment AWS Best Practice Reference Architecture Customer Enterprise Services and Tools Native AWS, Repurchase, Rehost, Retire Required Local Servers and Storage Retain "Migratable" Applications Rehost Citrix as a Service (XenApp) Rehost Private Storage Replatform Solaris to Red Hat Enterprise Linux Refactor PowerBuilder to "Generic" Platform Refactor Public Event Website New Build
  • 26. 26 Risk-Based Approach to Address Issues Early and Gain Buy-in Risk Identification and Mitigation Risk Mitigation Approach Heavy application dependency entanglement Move multiple applications in blocks, troubleshoot and update config/code in Cloud environment Moving off Exadata could create data access performance issues Add resources, refactor SQL queries and associated code, refactor data access workflow, tune and optimize databases Application performance issues Add resources, optimize garbage collection, optimize session management, destroy unreachable objects, close database connections and statements, improve error catching Public/Private Cloud Latency Optimize networking, deploy local caching in Public Cloud (ex. Cloud OnTap) SPARC to x86 “Endian” data conversion, code refactoring, emulation (worst case) WAN performance issues Optimize WAN accelerators, increase circuits in case of bottlenecks, CloudFront where applicable, code changes to reduce data transfer load Public Cloud Interoperability Recommend using Azure for AD and Mobile Device Management, do not recommend running and syncing Live/Live applications across AWS and Azure Oracle 12c RDBMS and Middleware Upgrade RDBMS and Middleware software versions as needed, make required application code changes to support upgrades Potential for Unexpected Costs “Elasticity Engineering”
  • 27. 27 Landing Zone: Best Practice HA Architecture Customer Users Start with AWS Reference Architecture to enforce HA Best Practices… • Provides an out-of-the-box template architecture suitable for most HA enterprise systems • Minimizes “design sprawl” by specifying proven top- level architecture • Provides robust “wrapper” services for existing applications
  • 28. 28 Landing Zone: Specific Implications of Migration Strategies …then move to specific implementation details populating the reference architecture with well-formed systems: • Focus is on complex migration issues, not infrastructure or environment • Decouples each Technology Family from overall environment to minimize risk and facilitate iterative rollout of services • From here: Elasticity and automated orchestration to enforce “clean,” cost-effective environment Technology Families Mapped to AWS Migration Strategy Technology Family Migration Strategy Landing Zone Considerations General AWS Environment AWS Best Practice Reference Architecture AZ's, Region DR, VPC Architecture, Security groups/access control, STIG baselines of target OS, Secure network architecture Customer Enterprise Services and Tools Native AWS, Repurchase, Rehost, Retire Analyze services, Determine 1901 Group / AWS overlap and Deploy Native AWS, Rehost, or Retire Required Local Servers and Storage Retain Write data to S3/Glacier for DR and long term storage "Migratable" Applications Rehost Automated cloud migration tool, EC2, EBS, ELB Citrix as a Service (XenApp) Rehost Build Citrix HA environment, Deploy FIPS compliant NetScaler in Private cloud, Perform automated cloud migration Private Storage Replatform Build private storage and migrate data, AWS DirectConnect to GovCloud Solaris to Red Hat Enterprise Linux Refactor Build RHEL target architecture, Middleware and Application code updates PowerBuilder to "Generic" Platform Refactor Auto convert to JSF, Refactor code, Data access changes for SQL Server Public Event Website New Build Lambda, S3, Rekognition, WAF, Shield, ElastiSearch
  • 29. 29 Conclusions 1. Structured Pre-Migration Discovery leads to accurate and actionable decomposition of Technology Families into AWS best practice Migration Strategies 2. The Migration Strategy view leads to specific Landing Zone implications and requirements, guiding detail Landing Zone design 3. When built within AWS best practice architectures, the resulting Cloud Landing Zone reduces risk, ensures security, high availability, performance, scalability, and above all, migration success