SlideShare une entreprise Scribd logo
1  sur  86
Télécharger pour lire hors ligne
A  Pragmatic  Approach  to  
Workload  Migrations
Carlos  Conde  – Technology  Evangelist
Many	
  enterprises	
  worry	
  that	
  these	
  are	
  the	
  only	
  two	
  choices:
Build  a  
“Private” Cloud
Rip  everything  out  
and  move  to  AWS
#1 #2
Cloud	
  isn’t	
  an	
  “All	
  or	
  Nothing”	
  choice
Corporate  
Data  Centers
On-­Premises  
Resources
Cloud  
Resources
Integration
SPEED  &  AGILITY
Infrastructure  in  minutes,  not  weeks.
COST  REDUCTION
50  price  reductions  since  2006.
Replace  capital  expenditure  with  variable  expense.
AWS  Assurance  Programs
aws.amazon.com /  compliance
FOCUS  ON  YOUR  BUSINESS
No  time  &  resources  spent  on  undifferentiated  IT.
Prepare  full  migration  to  AWS.
HYBRID  WORKLOADS
Dev &  Test  environments    •    Burst  capacity •    
Highly  secure  apps •    App  migration    •    Storage  &  
Archiving    •    Disaster  recovery    •    Production  app  
enrichment    •    Load  testing    •    Remote  monitoring    •    
etc.
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Hypervisors AMIs,  EC2  instances
Access  Control IAM,  Directory  Services
Data  storage  &  Applications
Development  &  Operations
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Oracle  Secure  
Backup  Module
Oracle  RMan Ú Amazon  S3
RESTORE  TIMES  REDUCED  FROM  15  TO  2½  HOURS
Amazon  
Storage  Gateway
Virtual  tape  library
On-­premises  snapshots  to  AWS
AWS  Virtual  Private  Network  (IPSec VPN)
o IPSec hardware  VPN  connection  
Supported  VPN  appliances:  
https://aws.amazon.com/vpc/faqs/#C9
o Encryption  and  Validation
o Private  RFC  1918  Addressing
o Uses  Border  Gateway  Protocol  (BGP)  
for  routing  and  fail-­over
o VPN  Service  provides  managed  
redundant  end-­points
http://docs.aws.amazon.com/AmazonVPC/latest/UserGuide
/VPC_VPN.html
Virtual
Gateway
Corporate	
  
data	
  center
Users
Data	
  center	
  router
Servers
Internet
IPSec	
  VPN
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
DEV  &  TEST  ENVIRONMENTS
AWS  region
Web
layerPrivate
connection
Your  data  center
Internet
Application
layer
Database
layer
Auto  Scaling
AWS  region
Public-­facing
web  app
Public  app
w/back-­end
integration
Your  Data  
Center
Private app
w/back-­end
integration
Core/shared
services
AWS  Direct  Connect
Location
AWS  Direct  Connect
o Requires  Layer  2  single  mode  fiber  
1000BASE-­LX  or  10GBASE-­LR
o Requires  802.1Q  VLANs  across  
connection.
Ø Tagging  of  IP  traffic
o Routing  uses  BGP  A/A  or  A/P  
multipath.
o Each  DX  is  mapped  to  a  single  AWS  
Region
o Various  Partners  for  every  Region
http://aws.amazon.com/directconnect/
Virtual
Gateway
Corporate	
  
data	
  center
Users
Data	
  center	
  router
Servers
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
Customer	
  
router
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
With  AWS  regions  just  another  spoke  on  your  global  network,
it’s  easy  to  bring  the  cloud  to  you  as  you  expand  around  the  world.
US  customer  
data  center
EU-­West-­1  region
EU  customer  
data  center
Customer  MPLS  
backbone
AWS  Direct  
Connect  PoP
Ireland  or  London
US-­West-­1  region
AWS  Direct  
Connect  PoP
Virginia  or  NYC
AP-­Southeast-­1  
region
AWS  Direct  
Connect  PoP
Singapore
AP  customer  
data  center
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Access  Control IAM,  Directory  Services
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
Active  Directory  and  LDAP  
o Reduced  back-­reach  Traffic
o Reduced  Latency  for  Authentication
o Additional  Resiliency
o Enablement  of  both:      
Ø Multi-­Master  Read/Write  Domain  
Controllers
Ø Read-­only  Domain  Controllers  (RODCs)
² Requires  IPSec VPN  or  Direct  Connect  
connectivity
http://aws.amazon.com/microsoft/whitepapers/ad-­reference-­
architecture/
Virtual
Gateway
Corporate	
  
data	
  center
Users
Data	
  center	
  router
Servers
VPC	
  Subnet
Availability	
  Zone
Security	
  Groups
VPC	
  Subnet
Availability	
  Zone
Security	
  Groups
AD.Domain
Domain	
  
controller
Domain	
  
controller
Domain	
  
controller
Active	
  Directory	
  
Replication
Customer	
  
router
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
AWS  Directory  Service  
o Deploys  in  two  modes
Ø Directory  Service  Connect
Ø Simple   AD  -­ built  on  Samba  4  Active  
Directory  compatible  server
o Simplifies  IAM  Federation
Ø Avoids  complexity  and  cost  of  hosting  
SAML-­based  federation  infrastructure
Ø Acts  as  a  proxy  -­ no  data  is  stored  on  
AWS  infrastructure
Ø Supports  existing  RADIUS-­based  MFA
² Requires  IPSec VPN  or  Direct  Connect  
connectivity
http://aws.amazon.com/directoryservice/
Virtual
Gateway
data	
  center
Users
Data	
  center	
  router
Servers
VPC	
  Subnet
Availability	
  Zone
Security	
  Groups
VPC	
  Subnet
Availability	
  Zone
Security	
  Groups
AD.Domain
Domain	
  
controller
AD	
  Connector
AD	
  Connector
AD	
  Connector
Customer	
  
router
Integrate  identity  management  with  AWS
• Secure  access  to  AWS   resources  using  your  IDM
• Provide  SSO  to  AWS   Management  Console  or  API’s
• Build  your  own  SSO  federation  using  AWS  STS  service,  or
• Federate  with  on-­premise  directories  like  Active  Directory,  
TFIM,  OAM  or  another  SAML  2.0  compliant  IdP
AWS  Federation/Account  Governance  
Financial	
  users,	
  
controllers SOC/AuditorsGlobal	
  AWS	
  admin
Billing	
  account
Software	
  development
Non-­‐prod
account	
  #1
Production	
  
account	
  #1
User	
  management
account
Security	
  /	
  Audit
account
Non-­‐prod
account.	
  #2
App	
  owners
DevOps teams
Security/auditProductionDev/test/sandboxFinancial
Consolidated	
  Billing,	
  
Billing	
  Alerts
Read-­‐only	
  access	
  
for	
  all	
  accounts
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Hypervisors AMIs,  EC2  instances
Access  Control IAM,  Directory  Services
Management  
Portal  for  vCenter
Management  Pack  
for  SCOM
Systems  Manager  
for  SCVMM
AWS  Management  Portal  for  vCenter
vCenter Image  Migration
1. The  vSphere client  authorizes  
import  to  the  environment.
2. The  management  portal  verifies  
that  the  user  has  permission  to  
migrate  VMs  to  the  environment  
and  returns  a  token.
3. The  vSphere client  sends  an  
import  request  to  the  connector  
along  with  the  token.
4. The  connector  verifies  the  token.
5. The  connector  verifies  that  the  user  
has  permission  to  export  the  VM.
6. The  connector  starts  the  migration.
7. The  connector  sends  a  response  to  
the  vSphere client  with  the  import  
task  ID.
Bidirectional  Gold  Image  Replication
AWS Cloud
Legacy DC
EC2  AMIs
VM  Images
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Hypervisors AMIs,  EC2  instances
Access  Control IAM,  Directory  Services
Development  &  Operations
Integrating  AWS  into  your  operations
•
AWS  CloudWatch  provides  real-­time  insight  into  your  AWS  
services,  integrate  your  own  metrics,  create  and  act  on  alarms
• AWS  SNS  allows  integration  with  your  alerting  systems  
• Your  current  tools  still  work  – install  on  EC2  instance
• Your  tools  already  have  AWS  API  integration
• Established  processes  don’t  get  thrown  away
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
Operations  Tools  and  Monitoring
o Security  Monitoring  integration  
points  with  with  CloudTrail  and  
SIEM  Aggregator.
o Logging  with  CloudTrail  and  SNMP  
MIBs  to  SIEM  Aggregator.
o Platform  and  App  Health  to  SIEM  
Aggregator  via  agent  on  EC2  guest.
o Access  to  Patching  and  Updates  for  
AMI  by  on  premises  Update  Server.  
Virtual
Gateway
data	
  center
Users
Data	
  center	
  router
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
Update
Servers
SIEM
Aggregator
CloudTrail
CloudWatch
CloudTrail	
  S3	
  
Bucket
Customer	
  
router
Customer	
  
router
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
Continuous  Integration  and  Deployment
o Automates  application  deployments  
for  both  On-­Premise  and  AWS  EC2  
instances  with  use  of  CodeDeploy
o Reuse  existing  scripts  and  tools
Ø Bash,  PowerShell,  Chef,  
Puppet,  anything…
o Integrate  with  developer  tool  chain
Ø GitHub,  Jenkins,  CloudBees,  
TravisCI,  Eclipse…
Virtual
Gateway
data	
  center
Users
Data	
  center	
  router
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
AWS	
  CodeDeployServers
AWS	
  CloudFormation
S3 bucket
AgentAgentAgent
AgentAgentAgent
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Hypervisors AMIs,  EC2  instances
Access  Control IAM,  Directory  Services
Data  storage  &  Applications
Operations  & Automation
Customer	
  
router
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
Storage  
Expansion
o Virtual  volumes  presented  to  
local  network  iSCSI,  NFS  
and  CIFS  volumes
o Local  disk  cache  to  provide  
fast  on-­premises  access
o Gateway  side  encryption  for  
security
Virtual
Gateway
Corporate	
  
data	
  center
Users
Data	
  center	
  router
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
Amazon	
  S3
AWS	
  Storage	
  
Gateway
iSCSI
Storage	
  
Appliance
AWS	
  Storage	
  
Gateway
iSCSI
Servers
AWS	
  Storage	
  
Gateway
Customer	
  
router
AWS	
  Direct	
  Connect
Location
AWS	
  Direct	
  Connect	
  
routers
Backup  &
Archiving
o Backup  gateways  
integrated  with  Amazon  S3
o Leverage  Amazon  
S3  archival  to  
Amazon  Glacier
o Take  advantage  of  current  
investments  and  solutions  
for  options  
o De-­duplication
o Compression
o WAN  Acceleration
Virtual
Gateway
data	
  center
Users
Data	
  center	
  router
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
VPC	
  Subnet
Availability	
  Zone
Security	
  Group
Amazon	
  S3
Amazon	
  Glacier
VTL
AWS	
  Storage	
  
Gateway
iSCSI
Backup	
  
System
VTL
AWS	
  Storage	
  
Gateway
iSCSI
Servers
VTL
AWS	
  Storage	
  
Gateway
SAP  HANA
Production  ready  with  up  to  244  GiB of  
RAM  +  clustering
http://aws.amazon.com/blogs/aws/sap-­hana-­production-­ready-­on-­aws/
– SAP  HANA  Hybrid  deployment
Corporate  Data  Center
Amazon  Virtual  Private  Cloud  (VPC)
Availability  Zone
VPC  Subnet
BW  ABAP  7.31  /  NW  JAVA  7.40  
BW BI-­JAVA
DEV QA
2  X  244  GB  nodes 2  X  244  GB  nodes
BW BI-­JAVA
Internet
SAP  OSS
BA
C
A  =  Virtual  Private  Gateway
B  =  Customer  Gateway
C  =  VPN  Connection  
UAT  /  DR PRD
BW BI-­JAVA BW BI-­JAVA
Web  Disp
Web  Disp
HANA
5  X  0.5  TB  nodes 5  X  0.5  TB  nodes
SAP
HANA
SAP
HANA
SAP
HANA
SAP
HANA
Extend  Local  Applications  Capabilities:
Amazon  WorkSpaces,  WorkDocs,  Workmail
Amazon  Redshift
Amazon  ML
Amazon  CloudSearch
Amazon  CloudHSM
Amazon  SES
Amazon  SWF
…
BACKUPS  +  APPS  +  IAM
è DISASTER  RECOVERY
SCENARIO  #1
COLD  DR
SCENARIO  #2
WARM  DR
SCENARIO  #3
INTERNAL  APP
VPC Subnet B
Region
Availability Zone
Client-to-site VPN Site-to-site VPN
S3 Buckets
with Objects
Bastion Host
Internet
On-premise
Data Centre A
Remote
Desktops
AWS Direct Connect
On-premise
Data Centre B
VPC Subnet D VPC Subnet F
Databases
VPC Subnet E
Applications
VPC Subnet A
SmartSentinel
VPC Subnet G
File
Servers
VPC Subnet C
Active
Directory
Proxy Server
SCALABILITY
MAINTAINABILITY
RELIABILITY
DURABILITY
CONFIGURABILITY
…
RESILIENCE
Ability  to  cope  with  change
IF  SOMETHING  IS  HARD
REPETITION  MAKES  IT  EASIER
SIMULATION  ENVIRONMENT
FOR  CRISIS  SITUATIONS
GOOD WEATHER DOESN’T MAKE GOOD SAILORS
CLOUDFORMATION
TEMPLATE
SIMULATE FAILURES
• TERMINATE  RESOURCES
• CHANGE  SECURITY  GROUPS
• CHANGE  IAM  ROLES
• DISABLE  IAM  USER
• CHANGE  /ETC/HOSTS  FILE
• AMAZON  RDS  FAIL-­OVER  TEST
VALIDATE  YOUR  ASSUMPTIONS
PROVE  YOUR  ARCHITECTURE
KNOW  YOUR  PROCEDURES
LEARN FROM  YOUR  FAILURES
On-­
premises  
IT  
Datacenter Regions,  AZs
Cloud  
Services
Network VPC,  Direct  Connect
Hypervisors AMIs,  EC2  instances
Access  Control IAM,  Directory  Services
Data  storage  &  Applications
Operations  & Automation
HYBRID  WORKLOADS
Dev &  Test  environments    •    Burst  capacity •    
Highly  secure  apps •    App  migration    •    Storage  &  
Archiving    •    Disaster  recovery    •    Production  app  
enrichment    •    Load  testing    •    Remote  monitoring    •    
etc.
ON-­PREMISES
Experiment    Infrequently
Failure  is  expensive
Less  Innovation
Experiment  Often
Fail  quickly  at  a  low  cost
More    Innovation
$  Millions Nearly  $0
AWS  Cloud  Adoption  
Framework
Describes  the  perspectives  in  planning,  
creating,  managing,  and  supporting  a  modern  
IT  service.
Offers  practical  guidance  and  comprehensive  
guidelines  for  establishing,  developing  and  
running  AWS  cloud-­enabled  environments.
http://bit.ly/AWSCAF
People
Perspective
Process
Perspective
Security
Perspective
Maturity
Perspective
Operations
Perspective
Business
Perspective  
Platform
Perspective
Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay

Contenu connexe

Tendances

Amazon.com Corporate IT apps Migration to AWS
Amazon.com Corporate IT apps Migration to AWSAmazon.com Corporate IT apps Migration to AWS
Amazon.com Corporate IT apps Migration to AWS
Amazon Web Services
 

Tendances (20)

Amazon.com Corporate IT apps Migration to AWS
Amazon.com Corporate IT apps Migration to AWSAmazon.com Corporate IT apps Migration to AWS
Amazon.com Corporate IT apps Migration to AWS
 
B1 – Migrating enterprise applications to aws
B1 – Migrating enterprise applications to awsB1 – Migrating enterprise applications to aws
B1 – Migrating enterprise applications to aws
 
(ENT306) Application Portfolio Migration | AWS re:Invent 2014
(ENT306) Application Portfolio Migration | AWS re:Invent 2014(ENT306) Application Portfolio Migration | AWS re:Invent 2014
(ENT306) Application Portfolio Migration | AWS re:Invent 2014
 
Migration Recipes for Success - AWS Summit Cape Town 2017
Migration Recipes for Success - AWS Summit Cape Town 2017 Migration Recipes for Success - AWS Summit Cape Town 2017
Migration Recipes for Success - AWS Summit Cape Town 2017
 
Cloud Migration, Application Modernization and Security for Partners
Cloud Migration, Application Modernization and Security for PartnersCloud Migration, Application Modernization and Security for Partners
Cloud Migration, Application Modernization and Security for Partners
 
Boot camp - Migration to AWS
Boot camp - Migration to AWSBoot camp - Migration to AWS
Boot camp - Migration to AWS
 
Migration Planning
Migration PlanningMigration Planning
Migration Planning
 
CSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps sessionCSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps session
 
SMS-and-CloudEndure-Module4
SMS-and-CloudEndure-Module4SMS-and-CloudEndure-Module4
SMS-and-CloudEndure-Module4
 
Simplify Your Database Migration to AWS | AWS Public Sector Summit 2016
Simplify Your Database Migration to AWS | AWS Public Sector Summit 2016Simplify Your Database Migration to AWS | AWS Public Sector Summit 2016
Simplify Your Database Migration to AWS | AWS Public Sector Summit 2016
 
How a Global Healthcare Company Built a Migration Factory to Quickly Move Tho...
How a Global Healthcare Company Built a Migration Factory to Quickly Move Tho...How a Global Healthcare Company Built a Migration Factory to Quickly Move Tho...
How a Global Healthcare Company Built a Migration Factory to Quickly Move Tho...
 
Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid ITAsk The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
 
Migration to Cloud - How difficult is it ? A sample migration scenario
Migration to Cloud - How difficult is it ? A sample migration scenarioMigration to Cloud - How difficult is it ? A sample migration scenario
Migration to Cloud - How difficult is it ? A sample migration scenario
 
AWS re:Invent 2016: Preparing for a Large-Scale Migration to AWS (ENT212)
AWS re:Invent 2016: Preparing for a Large-Scale Migration to AWS (ENT212)AWS re:Invent 2016: Preparing for a Large-Scale Migration to AWS (ENT212)
AWS re:Invent 2016: Preparing for a Large-Scale Migration to AWS (ENT212)
 
Pragmatic Enterprise Application Migration to AWS
Pragmatic Enterprise Application Migration to AWSPragmatic Enterprise Application Migration to AWS
Pragmatic Enterprise Application Migration to AWS
 
Migrating to Cloud - A Step by Step
Migrating to Cloud - A Step by Step Migrating to Cloud - A Step by Step
Migrating to Cloud - A Step by Step
 
Cloud Migration Cookbook: A Guide To Moving Your Apps To The Cloud
Cloud Migration Cookbook: A Guide To Moving Your Apps To The CloudCloud Migration Cookbook: A Guide To Moving Your Apps To The Cloud
Cloud Migration Cookbook: A Guide To Moving Your Apps To The Cloud
 
Cloud Migration and Portability Best Practices
Cloud Migration and Portability Best PracticesCloud Migration and Portability Best Practices
Cloud Migration and Portability Best Practices
 
Migrating to AWS
Migrating to AWSMigrating to AWS
Migrating to AWS
 
AWS Partner Webcast - Data Center Migration to the AWS Cloud
AWS Partner Webcast - Data Center Migration to the AWS CloudAWS Partner Webcast - Data Center Migration to the AWS Cloud
AWS Partner Webcast - Data Center Migration to the AWS Cloud
 

En vedette

Why Firms Use Incentives That Have No Incentive Effects
Why Firms Use Incentives That Have No Incentive EffectsWhy Firms Use Incentives That Have No Incentive Effects
Why Firms Use Incentives That Have No Incentive Effects
Callidus Software
 
Marco Tullio Giordano, Digital Identity - part3
Marco Tullio Giordano, Digital Identity - part3Marco Tullio Giordano, Digital Identity - part3
Marco Tullio Giordano, Digital Identity - part3
Andrea Rossetti
 
08 Testy VěDěLi Jste
08  Testy  VěDěLi Jste08  Testy  VěDěLi Jste
08 Testy VěDěLi Jste
jedlickak07
 
09 FóRky Kurs Automatiky
09  FóRky  Kurs Automatiky09  FóRky  Kurs Automatiky
09 FóRky Kurs Automatiky
jedlickak07
 

En vedette (20)

Amazon Ec2 Application Design
Amazon Ec2 Application DesignAmazon Ec2 Application Design
Amazon Ec2 Application Design
 
CPN209 Your Amazon Linux AMI - AWS re: Invent 2012
CPN209 Your Amazon Linux AMI - AWS re: Invent 2012CPN209 Your Amazon Linux AMI - AWS re: Invent 2012
CPN209 Your Amazon Linux AMI - AWS re: Invent 2012
 
AWS Webcast - Build high-scale applications with Amazon DynamoDB
AWS Webcast - Build high-scale applications with Amazon DynamoDBAWS Webcast - Build high-scale applications with Amazon DynamoDB
AWS Webcast - Build high-scale applications with Amazon DynamoDB
 
Hybrid IT Approach and Technologies with the AWS Cloud
Hybrid IT Approach and Technologies with the AWS CloudHybrid IT Approach and Technologies with the AWS Cloud
Hybrid IT Approach and Technologies with the AWS Cloud
 
ARC204 AWS Infrastructure Automation - AWS re: Invent 2012
ARC204 AWS Infrastructure Automation - AWS re: Invent 2012ARC204 AWS Infrastructure Automation - AWS re: Invent 2012
ARC204 AWS Infrastructure Automation - AWS re: Invent 2012
 
(ARC308) Nike's Journey into Microservices | AWS re:Invent 2014
(ARC308) Nike's Journey into Microservices | AWS re:Invent 2014(ARC308) Nike's Journey into Microservices | AWS re:Invent 2014
(ARC308) Nike's Journey into Microservices | AWS re:Invent 2014
 
ケーズホールディングス 経営の特徴「がんばらない経営」
ケーズホールディングス 経営の特徴「がんばらない経営」ケーズホールディングス 経営の特徴「がんばらない経営」
ケーズホールディングス 経営の特徴「がんばらない経営」
 
Awsome day outro cph 201509
Awsome day outro cph 201509Awsome day outro cph 201509
Awsome day outro cph 201509
 
getting started with amazon aurora
getting started with amazon auroragetting started with amazon aurora
getting started with amazon aurora
 
Why Firms Use Incentives That Have No Incentive Effects
Why Firms Use Incentives That Have No Incentive EffectsWhy Firms Use Incentives That Have No Incentive Effects
Why Firms Use Incentives That Have No Incentive Effects
 
Sab
SabSab
Sab
 
ETE
ETEETE
ETE
 
Software Lliure
Software LliureSoftware Lliure
Software Lliure
 
Insectes
InsectesInsectes
Insectes
 
she (alvaro)
she (alvaro)she (alvaro)
she (alvaro)
 
Syzygy3
Syzygy3Syzygy3
Syzygy3
 
Marco Tullio Giordano, Digital Identity - part3
Marco Tullio Giordano, Digital Identity - part3Marco Tullio Giordano, Digital Identity - part3
Marco Tullio Giordano, Digital Identity - part3
 
Irrigation Development in Egypt
Irrigation Development in EgyptIrrigation Development in Egypt
Irrigation Development in Egypt
 
08 Testy VěDěLi Jste
08  Testy  VěDěLi Jste08  Testy  VěDěLi Jste
08 Testy VěDěLi Jste
 
09 FóRky Kurs Automatiky
09  FóRky  Kurs Automatiky09  FóRky  Kurs Automatiky
09 FóRky Kurs Automatiky
 

Similaire à Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay

Similaire à Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay (20)

Deep Dive: Hybrid Architectures
Deep Dive: Hybrid ArchitecturesDeep Dive: Hybrid Architectures
Deep Dive: Hybrid Architectures
 
Running Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWSRunning Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWS
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing Zone
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Deep Dive - Hybrid Architectures
Deep Dive - Hybrid ArchitecturesDeep Dive - Hybrid Architectures
Deep Dive - Hybrid Architectures
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
 
Secure your AWS Account and your Organization's Accounts
Secure your AWS Account and your Organization's Accounts Secure your AWS Account and your Organization's Accounts
Secure your AWS Account and your Organization's Accounts
 
AWS User Group Hungary - re:Invent review
AWS User Group Hungary - re:Invent reviewAWS User Group Hungary - re:Invent review
AWS User Group Hungary - re:Invent review
 
Secure Your AWS Account and Your Organization's Accounts - SID202 - Chicago A...
Secure Your AWS Account and Your Organization's Accounts - SID202 - Chicago A...Secure Your AWS Account and Your Organization's Accounts - SID202 - Chicago A...
Secure Your AWS Account and Your Organization's Accounts - SID202 - Chicago A...
 
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
 
AWS June Webinar Series - Deep dive: Hybrid Architectures
AWS June Webinar Series - Deep dive: Hybrid ArchitecturesAWS June Webinar Series - Deep dive: Hybrid Architectures
AWS June Webinar Series - Deep dive: Hybrid Architectures
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
 
Architecting Hybrid Infrastructure
Architecting Hybrid InfrastructureArchitecting Hybrid Infrastructure
Architecting Hybrid Infrastructure
 
Intro & Security Update
Intro & Security UpdateIntro & Security Update
Intro & Security Update
 
Real World Hybrid Operations and Apps on AWS
Real World Hybrid Operations and Apps on AWS Real World Hybrid Operations and Apps on AWS
Real World Hybrid Operations and Apps on AWS
 
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
 
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
 
(ENT401) Hybrid Infrastructure Integration | AWS re:Invent 2014
(ENT401) Hybrid Infrastructure Integration | AWS re:Invent 2014(ENT401) Hybrid Infrastructure Integration | AWS re:Invent 2014
(ENT401) Hybrid Infrastructure Integration | AWS re:Invent 2014
 

Plus de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Plus de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Dernier

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Dernier (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 

Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay

  • 1. A  Pragmatic  Approach  to   Workload  Migrations Carlos  Conde  – Technology  Evangelist
  • 2. Many  enterprises  worry  that  these  are  the  only  two  choices: Build  a   “Private” Cloud Rip  everything  out   and  move  to  AWS #1 #2
  • 3. Cloud  isn’t  an  “All  or  Nothing”  choice Corporate   Data  Centers On-­Premises   Resources Cloud   Resources Integration
  • 4. SPEED  &  AGILITY Infrastructure  in  minutes,  not  weeks.
  • 5. COST  REDUCTION 50  price  reductions  since  2006. Replace  capital  expenditure  with  variable  expense.
  • 6.
  • 8. FOCUS  ON  YOUR  BUSINESS No  time  &  resources  spent  on  undifferentiated  IT. Prepare  full  migration  to  AWS.
  • 9. HYBRID  WORKLOADS Dev &  Test  environments    •    Burst  capacity •     Highly  secure  apps •    App  migration    •    Storage  &   Archiving    •    Disaster  recovery    •    Production  app   enrichment    •    Load  testing    •    Remote  monitoring    •     etc.
  • 10. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Hypervisors AMIs,  EC2  instances Access  Control IAM,  Directory  Services Data  storage  &  Applications Development  &  Operations
  • 11. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services
  • 12. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect
  • 13. Oracle  Secure   Backup  Module Oracle  RMan Ú Amazon  S3
  • 14. RESTORE  TIMES  REDUCED  FROM  15  TO  2½  HOURS
  • 15. Amazon   Storage  Gateway Virtual  tape  library On-­premises  snapshots  to  AWS
  • 16.
  • 17.
  • 18.
  • 19.
  • 20. AWS  Virtual  Private  Network  (IPSec VPN) o IPSec hardware  VPN  connection   Supported  VPN  appliances:   https://aws.amazon.com/vpc/faqs/#C9 o Encryption  and  Validation o Private  RFC  1918  Addressing o Uses  Border  Gateway  Protocol  (BGP)   for  routing  and  fail-­over o VPN  Service  provides  managed   redundant  end-­points http://docs.aws.amazon.com/AmazonVPC/latest/UserGuide /VPC_VPN.html Virtual Gateway Corporate   data  center Users Data  center  router Servers Internet IPSec  VPN VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group
  • 21. DEV  &  TEST  ENVIRONMENTS
  • 22.
  • 23.
  • 24.
  • 25.
  • 26.
  • 27.
  • 28. AWS  region Web layerPrivate connection Your  data  center Internet Application layer Database layer Auto  Scaling
  • 29. AWS  region Public-­facing web  app Public  app w/back-­end integration Your  Data   Center Private app w/back-­end integration Core/shared services AWS  Direct  Connect Location
  • 30. AWS  Direct  Connect o Requires  Layer  2  single  mode  fiber   1000BASE-­LX  or  10GBASE-­LR o Requires  802.1Q  VLANs  across   connection. Ø Tagging  of  IP  traffic o Routing  uses  BGP  A/A  or  A/P   multipath. o Each  DX  is  mapped  to  a  single  AWS   Region o Various  Partners  for  every  Region http://aws.amazon.com/directconnect/ Virtual Gateway Corporate   data  center Users Data  center  router Servers VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group Customer   router AWS  Direct  Connect Location AWS  Direct  Connect   routers
  • 31. With  AWS  regions  just  another  spoke  on  your  global  network, it’s  easy  to  bring  the  cloud  to  you  as  you  expand  around  the  world. US  customer   data  center EU-­West-­1  region EU  customer   data  center Customer  MPLS   backbone AWS  Direct   Connect  PoP Ireland  or  London US-­West-­1  region AWS  Direct   Connect  PoP Virginia  or  NYC AP-­Southeast-­1   region AWS  Direct   Connect  PoP Singapore AP  customer   data  center
  • 32. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Access  Control IAM,  Directory  Services
  • 33. AWS  Direct  Connect Location AWS  Direct  Connect   routers Active  Directory  and  LDAP   o Reduced  back-­reach  Traffic o Reduced  Latency  for  Authentication o Additional  Resiliency o Enablement  of  both:       Ø Multi-­Master  Read/Write  Domain   Controllers Ø Read-­only  Domain  Controllers  (RODCs) ² Requires  IPSec VPN  or  Direct  Connect   connectivity http://aws.amazon.com/microsoft/whitepapers/ad-­reference-­ architecture/ Virtual Gateway Corporate   data  center Users Data  center  router Servers VPC  Subnet Availability  Zone Security  Groups VPC  Subnet Availability  Zone Security  Groups AD.Domain Domain   controller Domain   controller Domain   controller Active  Directory   Replication Customer   router
  • 34. AWS  Direct  Connect Location AWS  Direct  Connect   routers AWS  Directory  Service   o Deploys  in  two  modes Ø Directory  Service  Connect Ø Simple   AD  -­ built  on  Samba  4  Active   Directory  compatible  server o Simplifies  IAM  Federation Ø Avoids  complexity  and  cost  of  hosting   SAML-­based  federation  infrastructure Ø Acts  as  a  proxy  -­ no  data  is  stored  on   AWS  infrastructure Ø Supports  existing  RADIUS-­based  MFA ² Requires  IPSec VPN  or  Direct  Connect   connectivity http://aws.amazon.com/directoryservice/ Virtual Gateway data  center Users Data  center  router Servers VPC  Subnet Availability  Zone Security  Groups VPC  Subnet Availability  Zone Security  Groups AD.Domain Domain   controller AD  Connector AD  Connector AD  Connector Customer   router
  • 35. Integrate  identity  management  with  AWS • Secure  access  to  AWS   resources  using  your  IDM • Provide  SSO  to  AWS   Management  Console  or  API’s • Build  your  own  SSO  federation  using  AWS  STS  service,  or • Federate  with  on-­premise  directories  like  Active  Directory,   TFIM,  OAM  or  another  SAML  2.0  compliant  IdP
  • 36. AWS  Federation/Account  Governance   Financial  users,   controllers SOC/AuditorsGlobal  AWS  admin Billing  account Software  development Non-­‐prod account  #1 Production   account  #1 User  management account Security  /  Audit account Non-­‐prod account.  #2 App  owners DevOps teams Security/auditProductionDev/test/sandboxFinancial Consolidated  Billing,   Billing  Alerts Read-­‐only  access   for  all  accounts
  • 37. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Hypervisors AMIs,  EC2  instances Access  Control IAM,  Directory  Services
  • 38. Management   Portal  for  vCenter Management  Pack   for  SCOM Systems  Manager   for  SCVMM
  • 39. AWS  Management  Portal  for  vCenter
  • 40. vCenter Image  Migration 1. The  vSphere client  authorizes   import  to  the  environment. 2. The  management  portal  verifies   that  the  user  has  permission  to   migrate  VMs  to  the  environment   and  returns  a  token. 3. The  vSphere client  sends  an   import  request  to  the  connector   along  with  the  token. 4. The  connector  verifies  the  token. 5. The  connector  verifies  that  the  user   has  permission  to  export  the  VM. 6. The  connector  starts  the  migration. 7. The  connector  sends  a  response  to   the  vSphere client  with  the  import   task  ID.
  • 41. Bidirectional  Gold  Image  Replication AWS Cloud Legacy DC EC2  AMIs VM  Images
  • 42. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Hypervisors AMIs,  EC2  instances Access  Control IAM,  Directory  Services Development  &  Operations
  • 43. Integrating  AWS  into  your  operations • AWS  CloudWatch  provides  real-­time  insight  into  your  AWS   services,  integrate  your  own  metrics,  create  and  act  on  alarms • AWS  SNS  allows  integration  with  your  alerting  systems   • Your  current  tools  still  work  – install  on  EC2  instance • Your  tools  already  have  AWS  API  integration • Established  processes  don’t  get  thrown  away
  • 44. AWS  Direct  Connect Location AWS  Direct  Connect   routers Operations  Tools  and  Monitoring o Security  Monitoring  integration   points  with  with  CloudTrail  and   SIEM  Aggregator. o Logging  with  CloudTrail  and  SNMP   MIBs  to  SIEM  Aggregator. o Platform  and  App  Health  to  SIEM   Aggregator  via  agent  on  EC2  guest. o Access  to  Patching  and  Updates  for   AMI  by  on  premises  Update  Server.   Virtual Gateway data  center Users Data  center  router VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group Update Servers SIEM Aggregator CloudTrail CloudWatch CloudTrail  S3   Bucket Customer   router
  • 45. Customer   router AWS  Direct  Connect Location AWS  Direct  Connect   routers Continuous  Integration  and  Deployment o Automates  application  deployments   for  both  On-­Premise  and  AWS  EC2   instances  with  use  of  CodeDeploy o Reuse  existing  scripts  and  tools Ø Bash,  PowerShell,  Chef,   Puppet,  anything… o Integrate  with  developer  tool  chain Ø GitHub,  Jenkins,  CloudBees,   TravisCI,  Eclipse… Virtual Gateway data  center Users Data  center  router VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group AWS  CodeDeployServers AWS  CloudFormation S3 bucket AgentAgentAgent AgentAgentAgent
  • 46. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Hypervisors AMIs,  EC2  instances Access  Control IAM,  Directory  Services Data  storage  &  Applications Operations  & Automation
  • 47. Customer   router AWS  Direct  Connect Location AWS  Direct  Connect   routers Storage   Expansion o Virtual  volumes  presented  to   local  network  iSCSI,  NFS   and  CIFS  volumes o Local  disk  cache  to  provide   fast  on-­premises  access o Gateway  side  encryption  for   security Virtual Gateway Corporate   data  center Users Data  center  router VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group Amazon  S3 AWS  Storage   Gateway iSCSI Storage   Appliance AWS  Storage   Gateway iSCSI Servers AWS  Storage   Gateway
  • 48. Customer   router AWS  Direct  Connect Location AWS  Direct  Connect   routers Backup  & Archiving o Backup  gateways   integrated  with  Amazon  S3 o Leverage  Amazon   S3  archival  to   Amazon  Glacier o Take  advantage  of  current   investments  and  solutions   for  options   o De-­duplication o Compression o WAN  Acceleration Virtual Gateway data  center Users Data  center  router VPC  Subnet Availability  Zone Security  Group VPC  Subnet Availability  Zone Security  Group Amazon  S3 Amazon  Glacier VTL AWS  Storage   Gateway iSCSI Backup   System VTL AWS  Storage   Gateway iSCSI Servers VTL AWS  Storage   Gateway
  • 49.
  • 50.
  • 51. SAP  HANA
Production  ready  with  up  to  244  GiB of   RAM  +  clustering http://aws.amazon.com/blogs/aws/sap-­hana-­production-­ready-­on-­aws/
  • 52. – SAP  HANA  Hybrid  deployment Corporate  Data  Center Amazon  Virtual  Private  Cloud  (VPC) Availability  Zone VPC  Subnet BW  ABAP  7.31  /  NW  JAVA  7.40   BW BI-­JAVA DEV QA 2  X  244  GB  nodes 2  X  244  GB  nodes BW BI-­JAVA Internet SAP  OSS BA C A  =  Virtual  Private  Gateway B  =  Customer  Gateway C  =  VPN  Connection   UAT  /  DR PRD BW BI-­JAVA BW BI-­JAVA Web  Disp Web  Disp HANA 5  X  0.5  TB  nodes 5  X  0.5  TB  nodes SAP HANA SAP HANA SAP HANA SAP HANA
  • 53. Extend  Local  Applications  Capabilities: Amazon  WorkSpaces,  WorkDocs,  Workmail Amazon  Redshift Amazon  ML Amazon  CloudSearch Amazon  CloudHSM Amazon  SES Amazon  SWF …
  • 54. BACKUPS  +  APPS  +  IAM è DISASTER  RECOVERY
  • 56.
  • 57.
  • 58.
  • 60.
  • 61.
  • 63.
  • 64.
  • 65.
  • 66.
  • 67.
  • 68.
  • 69. VPC Subnet B Region Availability Zone Client-to-site VPN Site-to-site VPN S3 Buckets with Objects Bastion Host Internet On-premise Data Centre A Remote Desktops AWS Direct Connect On-premise Data Centre B VPC Subnet D VPC Subnet F Databases VPC Subnet E Applications VPC Subnet A SmartSentinel VPC Subnet G File Servers VPC Subnet C Active Directory Proxy Server
  • 72.
  • 73.
  • 74.
  • 75. IF  SOMETHING  IS  HARD REPETITION  MAKES  IT  EASIER
  • 77. GOOD WEATHER DOESN’T MAKE GOOD SAILORS
  • 80. • TERMINATE  RESOURCES • CHANGE  SECURITY  GROUPS • CHANGE  IAM  ROLES • DISABLE  IAM  USER • CHANGE  /ETC/HOSTS  FILE • AMAZON  RDS  FAIL-­OVER  TEST
  • 81. VALIDATE  YOUR  ASSUMPTIONS PROVE  YOUR  ARCHITECTURE KNOW  YOUR  PROCEDURES LEARN FROM  YOUR  FAILURES
  • 82. On-­ premises   IT   Datacenter Regions,  AZs Cloud   Services Network VPC,  Direct  Connect Hypervisors AMIs,  EC2  instances Access  Control IAM,  Directory  Services Data  storage  &  Applications Operations  & Automation
  • 83. HYBRID  WORKLOADS Dev &  Test  environments    •    Burst  capacity •     Highly  secure  apps •    App  migration    •    Storage  &   Archiving    •    Disaster  recovery    •    Production  app   enrichment    •    Load  testing    •    Remote  monitoring    •     etc.
  • 84. ON-­PREMISES Experiment    Infrequently Failure  is  expensive Less  Innovation Experiment  Often Fail  quickly  at  a  low  cost More    Innovation $  Millions Nearly  $0
  • 85. AWS  Cloud  Adoption   Framework Describes  the  perspectives  in  planning,   creating,  managing,  and  supporting  a  modern   IT  service. Offers  practical  guidance  and  comprehensive   guidelines  for  establishing,  developing  and   running  AWS  cloud-­enabled  environments. http://bit.ly/AWSCAF People Perspective Process Perspective Security Perspective Maturity Perspective Operations Perspective Business Perspective   Platform Perspective