SlideShare une entreprise Scribd logo
1  sur  20
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Sandy Ramamoorthy
Sr. Manager, Product Management, Amazon Web Services
Too Many Tools?
How AWS Systems Manager Bridges Operational Models
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Challenges
• Operate safely and securely at scale
• Unable to visualise complex applications and environments
intuitively
• Diverse set of tools for managing hybrid Cloud
• Complex licensing and hard to manage the management
infrastructure
• Ability to build custom solutions
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Systems Manager
Operations Cockpit for your Cloud Environment
 Group the building blocks of your applications or environment
 Visualise operational insights for applications
 Brings other AWS services in a single console
 Act using AWS best practices with built-in safeties
 Securely manage, stay compliant with patching
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Wide Choice To Leverage Your Investment
• Works in hybrid and multi-cloud environments
• Preserve existing investments with Ansible, PowerShell DSC and
InSpec for configuration and compliance
• Open Source support
• Cross-platform: Windows and Linux support
• API driven and fully extensible
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Systems Manager Customers & Partners
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Model Your Environment - Resource Groups
Define the building blocks of your application
• Give a meaning to a collection of AWS
resources (as an application, env, or business
unit)
• Group AWS resources based on tags using a
simple query
• Interact with a group directly rather than
individual resources
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Improved Visibility And Control
Setup operational dashboards
• Build and customise your own ops-
dashboards
• Leverage your existing Amazon
CloudWatch dashboards
• Monitor Compliance
• Visualise your application’s metrics
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• Bootstrap instances on launch with image
builds that are compliant
• Set patch baselines with custom-defined
approvals rules
• Schedule periodic scan for compliance
• Automate Windows and Linux patching
using the custom-defined rules and
Maintenance Windows
Create Patch Baselines
Schedule Patch operation
(Scan/Patch)
Maintain Security and
Compliance
Compliance With Patch Manager
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Demo
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Safe And Secure Remote Management
• Remote management at scale without
SSH-access or bastion hosts
• Automate RBAC and audit
• Rate control for safety
• Run from external locations such as
public or private GitHub repositories
VPC2
Corp data
center
VPC1
Tags
CloudTrail
Auditing
IAM
Tags
Amazon
CloudWatch
Events
Run
Command
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Gain Insights From Multi-Account Instances
Account
2
Corp data
center
Amazon S3
Data Lake
Account
1
Any BI
Tool!
Amazon
QuickSight
AWS Config
Inventory
• Collect inventory - applications, files
metadata, Windows services, registry, roles
and features
• Sync cross-account/region inventory to
Amazon S3
• Analyse using Amazon Athena, Amazon
QuickSight or any BI tool
• Build solutions e.g. track applications
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Easy To Use Automation
• Convert manual and repetitive tasks into
automated steps
• Use predefined runbooks or create your
own runbooks
• Delegated administration to safely
perform operations at scale
• Enable approval steps
Automation document
Run the automation
Role and
permission
input
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• Separate configuration data from code
• Granular RBAC for parameters based on
hierarchies, tags or specific parameters
• Setup change notifications and trigger
automated actions
Dev Test Prod
App
/app/test/db_password /app/prod/db_password
email notification
Change
notifications
(event-based)
Config And Secrets Data Management
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Manage Configuration Drift
State
Manager
instances
• Enforce OS configurations such as
firewall rules and anti-virus settings
• Bootstrap instances automatically
on launch
• Check compliance status
• Automatically re-apply policies to
prevent drift
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Systems Manager Capabilities
Run Command
State Manager
Inventory Maintenance
Window
Patch Manager Automation Parameter
Store
Resource
Groups
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Demo
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Other Enterprise Features
• Available in all AWS regions including GovCloud
• Accessible through AWS PrivateLink
• SSM Agent is installed on AWS Windows Server and Amazon Linux
AMIs
• Systems Manager is SOC, ISO and PCI compliant, HIPAA enabled
• Integrated with AWS services such as
• AWS IAM: granular RBAC
• AWS CloudTrail: audited actions
• Amazon CloudWatch Events: notification and remediation
• AWS Config: configuration history
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Useful Links
• Product Page: https://aws.amazon.com/systems-manager/
• AWS Management Tools Blog:
https://aws.amazon.com/blogs/mt/category/management-
tools/amazon-ec2-systems-manager/
• AWS Blog:
https://aws.amazon.com/blogs/aws/category/amazon-ec2-
systems-manager/
• Feedback: ec2-ssm-feedback@amazon.com
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
https://aws.amazon.com/systems-manager/
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank You

Contenu connexe

Tendances

Best Practices for Security at Scale
Best Practices for Security at ScaleBest Practices for Security at Scale
Best Practices for Security at ScaleAmazon Web Services
 
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...Amazon Web Services
 
Introduction to WAF and Network Application Security
Introduction to WAF and Network Application SecurityIntroduction to WAF and Network Application Security
Introduction to WAF and Network Application SecurityAlibaba Cloud
 
Azure realtime-interview questions - part 7
Azure realtime-interview questions - part 7Azure realtime-interview questions - part 7
Azure realtime-interview questions - part 7Malleswar Reddy
 
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...Amazon Web Services
 
SecuringYourCustomersDataFromDayOne_SFStartupDay
SecuringYourCustomersDataFromDayOne_SFStartupDaySecuringYourCustomersDataFromDayOne_SFStartupDay
SecuringYourCustomersDataFromDayOne_SFStartupDayAmazon Web Services
 
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOne
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOneAWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOne
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOneAmazon Web Services
 
Maturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsMaturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsAmazon Web Services
 
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360Kemp
 
AWS Well-Architected Review
AWS Well-Architected ReviewAWS Well-Architected Review
AWS Well-Architected ReviewAndrej Maya
 
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...Amazon Web Services
 
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Amazon Web Services
 
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...Amazon Web Services
 
Successful Cloud Adoption for the Enterprise. Not If. When.
Successful Cloud Adoption for the Enterprise. Not If. When.Successful Cloud Adoption for the Enterprise. Not If. When.
Successful Cloud Adoption for the Enterprise. Not If. When.Amazon Web Services
 
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...Amazon Web Services
 

Tendances (20)

Best Practices for Security at Scale
Best Practices for Security at ScaleBest Practices for Security at Scale
Best Practices for Security at Scale
 
AWS Security By Design
AWS Security By DesignAWS Security By Design
AWS Security By Design
 
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...
Building Performance Clinical Systems' HIPAA-Compliant Clinical Workflow Plat...
 
Optimizing Wordpress For Speed And Security
Optimizing Wordpress For Speed And SecurityOptimizing Wordpress For Speed And Security
Optimizing Wordpress For Speed And Security
 
Introduction to WAF and Network Application Security
Introduction to WAF and Network Application SecurityIntroduction to WAF and Network Application Security
Introduction to WAF and Network Application Security
 
Azure realtime-interview questions - part 7
Azure realtime-interview questions - part 7Azure realtime-interview questions - part 7
Azure realtime-interview questions - part 7
 
AWS Security by Design
AWS Security by Design AWS Security by Design
AWS Security by Design
 
Securing Your Customers Data From Day One
Securing Your Customers Data From Day OneSecuring Your Customers Data From Day One
Securing Your Customers Data From Day One
 
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...
Leo Zhadanovsky - Building Web Apps with AWS CodeStar and AWS Elastic Beansta...
 
SecuringYourCustomersDataFromDayOne_SFStartupDay
SecuringYourCustomersDataFromDayOne_SFStartupDaySecuringYourCustomersDataFromDayOne_SFStartupDay
SecuringYourCustomersDataFromDayOne_SFStartupDay
 
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOne
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOneAWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOne
AWS18_StartupDayToronto_SecuringYourCustomersDataFromDayOne
 
Maturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsMaturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOps
 
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
 
AWS-Data-Migration-module3
AWS-Data-Migration-module3AWS-Data-Migration-module3
AWS-Data-Migration-module3
 
AWS Well-Architected Review
AWS Well-Architected ReviewAWS Well-Architected Review
AWS Well-Architected Review
 
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...
How Federal Home Loan Bank of Chicago Maintains Control in the Cloud (ENT207)...
 
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
 
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...
A Self-Defending Border: Protect Your Web-Facing Workloads with AWS Security ...
 
Successful Cloud Adoption for the Enterprise. Not If. When.
Successful Cloud Adoption for the Enterprise. Not If. When.Successful Cloud Adoption for the Enterprise. Not If. When.
Successful Cloud Adoption for the Enterprise. Not If. When.
 
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...
Streamline Your Desktop Operations and Improve Security with Amazon WorkSpace...
 

Similaire à Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summit Sydney 2018

Too Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational ModelsToo Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational ModelsAmazon Web Services
 
Simplify Operations, Compliance and Governance using AWS Systems Manager
Simplify Operations, Compliance and Governance using AWS Systems ManagerSimplify Operations, Compliance and Governance using AWS Systems Manager
Simplify Operations, Compliance and Governance using AWS Systems ManagerAmazon Web Services
 
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAmazon Web Services
 
How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfAmazon Web Services
 
Managing Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdfManaging Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdfAmazon Web Services
 
Pragmatic container security - DEM11-R - AWS re:Inforce 2019
Pragmatic container security - DEM11-R - AWS re:Inforce 2019 Pragmatic container security - DEM11-R - AWS re:Inforce 2019
Pragmatic container security - DEM11-R - AWS re:Inforce 2019 Amazon Web Services
 
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018Amazon Web Services
 
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018Bhuvaneswari Subramani
 
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdfNirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdfAmazon Web Services
 
Securing Your Customers Data From Day One
Securing Your Customers Data From Day OneSecuring Your Customers Data From Day One
Securing Your Customers Data From Day OneAmazon Web Services
 
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Amazon Web Services
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesAmazon Web Services
 
Estate and Patch Management Infrastructure and Operations as Code
Estate and Patch Management Infrastructure and Operations as CodeEstate and Patch Management Infrastructure and Operations as Code
Estate and Patch Management Infrastructure and Operations as CodeAmazon Web Services
 
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Amazon Web Services
 
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...Amazon Web Services
 
ENT401 Deep Dive with Amazon EC2 Systems Manager
ENT401 Deep Dive with Amazon EC2 Systems ManagerENT401 Deep Dive with Amazon EC2 Systems Manager
ENT401 Deep Dive with Amazon EC2 Systems ManagerAmazon Web Services
 

Similaire à Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summit Sydney 2018 (20)

Too Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational ModelsToo Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational Models
 
Simplify Operations, Compliance and Governance using AWS Systems Manager
Simplify Operations, Compliance and Governance using AWS Systems ManagerSimplify Operations, Compliance and Governance using AWS Systems Manager
Simplify Operations, Compliance and Governance using AWS Systems Manager
 
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
 
Management@Scale
Management@ScaleManagement@Scale
Management@Scale
 
How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdf
 
Managing Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdfManaging Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdf
 
Pragmatic container security - DEM11-R - AWS re:Inforce 2019
Pragmatic container security - DEM11-R - AWS re:Inforce 2019 Pragmatic container security - DEM11-R - AWS re:Inforce 2019
Pragmatic container security - DEM11-R - AWS re:Inforce 2019
 
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018
Security Best Practices for Microsoft Workloads (WIN307) - AWS re:Invent 2018
 
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
 
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdfNirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf
Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf
 
Securing Your Customers Data From Day One
Securing Your Customers Data From Day OneSecuring Your Customers Data From Day One
Securing Your Customers Data From Day One
 
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation Techniques
 
Estate and Patch Management Infrastructure and Operations as Code
Estate and Patch Management Infrastructure and Operations as CodeEstate and Patch Management Infrastructure and Operations as Code
Estate and Patch Management Infrastructure and Operations as Code
 
Deep Dive on AWS CloudFormation
Deep Dive on AWS CloudFormationDeep Dive on AWS CloudFormation
Deep Dive on AWS CloudFormation
 
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
 
How AI is disrupting the world
How AI is disrupting the world How AI is disrupting the world
How AI is disrupting the world
 
Mitigating techniques
Mitigating techniquesMitigating techniques
Mitigating techniques
 
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
 
ENT401 Deep Dive with Amazon EC2 Systems Manager
ENT401 Deep Dive with Amazon EC2 Systems ManagerENT401 Deep Dive with Amazon EC2 Systems Manager
ENT401 Deep Dive with Amazon EC2 Systems Manager
 

Plus de Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Plus de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summit Sydney 2018

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Sandy Ramamoorthy Sr. Manager, Product Management, Amazon Web Services Too Many Tools? How AWS Systems Manager Bridges Operational Models
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Challenges • Operate safely and securely at scale • Unable to visualise complex applications and environments intuitively • Diverse set of tools for managing hybrid Cloud • Complex licensing and hard to manage the management infrastructure • Ability to build custom solutions
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Systems Manager Operations Cockpit for your Cloud Environment  Group the building blocks of your applications or environment  Visualise operational insights for applications  Brings other AWS services in a single console  Act using AWS best practices with built-in safeties  Securely manage, stay compliant with patching
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Wide Choice To Leverage Your Investment • Works in hybrid and multi-cloud environments • Preserve existing investments with Ansible, PowerShell DSC and InSpec for configuration and compliance • Open Source support • Cross-platform: Windows and Linux support • API driven and fully extensible
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Systems Manager Customers & Partners
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Model Your Environment - Resource Groups Define the building blocks of your application • Give a meaning to a collection of AWS resources (as an application, env, or business unit) • Group AWS resources based on tags using a simple query • Interact with a group directly rather than individual resources
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Improved Visibility And Control Setup operational dashboards • Build and customise your own ops- dashboards • Leverage your existing Amazon CloudWatch dashboards • Monitor Compliance • Visualise your application’s metrics
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. • Bootstrap instances on launch with image builds that are compliant • Set patch baselines with custom-defined approvals rules • Schedule periodic scan for compliance • Automate Windows and Linux patching using the custom-defined rules and Maintenance Windows Create Patch Baselines Schedule Patch operation (Scan/Patch) Maintain Security and Compliance Compliance With Patch Manager
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Demo
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Safe And Secure Remote Management • Remote management at scale without SSH-access or bastion hosts • Automate RBAC and audit • Rate control for safety • Run from external locations such as public or private GitHub repositories VPC2 Corp data center VPC1 Tags CloudTrail Auditing IAM Tags Amazon CloudWatch Events Run Command
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Gain Insights From Multi-Account Instances Account 2 Corp data center Amazon S3 Data Lake Account 1 Any BI Tool! Amazon QuickSight AWS Config Inventory • Collect inventory - applications, files metadata, Windows services, registry, roles and features • Sync cross-account/region inventory to Amazon S3 • Analyse using Amazon Athena, Amazon QuickSight or any BI tool • Build solutions e.g. track applications
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Easy To Use Automation • Convert manual and repetitive tasks into automated steps • Use predefined runbooks or create your own runbooks • Delegated administration to safely perform operations at scale • Enable approval steps Automation document Run the automation Role and permission input
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. • Separate configuration data from code • Granular RBAC for parameters based on hierarchies, tags or specific parameters • Setup change notifications and trigger automated actions Dev Test Prod App /app/test/db_password /app/prod/db_password email notification Change notifications (event-based) Config And Secrets Data Management
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Manage Configuration Drift State Manager instances • Enforce OS configurations such as firewall rules and anti-virus settings • Bootstrap instances automatically on launch • Check compliance status • Automatically re-apply policies to prevent drift
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Systems Manager Capabilities Run Command State Manager Inventory Maintenance Window Patch Manager Automation Parameter Store Resource Groups
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Demo
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Other Enterprise Features • Available in all AWS regions including GovCloud • Accessible through AWS PrivateLink • SSM Agent is installed on AWS Windows Server and Amazon Linux AMIs • Systems Manager is SOC, ISO and PCI compliant, HIPAA enabled • Integrated with AWS services such as • AWS IAM: granular RBAC • AWS CloudTrail: audited actions • Amazon CloudWatch Events: notification and remediation • AWS Config: configuration history
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Useful Links • Product Page: https://aws.amazon.com/systems-manager/ • AWS Management Tools Blog: https://aws.amazon.com/blogs/mt/category/management- tools/amazon-ec2-systems-manager/ • AWS Blog: https://aws.amazon.com/blogs/aws/category/amazon-ec2- systems-manager/ • Feedback: ec2-ssm-feedback@amazon.com
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. https://aws.amazon.com/systems-manager/ Thank you!
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank You