SlideShare une entreprise Scribd logo
1  sur  27
Télécharger pour lire hors ligne
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Steven Bridle
Senior Cloud Architect, Professional Services, Amazon Web Services
Frank Fan
Partner Solutions Architect, AWS Partner Program, Amazon Web Services
VMware Cloud on AWS
The Next Generation
Hybrid Cloud Architecture
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
What is VMware Cloud on AWS
AWS global infrastructure
VMware Cloud on AWS
Customer
data center
AWS services
vCentervCenter
vSAN NSXvSphere
Hybrid
linked-mode
AWS
Lambda
Amazon
S3
Amazon
RDS
Amazon
Kinesis
Amazon
ML
Amazon
Redshift
Elastic
Network
Adapter
VMware vRealize Suite, PowerCLI AWS CloudFormation, CLI
On-Prem
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
What does it look like on AWS?
Compute
- 36 PCPUs (72 vCPUs)
- Intel Xeon E5 2686 v4
(Broadwell)
- 512GB RAM
- 8 x 2TB NVMe local SSD
- Dedicated Host
vSphere Features
- vSphere HA
- vMotion
- DRS
- Elastic DRS
Storage
- ESXi boot-from-EBS
- 16TB NVMe-backed local raw
storage
Networking
- 25 Gbps
- VMware Cloud ENI
Amazon Bare Metal
EC2
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
VMware Cloud on AWS target use cases
Data Center Extension
Footprint Expansion
On-demand Capacity
Test/Dev
B
Expand
Maintain
Disaster Recovery
Protect Additional
Workloads
DR Data Center
Replacement
Add or Modernize DR
Solutions
C
Primary Secondary
Cloud Migrations
Application Specific
Data Center Wide
Infrastructure Refresh
A
Consolidate Migrate
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
US West
Oregon
US East
N. Virginia
Europe London
Region Availability Now Available
Already Available in this region
Asia Pacific
Sydney
Europe Frankfurt
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
What's New?
Start production
with a minimum of
3 hosts
vSAN with AWS
EBS volumes
AWS KMS
Support
Full connectivity
over Direct
Connect
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Account Structure
VMware Cloud
SDDC account
 Is owned, operated, and paid directly by the customer
 Private connectivity to VMware Cloud SDDC
 Full access to the native AWS services
 A new AWS account to run SDDC resources
 Is owned, operated, and paid directly by VMware
 Is single tenant for all SDDC resources
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Connecting to an AWS Account
IAM
Cross Account
Role
AWS
Managed Policy
Customer-Owned
AWS Account
CloudFormation
Template
VMware Cloud on AWS
SDDC Account Customer
IAM UserVMware Cloud
Management Services
vmc.vmware.com
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Customer AWS account connectivity
VMware Cloud on AWS
SDDC Account
Host-1
Host-2
Host-3
Host-4
CGW
Customer Owned
AWS Account
VPC Subnet 1 VPC Subnet 2
Customer
Workloads
Amazon
Redshift
Logical Network
Route Table
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Challenges of Organisation X
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Requirements of Organisation X
AWS global infrastructure
VMware Cloud on AWS
Customer
data center
VMware vRealize Suite, PowerCLI
On-Prem
Proxy
Tier
Application
Tier
Database Tier
vCenter vCenter
Seamless Migration
1
Scalability &
Performance
2
Backup & Disaster
Recovery
3
Secure Protection
4
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Seamless Migration
HYBRIDITY SECURITY
ON-PREMISES CLOUD
LARGE SCALE MIGRATION
Active VMs
Hybrid Interconnect
Any-to-Any vSphere version
VMware NSX Hybrid Connect
1
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Scalability & performance (storage)
172.29.1.0/24
CGW
Application Tier
VMware Cloud on AWS SDDC
Account
Customer
AWS Account
Amazon S3
VPC Endpoint
ENI
Amazon EFS
2
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Scalability & performance (database)
CGW
VMware Cloud on AWS SDDC
Account
Customer AWS Account
ENI
RDS
Application Tier
2
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Scalability & performance (load
balancer)
172.29.1.0/24
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS SDDC
Account
Customer
AWS Account
ALBIGW
IP Target Group
• 172.31.1.100
• 172.31.1.101
Visitor
ENI
2
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Backup and disaster recovery
Backup & Restore Pilot light Warm standby in AWS Hot standby
Active/Active
Low High
RPO: Hours
RTO: Hours
Cost: $
RPO: Minutes
RTO: Hours
Cost: $$
RPO: Minutes
RTO: Minutes
Cost: $$$
RPO: Seconds
RTO: Real time
Cost: $$$$
3
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Backup & disaster recovery
Customer Data Center
AWS
Direct
Connect
vSphere Environment
ESXi
Internet
Amazon
Route 53
Internet
AWS Storage
Gateway VM AWS Storage
Gateway
S3
bucket
ESXi
Amazon EC2
VMware Cloud on AWS
SDDC
NSX
CGW
Backup Server Backup Server
1
4
3
2
3
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Stretched clusters
AWS Availability
Zone A
AWS Availability
Zone B
… …
vSphere HA/DRS span across AZ
NSX logical networks
Stretched Clusters
… …
vSAN stretched cluster
VMware Cloud on AWS SDDC
AWS Region
 Not necessary to architect in
the application
 Synchronous replication
between AZs
3
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Backup & disaster recovery
Disaster Recovery to VMware Cloud
1~~~~~~~~
2~~~~~~
3~~~~~~~~
4~~~~~~~
VM
VM
VM VM
VM
VM
VM
VM
VM
VM
VM
VM VM
VM
VM
VM
VM
VM
vSphere VMware Cloud on AWS
VMware Site Recovery can solve these
common DR challenges by helping you:
• Accelerate time-to-protection
• Simplify DR operations
• Apply Cloud Economics
Key Features:
• Ease of initial setup and ongoing
management
• Simple failover with one-click
• Predictable failback with one-click
• Non-disruptive, on-demand testing
• No IP change needed
3
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Secure public facing applications
Visitor
CloudFront
Route 53
172.29.1.0/24
Customer
AWS Account
ALBIGW
WAF
ENI
Shield
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS SDDC
Account
Edge Location
4
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Compliance as Code
Author
Compliance checks in InSpec (human
readable, open-source DSL) on
S3/GitHub
Run Compliance scans
Using Run Command or periodic scans
using State Manager
View Compliance
On Compliance UI or APIs
VMs or EC2 Instances
AWS System Manager
describe
package('audit.x86_64’) do
it { should be_installed }
end
4
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Review base topology
VMware
Cloud ENI
Customer
Data Center
IGW
DMZ-Out(Public)
ESXi ESXi ESXi ESXi
Resource Pool
DMZ-In
(Private)
App
(Private)
DMZ-Out
(Public)
IGW
Compute
Gateway
Compute
Gateway
Management
Gateway
OS
RWP
OS
DB2
OS
APP2
OS
DB1
OS
APP1
Amazon EC2
AZ A AZ B AZ C
VMware Cloud VPC AWS Customer VPC
Reverse Web Proxy
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Sample hybrid architecture
VMware Cloud VPC
ESXi
Amazon EC2
ESXi ESXi ESXi
Resource Pool
RDS
Aurora
(shared)
AWS Customer VPC
AZ A AZ B AZ C
OS
DB1
Customer Data
Center
Route53
SSL Encrypted
Traffic
OS
APP2
OS
APP1
OS
RWP
DMZ-Out(Public)
DMZ-In
(Private)
App(Private)
DMZ-Out
(Public) ACM
ELB
NFS S3-backed
Cluster File System
Reverse Web Proxy
& Application Load-
Balancer
OS
APP2
OS
APP2
OS
VMware
Cloud ENI
IGWIGW
Compute
Gateway
Compute
Gateway
Management
Gateway
AWS System Manager
Amazon
S3
AWS Region Services
OS
DB2
Reverse Web Proxy
Shield
CloudFront
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Demonstration
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Hybrid cloud journey of Organisation X
Seamless
Migration
1
Secure Protection
2
Scalability &
Performance
3
Backup & Disaster
Recovery
4
 Application Load
Balancer
 Relational Database
Services (RDS)
 Amazon Elastic File
System (Amazon EFS)
 Amazon S3
 VMware Site Recovery
 Amazon Route 53
 Amazon CloudFront
 AWS WAF
 AWS Shield
 Cold Migration
 Live Migration
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
• Public Website: aws.amazon.com/vmware
cloud.vmware.com/vmc-aws
• Public Videos: VMware Cloud on AWS Youtube
(includes re:Invent 2017 breakouts)
• Social Media: @awscloud #VMWonAWS
VMware Cloud on AWS Resources
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Thank you

Contenu connexe

Plus de Amazon Web Services

Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSAmazon Web Services
 
AWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAmazon Web Services
 
Crea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSightCrea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSightAmazon Web Services
 
Costruisci modelli di Machine Learning con Amazon SageMaker Autopilot
Costruisci modelli di Machine Learning con Amazon SageMaker AutopilotCostruisci modelli di Machine Learning con Amazon SageMaker Autopilot
Costruisci modelli di Machine Learning con Amazon SageMaker AutopilotAmazon Web Services
 
Migra le tue file shares in cloud con FSx for Windows
Migra le tue file shares in cloud con FSx for Windows Migra le tue file shares in cloud con FSx for Windows
Migra le tue file shares in cloud con FSx for Windows Amazon Web Services
 
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?Amazon Web Services
 
Protect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced AttacksProtect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced AttacksAmazon Web Services
 
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Amazon Web Services
 

Plus de Amazon Web Services (20)

Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWS
 
AWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei server
 
Crea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSightCrea dashboard interattive con Amazon QuickSight
Crea dashboard interattive con Amazon QuickSight
 
Costruisci modelli di Machine Learning con Amazon SageMaker Autopilot
Costruisci modelli di Machine Learning con Amazon SageMaker AutopilotCostruisci modelli di Machine Learning con Amazon SageMaker Autopilot
Costruisci modelli di Machine Learning con Amazon SageMaker Autopilot
 
Migra le tue file shares in cloud con FSx for Windows
Migra le tue file shares in cloud con FSx for Windows Migra le tue file shares in cloud con FSx for Windows
Migra le tue file shares in cloud con FSx for Windows
 
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
 
Protect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced AttacksProtect your applications from DDoS/BOT & Advanced Attacks
Protect your applications from DDoS/BOT & Advanced Attacks
 
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
 

VMware Cloud on AWS - Technical Deep Dive

  • 1. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Steven Bridle Senior Cloud Architect, Professional Services, Amazon Web Services Frank Fan Partner Solutions Architect, AWS Partner Program, Amazon Web Services VMware Cloud on AWS The Next Generation Hybrid Cloud Architecture
  • 2. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. What is VMware Cloud on AWS AWS global infrastructure VMware Cloud on AWS Customer data center AWS services vCentervCenter vSAN NSXvSphere Hybrid linked-mode AWS Lambda Amazon S3 Amazon RDS Amazon Kinesis Amazon ML Amazon Redshift Elastic Network Adapter VMware vRealize Suite, PowerCLI AWS CloudFormation, CLI On-Prem
  • 3. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. What does it look like on AWS? Compute - 36 PCPUs (72 vCPUs) - Intel Xeon E5 2686 v4 (Broadwell) - 512GB RAM - 8 x 2TB NVMe local SSD - Dedicated Host vSphere Features - vSphere HA - vMotion - DRS - Elastic DRS Storage - ESXi boot-from-EBS - 16TB NVMe-backed local raw storage Networking - 25 Gbps - VMware Cloud ENI Amazon Bare Metal EC2
  • 4. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. VMware Cloud on AWS target use cases Data Center Extension Footprint Expansion On-demand Capacity Test/Dev B Expand Maintain Disaster Recovery Protect Additional Workloads DR Data Center Replacement Add or Modernize DR Solutions C Primary Secondary Cloud Migrations Application Specific Data Center Wide Infrastructure Refresh A Consolidate Migrate
  • 5. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. US West Oregon US East N. Virginia Europe London Region Availability Now Available Already Available in this region Asia Pacific Sydney Europe Frankfurt
  • 6. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. What's New? Start production with a minimum of 3 hosts vSAN with AWS EBS volumes AWS KMS Support Full connectivity over Direct Connect
  • 7. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Account Structure VMware Cloud SDDC account  Is owned, operated, and paid directly by the customer  Private connectivity to VMware Cloud SDDC  Full access to the native AWS services  A new AWS account to run SDDC resources  Is owned, operated, and paid directly by VMware  Is single tenant for all SDDC resources
  • 8. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Connecting to an AWS Account IAM Cross Account Role AWS Managed Policy Customer-Owned AWS Account CloudFormation Template VMware Cloud on AWS SDDC Account Customer IAM UserVMware Cloud Management Services vmc.vmware.com
  • 9. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Customer AWS account connectivity VMware Cloud on AWS SDDC Account Host-1 Host-2 Host-3 Host-4 CGW Customer Owned AWS Account VPC Subnet 1 VPC Subnet 2 Customer Workloads Amazon Redshift Logical Network Route Table
  • 10. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Challenges of Organisation X
  • 11. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Requirements of Organisation X AWS global infrastructure VMware Cloud on AWS Customer data center VMware vRealize Suite, PowerCLI On-Prem Proxy Tier Application Tier Database Tier vCenter vCenter Seamless Migration 1 Scalability & Performance 2 Backup & Disaster Recovery 3 Secure Protection 4
  • 12. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Seamless Migration HYBRIDITY SECURITY ON-PREMISES CLOUD LARGE SCALE MIGRATION Active VMs Hybrid Interconnect Any-to-Any vSphere version VMware NSX Hybrid Connect 1
  • 13. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Scalability & performance (storage) 172.29.1.0/24 CGW Application Tier VMware Cloud on AWS SDDC Account Customer AWS Account Amazon S3 VPC Endpoint ENI Amazon EFS 2
  • 14. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Scalability & performance (database) CGW VMware Cloud on AWS SDDC Account Customer AWS Account ENI RDS Application Tier 2
  • 15. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Scalability & performance (load balancer) 172.29.1.0/24 CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Customer AWS Account ALBIGW IP Target Group • 172.31.1.100 • 172.31.1.101 Visitor ENI 2
  • 16. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Backup and disaster recovery Backup & Restore Pilot light Warm standby in AWS Hot standby Active/Active Low High RPO: Hours RTO: Hours Cost: $ RPO: Minutes RTO: Hours Cost: $$ RPO: Minutes RTO: Minutes Cost: $$$ RPO: Seconds RTO: Real time Cost: $$$$ 3
  • 17. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Backup & disaster recovery Customer Data Center AWS Direct Connect vSphere Environment ESXi Internet Amazon Route 53 Internet AWS Storage Gateway VM AWS Storage Gateway S3 bucket ESXi Amazon EC2 VMware Cloud on AWS SDDC NSX CGW Backup Server Backup Server 1 4 3 2 3
  • 18. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Stretched clusters AWS Availability Zone A AWS Availability Zone B … … vSphere HA/DRS span across AZ NSX logical networks Stretched Clusters … … vSAN stretched cluster VMware Cloud on AWS SDDC AWS Region  Not necessary to architect in the application  Synchronous replication between AZs 3
  • 19. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Backup & disaster recovery Disaster Recovery to VMware Cloud 1~~~~~~~~ 2~~~~~~ 3~~~~~~~~ 4~~~~~~~ VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM vSphere VMware Cloud on AWS VMware Site Recovery can solve these common DR challenges by helping you: • Accelerate time-to-protection • Simplify DR operations • Apply Cloud Economics Key Features: • Ease of initial setup and ongoing management • Simple failover with one-click • Predictable failback with one-click • Non-disruptive, on-demand testing • No IP change needed 3
  • 20. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Secure public facing applications Visitor CloudFront Route 53 172.29.1.0/24 Customer AWS Account ALBIGW WAF ENI Shield CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Edge Location 4
  • 21. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Compliance as Code Author Compliance checks in InSpec (human readable, open-source DSL) on S3/GitHub Run Compliance scans Using Run Command or periodic scans using State Manager View Compliance On Compliance UI or APIs VMs or EC2 Instances AWS System Manager describe package('audit.x86_64’) do it { should be_installed } end 4
  • 22. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Review base topology VMware Cloud ENI Customer Data Center IGW DMZ-Out(Public) ESXi ESXi ESXi ESXi Resource Pool DMZ-In (Private) App (Private) DMZ-Out (Public) IGW Compute Gateway Compute Gateway Management Gateway OS RWP OS DB2 OS APP2 OS DB1 OS APP1 Amazon EC2 AZ A AZ B AZ C VMware Cloud VPC AWS Customer VPC Reverse Web Proxy
  • 23. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Sample hybrid architecture VMware Cloud VPC ESXi Amazon EC2 ESXi ESXi ESXi Resource Pool RDS Aurora (shared) AWS Customer VPC AZ A AZ B AZ C OS DB1 Customer Data Center Route53 SSL Encrypted Traffic OS APP2 OS APP1 OS RWP DMZ-Out(Public) DMZ-In (Private) App(Private) DMZ-Out (Public) ACM ELB NFS S3-backed Cluster File System Reverse Web Proxy & Application Load- Balancer OS APP2 OS APP2 OS VMware Cloud ENI IGWIGW Compute Gateway Compute Gateway Management Gateway AWS System Manager Amazon S3 AWS Region Services OS DB2 Reverse Web Proxy Shield CloudFront
  • 24. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Demonstration
  • 25. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Hybrid cloud journey of Organisation X Seamless Migration 1 Secure Protection 2 Scalability & Performance 3 Backup & Disaster Recovery 4  Application Load Balancer  Relational Database Services (RDS)  Amazon Elastic File System (Amazon EFS)  Amazon S3  VMware Site Recovery  Amazon Route 53  Amazon CloudFront  AWS WAF  AWS Shield  Cold Migration  Live Migration
  • 26. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. • Public Website: aws.amazon.com/vmware cloud.vmware.com/vmc-aws • Public Videos: VMware Cloud on AWS Youtube (includes re:Invent 2017 breakouts) • Social Media: @awscloud #VMWonAWS VMware Cloud on AWS Resources
  • 27. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Thank you