aws summit - auckland 2017 - cloud ops

47
AUCKLAND

Upload: api-talent

Post on 22-Jan-2018

183 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: AWS Summit - Auckland 2017 - Cloud Ops

AUCKLAND

Page 2: AWS Summit - Auckland 2017 - Cloud Ops

Cloud OpsLife after an AWS Migration

Paul Dunlop – Principal Cloud Architect

@pauldunlopnz

@apitalent

Page 3: AWS Summit - Auckland 2017 - Cloud Ops
Page 4: AWS Summit - Auckland 2017 - Cloud Ops
Page 5: AWS Summit - Auckland 2017 - Cloud Ops
Page 6: AWS Summit - Auckland 2017 - Cloud Ops
Page 7: AWS Summit - Auckland 2017 - Cloud Ops
Page 8: AWS Summit - Auckland 2017 - Cloud Ops
Page 9: AWS Summit - Auckland 2017 - Cloud Ops
Page 10: AWS Summit - Auckland 2017 - Cloud Ops

Somethings Missing!

Page 11: AWS Summit - Auckland 2017 - Cloud Ops

“Service Delivery Platform”

Backups?

Monitoring?Logging?

Active Directory?

Automation?

Service Limits?

Patch Management?

Image Maintenance?

Identity & Access?

Security?

Hybrid / Network

Connectivity?

Billing?Tagging?

Configuration Management?

Page 12: AWS Summit - Auckland 2017 - Cloud Ops

SDP Exists in Every Account

Page 13: AWS Summit - Auckland 2017 - Cloud Ops

Review SDP Artefacts

Page 14: AWS Summit - Auckland 2017 - Cloud Ops

Network Connectivity

Did Anyone Think About

Routing?Network Register

Page 15: AWS Summit - Auckland 2017 - Cloud Ops
Page 16: AWS Summit - Auckland 2017 - Cloud Ops

Identity & Access

User Accounts In Each AWS Account Is Like

Having Local Users On Every Windows

Server. Don’t do it.

Page 17: AWS Summit - Auckland 2017 - Cloud Ops

RPG

Page 18: AWS Summit - Auckland 2017 - Cloud Ops

IAM Roles, Policies, Groups (RPG)

Page 19: AWS Summit - Auckland 2017 - Cloud Ops
Page 20: AWS Summit - Auckland 2017 - Cloud Ops

Tagging

Security

Billing

Business

Automation

Page 21: AWS Summit - Auckland 2017 - Cloud Ops
Page 22: AWS Summit - Auckland 2017 - Cloud Ops
Page 23: AWS Summit - Auckland 2017 - Cloud Ops

Backups

How Can I Use Tags To Backup

My Instances?

Page 24: AWS Summit - Auckland 2017 - Cloud Ops
Page 25: AWS Summit - Auckland 2017 - Cloud Ops

Patch & Image Management

HOW DO I KEEP MY EC2 INSTANCES

PATCHED

HOW DO I PATCH MY GOLD IMAGES?

Page 26: AWS Summit - Auckland 2017 - Cloud Ops

EC2 Systems Manager

Page 27: AWS Summit - Auckland 2017 - Cloud Ops

EC2 / PATCHES IS SIMILAR TO WSUS

27

Page 28: AWS Summit - Auckland 2017 - Cloud Ops
Page 29: AWS Summit - Auckland 2017 - Cloud Ops
Page 30: AWS Summit - Auckland 2017 - Cloud Ops

Configuration Management

HOW DO WE TRACK AWS RESOURCE

STATE AND CONFIGURATION

CHANGES IN AWS?

Page 31: AWS Summit - Auckland 2017 - Cloud Ops

• Config is also Rules based

• Rules can be Lambda functions

Page 32: AWS Summit - Auckland 2017 - Cloud Ops

Enable It

On All

Accounts

Page 33: AWS Summit - Auckland 2017 - Cloud Ops

Security Auditing

AWS CloudTrail

Event Occurs

Generating API

Activity

Cloudtrail

Captures And

Records The API

Activity

Page 34: AWS Summit - Auckland 2017 - Cloud Ops

Enable It

On All

Accounts

Page 35: AWS Summit - Auckland 2017 - Cloud Ops

Pro Tip

System Logs And Application Metrics

Are Not Logged By Default

CloudWatch

Amazon CloudWatch collects and tracks

metrics, collects and monitors log files, set

alarms, and automatically react to changes in

your AWS resources.

Page 36: AWS Summit - Auckland 2017 - Cloud Ops
Page 37: AWS Summit - Auckland 2017 - Cloud Ops

Bucket Overflow

OPS

Page 38: AWS Summit - Auckland 2017 - Cloud Ops

38

Page 39: AWS Summit - Auckland 2017 - Cloud Ops

Centralise Logging

Page 40: AWS Summit - Auckland 2017 - Cloud Ops
Page 41: AWS Summit - Auckland 2017 - Cloud Ops

Optimisation & Automation

Page 42: AWS Summit - Auckland 2017 - Cloud Ops

Service Limits

https://aws.amazon.com/answers/account-management/limit-monitor/

Page 43: AWS Summit - Auckland 2017 - Cloud Ops
Page 44: AWS Summit - Auckland 2017 - Cloud Ops

• Each AWS account comes

with a Service Delivery

Platform

• Architects should advocate

the Cloud Center of

Excellence and drive new

operational standards

• Automate, Centralise & Log

everything

Page 45: AWS Summit - Auckland 2017 - Cloud Ops

IMPORTANT MESSAGE

BEFORE YOU GO :)

Page 46: AWS Summit - Auckland 2017 - Cloud Ops

API Talent Booth Promotions

Crazy Cloud Native Idea

Migration and Managed Services

This might be an API or other type

of cloud native app. We will select two

best ideas from the jar and implement

them.

We’ll migrate a lucky customers’ workloads

to AWS and provide 12 months managed

services!

JAR 1

JAR 2

Page 47: AWS Summit - Auckland 2017 - Cloud Ops

@pauldunlopnz

@apitalent

Paul Dunlop – Principal Cloud Architect