SlideShare a Scribd company logo
1 of 30
©  2016,  Amazon  Web  Services,  Inc.  or  its  Affiliates.  All  rights  reserved.
Phil  Barlow    
Solutions  Architect,  Amazon  Web  Services
Creating  Your  Hybrid  Cloud  with  AWS
Technical  201
The  Goal  For  Today
Your  Data  Center
Orchestration Orchestration
Integrated
Integrated
The  Foundations
Connectivity
Perimeter  Security
Extending  DNS
Federated  Authentication
Integrated  Monitoring
1
2
3
4
5
VPC  Subnet
Availability  Zone
Security  group
VPC  subnet
Availability  Zone
Security  group
Connectivity
1. Most  Specific  Route
2. Direct  Connect
3. Static  VPN
4. Dynamic  VPN
5. Shortest  AS  Path  (BGP)
Your  
data  center
Data  center  router
Customer  
Router
Servers
IPSec  VPN
Peering  Point
AWS  DX  routers
Virtual
Gateway
Traditional  Zone  Model
Prod Pre-­Prod Test Dev
Corporate  
data  center
VPC  Design  Considerations
Production
• Trusted  Zones
• Managed  Independently
• SG  will  govern  Ingress  &  
Egress  based  on  App
• A  Proxy  Layer  could  simplify
• Be  flexible  with  your  VPC  
design
Pre  Production Dev  &  Test
Corporate  
data  center
Availability  Zone
Availability  Zone
Hybrid  DNS  Architecture
Corporate  
data  center
Users
On  Prem DNS  
Forwarders
Virtual
Gateway
AWS  Directory  
Service
Customer
Gateway
VPC
Provided  DNS
Route  53
Private
Hosted  Zone
AWS  Directory  
Service
Hybrid  Access  Control
AWS  IAM
AWS  Directory  
Service
• Utilise existing  IDM  policies
• Provide  SSO  to  Apps,  Console  
and  API’s
• AD  Connector
• Enterprise  Federation  with  
SAML  2.0  compliant  IdP
Hybrid  Visibility
AWS Partner  &  Opensource
Metric  and
Performance  
Data
Security  Data
Analytics
AWS
CloudTrail
Amazon  
CloudWatch
Logs
Amazon
Elasticsearch
Amazon  
Kinesis
VPC
Flow  logs
AWS
Lambda
Amazon  
CloudWatch
Integrated  Environments
Connected
Secure
Seamless  Application  Communication
Controlled  Access
Visibility
1
2
3
4
5
Evolution  Of  Orchestration
EVOLVING
VM
SNOWFLAKES CICD
Separate Building Config Mgmt DevOps
AWS  Tools
Existing  
Tools
Skills/Process
Build  Style AUTOMATION
Build  &  Migrate
Evolution  Of  Orchestration
AUTOMATIONEVOLVING
VM
SNOWFLAKES CICD
Separate Building Config Mgmt DevOps
AWS  Tools
Existing  
Tools
Skills/Process
Build  Style
Working  With  Landscapes
Admin UsersCloudFormation
Template AWS  Service  Catalog
CloudFormation
Stack
Product
Owner
Creates  portfolio
Adds  constraints  
and  grant  access
1
4
5
Administrators
and
Product  Owners
Portfolio
Users
Browse  Products
6Launch  Products
AWS  
CloudFormation
template
Creates  
product
3Authors  template
2
ProductX ProductY ProductZ
7
Deploys  
stacks Events
Events
8
8
Service  Catalog  Flow
Evolution  Of  Orchestration
AUTOMATIONEVOLVING
VM
SNOWFLAKES CICD
Separate Building Config Mgmt DevOps
AWS  Tools
Existing  
Tools
Skills/Process
Build  Style
Working  With  Landscapes
Admin UsersCloudFormation
Template AWS  Service  Catalog
CloudFormation
Stack
Product
Owner
Build  A  Pipeline
AWS
CloudFormation
AWS
CodePipeline
Amazon
S3
AWS
CodeDeploy
Github
Amazon  
EC2
Demo
Tagline   or  document   title20 |
Rajiv  Sri  Skantha  Rajah,  
Head  of  Technology  Architecture,  CTO  Function
Hybrid	
  Cloud	
  Evolution
Who  we  are…
4000
financial  advisers
5400
employees
800,000  
shareholders  
4  million+  
customers
$226  bn
assets  under  mgmt
Helping  people  own  tomorrow
Reference:  2015  annual  report
DevOps Lifecycle
Leverage  Cloud  (Private  and  Public)  services  as  an  innovation   platform  which  can  meet  the  
needs  for  rapid  experimentation   using  new  /  disruptive  technologies…   through  high  degrees  of  
automation
Business
Developers
(application)
IT  Operations
(Technology)
Enterprise
Agility
IT
AgilityCommodity  Services  e.g.  Compute,  Hosting,  Network,  Storage  etc…
Foundational  Services  e.g.  Assurance,  IDAM,  Integration,  etc…  
Technology  Services Application  Services Platform  Services
Service  Interface  e.g.  Self  Service  Portal,  API’s
Cloud  Services
Innovation
4
3
2
1 Customer  Insight  Driven  Design
Customers
Business  
Owners
Development  /  
Test
Operations  /  
Production
GrowthValue
• Using  customer  insight  to  
evolve  our  solutions
• Incremental  deployment  with  
shorter  cycle  times  from  
experimentation,  prototyping  
and  through  to  production  
scale
• Snap  in  and  out  technical  
services  to  deliver  business  
outcomes
• Strengthen  core  foundational  
services  to  provide  a  stable  
platform  to  enable  the  
adoption  of  new  technology  
services
4
3
2
1
How  we  started  our  Cloud  1.0  Journey?
Cloud  Program  
Migration  
Factory
Australian   Region  
opened   for  business
2015…  
Cloud  Program  
Completes
Cloud  
Program  
Initiated
Commence  build  of  
migration factory
Migrated   a  range   of  production  
low  value   systems
~70%  
of  midrange
hosted  across   Private  
and  Public  Cloud
~30%  
Reduction   in  
Infrastructure  
Costs
Focused   on  cost  optimisation,  elastic  compute  and  
consumption   based   pricing…contestability  was  priority..  
portability  was  important
Mode  1  
moves  to  
BAU
Mode  2  
continues  
journey
2012…  
Our  journey  
Begins
Incubator   approach   to  test,  learn  
and   validate   solution   and   controls
...The  question  is  no  longer:  
‘How  do  I  move  to  the  cloud?’  
Detailed  assessment  
applications for  
suitability
Migrated   a  range   of  production  
high   value  systems
Define  
migration  
scope
Zone  2
Onshore   -­ Virtual  Private Cloud
Zone  1
Onsite -­ Private Cloud
Zone  0
Traditional   Managed Services
Zone  3
Onshore   -­ Virtual  Private Cloud
Zone  4
Onshore   -­ Virtual  Private Cloud
Production,  
Critical
Non-­prod,  
non-­critical
Isolated  Lab
Confidential  
Data
Public  Data
Cloud  
Zones  (IaaS)
Workload  
Types
Data  
Classification
Our  implementation  of  a  Hybrid  Cloud  environment  comprised  
of  multiple  zones  based  on  service  levels  and  technical  
capabilities…workloads  were  assessed  and  placed  into  the  most  
appropriate  zones
‘Now  that  I’m  in  the  
cloud,  how  do  I  make  
sure  I’ve  optimized  my  
investment  and  risk  
exposure”
Cloud  2.0  is  shifting  to  include  opportunities  relating  to  business  agility  and  
developer  productivity…  Cloud  native  workloads  take  maximum  advantage  of  
the  benefits  of  cloud
Cloud  2.0….Evolution  and  Maturing  of  Cloud…
Automation
Auto   Scaling
Auto   Healing
Cloud  Centre  
of  Excellence  
(COE)
• Identify  opportunities to  
further  drive  efficiencies
Cloud  Centre  of  Excellence
-­Keep  abreast  of  new  cloud  services  
-­Support  the  automation  build  factory
-­Educate  and  train  teams  on  cloud  best  practises
Cloud  2.0  first  principle Migrate  AEM  to  Mode  2  operation
One  Click  
Deploy
100%  
Re-­Architected  our  
integration  platform
§ Leverage  cloud  as  an  innovation  
platform…  shift  the  culture
§ Nothing  hand  crafted…  all  automated
§ Security  by  design…
§ Application  AND Infrastructure  is  versioned  
together
§ Consistency  is  key…  across  all  
environments
§ Architect  for  failure…  chaos  engineering
Key  Insights  /  Learnings
A  Hybrid  Car  uses  2  Engines.  
I  give  one  Petrol  and  the  other  Electricity.  
They  both  deliver  propulsion  but  the  way  it  is  delivered  has  
different  characteristics.  
I  have  a  policy  for  when  either  is  used:
Integrate  the  Infrastructure  and Integrate  the  Orchestration.
Parting  Thought
AWS  Training  &  Certification
Intro  Videos  &  Labs  
Free  videos  and  labs  to  
help  you  learn  to  work  
with  30+  AWS  services  
– in  minutes!
Training  Classes
In-­person  and  online  
courses  to  build  
technical  skills  –
taught  by  accredited  
AWS  instructors
Online  Labs  
Practice  working  with  
AWS  services  in  live  
environment  –
Learn  how  related  
services  work  
together
AWS  Certification
Validate  technical  
skills  and  expertise    -­
identify  qualified  IT  
talent  or  show  you  
are  AWS  cloud  ready
Learn  more:  aws.amazon.com/training
Your  Training  Next  Steps:
ü Visit  the  AWS  Training  &  Certification  pod  to  discuss  your  
training  plan  &  AWS  Summit  training  offer
ü Register  &  attend  AWS  instructor  led  training
ü Get  Certified
AWS  Certified?  Visit  the  AWS  Summit  Certification  Lounge  to  pick  up  your  swag
Learn  more:  aws.amazon.com/training
Thank  you!

More Related Content

What's hot

What's hot (20)

A Walk in the Cloud with AWS Lambda
A Walk in the Cloud with AWS LambdaA Walk in the Cloud with AWS Lambda
A Walk in the Cloud with AWS Lambda
 
Deep dive into AWS IAM
Deep dive into AWS IAMDeep dive into AWS IAM
Deep dive into AWS IAM
 
AWS IoT를 통해 클라우드로 세상을 연결하는 방법 - 이종화 솔루션즈 아키텍트, AWS / 최원근 솔루션즈 아키텍트, AWS :: AW...
AWS IoT를 통해 클라우드로 세상을 연결하는 방법 - 이종화 솔루션즈 아키텍트, AWS / 최원근 솔루션즈 아키텍트, AWS :: AW...AWS IoT를 통해 클라우드로 세상을 연결하는 방법 - 이종화 솔루션즈 아키텍트, AWS / 최원근 솔루션즈 아키텍트, AWS :: AW...
AWS IoT를 통해 클라우드로 세상을 연결하는 방법 - 이종화 솔루션즈 아키텍트, AWS / 최원근 솔루션즈 아키텍트, AWS :: AW...
 
A Brief Look at Serverless Architecture
A Brief Look at Serverless ArchitectureA Brief Look at Serverless Architecture
A Brief Look at Serverless Architecture
 
Amazon S3 and EC2
Amazon S3 and EC2Amazon S3 and EC2
Amazon S3 and EC2
 
AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019
 
[AWS Builders] Effective AWS Glue
[AWS Builders] Effective AWS Glue[AWS Builders] Effective AWS Glue
[AWS Builders] Effective AWS Glue
 
Amazon SQS overview
Amazon SQS overviewAmazon SQS overview
Amazon SQS overview
 
AWS 101: Introduction to AWS
AWS 101: Introduction to AWSAWS 101: Introduction to AWS
AWS 101: Introduction to AWS
 
Introduction to Amazon EC2
Introduction to Amazon EC2Introduction to Amazon EC2
Introduction to Amazon EC2
 
Intro to AWS: EC2 & Compute Services
Intro to AWS: EC2 & Compute ServicesIntro to AWS: EC2 & Compute Services
Intro to AWS: EC2 & Compute Services
 
AWS Lambda
AWS LambdaAWS Lambda
AWS Lambda
 
AWS vs Azure vs Google (GCP) - Slides
AWS vs Azure vs Google (GCP) - SlidesAWS vs Azure vs Google (GCP) - Slides
AWS vs Azure vs Google (GCP) - Slides
 
Intro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute ServicesIntro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute Services
 
Lambda를 활용한 서버없는 아키텍쳐 구현하기 :: 김기완 :: AWS Summit Seoul 2016
Lambda를 활용한 서버없는 아키텍쳐 구현하기 :: 김기완 :: AWS Summit Seoul 2016Lambda를 활용한 서버없는 아키텍쳐 구현하기 :: 김기완 :: AWS Summit Seoul 2016
Lambda를 활용한 서버없는 아키텍쳐 구현하기 :: 김기완 :: AWS Summit Seoul 2016
 
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
 
AWS Data Transfer Services Deep Dive
AWS Data Transfer Services Deep Dive AWS Data Transfer Services Deep Dive
AWS Data Transfer Services Deep Dive
 
Amazon ECS
Amazon ECSAmazon ECS
Amazon ECS
 
Amazon simple storage service (amazon s3)
Amazon simple storage service (amazon s3)Amazon simple storage service (amazon s3)
Amazon simple storage service (amazon s3)
 
Introduction to AWS Cost Management
Introduction to AWS Cost ManagementIntroduction to AWS Cost Management
Introduction to AWS Cost Management
 

Viewers also liked

Hybrid ERP Pov
Hybrid ERP PovHybrid ERP Pov
Hybrid ERP Pov
Tim Hofer
 

Viewers also liked (20)

AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises W...
 
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
 
Building an AWS Hybrid Cloud
Building an AWS Hybrid CloudBuilding an AWS Hybrid Cloud
Building an AWS Hybrid Cloud
 
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
Hybrid IT Approach and Technologies with the AWS Cloud | AWS Public Sector Su...
 
AWS re:Invent 2016: How to Manage Inventory, Patching, and System Images for ...
AWS re:Invent 2016: How to Manage Inventory, Patching, and System Images for ...AWS re:Invent 2016: How to Manage Inventory, Patching, and System Images for ...
AWS re:Invent 2016: How to Manage Inventory, Patching, and System Images for ...
 
Hybrid ERP Pov
Hybrid ERP PovHybrid ERP Pov
Hybrid ERP Pov
 
AWSome Day Thailand Keynote 2015
AWSome Day Thailand Keynote 2015AWSome Day Thailand Keynote 2015
AWSome Day Thailand Keynote 2015
 
Azure and/or AWS: How to Choose the best cloud platform for your project
Azure and/or AWS: How to Choose the best cloud platform for your projectAzure and/or AWS: How to Choose the best cloud platform for your project
Azure and/or AWS: How to Choose the best cloud platform for your project
 
Keeping Developers and Auditors Happy in the Cloud
Keeping Developers and Auditors Happy in the Cloud Keeping Developers and Auditors Happy in the Cloud
Keeping Developers and Auditors Happy in the Cloud
 
Advanced security best practices - Masterclass - Pop-up Loft Tel Aviv
Advanced security best practices - Masterclass - Pop-up Loft Tel AvivAdvanced security best practices - Masterclass - Pop-up Loft Tel Aviv
Advanced security best practices - Masterclass - Pop-up Loft Tel Aviv
 
IAM Best Practices to Live By - Pop-up Loft Tel Aviv
IAM Best Practices to Live By - Pop-up Loft Tel AvivIAM Best Practices to Live By - Pop-up Loft Tel Aviv
IAM Best Practices to Live By - Pop-up Loft Tel Aviv
 
The Nordic Startup Scene
The Nordic Startup SceneThe Nordic Startup Scene
The Nordic Startup Scene
 
Maintaining Trust & Control of your Data in the Cloud
Maintaining Trust & Control of your Data in the CloudMaintaining Trust & Control of your Data in the Cloud
Maintaining Trust & Control of your Data in the Cloud
 
The Science of Saving with AWS Reserved Instances -Session Sponsored by Cloud...
The Science of Saving with AWS Reserved Instances -Session Sponsored by Cloud...The Science of Saving with AWS Reserved Instances -Session Sponsored by Cloud...
The Science of Saving with AWS Reserved Instances -Session Sponsored by Cloud...
 
What's (nearly) new | AWS Security Roadshow Dublin
What's (nearly) new | AWS Security Roadshow DublinWhat's (nearly) new | AWS Security Roadshow Dublin
What's (nearly) new | AWS Security Roadshow Dublin
 
AWS vs AZURE : Public Cloud Comparison
AWS vs AZURE : Public Cloud ComparisonAWS vs AZURE : Public Cloud Comparison
AWS vs AZURE : Public Cloud Comparison
 
Deploying a Disaster Recovery Site on AWS: Minimal Cost with Maximum Efficiency
Deploying a Disaster Recovery Site on AWS: Minimal Cost with Maximum EfficiencyDeploying a Disaster Recovery Site on AWS: Minimal Cost with Maximum Efficiency
Deploying a Disaster Recovery Site on AWS: Minimal Cost with Maximum Efficiency
 
AWSome Day Intro - Copenhagen 20160309
AWSome Day Intro - Copenhagen 20160309AWSome Day Intro - Copenhagen 20160309
AWSome Day Intro - Copenhagen 20160309
 
Hybrid strategy
Hybrid strategyHybrid strategy
Hybrid strategy
 
Startup Showcase - Mojang
Startup Showcase - MojangStartup Showcase - Mojang
Startup Showcase - Mojang
 

Similar to Creating your Hybrid Cloud with AWS -Technical 201

RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
RightScale
 
Steve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud ComputingSteve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud Computing
Mauricio Godoy
 

Similar to Creating your Hybrid Cloud with AWS -Technical 201 (20)

Getting Started with Windows Workloads on Amazon EC2 - Toronto
 Getting Started with Windows Workloads on Amazon EC2 - Toronto Getting Started with Windows Workloads on Amazon EC2 - Toronto
Getting Started with Windows Workloads on Amazon EC2 - Toronto
 
Operating and Managing Hybrid Cloud on AWS
Operating and Managing Hybrid Cloud on AWSOperating and Managing Hybrid Cloud on AWS
Operating and Managing Hybrid Cloud on AWS
 
Migrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWSMigrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWS
 
Cloud Computing & Sun Vision 03262009
Cloud Computing & Sun Vision 03262009Cloud Computing & Sun Vision 03262009
Cloud Computing & Sun Vision 03262009
 
2011.11.22 - Cloud Infrastructure Provider - 8ème Forum du Club Cloud des Par...
2011.11.22 - Cloud Infrastructure Provider - 8ème Forum du Club Cloud des Par...2011.11.22 - Cloud Infrastructure Provider - 8ème Forum du Club Cloud des Par...
2011.11.22 - Cloud Infrastructure Provider - 8ème Forum du Club Cloud des Par...
 
The Ultimate Guide to Cloud Migration - A Whitepaper by RapidValue
The Ultimate Guide to Cloud Migration - A Whitepaper by RapidValueThe Ultimate Guide to Cloud Migration - A Whitepaper by RapidValue
The Ultimate Guide to Cloud Migration - A Whitepaper by RapidValue
 
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
 
RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
RightScale Webinar: Operationalize Your Enterprise AWS Usage Through an IT Ve...
 
Benefits of Cloud Computing
Benefits of Cloud ComputingBenefits of Cloud Computing
Benefits of Cloud Computing
 
Oracle Keynote Cloud Expo 11-04-09
Oracle Keynote Cloud Expo 11-04-09Oracle Keynote Cloud Expo 11-04-09
Oracle Keynote Cloud Expo 11-04-09
 
re:Invent 2019 ARC217-R: Operating and managing hybrid cloud on AWS
re:Invent 2019 ARC217-R: Operating and managing hybrid cloud on AWSre:Invent 2019 ARC217-R: Operating and managing hybrid cloud on AWS
re:Invent 2019 ARC217-R: Operating and managing hybrid cloud on AWS
 
AWS APAC Webinar Week - Training & Certification Masterclass
AWS APAC Webinar Week - Training & Certification MasterclassAWS APAC Webinar Week - Training & Certification Masterclass
AWS APAC Webinar Week - Training & Certification Masterclass
 
AWS Enterprise Summit Netherlands - Creating a Landing Zone
AWS Enterprise Summit Netherlands - Creating a Landing ZoneAWS Enterprise Summit Netherlands - Creating a Landing Zone
AWS Enterprise Summit Netherlands - Creating a Landing Zone
 
(SEC321) Implementing Policy, Governance & Security for Enterprises
(SEC321) Implementing Policy, Governance & Security for Enterprises(SEC321) Implementing Policy, Governance & Security for Enterprises
(SEC321) Implementing Policy, Governance & Security for Enterprises
 
It summit 2014_migrating_applications_to_the_cloud-5
It summit 2014_migrating_applications_to_the_cloud-5It summit 2014_migrating_applications_to_the_cloud-5
It summit 2014_migrating_applications_to_the_cloud-5
 
Continuous Delivery to the cloud - Innovate 2014
Continuous Delivery to the cloud - Innovate 2014Continuous Delivery to the cloud - Innovate 2014
Continuous Delivery to the cloud - Innovate 2014
 
Develop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
Develop an Enterprise-wide Cloud Adoption Strategy – Chris MerriganDevelop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
Develop an Enterprise-wide Cloud Adoption Strategy – Chris Merrigan
 
Mahika cloud services
Mahika cloud servicesMahika cloud services
Mahika cloud services
 
Steve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud ComputingSteve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud Computing
 
Automate the Provisioning of Secure Developer Environments on AWS PPT
 Automate the Provisioning of Secure Developer Environments on AWS PPT Automate the Provisioning of Secure Developer Environments on AWS PPT
Automate the Provisioning of Secure Developer Environments on AWS PPT
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Recently uploaded (20)

Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 

Creating your Hybrid Cloud with AWS -Technical 201

  • 1. ©  2016,  Amazon  Web  Services,  Inc.  or  its  Affiliates.  All  rights  reserved. Phil  Barlow     Solutions  Architect,  Amazon  Web  Services Creating  Your  Hybrid  Cloud  with  AWS Technical  201
  • 2. The  Goal  For  Today Your  Data  Center Orchestration Orchestration Integrated Integrated
  • 3. The  Foundations Connectivity Perimeter  Security Extending  DNS Federated  Authentication Integrated  Monitoring 1 2 3 4 5
  • 4. VPC  Subnet Availability  Zone Security  group VPC  subnet Availability  Zone Security  group Connectivity 1. Most  Specific  Route 2. Direct  Connect 3. Static  VPN 4. Dynamic  VPN 5. Shortest  AS  Path  (BGP) Your   data  center Data  center  router Customer   Router Servers IPSec  VPN Peering  Point AWS  DX  routers Virtual Gateway
  • 5. Traditional  Zone  Model Prod Pre-­Prod Test Dev Corporate   data  center
  • 6. VPC  Design  Considerations Production • Trusted  Zones • Managed  Independently • SG  will  govern  Ingress  &   Egress  based  on  App • A  Proxy  Layer  could  simplify • Be  flexible  with  your  VPC   design Pre  Production Dev  &  Test Corporate   data  center
  • 7. Availability  Zone Availability  Zone Hybrid  DNS  Architecture Corporate   data  center Users On  Prem DNS   Forwarders Virtual Gateway AWS  Directory   Service Customer Gateway VPC Provided  DNS Route  53 Private Hosted  Zone AWS  Directory   Service
  • 8. Hybrid  Access  Control AWS  IAM AWS  Directory   Service • Utilise existing  IDM  policies • Provide  SSO  to  Apps,  Console   and  API’s • AD  Connector • Enterprise  Federation  with   SAML  2.0  compliant  IdP
  • 9. Hybrid  Visibility AWS Partner  &  Opensource Metric  and Performance   Data Security  Data Analytics AWS CloudTrail Amazon   CloudWatch Logs Amazon Elasticsearch Amazon   Kinesis VPC Flow  logs AWS Lambda Amazon   CloudWatch
  • 10. Integrated  Environments Connected Secure Seamless  Application  Communication Controlled  Access Visibility 1 2 3 4 5
  • 11. Evolution  Of  Orchestration EVOLVING VM SNOWFLAKES CICD Separate Building Config Mgmt DevOps AWS  Tools Existing   Tools Skills/Process Build  Style AUTOMATION
  • 13. Evolution  Of  Orchestration AUTOMATIONEVOLVING VM SNOWFLAKES CICD Separate Building Config Mgmt DevOps AWS  Tools Existing   Tools Skills/Process Build  Style
  • 14. Working  With  Landscapes Admin UsersCloudFormation Template AWS  Service  Catalog CloudFormation Stack Product Owner
  • 15. Creates  portfolio Adds  constraints   and  grant  access 1 4 5 Administrators and Product  Owners Portfolio Users Browse  Products 6Launch  Products AWS   CloudFormation template Creates   product 3Authors  template 2 ProductX ProductY ProductZ 7 Deploys   stacks Events Events 8 8 Service  Catalog  Flow
  • 16. Evolution  Of  Orchestration AUTOMATIONEVOLVING VM SNOWFLAKES CICD Separate Building Config Mgmt DevOps AWS  Tools Existing   Tools Skills/Process Build  Style
  • 17. Working  With  Landscapes Admin UsersCloudFormation Template AWS  Service  Catalog CloudFormation Stack Product Owner
  • 19. Demo
  • 20. Tagline   or  document   title20 | Rajiv  Sri  Skantha  Rajah,   Head  of  Technology  Architecture,  CTO  Function Hybrid  Cloud  Evolution
  • 21. Who  we  are… 4000 financial  advisers 5400 employees 800,000   shareholders   4  million+   customers $226  bn assets  under  mgmt Helping  people  own  tomorrow Reference:  2015  annual  report
  • 22. DevOps Lifecycle Leverage  Cloud  (Private  and  Public)  services  as  an  innovation   platform  which  can  meet  the   needs  for  rapid  experimentation   using  new  /  disruptive  technologies…   through  high  degrees  of   automation Business Developers (application) IT  Operations (Technology) Enterprise Agility IT AgilityCommodity  Services  e.g.  Compute,  Hosting,  Network,  Storage  etc… Foundational  Services  e.g.  Assurance,  IDAM,  Integration,  etc…   Technology  Services Application  Services Platform  Services Service  Interface  e.g.  Self  Service  Portal,  API’s Cloud  Services Innovation 4 3 2 1 Customer  Insight  Driven  Design Customers Business   Owners Development  /   Test Operations  /   Production GrowthValue • Using  customer  insight  to   evolve  our  solutions • Incremental  deployment  with   shorter  cycle  times  from   experimentation,  prototyping   and  through  to  production   scale • Snap  in  and  out  technical   services  to  deliver  business   outcomes • Strengthen  core  foundational   services  to  provide  a  stable   platform  to  enable  the   adoption  of  new  technology   services 4 3 2 1
  • 23. How  we  started  our  Cloud  1.0  Journey? Cloud  Program   Migration   Factory Australian   Region   opened   for  business 2015…   Cloud  Program   Completes Cloud   Program   Initiated Commence  build  of   migration factory Migrated   a  range   of  production   low  value   systems ~70%   of  midrange hosted  across   Private   and  Public  Cloud ~30%   Reduction   in   Infrastructure   Costs Focused   on  cost  optimisation,  elastic  compute  and   consumption   based   pricing…contestability  was  priority..   portability  was  important Mode  1   moves  to   BAU Mode  2   continues   journey 2012…   Our  journey   Begins Incubator   approach   to  test,  learn   and   validate   solution   and   controls ...The  question  is  no  longer:   ‘How  do  I  move  to  the  cloud?’   Detailed  assessment   applications for   suitability Migrated   a  range   of  production   high   value  systems Define   migration   scope Zone  2 Onshore   -­ Virtual  Private Cloud Zone  1 Onsite -­ Private Cloud Zone  0 Traditional   Managed Services Zone  3 Onshore   -­ Virtual  Private Cloud Zone  4 Onshore   -­ Virtual  Private Cloud Production,   Critical Non-­prod,   non-­critical Isolated  Lab Confidential   Data Public  Data Cloud   Zones  (IaaS) Workload   Types Data   Classification Our  implementation  of  a  Hybrid  Cloud  environment  comprised   of  multiple  zones  based  on  service  levels  and  technical   capabilities…workloads  were  assessed  and  placed  into  the  most   appropriate  zones ‘Now  that  I’m  in  the   cloud,  how  do  I  make   sure  I’ve  optimized  my   investment  and  risk   exposure”
  • 24. Cloud  2.0  is  shifting  to  include  opportunities  relating  to  business  agility  and   developer  productivity…  Cloud  native  workloads  take  maximum  advantage  of   the  benefits  of  cloud Cloud  2.0….Evolution  and  Maturing  of  Cloud… Automation Auto   Scaling Auto   Healing Cloud  Centre   of  Excellence   (COE) • Identify  opportunities to   further  drive  efficiencies Cloud  Centre  of  Excellence -­Keep  abreast  of  new  cloud  services   -­Support  the  automation  build  factory -­Educate  and  train  teams  on  cloud  best  practises Cloud  2.0  first  principle Migrate  AEM  to  Mode  2  operation One  Click   Deploy 100%   Re-­Architected  our   integration  platform
  • 25. § Leverage  cloud  as  an  innovation   platform…  shift  the  culture § Nothing  hand  crafted…  all  automated § Security  by  design… § Application  AND Infrastructure  is  versioned   together § Consistency  is  key…  across  all   environments § Architect  for  failure…  chaos  engineering Key  Insights  /  Learnings
  • 26.
  • 27. A  Hybrid  Car  uses  2  Engines.   I  give  one  Petrol  and  the  other  Electricity.   They  both  deliver  propulsion  but  the  way  it  is  delivered  has   different  characteristics.   I  have  a  policy  for  when  either  is  used: Integrate  the  Infrastructure  and Integrate  the  Orchestration. Parting  Thought
  • 28. AWS  Training  &  Certification Intro  Videos  &  Labs   Free  videos  and  labs  to   help  you  learn  to  work   with  30+  AWS  services   – in  minutes! Training  Classes In-­person  and  online   courses  to  build   technical  skills  – taught  by  accredited   AWS  instructors Online  Labs   Practice  working  with   AWS  services  in  live   environment  – Learn  how  related   services  work   together AWS  Certification Validate  technical   skills  and  expertise    -­ identify  qualified  IT   talent  or  show  you   are  AWS  cloud  ready Learn  more:  aws.amazon.com/training
  • 29. Your  Training  Next  Steps: ü Visit  the  AWS  Training  &  Certification  pod  to  discuss  your   training  plan  &  AWS  Summit  training  offer ü Register  &  attend  AWS  instructor  led  training ü Get  Certified AWS  Certified?  Visit  the  AWS  Summit  Certification  Lounge  to  pick  up  your  swag Learn  more:  aws.amazon.com/training