SlideShare a Scribd company logo
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Alex Coqueiro
Public Sector Solutions Architect
Abril, 2016
Comenzando con la nube híbrida
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
Cloud is an ALL or NOTHING proposition
The Good News is it isn’t an ‘All or Nothing’ Choice
Corporate
Data Centers
On-Premises
Resources
Cloud
Resources
Integration
Hybrid IT
Hybrid IT: A Definition
http://www.gartner.com/technology/research/technical-professionals/hybrid-cloud.jsp
“Hybrid IT is the result of combining internal and
external services, usually from a combination of
internal and public clouds, in support of a business
outcome.”
http://www.gartner.com/technology/research/technical-professionals/hybrid-cloud.jsp
“Hybrid IT is the result of combining internal and
external services, usually from a combination of
internal and public clouds, in support of a business
outcome.”
Hybrid IT: A Definition
Your Data Center
Your Data Center
Extending Your DC to your Cloud Provider
Your Data Center
Your LAN
Segments
AWS VPC
Integrated
networking
# 10.0.100.0
# 10.0.200.0
Integrating AWS with existing On-Prem Infrastructure
Integrated
access control
Microsoft Active
Directory
Custom
LDAP
Commom Hybrid
Workloads
App 1
AWS Storage
Gateway
Single pane
of glass
Enterprise
Integration
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
Direct ConnectVirtual Private
Cloud (VPC)
Services: Networking
Trend: Integrated Network
Your Data Center
Project A
Deployed
Virtual Private
Cloud (VPC)
Direct Connect
VPN
Tunnels
Customer VPN
Gateway
Directory
Server
Database
Server
Application
Server
Client
VPC Configuration
• VPC CIDR Network: 10.100.0.0/16
• VPC Subnet 1: 10.100.0.0/23
• VPC Subnet 2: 10.100.2.0/23
• VPN Type: Dynamic BGP
• Security Group: HTTP, HTTPS, SSH, ICMP
Data Center Configuration
• Corporate Network: 10.96.0.0/16
• DC Network: 10.96.24.0/21
• VPN Gateway IP: 54.254.241.240
Your First Virtual Private Cloud
Application
Server
Availability Zone BAvailability Zone A
VPN
Tunnels
Customer VPN
Gateway
Directory
Server
Database
Server
Application
Server
Client
Other VPC Features
• Multiple VPCs per account
• Multiple network interfaces per EC2 instance
• Multiple IPs per interface
• Move network interfaces between EC2 instances
• Egress filtering with security groups and network ACLs
• Virtual network peering between VPCs
• Direct Connect cross region routing
• Support for dedicated instance, single tenant EC2
Services: Networking
Application
Server
Availability Zone BAvailability Zone A
VPC Released 2009
• Mature virtual networking service
• Highly scalable, up to 64K hosts per VPC
• Features focused on enterprise integration
Integrate your network with Amazon VPC
• Connect via standard IPSEC Internet VPN tunnels, or
• Private link to AWS Direct Connect peering location,
or a combination of both
• Connection port speeds from 50M to 10G, you choose the
connection speed you want
• Connect multiple VPCs using industry standard VLANs and
layer 3 routing protocols
• Integrate your network to your private VPC resources
• Deploy your own network equipment into Direct Connect
peering location, e.g. WAN Optimization Devices
Compute Storage
AWS Global Infrastructure
Database
App Services
Deployment & Administration
Networking
Customer VPC
Internet VPN
Connection
Customer IPSEC
Router/Firewall
Customer Direct
Connect Router
Private Direct
Connect
Customer Corporate
Network
Services: Networking: Direct Connect
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
Common Hybrid Workloads
Common Hybrid Workloads
AWS Storage
Gateway
AWS S3
Simple Storage
Service
Services: Storage
Application
Server
Virtual
Server
File
Server
Database
Server
Backup
System
On-premise backup server with S3
• Eliminate tape, hardware, off-site storage
• Reduce capital expense for backup infrastructure
• Never worry about backup durability
• Never run out of backup capacity
• Backup gateway integrated to Amazon S3
• Data stored off-site, with high durability, in multiple locations
• Take advantage of advanced storage optimization options,
De-duplication, compression, WAN acceleration
Backup and Archive
Amazon S3
Application
Server
Virtual
Server
File
Server
Database
Server
Amazon S3
Solutions supporting backup and archive to S3
Veeam Backup & Replication
Symantec Net Backup
Oracle RMAN and Secure Backup Module
CommVault Simpana
AWS Storage Gateway VTL
Riverbed Whitewater
Backup
System
Backup and Archive
On-premise storage appliance with S3
• Reduce capital expense for storage infrastructure
• Never worry about storage durability
• Never run out of storage capacity
• Storage appliance integrated to Amazon S3
• Data durably stored off-site in multiple locations
• Virtual volumes presented to local network as
iSCSI volumes, NFS, CIFS
• Local disk cache to provide fast on-premise access
• Take advantage of advanced storage optimization options,
Block based de-duplication, compression, WAN acceleration
• Security through gateway side encryption
Application
Server
Virtual
Server
File
Server
Database
Server
S3 Integrated
Appliance
Storage Expansion
Amazon S3
Application
Server
Virtual
Server
File
Server
Database
Server
S3 Integrated
Appliance
Solutions supporting storage expansion to S3
TwinStrata CloudArray
Riverbed Whitewater
Panzura Global NAS
Aspera on-demand
AWS Storage Gateway Cached Volumes
Storage Expansion
Amazon S3
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
How do I integrate AWS?
Access
Control
Identity
Federation
Development Operations
AWS Directory
Services
AWS Identity and
Access
Management
Services: Security
Securing Your AWS Resources
AWS Identity and Access Management
• AWS IAM enables you to securely control access to AWS
services and resources
• Fine grained control of user permissions, resources and actions.
You get to choose who can do what in your AWS environment
and from where
• You can easily add multi factor authentication using smartphone
apps or hardware tokens
• Create users or groups
• Assign permissions to groups
• Where actions are allowed from
Application
Server
• Who can create subnets
• Who can modify security groups
• Who can launch EC2 instances,
into which subnet
• Grant rights to applications
• To access AWS resources
• With built-in key rotation
• No storing of credentials in code
• Secure access to console
• Require MFA on API action
New directory in AWS
Directory Integration
AWS Directory Service
Connect existing directory to AWS
Simple AD AD Connector
Based on Samba 4
Custom federation proxy
On-premises
Microsoft AD
AD Connector
AD
CAA-AdministratorAccessRole
CAA-NetworkAccessRole
CAA-CloudEngineerRole
CAA-ReadOnlyAccessRole
NetworkAccessRole - “Action”:[stsAssumeRole],
“Resource”: “arn:aws:iam::[account1-id]:role/IAM-1-NetworkAccessRole-*
“Resource”: “arn:aws:iam::[account2-id]:role/IAM-1-NetworkAccessRole-*
“Resource”: “arn:aws:iam::[account2-id]:role/IAM-1-NetworkAccessRole-*
Management
account
1
2
3
Application account
4
Switch role
AdministratorAccessRole
NetworkAccessRole
CloudEngineerRole
ReadOnlyAccessRole
Trusted entities: Assume role policy document
“Principal”:
“AWS”:“arn:aws:iam::[management-account-id]:role/CAA-NetworkAccessRole”
“Action”: “sts:AssumeRole”
mycompany.awsapps.com/console
AWS CodeDeploy
Services: Application
Coordinate automated deployment
Scale from 1 instance to thousands
Deploy without downtime
Centralize deployment control and monitoring
Staging
CodeDeployv1, v2, v3
Production
Dev
Just like Amazon
Application
revisions
Deployment groups
Set up your target environments (Hybrid or Not)
Agent Agent Agent
Staging
Agent Agent
Agent Agent
Agent
Agent
Production
Deployment group (on-premises)Deployment group (AWS)
Group instances by:
• Auto Scaling group
• Amazon EC2 tag
• On-premises tag
Operations On AWS into existing Tools
Management
Portal for vCenter
Management Pack
for SCOM
Systems Manager
for SCVMM
Operations On AWS
Integrating AWS into your operations
• AWS CloudWatch provides real-time insight into your AWS
services, integrate your own metrics, create and act on alarms
• AWS SNS allows integration with your alerting systems
• Your current tools still work – install on EC2 instance
• Your tools already have AWS API integration
Direct ConnectTunnels
Backup &
Archive
Storage
Expansion
Common Hybrid
Workloads
What is
Hybrid IT?
Integrated
Network
Next
Steps
Control
Enterprise
Integration
Federation Dev Operations
Today we’ll cover
Try It!
Proof of concept will
answer tons of
questions
Think cloud first
for all new
deployments
Gracias

More Related Content

PDF
천만 사용자를 위한 AWS 아키텍처 보안 모범 사례 (윤석찬, 테크에반젤리스트)
PDF
AWS re:Invent 2016 recap (part 1)
PDF
Deep Dive: Amazon Relational Database Service (March 2017)
PDF
Advanced Task Scheduling with Amazon ECS
PDF
How to run your startup on Amazon Web Services, by Alex Iskold
PDF
Running Docker clusters on AWS (November 2016)
PDF
컴퓨팅 서비스 업데이트 - EC2, ECS, Lambda (김상필) :: re:Invent re:Cap Webinar 2015
PDF
VMware and AWS together (June 2017)
천만 사용자를 위한 AWS 아키텍처 보안 모범 사례 (윤석찬, 테크에반젤리스트)
AWS re:Invent 2016 recap (part 1)
Deep Dive: Amazon Relational Database Service (March 2017)
Advanced Task Scheduling with Amazon ECS
How to run your startup on Amazon Web Services, by Alex Iskold
Running Docker clusters on AWS (November 2016)
컴퓨팅 서비스 업데이트 - EC2, ECS, Lambda (김상필) :: re:Invent re:Cap Webinar 2015
VMware and AWS together (June 2017)

Viewers also liked (20)

PDF
Servicios de storage de AWS
PDF
Escalando a sus primeros 10 millones de usuarios
PDF
EC2 Cómputo en la nube a profundidad
PDF
Construya APIs seguras y escalables
PDF
Docker ECS en AWS
PDF
PDF
Como reducir costos en AWS
PDF
Servicios de bases de datos administradas en AWS
PDF
Creando su primera aplicación de Big Data en AWS
PDF
Comenzando con los servicios móviles en AWS
PDF
Hybrid ECM: Con la cabeza en las nubes y los pies en la tierra
DOCX
Poncho en forma de hojas
PPTX
Arquitectuara
PPTX
González vivian trabajo final - copia
PPTX
slideshare
PPT
PPTX
El agua en los reinos
PPTX
Inteligencias multiples
PPT
Presentación alfombra mágica
PPTX
Redes sociales en los jovenes
Servicios de storage de AWS
Escalando a sus primeros 10 millones de usuarios
EC2 Cómputo en la nube a profundidad
Construya APIs seguras y escalables
Docker ECS en AWS
Como reducir costos en AWS
Servicios de bases de datos administradas en AWS
Creando su primera aplicación de Big Data en AWS
Comenzando con los servicios móviles en AWS
Hybrid ECM: Con la cabeza en las nubes y los pies en la tierra
Poncho en forma de hojas
Arquitectuara
González vivian trabajo final - copia
slideshare
El agua en los reinos
Inteligencias multiples
Presentación alfombra mágica
Redes sociales en los jovenes
Ad

Similar to Comenzando com la nube hibrida (20)

PDF
AWS를 활용한 금융권 hybrid cloud 구축하기 :: Felix Candelario :: AWS ...
PDF
Hybrid cloud for financial sector :: Felix Candelario :: AWS Finance Seminar
PPTX
Introduction to Hybrid Cloud on AWS
PDF
AWS Innovate: Best of Both Worlds: Leveraging Hybrid IT with AWS- Dhruv Singhal
PPTX
Running Hybrid Cloud Patterns on AWS
PDF
Introduction to Amazon Web Services
PPTX
Hybrid Cloud on AWS - Introduction and Art of the Possible
PPTX
How Easy to Automate Application Deployment on AWS
PDF
Expandindo seu Data Center com uma infraestrutura hibrida
PDF
Cloud Native Computing - Part II - Public Cloud (AWS)
PPTX
Hybrid Cloud Customer Use Cases on AWS
PPTX
Hybrid Cloud on AWS
PPTX
AWS SSA Webinar 7 - Getting Started on AWS
PPTX
AWSome Day Roadshow 2017
PPTX
Modernizing your AWS Deployment - January 2017
PDF
Aws Architecture Fundamentals
PDF
AWS 101 December 2014
PDF
AWS Architecture Fundamentals - Houston
PDF
Blur the boundaries between your on-premises to AWS cloud by embracing VMWare...
PDF
Aws and Alfresco Solutions
AWS를 활용한 금융권 hybrid cloud 구축하기 :: Felix Candelario :: AWS ...
Hybrid cloud for financial sector :: Felix Candelario :: AWS Finance Seminar
Introduction to Hybrid Cloud on AWS
AWS Innovate: Best of Both Worlds: Leveraging Hybrid IT with AWS- Dhruv Singhal
Running Hybrid Cloud Patterns on AWS
Introduction to Amazon Web Services
Hybrid Cloud on AWS - Introduction and Art of the Possible
How Easy to Automate Application Deployment on AWS
Expandindo seu Data Center com uma infraestrutura hibrida
Cloud Native Computing - Part II - Public Cloud (AWS)
Hybrid Cloud Customer Use Cases on AWS
Hybrid Cloud on AWS
AWS SSA Webinar 7 - Getting Started on AWS
AWSome Day Roadshow 2017
Modernizing your AWS Deployment - January 2017
Aws Architecture Fundamentals
AWS 101 December 2014
AWS Architecture Fundamentals - Houston
Blur the boundaries between your on-premises to AWS cloud by embracing VMWare...
Aws and Alfresco Solutions
Ad

More from Amazon Web Services LATAM (20)

PPTX
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
PPTX
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
PPTX
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
PPTX
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
PPTX
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
PPTX
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
PPTX
Automatice el proceso de entrega con CI/CD en AWS
PPTX
Automatize seu processo de entrega de software com CI/CD na AWS
PPTX
Cómo empezar con Amazon EKS
PPTX
Como começar com Amazon EKS
PPTX
Ransomware: como recuperar os seus dados na nuvem AWS
PPTX
Ransomware: cómo recuperar sus datos en la nube de AWS
PPTX
Ransomware: Estratégias de Mitigação
PPTX
Ransomware: Estratégias de Mitigación
PPTX
Aprenda a migrar y transferir datos al usar la nube de AWS
PPTX
Aprenda como migrar e transferir dados ao utilizar a nuvem da AWS
PPTX
Cómo mover a un almacenamiento de archivos administrados
PPTX
Simplifique su BI con AWS
PPTX
Simplifique o seu BI com a AWS
PPTX
Os benefícios de migrar seus workloads de Big Data para a AWS
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
AWS para terceiro setor - Sessão 1 - Introdução à nuvem
AWS para terceiro setor - Sessão 2 - Armazenamento e Backup
AWS para terceiro setor - Sessão 3 - Protegendo seus dados.
Automatice el proceso de entrega con CI/CD en AWS
Automatize seu processo de entrega de software com CI/CD na AWS
Cómo empezar con Amazon EKS
Como começar com Amazon EKS
Ransomware: como recuperar os seus dados na nuvem AWS
Ransomware: cómo recuperar sus datos en la nube de AWS
Ransomware: Estratégias de Mitigação
Ransomware: Estratégias de Mitigación
Aprenda a migrar y transferir datos al usar la nube de AWS
Aprenda como migrar e transferir dados ao utilizar a nuvem da AWS
Cómo mover a un almacenamiento de archivos administrados
Simplifique su BI con AWS
Simplifique o seu BI com a AWS
Os benefícios de migrar seus workloads de Big Data para a AWS

Recently uploaded (20)

PDF
Encapsulation theory and applications.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Electronic commerce courselecture one. Pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Modernizing your data center with Dell and AMD
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPT
Teaching material agriculture food technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Encapsulation theory and applications.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
MYSQL Presentation for SQL database connectivity
Encapsulation_ Review paper, used for researhc scholars
NewMind AI Monthly Chronicles - July 2025
Electronic commerce courselecture one. Pdf
NewMind AI Weekly Chronicles - August'25 Week I
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Per capita expenditure prediction using model stacking based on satellite ima...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The Rise and Fall of 3GPP – Time for a Sabbatical?
Modernizing your data center with Dell and AMD
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Teaching material agriculture food technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf

Comenzando com la nube hibrida

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Alex Coqueiro Public Sector Solutions Architect Abril, 2016 Comenzando con la nube híbrida
  • 2. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 3. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 4. Cloud is an ALL or NOTHING proposition
  • 5. The Good News is it isn’t an ‘All or Nothing’ Choice Corporate Data Centers On-Premises Resources Cloud Resources Integration
  • 7. Hybrid IT: A Definition http://www.gartner.com/technology/research/technical-professionals/hybrid-cloud.jsp “Hybrid IT is the result of combining internal and external services, usually from a combination of internal and public clouds, in support of a business outcome.”
  • 8. http://www.gartner.com/technology/research/technical-professionals/hybrid-cloud.jsp “Hybrid IT is the result of combining internal and external services, usually from a combination of internal and public clouds, in support of a business outcome.” Hybrid IT: A Definition
  • 11. Extending Your DC to your Cloud Provider Your Data Center Your LAN Segments AWS VPC
  • 12. Integrated networking # 10.0.100.0 # 10.0.200.0 Integrating AWS with existing On-Prem Infrastructure Integrated access control Microsoft Active Directory Custom LDAP Commom Hybrid Workloads App 1 AWS Storage Gateway Single pane of glass Enterprise Integration
  • 13. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 14. Direct ConnectVirtual Private Cloud (VPC) Services: Networking
  • 15. Trend: Integrated Network Your Data Center Project A Deployed Virtual Private Cloud (VPC) Direct Connect
  • 16. VPN Tunnels Customer VPN Gateway Directory Server Database Server Application Server Client VPC Configuration • VPC CIDR Network: 10.100.0.0/16 • VPC Subnet 1: 10.100.0.0/23 • VPC Subnet 2: 10.100.2.0/23 • VPN Type: Dynamic BGP • Security Group: HTTP, HTTPS, SSH, ICMP Data Center Configuration • Corporate Network: 10.96.0.0/16 • DC Network: 10.96.24.0/21 • VPN Gateway IP: 54.254.241.240 Your First Virtual Private Cloud Application Server Availability Zone BAvailability Zone A
  • 17. VPN Tunnels Customer VPN Gateway Directory Server Database Server Application Server Client Other VPC Features • Multiple VPCs per account • Multiple network interfaces per EC2 instance • Multiple IPs per interface • Move network interfaces between EC2 instances • Egress filtering with security groups and network ACLs • Virtual network peering between VPCs • Direct Connect cross region routing • Support for dedicated instance, single tenant EC2 Services: Networking Application Server Availability Zone BAvailability Zone A VPC Released 2009 • Mature virtual networking service • Highly scalable, up to 64K hosts per VPC • Features focused on enterprise integration
  • 18. Integrate your network with Amazon VPC • Connect via standard IPSEC Internet VPN tunnels, or • Private link to AWS Direct Connect peering location, or a combination of both • Connection port speeds from 50M to 10G, you choose the connection speed you want • Connect multiple VPCs using industry standard VLANs and layer 3 routing protocols • Integrate your network to your private VPC resources • Deploy your own network equipment into Direct Connect peering location, e.g. WAN Optimization Devices Compute Storage AWS Global Infrastructure Database App Services Deployment & Administration Networking Customer VPC Internet VPN Connection Customer IPSEC Router/Firewall Customer Direct Connect Router Private Direct Connect Customer Corporate Network Services: Networking: Direct Connect
  • 19. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 22. AWS Storage Gateway AWS S3 Simple Storage Service Services: Storage
  • 23. Application Server Virtual Server File Server Database Server Backup System On-premise backup server with S3 • Eliminate tape, hardware, off-site storage • Reduce capital expense for backup infrastructure • Never worry about backup durability • Never run out of backup capacity • Backup gateway integrated to Amazon S3 • Data stored off-site, with high durability, in multiple locations • Take advantage of advanced storage optimization options, De-duplication, compression, WAN acceleration Backup and Archive Amazon S3
  • 24. Application Server Virtual Server File Server Database Server Amazon S3 Solutions supporting backup and archive to S3 Veeam Backup & Replication Symantec Net Backup Oracle RMAN and Secure Backup Module CommVault Simpana AWS Storage Gateway VTL Riverbed Whitewater Backup System Backup and Archive
  • 25. On-premise storage appliance with S3 • Reduce capital expense for storage infrastructure • Never worry about storage durability • Never run out of storage capacity • Storage appliance integrated to Amazon S3 • Data durably stored off-site in multiple locations • Virtual volumes presented to local network as iSCSI volumes, NFS, CIFS • Local disk cache to provide fast on-premise access • Take advantage of advanced storage optimization options, Block based de-duplication, compression, WAN acceleration • Security through gateway side encryption Application Server Virtual Server File Server Database Server S3 Integrated Appliance Storage Expansion Amazon S3
  • 26. Application Server Virtual Server File Server Database Server S3 Integrated Appliance Solutions supporting storage expansion to S3 TwinStrata CloudArray Riverbed Whitewater Panzura Global NAS Aspera on-demand AWS Storage Gateway Cached Volumes Storage Expansion Amazon S3
  • 27. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 28. How do I integrate AWS? Access Control Identity Federation Development Operations
  • 29. AWS Directory Services AWS Identity and Access Management Services: Security
  • 30. Securing Your AWS Resources AWS Identity and Access Management • AWS IAM enables you to securely control access to AWS services and resources • Fine grained control of user permissions, resources and actions. You get to choose who can do what in your AWS environment and from where • You can easily add multi factor authentication using smartphone apps or hardware tokens • Create users or groups • Assign permissions to groups • Where actions are allowed from Application Server • Who can create subnets • Who can modify security groups • Who can launch EC2 instances, into which subnet • Grant rights to applications • To access AWS resources • With built-in key rotation • No storing of credentials in code • Secure access to console • Require MFA on API action
  • 31. New directory in AWS Directory Integration AWS Directory Service Connect existing directory to AWS Simple AD AD Connector Based on Samba 4 Custom federation proxy On-premises Microsoft AD
  • 32. AD Connector AD CAA-AdministratorAccessRole CAA-NetworkAccessRole CAA-CloudEngineerRole CAA-ReadOnlyAccessRole NetworkAccessRole - “Action”:[stsAssumeRole], “Resource”: “arn:aws:iam::[account1-id]:role/IAM-1-NetworkAccessRole-* “Resource”: “arn:aws:iam::[account2-id]:role/IAM-1-NetworkAccessRole-* “Resource”: “arn:aws:iam::[account2-id]:role/IAM-1-NetworkAccessRole-* Management account 1 2 3 Application account 4 Switch role AdministratorAccessRole NetworkAccessRole CloudEngineerRole ReadOnlyAccessRole Trusted entities: Assume role policy document “Principal”: “AWS”:“arn:aws:iam::[management-account-id]:role/CAA-NetworkAccessRole” “Action”: “sts:AssumeRole” mycompany.awsapps.com/console
  • 34. Coordinate automated deployment Scale from 1 instance to thousands Deploy without downtime Centralize deployment control and monitoring Staging CodeDeployv1, v2, v3 Production Dev Just like Amazon Application revisions Deployment groups
  • 35. Set up your target environments (Hybrid or Not) Agent Agent Agent Staging Agent Agent Agent Agent Agent Agent Production Deployment group (on-premises)Deployment group (AWS) Group instances by: • Auto Scaling group • Amazon EC2 tag • On-premises tag
  • 36. Operations On AWS into existing Tools Management Portal for vCenter Management Pack for SCOM Systems Manager for SCVMM
  • 37. Operations On AWS Integrating AWS into your operations • AWS CloudWatch provides real-time insight into your AWS services, integrate your own metrics, create and act on alarms • AWS SNS allows integration with your alerting systems • Your current tools still work – install on EC2 instance • Your tools already have AWS API integration
  • 38. Direct ConnectTunnels Backup & Archive Storage Expansion Common Hybrid Workloads What is Hybrid IT? Integrated Network Next Steps Control Enterprise Integration Federation Dev Operations Today we’ll cover
  • 39. Try It! Proof of concept will answer tons of questions Think cloud first for all new deployments