26
© 2013 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc. 出張レポート 2013年12月02日 #reinvent

AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

  • Upload
    dohanh

  • View
    214

  • Download
    1

Embed Size (px)

Citation preview

Page 1: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

© 2013 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

出張レポート

2013年12月02日

#reinvent

Page 2: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

re:Inventに合わせ、多くの新サービスと新機能が追加 Amazon WorkSpaces

Amazon AppStream

Amazon Kinesis

AWS CloudTrai

Amazon RDS

PostgreSQL engine support

Cross Region Read Replica

Cross Region Snapshot

New EC2 Instances

11月12日 (火) 〜 11月15日 (金) の4日間 ラスベガス・ベネチアンホテルで開催 http://bit.ly/reinvent2013

Page 3: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon
Page 4: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon
Page 5: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

re:Inventのデベロッパーアクティビティ

Page 6: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

GameDayとは

• あるシステムを少人数チームで構築し、攻撃と修復側でシステムのレジリエンシを高めるための訓練

• 攻撃する側と守備する側でIAMキーを交換

• 決められたルールにのっとり、攻撃側は構築したシステムのAWS部分を攻撃し、攻撃内容を記録

• 守備側は攻撃された内容を把握し、攻撃前の状態に戻せるよう復元する

• 最後に攻撃・守備側で相互に内容を評価

Page 7: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

re:Invent GameDay

• re:Invent前日実施で、参加者250名

• 専任チームを作り、対応

• IAMでのキーの交換を自動的・ランダムに行う仕組みを構築し、対戦者を特定させない

• IAMキー交換時に権限を限定する仕組み

Page 8: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

GameDay

Page 9: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

ハッカソン

Page 10: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

ハンズオンラボ、認定試験

Page 11: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

アイレットさん大活躍

Page 12: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

Re:Play

Page 13: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

SAお勧め!ブレイクアウトセッション

Page 14: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

re:Invent 2013 ブレイクアウトセッション概要

• 3日間で204のブレイクアウトセッション

• 4つのレベル分け(100,200,300,400) – 50%以上が300,400レベル

• 12のトラック Architecture(ARC) App Service(SVC) Big Data+HPC(BDT)

Compute+Networking(CPN) Databases (DAT) Deployment +

Management (DMG)

Enterprise IT (ENT) Digital Media (MED) Mobile+ Gaming(MBL)

Partners, Security (SEC) SDK + Tools (TLS) Storage (STG)

Page 15: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

27

26

25

21 19

18

17

13

13

12

7 6

Big Data+HPC(BDTEnterprise ITArchitectureSecurityDatabasesCompute+NetworkingDeployment + ManagementStorageMobile+GamingApp Service(Digital Media

Page 16: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

STG302

Maximizing EC2 and EBS Disk Performance

• EBS使っている人はこれは見ましょう!

• 見てない人はいつかモグリと言われます!

• さすがMilesといった内容でした。EBSのI/Oに関す

る解説が非常にわかりやすいのと、それを裏付けるデータも合わせて紹介していました。

チョウ スゴイ!!

Page 17: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

ARC305

How Netflix Leverages Multiple Regions to

Increase Availability

• AZ障害も経験され、リアルな苦労話が満載でした。

• 基本的にStatelessを前提にアプリは全て組む方針のようですが、どうしてもStatefulにせざるを得ないアプリはCassandraを使ってリージョン間でデータのSyncをたえず行っているとのことです。

Page 18: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

BDT303

Using AWS to Build a Graph-Based Product

Recommendation System • Graphをベースにレコメンデーションの算出を行っている事例です。

• 「商品を見た」、「カートに追加」等々のアクションでエッジの重みづけを変えている。

• Groovyから派生した「Gremlin」と呼ばれるグラフへのクエリー言語を利用しているとのことです。

Page 19: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

SEC305

DDoS Resiliency with Amazon Web Services

• Route53がどういう形でDDoS対策になるかをとてもクーーーーールな絵で説明してくれてます

• Route53のネームサーバの動きもビジュアルに解説

• http://www.slideshare.net/AmazonWebServices/ddos-resiliency-with-amazon-web-services-sec305-aws-reinvent-2013

Page 20: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon
Page 21: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

CPN401

A Day in the Life of a Billion Packets

• VPCの仕組みがわかる話。VPC使っている人なら必須

• http://www.slideshare.net/AmazonWebServices/a-day-in-the-life-of-a-billion-packets-cpn401-aws-reinvent-2013

Page 22: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

DAT304

Mastering NoSQL: Advanced Amazon DynamoDB

Design Patterns for Ultra-High Performance Apps

• DynamoDBの利用イメージとテーブル設計が具体例付きで解説されているいいセッション

• http://www.slideshare.net/AmazonWebServices/amazon-dynamodb-design-patterns-for-ultrahigh-performance-apps-dat304-

aws-reinvent-2013-28436991

Page 23: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

SPOT201

Managing the Pace of Innovation: Behind the

Scenes at AWS

• どうやってAWSのようにイノベーションを起こせるようになるか。

• サービスを作る人向け。ただしスライドはあんまり意味がないので、ストリーミングで見て下さい!

大谷推薦

Page 24: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

その他

• DMG203 AWS Billing Deep Dive – 一部のBillingマニア必見 – http://www.slideshare.net/AmazonWebServices/aws-billing-deep-dive-dmg203-aws-reinvent-2013

• STG402 Advanced EBS Snapshot Management – EBSスナップショット用スクリプト「Arche」の紹介

• https://github.com/AWSLabs/arche

– EC2 consistens snapshotの作者Eric Hammondさん降臨で会場大興奮

• https://github.com/alestic/ec2-consistent-snapshot

Page 26: AWS Cloud Trail - d36cz9buwru1tt.cloudfront.netd36cz9buwru1tt.cloudfront.net/jp/reinvent/2013/documentation/...How Netflix Leverages Multiple Regions to ... DDoS Resiliency with Amazon

来年もぜひご参加を!!