25
Migra&on eines physikalischen Datacenters zu AWS Heterogene Herausforderung für den Übergang eines firmeneigenen physikalischen Datacenters in ein kompleA virtualisiertes Datacenter bei AWS [email protected]

AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Embed Size (px)

Citation preview

Page 1: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Migra&on  eines    physikalischen  Datacenters    

zu  AWS  

Heterogene  Herausforderung  für  den  Übergang    eines  firmeneigenen  physikalischen  Datacenters    in  ein  kompleA  virtualisiertes  Datacenter  bei  AWS    [email protected]  

Page 2: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Euroforum  Deutschland  SE  und  die  Informa  plc.  

Page 3: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Überführung  eines  phys.  Datacenters  zu  AWS  Eine  kleine  Revolu&on?  

Zeit   Zeit   Zeit  

König    Ludwig  2  

1500  

Public  Cloud  

2012  

Mein  Serverraum  

1996   2006  

Private  Cloud  Server  Virtual.  

1900  

Instustrial  Age  

1980  

Global  Economy  

Page 4: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

WirtschaQlichkeit  &  Flexibilität  

Server-­‐Performance    

Sicherheit    

Datenschutz  

Rechtliche  Anforderungen  

Technologie  

Page 5: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Project-­‐management  (Planung  ist  vieles  ...)  

Business-­‐  

Recovery  WirtschaQs-­‐Zyklen  (Flexibilität)  

Accoun&ng  Cash-­‐flow  und  Absc

hreibungen  

Page 6: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Cost  Center  Management  

Kosten-­‐Transparenz  (Kostenstellen)  

durch  Server  Tagging  

Page 7: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Nutzen  Sie  CloudVer&cal  Reports  

www.cloudver&cal.com  

Daily  reported  info  

Monthly  Report  

Page 8: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

  Encryp&on  (Server-­‐Volumes,  Storage,  Networks)    

=>  Got  some  experience  and  daily  improvements  

  Roll  based  Administra&on  “IAM”  

(e.g.  terminate  a  server)    

  Mul&factor  Authen&ca&on  (HW-­‐Token  take  Mme,  ..)    

Datenschutz:  

Page 9: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Encryp&on  

ProtectV  Master  

ProtectV  Secondary  

KeySec  App  Master  

KeySec  App  Secondary  

WAN  

AWS   Informa    (DE  /  UK)  

Page 10: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS
Page 11: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

089  32  16  8  

Mul&factor  Authen&ca&on  

Page 12: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

  Datacenter  located  in  Europe    (Ireland  and  in  ???)    Audi&ng    AuQragsdatenverarbeitung:  AWS  act  as    

Data  Processor  as  defined  in  SecMon  11    (§11  BDSG)  

Legal  Requirements  –    Bundesdatenschutzgesetz  &  European  Data  Protec&on  Law  

Page 13: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Legal  Requirements  –    AuQragsdatenverarbeitung:  

Page 14: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

  Develope  number  of  AMIs,  Storage  Types,  NICs,    

Load-­‐Balancer,  …  

  Backup      Rollout  of  a  dynamic  XenApp-­‐Farm  

  …  

Technology  :  

Page 15: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

System  Redundancy:      Mirroring  producMon  files  to  a  dedicated  server  in  another    Availability  Zone  (AZ)          Backup  (on  OS-­‐Level)  Daily  EBS  snapshot  in  regional  storage  area  (held  in  all  AZ)  using  the  “Volume  Shadow  Service”  from  AWS  

AZ  1  (prod)   AZ  2  (BRC)   AZ  3  Subnet  1  (LAN)   Subnet  11  (LAN)   Subnet  9  (Test)  Subnet  2  (DMZ1)  Subnet  12  (DMZ1)      Subnet  3  (DMZ2)  Subnet  13  (DMZ2)      

Backup:  

Page 16: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

The  backup  process  produces  …  

Naming  Conven&on!  

Page 17: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Citrix  Access     Supported  Citrix  Access  Gateway    (available  now)  

  Licensing  

Web  

Mobile  Client  

Corp.  Client  

Page 18: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Up&me  Management  

Suspend  instances  

Page 19: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Up&me  Management  

Suspend  Citrix  instances  

Page 20: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Long-­‐term  File-­‐Archive  in  AWS  S3  ...  

hap://corporate-­‐archive.s3-­‐website-­‐eu-­‐west-­‐1.amazonaws.com/html/    A  script  is  generaMng  a  browse-­‐able  link  structure  out  of  the  S3  flat  file  system  [Graphic  from  AWS]  

To  protect  this  “publicly  available  data”;    a  policy  for  the  bucket  “corporate-­‐archive”  is  blocks  all  IPs    apart  of  the  own  Proxy-­‐IPs  

Page 21: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Repor&ng:   Data  selected  directly  from  AWS!  

Page 22: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

Cost  and  Performance  Op&miza&on  

AWS-­‐Trusted  Advisor!  

Page 23: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

•  AWS:    EC2,  VPC,  Route  53,  RDS,  S3,  Glacier,        Direct  Connect,  IAM,  ..  

•  Citrix:  XenApp,  NetScaler,    •  Sophos:  Astaro/UTM9,    •  SafeNet:  ProtectV  •  CloudVerMcal  •  CloudOpMmizer  

Our  current  AWS  and  Partner  Services  

Page 24: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

What  are  our  next  steps!  

•  AutomaMon  of  AdministraMve  Processes  •  Cost-­‐  and  Performance  Tuning  •  Increase  Security  •  Test  and  Verify  Business  Recovery  FuncMon  

Page 25: AWS Summit Berlin 2013 - Euroforum - Moving an Entire Physical Data Center in AWS

…  und  bei  Fragen  wenden  Sie  sich  gerne  an        [email protected]