Mais conteúdo relacionado Semelhante a Hybrid Data Storage Made Easier with AWS Storage Gateway (20) Mais de Amazon Web Services (20) Hybrid Data Storage Made Easier with AWS Storage Gateway1. P U B L I C S E C T O R
S U M M I T
WASHINGTON, DC
2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
Hybrid storage made easier with
AWS Storage Gateway
Bhavin Patel
Product Manager
AWS
3 1 7 9 4 5
Brian Wiedl & Louis Masters
Cloud Infrastructure
Federal Home Loan Bank of NY
Robert Francois
Sr. Computer Systems Engineer
Congressional Budget Office
3. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Agenda
• Hybrid cloud storage overview
• Storage Gateway overview, use cases, and deep dive
• How Federal Home Loan Bank of NY uses Storage Gateway
• How Congressional Budget Office uses Storage Gateway
• Summary
4. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
5. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
What’s the hybrid cloud storage problem?
You have on-premises data
and applications …
… that want to use storage
and services in the cloud
AWS
Existing
Applications &
Data Archives
New Data
Sources
6. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Hybrid cloud storage example use cases
Move tape backups
to the cloud
Low latency access to data in
AWS for on-premises applications
Shift on-premises storage to
cloud-backed file shares
Provide on-premises access to virtually unlimited cloud storage
Regardless of your cloud adoption stage…
7. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
AWS hybrid cloud storage & data transfer portfolio
Online
data transfer
Hybrid
storage
Offline
data transfer
Edge locations for
Amazon Simple
Storage Service
(Amazon S3)-
enabled applications
Online transfer of
active data
Managed file
transfers into
Amazon S3
Load streaming data
into Amazon S3
Ship static data
into and out of
Amazon S3
Storage and
compute in
disconnected
environments
Access AWS
storage from
on-premises
AWS Storage
Gateway
AWS
DataSync
AWS
Transfer for
SFTP
Amazon
Kinesis Data
Firehose
AWS
Snowball
AWS Snowball
Edge
S3 Transfer
Acceleration
8. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
AWS CloudCustomer premises
Files
(NFS/SMB)
Volumes
(iSCSI)
Tapes
(iSCSI VTL)
AWS Storage Gateway
Integrated with AWS Identity and Access Management
(IAM), AWS Key Management Service (AWS KMS),
AWS CloudTrail, Amazon CloudWatch services
Amazon S3
Glacier
Amazon S3
Amazon Elastic
Block Store
(Amazon EBS)
AWS Storage Gateway
Configuration: VMware, Hyper-V,
Amazon Elastic Compute Cloud (Amazon EC2),
Hardware appliance
Amazon
Backup
Amazon S3
Glacier Deep
Archive
Storage Gateway serviceStorage Gateway
HTTPS
10. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Storage Gateway family
Store and access objects
in Amazon S3 from
file-based applications
with local caching
File Gateway
Windows & Linux apps.
using Amazon S3
Block storage on-premises
backed by cloud storage with
local caching, Amazon Elastic
Block Store (Amazon EBS)
snapshots, and clones,
integrated with AWS Backup
Volume Gateway
SAN-like
w/ cloud recovery
Drop-in replacement for
physical tape infrastructure
backed by cloud storage with
local caching
Tape Gateway
Easily switch tape
backups to AWS
11. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Storage Gateway benefits
Low-latency access to
frequently used data
No changes to
existing apps
* **
Multiple protocols Local caching
Minimize
network traffic
Optimized data transfer
* **
Secure & compliant Cost-effective
Management, monitoring,
and in-cloud workloads
AWS integrated
12. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
What’s new with Storage Gateway since re:Invent 2018
All
File
Volume
Jan.
2019
Feb.
2019
Mar.
2019
Apr.
2019
May
2019
Dec.
2018
Tape
13. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
14. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
File Gateway overview and use cases
Store and access objects in Amazon S3 from file-based applications with local caching
• Backup on-premises data to the cloud
• Shift on-premises storage to cloud-backed file shares
• Low latency access to data in AWS for on-premises applications
Use cases
On-Premise
NFS & SMB
File Gateway
HTTPS
Application Amazon S3
AWS Cloud
15. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Connect using NFS v3/v4 or SMB v2/v3 protocols
Files stored as native S3 objects
Metadata is preserved as object user metadata
SMB ACLs – Windows Access Control Entries for up to 10 AD users and groups
Fully managed local cache
Read-through, write-back, LRU managed
Optimized data transfers
Uploads only send changes, downloads retrieve file parts needed
Up to 4 Gbps writes
Notifications through Amazon CloudWatch (e.g., upload complete)
Object-level encryption with SSE-S3 or SSE-KMS
Refresh cache by prefix
Optimizes content distribution workloads
S3 object lock support
WORM storage for on-premises file-based applications
File Gateway capabilities
16. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Tape gateway overview and use cases
Present cloud-backed virtual tapes to on-premises backup applications
On-Premise
iSCSI VTL
Tape Gateway
HTTPS
Application
Storage Gateway service
(S3 Glacier Deep Archive)
OR (S3 Glacier)
Tape library
(Amazon S3)
Tape Shelf
• Tape-based backups and archives to cloudUse cases
AWS Cloud
17. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Tape Gateway capabilities
Emulates physical tape library through iSCSI-VTL protocol
Fully managed local cache for recent backups
Read-through, write-back, LRU managed
Virtual tapes stored in Amazon S3
Ejected virtual tapes archived as read-only in S3 Glacier or S3 Glacier Deep Archive
Move tapes in Amazon S3 Glacier to Amazon S3 Glacier Deep Archive
Easy retrieval of archived tapes to virtual tape library
Retrieve in 3-5 hours from S3 Glacier and within 12 hours from Deep Archive
Configurable encryption SSE-S3 or SSE-KMS
Compatible with all leading backup software
Performance
Client writes up to 2.3 Gbps, downloads up to 0.6 Gbps
18. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Volume Gateway overview and use cases
Present block storage on-premises backed by cloud storage
• Provide cloud-backed block storage to on-premises applications
• Backup on-premises data to the cloud
Use cases
Storage Gateway
service
On-Premise
iSCSI HTTPS
Application Amazon EBS
snapshots
AWS Cloud
Amazon
Backup
Volume Gateway
19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Volume Gateway capabilities
Presents block storage over iSCSI
Volumes stored in AWS reducing on-premises SAN footprint
Thin-provisioned (cached) or local (stored) volume types
Fully managed local cache
Read-through, write-back, LRU managed
Configurable encryption with SSE-S3 or SSE-KMS
Volume snapshots stored in Amazon EBS
Manage backups of volumes through AWS Backup
Move volumes between gateways using attach-detach feature
20. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Storage Gateway is available on a variety of form factors
21. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
About FHLBNY and our mission
• The Federal Home Loan Bank of New York (FHLBNY) helps community lenders in New Jersey,
New York, Puerto Rico and the U.S. Virgin Islands advance housing and community growth.
• The FHLBNY is part of the congressionally chartered, nationwide Federal Home Loan Bank
System, which was created in 1932 to provide a flexible credit liquidity source for member
community lenders engaged in home mortgage and neighborhood lending.
• The FHLBNY increases the availability of mortgages and home finance to families of all
income levels by offering high-value correspondent and cash management services to assist
our members in more effectively serving their neighborhoods and meeting their Community
Reinvestment Act responsibilities.
• The mission of the Federal Home Loan Bank of New York is to advance housing opportunity
and local community development by supporting members in serving their markets.
• The FHLBNY meets our mission by providing our members with access to economical
wholesale credit and assistance through our credit products, mortgage finance program,
housing and community lending programs, and correspondent services to increase the
availability of home finance to families of all incomes.
23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
The FHLBNY team
• Structured as a working group that comprises every area of technology
• Responsible for the management and maintenance of both Cloud and on premise
environments.
• Provides a stable and consistent form of liquidity to our membership throughout all
operating conditions and environments.
Cloud Operations Architecture
Data Governance Development
Business Continuity Infrastructure
Networking Storage
Information Security Security Operations
24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Cloud journey
• Initiated our first cloud migration in 2016
• Goal was to architect our AWS environment as close to our on premise
environment as possible
• Multiple levels of backup lifecycle, online digital through magnetic
tape
• Introduced Storage Gateway in the AWS environment for ready access
to our backups throughout their entire lifecycle.
• Consistent Cloud and on Premise environment
25. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Architecture
Designed to mirror our existing on-premise tape design
Storage Gateway Service
Tape Shelf
NetworkerInstances
26. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Architecture
• Required:
• All production volumes in the Cloud must be backed up
• Various backup schedules
• Regulatory and internal retention requirements
Storage Gateway Service
Tape Shelf
27. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Benefits, challenges & next steps
• Benefits
• No more physical tapes or drives
• Unlimited storage expandability
• Challenges
• Culture shock
• Performance
• Next Steps
• Expand usage into file gateway
• Use for on-premise tapes
• Deep Archive
28. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
29. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
About CBO and our team
• Congressional Budget Office helps U.S. Congress make
effective budget and economic policy
• Provides objective, impartial, and nonpartisan analysis
• Covers areas such as national security, health, labor, taxes,
energy, and macroeconomics
• Manages IT infrastructure for CBO
• Oversees multiple areas, including storage
• Supports internal business users who are mostly
economists or public policy analysts
30. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Our high-level challenges and why we use cloud
• Small agency and don’t have same budget as a large agency
• Ever-growing data generated & collected for analysis and reporting
• Store data for a long time to meet records keeping requirements
Challenges
• Cloud’s pay as you go model helps us operate within budgets
• Cloud makes us nimble and provides agility
• Cloud helps us innovate, provide capabilities, and focus on the
agency needs
Whycloud
31. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Our on-premises storage challenges & requirements
• Datasets continue to grow every day/month/year
• Keep expanding volumes to accommodate growing data
• Keep purchasing new storage disks and arrays
• Have limited manpower to manage on-premises systems
• Give our analysts access to data
Storage
Challenges
• Store data for a long time ~15 years
• Tier data to low cost storage
• Maintain current user experience (app access latency)
• Data durability & point in time backups
• Data sharing capabilities
Requirements
32. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Our Storage Gateway use cases
• Database backups & NARA records retention onto network
shares
• Not a lot of value dedicating shares on premises for
database backups and NARA records
• We use File Gateway with SMB shares for storage
Database &
NARA*
• Provide SMB file shares backed by Amazon S3 as a
File/Dataset Repository for analyst use (Read)
• The master analyst writes data directly to the S3 bucket
• We use RefreshCache ability to refresh gateway cache for
other analysts to read data on-premises
File shares
33. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
CBO environment for Storage Gateway use cases
S3
Standard
SMB users
SMB file share
Cache
File gateway
Database archives
NARA records
1. Writes
C. Reads
Master analyst
A. Writes
B. Refresh
Cache
S3 Infrequent
Access
Removal
Lifecycle Lifecycle
2. Async
uploads
SMB file share
S3 buckets
34. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Benefits we see from using Storage Gateway
• Provide limitless backend storage with just 5 TB of frontend storage
without re-engineering applications
• Don’t have to spend time expanding storage given to applications
• Storage Gateway cache helps to speed up our performance
• Tiered storage using amazon S3 Intelligent-Tiering meets our data
retention requirements at a low cost
• Have made 2 racks of tape/storage obsolete and reduced our data
center footprint on-premises
• Reduced our database and file retention scripts. Amazon S3 takes care
of which files are removed, archived, or kept
35. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Lessons learned
• Allows you to focus your limited resources and attention on critical requirements
• More fastest tier storage is now available for our most demanding application
• Less management/maintenance on less-critical requirements
• Currently only use Amazon S3 Standard and Infrequent Access (Amazon S3 Intelligent-Tiering)
• S3 Durability & Versioning policies streamline backup processes
• Having Lifecycle policies in Amazon S3 align with agency requirements reduces our workload
• Most used files remain accessible even in an internet outage however you must size your cache as
appropriate to your needs
• Use CloudWatch metrics to measure on-premises performance/bandwidth, Use bandwidth limits if
necessary
Tiered storage
Automation and lifecycle policies
Resiliency and cache
Monitoring and performance
36. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
37. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
How do I get started?
Visit aws.amazon.com/storagegateway
38. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Related breakouts
316002 – Hybrid Solutions at the Edge – Go Global Faster, Efficiently, and more
Securely using AWS Cloud in a Hybrid Environment
Mike Norton, PBS
Tom Creighton, Church of the Latter Day Saints
Tarshia Weldon, AWS
299946 – Running Containers in a Hybrid Environment
Latha Nagaraj, FINRA
Harsha Nippani, AWS
322073 – Make your Data Move: Best Practices for Migrating Data to AWS
Chris Rogers, AWS
39. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
P U B L I C S E C T O R
S U M M I T
Campaigns: Migrate offline media & digital medical images
https://pages.awscloud.com/offline-media-migration-poc.html
https://pages.awscloud.com/digital-medical-images-backup-archival.html
40. Thank you!
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
Bhavin Patel
bhpt@amazon.com
41. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T