SlideShare uma empresa Scribd logo
1 de 24
Baixar para ler offline
P U B L I C S E C T O R
S U M M I T
SINGAPORE
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
How AsiaPac is helping Customers to
build a Restricted Cloud Environment
on AWS
Sourav Ray
Cloud Architect
AsiaPac
Copyright © & Confidential
Copyright © & Confidential
An M1
company.
Since
Nov’18
EPPU
S/10
company
ISO
9001:2015
& Biz Safe
Level 3
certified
ICT
Solutions
Provider
Started
1990
Commercial, Enterprise, Education, Healthcare & Government
Copyright © & Confidential
Self Service Management Portal
Government / Enterprise Customers Self Service &
Service
Management
Hybrid Cloud
Management
System
Leading Telecommunications Provider
First telco to embark 5G live test in SG
Direct Connect
Local Loops
SDWAN
CMP
Frameworks
Blueprints
Modernization
• Bring workloads closer to
AWS
• Low latency connectivity
• Orchestration
Bring
close to
AWS
Migrate to
AWS or
Migrate to
AWS
Outpost/
VMC
Customer
Self
Manage
Creating Business Ecosystem
VMware Cloud on AWS
Exclusive Launch Partner
Copyright © & Confidential
Governance in
Restricted Cloud
Environment
§ Controlled access reducing Security Risks
§ Ensuring regulatory compliance like HIPAA, PCI, MTSC Tier 3, ISO etc.
§ Cost Optimization
§ Eliminate unnecessary IT and Cloud initiatives
§ DevOps process initiation and parameter definitions
§ Enhance management of Cloud resources
The Disciplines of CLOUD GOVERNANCE
Why is it important?
Our Approach to CLOUD GOVERNANCE
Cloud
Governance
Data
Security
Resource
Tagging
Structured
DevOps
Solutions
Security and
Log
Management
Monthly
Reports and
Analytics
Patch
Management
with
Approval
Process
Infrastructure
Monitoring
Application
Monitoring
Internal
Audits
Cost
Budgeting
Environment
Templatization
Authentication
&
Authorization
Our Approach to CLOUD GOVERNANCE
Cloud
Governance
Environment
Templatization
Data Security
Resource
Tagging
Structured
DevOps
Solutions
Security and
Log
Management
Authentication
and
Authorization
Monthly
Reports and
Analytics
Patch
Management
with Approval
process
Application
Monitoring
Infrastructure
Monitoring
Internal Audits Cost Budgeting
§ Compliance Audit
§ Security Audit
§ User Audit
§ Data Privacy Audit
§ Penetration Testing
Our Approach to CLOUD GOVERNANCE
Cloud
Governance
Environment
Templatization
Data Security
Resource
Tagging
Structured
DevOps
Solutions
Security and
Log
Management
Authentication
and
Authorization
Monthly
Reports and
Analytics
Patch
Management
with Approval
process
Application
Monitoring
Infrastructure
Monitoring
Internal Audits Cost Budgeting
§ Enforcing MFA for AWS
Management Console
§ Enforcing console login via on
premise AD authentication using
AWS SSO
§ Enforcing AWS Cognito for
application level authentication
§ Enforcing privileged access using
AWS IAM
Our Approach to CLOUD GOVERNANCE
Cloud
Governance
Environment
Templatization
Data Security
Resource
Tagging
Structured
DevOps
Solutions
Security and
Log
Management
Authentication
and
Authorization
Monthly
Reports and
Analytics
Patch
Management
with Approval
process
Application
Monitoring
Infrastructure
Monitoring
Internal Audits Cost Budgeting
Continuous
Integration
Micro-Services
Policy as Code and Automated
Monitoring
Our Approach to CLOUD GOVERNANCE
Cloud
Governance
Environment
Templatization
Data Security
Resource
Tagging
Structured
DevOps
Solutions
Security and
Log
Management
Authentication
and
Authorization
Monthly
Reports and
Analytics
Patch
Management
with Approval
process
Application
Monitoring
Infrastructure
Monitoring
Internal Audits Cost Budgeting
Launch
Instance
Create
Tags
Scan OS based
on Patch
Baseline
Generate
Missing
Patch List
SSM Document for Patch Scan
Stop
Instance
Create
Image
Create Tags Terminate
Instance
SSM Document for Patch Install
Launch
Instance
Update OS
Software
Generate
Installed
Patch List
Update
Parameter
Store
If approved
How to Regain a Healthy Governance
§ current state of all cloud users and their access rights across
the enterprise?
“WITHOUT REDUCING CLOUD AGILITY”
MANAGE
ENSURE
§ adherence to the overall costs to PAY PER USE model?
§ deployments and operations are in track with
compliance regulations and policies?
ENFORCE
§ security across all the environment workloads as well
as User Management?
Cloud Governance
Pain Areas
ASIAPAC MANAGED INFRASTRUCTURE & CLOUD SERVICES
Increase in
AWS
Workloads
Growth in
AWS account
Management
Cost Control
Security &
Compliance
GOVERNANCE
AT SCALE
Solutions to Governance at Scale
Design
Architecture
AZ-A AZ-B
IGW
Direct Connect
Internet
Web 1
RDS Master
IDS1 IDS2Mgmt 1EVM1 Mgmt 2 EVM2
ELB
ELB
Cyber Watch
Center
App1 App2 App3 App4 App5 App6
ELB
App7 App8 App9 App10 App11 App12
Web 2
Tier 1
NGFW
Tier 1
NGFW
RDS Slave
Tier 2
NGFW
Tier 2
NGFW
NAT
Gateway
NAT
Gateway
AD Server 1
AZ-A
AD Server 2
Event
Collector1
Event
Collector2
Customer On
Premise
Dev Server Dev Server
Bastion Host
API Server
Monitoring
Collector
AZ-B
AsiaPac NOC VPC
AsiaPac
EM7
Database
VPN Gateway2FA 2FA
API Server
On Premise SOC
AsiaPac
SysAdmin
IPSEC VPN
API
Server
Dev Server
IGW
Client VPN
IPSEC VPN
NAT Gateway
AZ-A AZ-B
App1 App2 App3 App4 App5 App6
ELB
Web 1
Master DB
Slave DB
App7 App8 App9 App10 App11 App12
Web 2
VPN
IGW
Firewall
ELB
NAT
Gateway
NAT
Gateway
ELB
Internet
AD Server 1
AZ-A
AD Server 2
Event
Collector1
Customer
Data Center
Dev Server
Bastion Host
API Server
DB Server
AZ-B
VPN Gateway2FA 2FA
API Server
On Premise
SOC
AsiaPac
SysAdmin
IPSEC VPN
API Server
CI CD
Server
IGW
Client VPN
IPSEC VPN
NAT Gateway
AZ-A
App1 App2 App3
ELB
ELB
Web 1
Master DB
App4 App5 App6
App7
IGW
Fwd Proxy
ELB
NAT
Gateway
Internet
VMware Cloud on AWS:
Jointly engineered Cloud Service
Service Overview:
§ VMware SDDC running on AWS bare metal
§ Delivered, operated, supported by VMware
§ On-demand capacity and flexible consumption
§ Seamless portability of hybrid large-scale workload
§ Direct access to native AWS services
Business Use Cases:
§ Data Center Extension
§ Disaster Recovery
§ Cloud Migration
§ Application Modernization
Cloud Motion:
Workload Mobility across Hybrid Clouds
Active Migrated VMs
CROSS-VERSION HYBRIDITY SECURITY
ON PREMISE CLOUD
LARGE SCALE WARM MIGRATION
Hybrid Interconnect
Any-to-Any vSphere Migration
vSphere 5.0 VMware Cloud
VMware Cloud on AWSOn-Premises Data Center
AWS Direct Connect
Compute
Storage
Network
Compute
Storage
Network
vSphere-based SDDC with NSX
CGW
Network A
MGW
N-S FW
Router
Network 172.16.10.0/24
Network 172.16.20.0/24
Govt
Network
Zone
VMC-VM
BGP Peering Session
Public
Internet
N-S FW
Governing Internet/Security
Posture from On Premise DC
Manage the Internet bound traffic on Public cloud
via On-premise security framework, so that control
and governance need not be re-architected and
use Public Cloud for the benefit of Agility and
Scale.
Use Cases:
§ Internet Separation or Network Zone
Separation for VDI/Any workloads.
§ Data Center Extension where Public
Cloud is used as Hot capacity/Cloud
Burst.
Leveraging Well Architected Framework on AWS
§ Expense Awareness
§ Cost-effective Resource
§ Match supply with
demand
§ Architecture
optimization
§ Select
§ Review
§ Monitoring
§ Trade-offs
§ Automated
Change
Management
§ Automated
Failure
Management
§ Centralized
Privileged
Management
§ Centralized
Monitoring
§ Data Security
§ Incident
Management plan
§ Prepare
§ Operate
§ Evolve
Cost
Optimization
Performance
Efficiency
ReliabilitySecurity
Operational
Excellence
Copyright © & Confidential
Providing Cloud Best Practices through
EXPERIENCE.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
Thank you!
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R
S U M M I T
Sourav Ray
Cloud Architect
AsiaPac

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

Getting Started with Serverless Architectures
Getting Started with Serverless ArchitecturesGetting Started with Serverless Architectures
Getting Started with Serverless Architectures
 
A Practitioners Guide to Securing Your Cloud
A Practitioners Guide to Securing Your CloudA Practitioners Guide to Securing Your Cloud
A Practitioners Guide to Securing Your Cloud
 
Architecting security and governance across your AWS environment
Architecting security and governance across your AWS environmentArchitecting security and governance across your AWS environment
Architecting security and governance across your AWS environment
 
An Amazonian approach to enterprise transformation
An Amazonian approach to enterprise transformationAn Amazonian approach to enterprise transformation
An Amazonian approach to enterprise transformation
 
AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019
 
Journey into the Cloud with VMware Cloud on AWS: Deep Dive - CMP303 - Anaheim...
Journey into the Cloud with VMware Cloud on AWS: Deep Dive - CMP303 - Anaheim...Journey into the Cloud with VMware Cloud on AWS: Deep Dive - CMP303 - Anaheim...
Journey into the Cloud with VMware Cloud on AWS: Deep Dive - CMP303 - Anaheim...
 
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
 
Breaking the Monolith using AWS Container Services
Breaking the Monolith using AWS Container ServicesBreaking the Monolith using AWS Container Services
Breaking the Monolith using AWS Container Services
 
WhyCloud?
WhyCloud?WhyCloud?
WhyCloud?
 
Reinventing SAP on AWS: Scale & Simplify SAP Operations on AWS
Reinventing SAP on AWS: Scale & Simplify SAP Operations on AWSReinventing SAP on AWS: Scale & Simplify SAP Operations on AWS
Reinventing SAP on AWS: Scale & Simplify SAP Operations on AWS
 
Enabling digital transformation of your business on AWS - DEM08-S - Mexico Ci...
Enabling digital transformation of your business on AWS - DEM08-S - Mexico Ci...Enabling digital transformation of your business on AWS - DEM08-S - Mexico Ci...
Enabling digital transformation of your business on AWS - DEM08-S - Mexico Ci...
 
Cloud Data Management with Veeam, N2WS, & AWS
Cloud Data Management with Veeam, N2WS, & AWSCloud Data Management with Veeam, N2WS, & AWS
Cloud Data Management with Veeam, N2WS, & AWS
 
VMware: The Fastest Path to Hybrid Cloud
VMware: The Fastest Path to Hybrid CloudVMware: The Fastest Path to Hybrid Cloud
VMware: The Fastest Path to Hybrid Cloud
 
Everything You Need to Know About Big Data: From Architectural Principles to ...
Everything You Need to Know About Big Data: From Architectural Principles to ...Everything You Need to Know About Big Data: From Architectural Principles to ...
Everything You Need to Know About Big Data: From Architectural Principles to ...
 
Migrating & Operating Microsoft Applications in AWS
Migrating & Operating Microsoft Applications in AWSMigrating & Operating Microsoft Applications in AWS
Migrating & Operating Microsoft Applications in AWS
 
.NET on AWS
.NET on AWS.NET on AWS
.NET on AWS
 
How to speed up and scale your innovation efforts - MAD203 - Chicago AWS Summit
How to speed up and scale your innovation efforts - MAD203 - Chicago AWS SummitHow to speed up and scale your innovation efforts - MAD203 - Chicago AWS Summit
How to speed up and scale your innovation efforts - MAD203 - Chicago AWS Summit
 
Cloud ibrido nella PA
Cloud ibrido nella PACloud ibrido nella PA
Cloud ibrido nella PA
 
Best practices for running Windows workloads on AWS
Best practices for running Windows workloads on AWSBest practices for running Windows workloads on AWS
Best practices for running Windows workloads on AWS
 
AWS Initiate Day Manchester 2019 – AWS Migrating Data to the Cloud
AWS Initiate Day Manchester 2019 – AWS Migrating Data to the CloudAWS Initiate Day Manchester 2019 – AWS Migrating Data to the Cloud
AWS Initiate Day Manchester 2019 – AWS Migrating Data to the Cloud
 

Semelhante a Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Environment on AWS

Semelhante a Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Environment on AWS (20)

Automate the Provisioning of Secure Developer Environments on AWS PPT
 Automate the Provisioning of Secure Developer Environments on AWS PPT Automate the Provisioning of Secure Developer Environments on AWS PPT
Automate the Provisioning of Secure Developer Environments on AWS PPT
 
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
 
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
 
Transform into a Cloud-First Business with SAP on AWS and Capgemini’s Cloud C...
Transform into a Cloud-First Business with SAP on AWS and Capgemini’s Cloud C...Transform into a Cloud-First Business with SAP on AWS and Capgemini’s Cloud C...
Transform into a Cloud-First Business with SAP on AWS and Capgemini’s Cloud C...
 
PARTNER PRESENTATION: Transform into a Cloud First Business with Capgemini’s ...
PARTNER PRESENTATION: Transform into a Cloud First Business with Capgemini’s ...PARTNER PRESENTATION: Transform into a Cloud First Business with Capgemini’s ...
PARTNER PRESENTATION: Transform into a Cloud First Business with Capgemini’s ...
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
 
VMware Cloud on AWS: The Fast Path to Cloud for Public Sector Organizations
VMware Cloud on AWS: The Fast Path to Cloud for Public Sector OrganizationsVMware Cloud on AWS: The Fast Path to Cloud for Public Sector Organizations
VMware Cloud on AWS: The Fast Path to Cloud for Public Sector Organizations
 
Succeeding with Secure Access Service Edge (SASE)
Succeeding with Secure Access Service Edge (SASE)Succeeding with Secure Access Service Edge (SASE)
Succeeding with Secure Access Service Edge (SASE)
 
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
 
VMware Cloud on AWS - The Next-Generation Hybrid Cloud
VMware Cloud on AWS - The Next-Generation Hybrid CloudVMware Cloud on AWS - The Next-Generation Hybrid Cloud
VMware Cloud on AWS - The Next-Generation Hybrid Cloud
 
VMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdfVMware Cloud on AWS - 100819.pdf
VMware Cloud on AWS - 100819.pdf
 
Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS
 
One And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptxOne And Done Multi-Cloud Load Balancing Done Right.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptx
 
New in Hong Kong Region
New in Hong Kong RegionNew in Hong Kong Region
New in Hong Kong Region
 
AWSome Day Philippines Keynote 2015
AWSome Day Philippines Keynote 2015AWSome Day Philippines Keynote 2015
AWSome Day Philippines Keynote 2015
 
We are Net3 Technology
We are Net3 TechnologyWe are Net3 Technology
We are Net3 Technology
 
Enterprise Network Transformation Powered by OrangeX, with Nokia Nuage and AW...
Enterprise Network Transformation Powered by OrangeX, with Nokia Nuage and AW...Enterprise Network Transformation Powered by OrangeX, with Nokia Nuage and AW...
Enterprise Network Transformation Powered by OrangeX, with Nokia Nuage and AW...
 
DEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS ExtensionsDEM16 Cisco ACI Anywhere – AWS Extensions
DEM16 Cisco ACI Anywhere – AWS Extensions
 
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
How Can I Build a Landing Zone & Extend my Operations into AWS to Support my ...
 
Getting Started with AWS Security
 Getting Started with AWS Security Getting Started with AWS Security
Getting Started with AWS Security
 

Mais de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Mais de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Environment on AWS

  • 1. P U B L I C S E C T O R S U M M I T SINGAPORE
  • 2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R S U M M I T How AsiaPac is helping Customers to build a Restricted Cloud Environment on AWS Sourav Ray Cloud Architect AsiaPac
  • 3. Copyright © & Confidential
  • 4. Copyright © & Confidential An M1 company. Since Nov’18 EPPU S/10 company ISO 9001:2015 & Biz Safe Level 3 certified ICT Solutions Provider Started 1990 Commercial, Enterprise, Education, Healthcare & Government
  • 5. Copyright © & Confidential
  • 6. Self Service Management Portal Government / Enterprise Customers Self Service & Service Management Hybrid Cloud Management System Leading Telecommunications Provider First telco to embark 5G live test in SG Direct Connect Local Loops SDWAN CMP Frameworks Blueprints Modernization • Bring workloads closer to AWS • Low latency connectivity • Orchestration Bring close to AWS Migrate to AWS or Migrate to AWS Outpost/ VMC Customer Self Manage Creating Business Ecosystem
  • 7. VMware Cloud on AWS Exclusive Launch Partner
  • 8. Copyright © & Confidential Governance in Restricted Cloud Environment
  • 9. § Controlled access reducing Security Risks § Ensuring regulatory compliance like HIPAA, PCI, MTSC Tier 3, ISO etc. § Cost Optimization § Eliminate unnecessary IT and Cloud initiatives § DevOps process initiation and parameter definitions § Enhance management of Cloud resources The Disciplines of CLOUD GOVERNANCE Why is it important?
  • 10. Our Approach to CLOUD GOVERNANCE Cloud Governance Data Security Resource Tagging Structured DevOps Solutions Security and Log Management Monthly Reports and Analytics Patch Management with Approval Process Infrastructure Monitoring Application Monitoring Internal Audits Cost Budgeting Environment Templatization Authentication & Authorization
  • 11. Our Approach to CLOUD GOVERNANCE Cloud Governance Environment Templatization Data Security Resource Tagging Structured DevOps Solutions Security and Log Management Authentication and Authorization Monthly Reports and Analytics Patch Management with Approval process Application Monitoring Infrastructure Monitoring Internal Audits Cost Budgeting § Compliance Audit § Security Audit § User Audit § Data Privacy Audit § Penetration Testing
  • 12. Our Approach to CLOUD GOVERNANCE Cloud Governance Environment Templatization Data Security Resource Tagging Structured DevOps Solutions Security and Log Management Authentication and Authorization Monthly Reports and Analytics Patch Management with Approval process Application Monitoring Infrastructure Monitoring Internal Audits Cost Budgeting § Enforcing MFA for AWS Management Console § Enforcing console login via on premise AD authentication using AWS SSO § Enforcing AWS Cognito for application level authentication § Enforcing privileged access using AWS IAM
  • 13. Our Approach to CLOUD GOVERNANCE Cloud Governance Environment Templatization Data Security Resource Tagging Structured DevOps Solutions Security and Log Management Authentication and Authorization Monthly Reports and Analytics Patch Management with Approval process Application Monitoring Infrastructure Monitoring Internal Audits Cost Budgeting Continuous Integration Micro-Services Policy as Code and Automated Monitoring
  • 14. Our Approach to CLOUD GOVERNANCE Cloud Governance Environment Templatization Data Security Resource Tagging Structured DevOps Solutions Security and Log Management Authentication and Authorization Monthly Reports and Analytics Patch Management with Approval process Application Monitoring Infrastructure Monitoring Internal Audits Cost Budgeting Launch Instance Create Tags Scan OS based on Patch Baseline Generate Missing Patch List SSM Document for Patch Scan Stop Instance Create Image Create Tags Terminate Instance SSM Document for Patch Install Launch Instance Update OS Software Generate Installed Patch List Update Parameter Store If approved
  • 15. How to Regain a Healthy Governance § current state of all cloud users and their access rights across the enterprise? “WITHOUT REDUCING CLOUD AGILITY” MANAGE ENSURE § adherence to the overall costs to PAY PER USE model? § deployments and operations are in track with compliance regulations and policies? ENFORCE § security across all the environment workloads as well as User Management? Cloud Governance Pain Areas
  • 16. ASIAPAC MANAGED INFRASTRUCTURE & CLOUD SERVICES Increase in AWS Workloads Growth in AWS account Management Cost Control Security & Compliance GOVERNANCE AT SCALE Solutions to Governance at Scale
  • 17. Design Architecture AZ-A AZ-B IGW Direct Connect Internet Web 1 RDS Master IDS1 IDS2Mgmt 1EVM1 Mgmt 2 EVM2 ELB ELB Cyber Watch Center App1 App2 App3 App4 App5 App6 ELB App7 App8 App9 App10 App11 App12 Web 2 Tier 1 NGFW Tier 1 NGFW RDS Slave Tier 2 NGFW Tier 2 NGFW NAT Gateway NAT Gateway AD Server 1 AZ-A AD Server 2 Event Collector1 Event Collector2 Customer On Premise Dev Server Dev Server Bastion Host API Server Monitoring Collector AZ-B AsiaPac NOC VPC AsiaPac EM7 Database VPN Gateway2FA 2FA API Server On Premise SOC AsiaPac SysAdmin IPSEC VPN API Server Dev Server IGW Client VPN IPSEC VPN NAT Gateway AZ-A AZ-B App1 App2 App3 App4 App5 App6 ELB Web 1 Master DB Slave DB App7 App8 App9 App10 App11 App12 Web 2 VPN IGW Firewall ELB NAT Gateway NAT Gateway ELB Internet AD Server 1 AZ-A AD Server 2 Event Collector1 Customer Data Center Dev Server Bastion Host API Server DB Server AZ-B VPN Gateway2FA 2FA API Server On Premise SOC AsiaPac SysAdmin IPSEC VPN API Server CI CD Server IGW Client VPN IPSEC VPN NAT Gateway AZ-A App1 App2 App3 ELB ELB Web 1 Master DB App4 App5 App6 App7 IGW Fwd Proxy ELB NAT Gateway Internet
  • 18. VMware Cloud on AWS: Jointly engineered Cloud Service Service Overview: § VMware SDDC running on AWS bare metal § Delivered, operated, supported by VMware § On-demand capacity and flexible consumption § Seamless portability of hybrid large-scale workload § Direct access to native AWS services Business Use Cases: § Data Center Extension § Disaster Recovery § Cloud Migration § Application Modernization
  • 19. Cloud Motion: Workload Mobility across Hybrid Clouds Active Migrated VMs CROSS-VERSION HYBRIDITY SECURITY ON PREMISE CLOUD LARGE SCALE WARM MIGRATION Hybrid Interconnect Any-to-Any vSphere Migration vSphere 5.0 VMware Cloud
  • 20. VMware Cloud on AWSOn-Premises Data Center AWS Direct Connect Compute Storage Network Compute Storage Network vSphere-based SDDC with NSX CGW Network A MGW N-S FW Router Network 172.16.10.0/24 Network 172.16.20.0/24 Govt Network Zone VMC-VM BGP Peering Session Public Internet N-S FW Governing Internet/Security Posture from On Premise DC Manage the Internet bound traffic on Public cloud via On-premise security framework, so that control and governance need not be re-architected and use Public Cloud for the benefit of Agility and Scale. Use Cases: § Internet Separation or Network Zone Separation for VDI/Any workloads. § Data Center Extension where Public Cloud is used as Hot capacity/Cloud Burst.
  • 21. Leveraging Well Architected Framework on AWS § Expense Awareness § Cost-effective Resource § Match supply with demand § Architecture optimization § Select § Review § Monitoring § Trade-offs § Automated Change Management § Automated Failure Management § Centralized Privileged Management § Centralized Monitoring § Data Security § Incident Management plan § Prepare § Operate § Evolve Cost Optimization Performance Efficiency ReliabilitySecurity Operational Excellence
  • 22. Copyright © & Confidential Providing Cloud Best Practices through EXPERIENCE.
  • 23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R S U M M I T
  • 24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R S U M M I T Thank you! © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.P U B L I C S E C T O R S U M M I T Sourav Ray Cloud Architect AsiaPac