O slideshow foi denunciado.
Utilizamos seu perfil e dados de atividades no LinkedIn para personalizar e exibir anúncios mais relevantes. Altere suas preferências de anúncios quando desejar.

Operando em Escala Preparando-se para a jornada

36 visualizações

Publicada em

Slide apresentado no Initiate Day São Paulo 2019- AWS Public Sector

Publicada em: Tecnologia
  • Seja o primeiro a comentar

  • Seja a primeira pessoa a gostar disto

Operando em Escala Preparando-se para a jornada

  1. 1. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. OperandoemEscala Preparando-separaajornada MelissaRavanini ArquitetadeSoluções–EspecialistaemHealthcare
  2. 2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. “The role of the musician is to go from concept to full execution. Put another way, it's to go from understanding the content of something to really learning how to communicate it and make sure it's well-received and lives in somebody else.” Yo-Yo Ma
  3. 3. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. First Steps… One Account
  4. 4. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. One Account Database Application Web / Presentation Database Application Web / Presentation Your First App First Steps…
  5. 5. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. One Account Database Application Web / Presentation Database Application Web / Presentation Your First App Database Application Web / Presentation Database Application Web / Presentation Your Second App First Steps…
  6. 6. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Second Account First Steps…
  7. 7. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Rest API Service Rest API Service Second Account Your Third App Rest API Service First Steps…
  8. 8. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Rest API Service Rest API Service Second Account Your Third App Rest API Service Rest API Service Rest API Service Your Fourth App Rest API Service First Steps…
  9. 9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. First Steps… One Account 1,000s of AccountsMany Accounts
  10. 10. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. First Steps… One Account 1,000s of AccountsMany Accounts
  11. 11. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Many Teams
  12. 12. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Many Teams Isolation
  13. 13. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Many Teams Isolation Security Controls
  14. 14. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Many Teams Isolation Security Controls Business Process
  15. 15. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Many Teams Isolation Security Controls Business Process Billing
  16. 16. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Pros • Complete security and resources isolation • Smaller blast radius • Simplified billing per account
  17. 17. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why is one not enough?… Pros • Complete security and resources isolation • Smaller blast radius • Simplified billing per account Cons • Aggregation/Distribution • Setup and operation overhead • More complex security policies across accounts
  18. 18. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Well Architected Framework: Pillars Operational Excellence Security Reliability Performance Efficiency Cost Optimization
  19. 19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Excellence: Principles • Perform operations as code
  20. 20. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Excellence: Principles • Perform operations as code • Make frequent, small, reversible changes
  21. 21. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Excellence: Principles • Perform operations as code • Make frequent, small, reversible changes • Refine operations procedures frequently
  22. 22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Excellence: Principles • Perform operations as code • Make frequent, small, reversible changes • Refine operations procedures frequently • Anticipate failure -> “pre-mortem”
  23. 23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Excellence: Principles • Perform operations as code • Make frequent, small, reversible changes • Refine operations procedures frequently • Anticipate failure -> “pre-mortem” • Learn from all operational failures
  24. 24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… Don't let the failures of today be the reason for the failures of tomorrow - Bobby Kennedy
  25. 25. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. The Journey Begins PREPARE • Shared understanding between teams • Know the regulations and compliances • Efforts on the most impactful actions
  26. 26. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. The Journey Begins PREPARE OPERATE • Outcomes measured by metrics • Operational health • Respond to events
  27. 27. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. The Journey Begins PREPARE EVOLVEOPERATE • Learning from experience • Share learning
  28. 28. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change
  29. 29. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change • Educate across the Organization
  30. 30. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change • Educate across the Organization • Live and Breathe Collaboration
  31. 31. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change • Educate across the Organization • Live and Breathe Collaboration • Embrace (constructive) Criticism
  32. 32. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change • Educate across the Organization • Live and Breathe Collaboration • Embrace (constructive) Criticism • Build Organizational Trust
  33. 33. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Helps?… • Create the conditions for change • Educate across the Organization • Live and Breathe Collaboration • Embrace (constructive) Criticism • Build Organizational Trust • Incremental Change is Powerful
  34. 34. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Practical First Steps?… Steps in that Evolution
  35. 35. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… AWS Organizations Master Data Center Consolidated billing Minimal resources Limited access No connection to DC Service Control Policies
  36. 36. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Core Accounts AWS Organizations Master Data Center Optional data center connectivity Security tools and audit Cross-account read/write Limited access AWS CloudTrail AWS Config Logging Security
  37. 37. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Security Core Accounts AWS Organizations Master Data Center Managed by network team Networking services AWS Direct Connect Limited access Logging Network
  38. 38. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Security Core Accounts AWS Organizations Master Network Data Center DNS LDAP/Active Directory Shared Services VPC Deployment tools Golden AMI Pipeline Scanning infrastructure Inactive instances Improper tags Snapshot lifecycle Monitoring Limited access Connected to DC Logging Shared Services
  39. 39. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Security Core Accounts AWS Organizations Master Shared Services Network Data Center Reduces access to Master Organizations account Billing reports Usage metrics and reporting Usage optimizations and RI management Limited access Logging Billing Tooling
  40. 40. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Data Center Logging Regulatory compliance Read-only access to needed logs Limited accessInternal Audit
  41. 41. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Innovation space AWS Credits Fixed spending limit Autonomous Experimentation No connection to DC Developer Accounts Developer Sandbox
  42. 42. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Developer Accounts Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Based on level of needed isolation Match your development lifecycle BU/Product/Resource Accounts Developer Sandbox
  43. 43. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Developer Accounts Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Develop and iterate quickly Collaboration space Stage of SDLC BU/Product/Resource Accounts Dev Developer Sandbox
  44. 44. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Dev BU/Product/Resource Accounts Developer Accounts Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Connected to DC Production-like Staging QA Automated deployments Pre-Prod Developer Sandbox
  45. 45. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Dev Pre-Prod BU/Product/Resource Accounts Developer Accounts Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Connected to DC Production applications Promoted from Pre-Prod Limited access Prod Developer Sandbox
  46. 46. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. So where do we begin?… Dev Pre-Prod BU/Product/Resource Accounts Developer Accounts Security Core Accounts AWS Organizations Master Billing Tooling Shared Services Network Internal Audit Data Center Logging Prod Product-specific common services Data lake Common tooling Common services Grows organically Shared to the BU/team Shared Services Developer Sandbox
  47. 47. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. And finally… Dev Pre-Prod BU/Product/Resource Accounts Developer Accounts Security Enterprise Accounts AWS Organizations Master Billing Tooling Shared Services Sandbox Network Internal Audit Data Center Logging Prod Shared Services Orgs: Account management Logging: Centralized logs Security: AWS Config Rules, security tools Shared services: Directory, DNS, limit monitoring Billing Tooling: Cost monitoring Sandbox: Experiments Dev: Development Pre-Prod: Staging Prod: ProductionDeveloper Sandbox
  48. 48. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Next Steps… • Everyone is on the same page • Empower People to succeed • Go Build https://aws.amazon.com/answers/aws-landing-zone/
  49. 49. Obrigada!

×