SlideShare a Scribd company logo
1 of 29
Download to read offline
10 MUST-HAVE
AUTOMATED CLOUD POLICIES
FOR IT GOVERNANCE
• Kim Weins
• VP Cloud Strategy & Spend Optimization, Flexera
• Ryan O’Leary
• Senior Director, Product Management, Flexera
Presenters
● Developing a cloud governance process
● How to maintain agility and flexibility of cloud use
● How to automate the remediation of policy violations
● 10 automated policies that should be your top priority
Agenda
2
Why Do Policies Need to Be “Multi-Cloud”?
3
Top Initiatives: Optimize Cloud, More Cloud
4
Few Organizations Are Automating Policies
5
A Common Policy Engine
RightScale
Cloud Management Platform
Orchestrate, automate and govern workloads
across all your environments.
VIRTUAL
SERVERS
PUBLIC
CLOUDS
ANY CLOUD
SERVICE
PRIVATE
CLOUDS
BARE METAL
SERVERS
CONTAINER
CLUSTERS
RightScale
Optima
Work collaboratively across the organization
to manage and optimize clouds costs.
RIGHTSCALE
EXTENSIBLE ORCHESTRATION API
Policy-Based Governance
User access controls and policies
Maturing Your Management of Cloud
7
Reactive Responsive PreventativeProactive
Fire drill Manual policies and
processes
Automated policies
and processes
Prevent issues
before they occur
Automated Policies
Breaking Down a Policy
From Alert Only to Fully Automated Resolution
9
Alert only
Alert
Approval
Automated
resolution
Fully
automated
resolution
Move toward full automation as you gain confidence in policy conditions
Policies Go Beyond Costs
10
Policies
Define and enforce governance rules
Cost
Unattached volumes
Old snapshots
Unused RIs
Underutilized VMs
...and more
Security
Unsecured storage
Open security groups
Disallowed ports
Open IAM policies
...and more
Compliance
Untagged resources
Invalid tags
Disallowed
configurations
...and more
Operational
No recent snapshots
No DB backup
No required alerts
Upsize instances
...and more
Customizing Out-of-the-Box Policies
11
Find untagged
resources
Apply default tags
when possible
Send an email
alert/report
Find untagged
resources
Apply default tags
when possible
Create a JIRA
ticket
Wait 48 hours and
terminate/delete
Out-of-the-Box Policy
“Tag Checker”
Customized Policy
“Delete Untagged”
Update resolution
in JIRA ticket
DEMO
COST POLICIES
Policy: Reserved Instance Alerts
14
RI < 95%
utilized?
Y
Email
Alert/Report
Pass
N
RI Alert Examples:
-Expiration
-Underutilized
-Coverage
Policy: Unattached Volumes (UAV)
15
Unattached >
x days?
Y
Email Alert
Pass
Action: Delete
volume
User specified
to delete?
Y
N
Email Alert
N
Policy: Downsize Instances
16
< x% avg CPU
and <y% max
mem used
Y
Email Alert
No action
Action:
Downsize
User specified
to downsize?
Y
N
Email Alert
N
Policy: Instance Scheduling via Tags
17
After shutdown &
before start time
Action: Stop
instance
Y
After start time &
before shutdown
Action: Start
instance
Y
Tag Syntax Example (M-F 8-5):
instance:schedule=8-17;MO,TU,WE,TH,FR;America/New_York
Policy: Leverage Azure Hybrid Benefit
18
SECURITY POLICIES
Policy: Security Group Anomalies
20
SG Has
Anomalies
Y
Email Alert
Pass
N
SG Anomaly Examples:
-High Open Ports
-ICMP Enabled
-Rules without Descriptions
Policy: Open Storage Buckets
21
Public storage
bucket?
Y
Email Alert
Pass
Action: Make
private
Check if
public tag?
N
Y
Pass
Slack Alert
N
OPERATIONAL POLICIES
Policy: No Recent Volume Snapshots
23
Volume has no
snapshots in last
x days
Y
Email Alert
No action
Action: Take
snapshot
User specified
to downsize?
Y
N
Email Alert
N
COMPLIANCE POLICIES
Policy: Tag Checker
25
Has required
tag?
Has valid
value?
Y
N
Can auto-tag?
Y
N
Email Alert
Y
N
Fixed after x
hours?
Pass
Pass
Y
Action:
Terminate
N
Policy: Disallowed Region
26
Allowed
region?
N
Alert with
Approval
Y
Pass
Action: Tag
as allowed
Y
Action:
Terminate
Approved?
N
DEMO
Contact sales@rightscale.com for more info
Q&A
28

More Related Content

What's hot

What's hot (20)

How to Set Up a Cloud Cost Optimization Process for your Enterprise
How to Set Up a Cloud Cost Optimization Process for your EnterpriseHow to Set Up a Cloud Cost Optimization Process for your Enterprise
How to Set Up a Cloud Cost Optimization Process for your Enterprise
 
Kubernetes and Terraform in the Cloud: How RightScale Does DevOps
Kubernetes and Terraform in the Cloud: How RightScale Does DevOpsKubernetes and Terraform in the Cloud: How RightScale Does DevOps
Kubernetes and Terraform in the Cloud: How RightScale Does DevOps
 
How to Manage Cloud Costs with RightScale Optima
How to Manage Cloud Costs with RightScale OptimaHow to Manage Cloud Costs with RightScale Optima
How to Manage Cloud Costs with RightScale Optima
 
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
 
Cloud Management for MSPs
Cloud Management for MSPsCloud Management for MSPs
Cloud Management for MSPs
 
12 Ways to Manage Cloud Costs and Optimize Cloud Spend
12 Ways to Manage Cloud Costs and Optimize Cloud Spend12 Ways to Manage Cloud Costs and Optimize Cloud Spend
12 Ways to Manage Cloud Costs and Optimize Cloud Spend
 
Tagging Best Practices for Cloud Governance
Tagging Best Practices for Cloud GovernanceTagging Best Practices for Cloud Governance
Tagging Best Practices for Cloud Governance
 
RightScale 2016 State of the Cloud Report
RightScale 2016 State of the Cloud ReportRightScale 2016 State of the Cloud Report
RightScale 2016 State of the Cloud Report
 
How to Use RightScale CMP to Manage Cloud: In-Depth Demo
How to Use RightScale CMP to Manage Cloud: In-Depth DemoHow to Use RightScale CMP to Manage Cloud: In-Depth Demo
How to Use RightScale CMP to Manage Cloud: In-Depth Demo
 
RightScale 2017 State of the Cloud
RightScale 2017 State of the CloudRightScale 2017 State of the Cloud
RightScale 2017 State of the Cloud
 
Got a Multi-Cloud Strategy? How RightScale CMP Helps
Got a Multi-Cloud Strategy? How RightScale CMP HelpsGot a Multi-Cloud Strategy? How RightScale CMP Helps
Got a Multi-Cloud Strategy? How RightScale CMP Helps
 
Best Practices for Your CMP RFP or RFI
Best Practices for Your CMP RFP or RFIBest Practices for Your CMP RFP or RFI
Best Practices for Your CMP RFP or RFI
 
Successful Cloud Orchestration with RightScale CMP
Successful Cloud Orchestration with RightScale CMPSuccessful Cloud Orchestration with RightScale CMP
Successful Cloud Orchestration with RightScale CMP
 
Cloud Acquisition Strategies: How to Buy the Cloud
Cloud Acquisition Strategies: How to Buy the CloudCloud Acquisition Strategies: How to Buy the Cloud
Cloud Acquisition Strategies: How to Buy the Cloud
 
Manage and Optimize Cloud Spend with RightScale Optima
Manage and Optimize Cloud Spend with RightScale OptimaManage and Optimize Cloud Spend with RightScale Optima
Manage and Optimize Cloud Spend with RightScale Optima
 
How Cost Optimization can help me reduce my Cloud bill by upto 75%
How Cost Optimization can help me reduce my Cloud bill by upto 75% How Cost Optimization can help me reduce my Cloud bill by upto 75%
How Cost Optimization can help me reduce my Cloud bill by upto 75%
 
Top 10 Cloud Trends for 2018 and Actions You Can Take Now
Top 10 Cloud Trends for 2018 and Actions You Can Take NowTop 10 Cloud Trends for 2018 and Actions You Can Take Now
Top 10 Cloud Trends for 2018 and Actions You Can Take Now
 
Hybrid Cloud Orchestration: How SuperChoice Does It
Hybrid Cloud Orchestration: How SuperChoice Does ItHybrid Cloud Orchestration: How SuperChoice Does It
Hybrid Cloud Orchestration: How SuperChoice Does It
 
How 2015 Cloud Trends Should Impact Your 2016 Cloud Strategy
How 2015 Cloud Trends Should Impact Your 2016 Cloud StrategyHow 2015 Cloud Trends Should Impact Your 2016 Cloud Strategy
How 2015 Cloud Trends Should Impact Your 2016 Cloud Strategy
 
Pivoting to Cloud: How an MSP Brokers Cloud Services
Pivoting to Cloud: How an MSP Brokers Cloud Services Pivoting to Cloud: How an MSP Brokers Cloud Services
Pivoting to Cloud: How an MSP Brokers Cloud Services
 

Similar to 10 Must-Have Automated Cloud Policies for IT Governance

Making Self-Service BI a Reality in the Enterprise
Making Self-Service BI a Reality in the EnterpriseMaking Self-Service BI a Reality in the Enterprise
Making Self-Service BI a Reality in the Enterprise
Cloudera, Inc.
 

Similar to 10 Must-Have Automated Cloud Policies for IT Governance (20)

CSA LATAM FORUM - NETSKOPE
CSA LATAM FORUM - NETSKOPECSA LATAM FORUM - NETSKOPE
CSA LATAM FORUM - NETSKOPE
 
Having Trouble Managing All Your Cloud Services? We Know!
Having Trouble Managing All Your Cloud Services? We Know!Having Trouble Managing All Your Cloud Services? We Know!
Having Trouble Managing All Your Cloud Services? We Know!
 
The Business Justification for APM
The Business Justification for APMThe Business Justification for APM
The Business Justification for APM
 
Security a Revenue Center: How Security Can Drive Your Business
Security a Revenue Center: How Security Can Drive Your BusinessSecurity a Revenue Center: How Security Can Drive Your Business
Security a Revenue Center: How Security Can Drive Your Business
 
How to Migrate to Cloud with Complete Confidence and Trust
How to Migrate to Cloud with Complete Confidence and TrustHow to Migrate to Cloud with Complete Confidence and Trust
How to Migrate to Cloud with Complete Confidence and Trust
 
Deep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and AutomationDeep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and Automation
 
How MSPs Can Be Successful in AWS, Azure, and Google Clouds
How MSPs Can Be Successful in AWS, Azure, and Google CloudsHow MSPs Can Be Successful in AWS, Azure, and Google Clouds
How MSPs Can Be Successful in AWS, Azure, and Google Clouds
 
The 5 Biggest Data Myths in Telco: Exposed
The 5 Biggest Data Myths in Telco: ExposedThe 5 Biggest Data Myths in Telco: Exposed
The 5 Biggest Data Myths in Telco: Exposed
 
Be Proactive, Not Reactive: Cloud Governance for Fast, Accurate Decision Making
Be Proactive, Not Reactive: Cloud Governance for Fast, Accurate Decision MakingBe Proactive, Not Reactive: Cloud Governance for Fast, Accurate Decision Making
Be Proactive, Not Reactive: Cloud Governance for Fast, Accurate Decision Making
 
AWS Summit Singapore - How to Reduce Spend and Improve Efficiency in your AWS...
AWS Summit Singapore - How to Reduce Spend and Improve Efficiency in your AWS...AWS Summit Singapore - How to Reduce Spend and Improve Efficiency in your AWS...
AWS Summit Singapore - How to Reduce Spend and Improve Efficiency in your AWS...
 
Share cics policy (2844)
Share cics policy (2844)Share cics policy (2844)
Share cics policy (2844)
 
Enterprise Cloud Strategy: 7 Areas You Need to Re-Think
Enterprise Cloud Strategy: 7 Areas You Need to Re-ThinkEnterprise Cloud Strategy: 7 Areas You Need to Re-Think
Enterprise Cloud Strategy: 7 Areas You Need to Re-Think
 
Making Self-Service BI a Reality in the Enterprise
Making Self-Service BI a Reality in the EnterpriseMaking Self-Service BI a Reality in the Enterprise
Making Self-Service BI a Reality in the Enterprise
 
So You Bought Oracle Ecm
So You Bought Oracle EcmSo You Bought Oracle Ecm
So You Bought Oracle Ecm
 
Optimizing your cloud
Optimizing your cloudOptimizing your cloud
Optimizing your cloud
 
For SMBs using MSPs (and VARs) | How to Save Money with Managed IT Services
For SMBs using MSPs (and VARs) | How to Save Money with Managed IT ServicesFor SMBs using MSPs (and VARs) | How to Save Money with Managed IT Services
For SMBs using MSPs (and VARs) | How to Save Money with Managed IT Services
 
RightScale News November 2013: Launch of Cloud Analytics
RightScale News November 2013: Launch of Cloud AnalyticsRightScale News November 2013: Launch of Cloud Analytics
RightScale News November 2013: Launch of Cloud Analytics
 
Cloud Applications Management Nirvana
Cloud Applications Management NirvanaCloud Applications Management Nirvana
Cloud Applications Management Nirvana
 
Governance Strategies & Tools for Cloud Formation
Governance Strategies & Tools for Cloud Formation Governance Strategies & Tools for Cloud Formation
Governance Strategies & Tools for Cloud Formation
 
Transpeye Overview V1 (1)
Transpeye Overview V1 (1)Transpeye Overview V1 (1)
Transpeye Overview V1 (1)
 

More from RightScale

More from RightScale (13)

Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBMComparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
 
Best Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and ComplianceBest Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and Compliance
 
9 Ways to Reduce Cloud Storage Costs
9 Ways to Reduce Cloud Storage Costs9 Ways to Reduce Cloud Storage Costs
9 Ways to Reduce Cloud Storage Costs
 
Serverless Comparison: AWS vs Azure vs Google vs IBM
Serverless Comparison: AWS vs Azure vs Google vs IBMServerless Comparison: AWS vs Azure vs Google vs IBM
Serverless Comparison: AWS vs Azure vs Google vs IBM
 
Best Practices for Cloud Managed Services Providers: The Path to CMP Success
Best Practices for Cloud Managed Services Providers: The Path to CMP SuccessBest Practices for Cloud Managed Services Providers: The Path to CMP Success
Best Practices for Cloud Managed Services Providers: The Path to CMP Success
 
Cloud Storage Comparison: AWS vs Azure vs Google vs IBM
Cloud Storage Comparison: AWS vs Azure vs Google vs IBMCloud Storage Comparison: AWS vs Azure vs Google vs IBM
Cloud Storage Comparison: AWS vs Azure vs Google vs IBM
 
AWS re:Invent 2017 Recap
AWS re:Invent 2017 RecapAWS re:Invent 2017 Recap
AWS re:Invent 2017 Recap
 
Cloud Instances Price Comparison: AWS vs Azure vs Google vs IBM
Cloud Instances Price Comparison: AWS vs Azure vs Google vs IBMCloud Instances Price Comparison: AWS vs Azure vs Google vs IBM
Cloud Instances Price Comparison: AWS vs Azure vs Google vs IBM
 
Orchestrating PaaS and IaaS+ with RightScale
Orchestrating PaaS and IaaS+ with RightScaleOrchestrating PaaS and IaaS+ with RightScale
Orchestrating PaaS and IaaS+ with RightScale
 
Managing Container-as-a-Service and Docker Clusters in the Cloud with RightScale
Managing Container-as-a-Service and Docker Clusters in the Cloud with RightScaleManaging Container-as-a-Service and Docker Clusters in the Cloud with RightScale
Managing Container-as-a-Service and Docker Clusters in the Cloud with RightScale
 
Understanding VMware Cloud on AWS
Understanding VMware Cloud on AWSUnderstanding VMware Cloud on AWS
Understanding VMware Cloud on AWS
 
Cloud Migration and Portability (with and without Containers)
Cloud Migration and Portability (with and without Containers)Cloud Migration and Portability (with and without Containers)
Cloud Migration and Portability (with and without Containers)
 
Compare Cloud Services: AWS vs Azure vs Google vs IBM
Compare Cloud Services: AWS vs Azure vs Google vs IBMCompare Cloud Services: AWS vs Azure vs Google vs IBM
Compare Cloud Services: AWS vs Azure vs Google vs IBM
 

Recently uploaded

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 

10 Must-Have Automated Cloud Policies for IT Governance

  • 1. 10 MUST-HAVE AUTOMATED CLOUD POLICIES FOR IT GOVERNANCE
  • 2. • Kim Weins • VP Cloud Strategy & Spend Optimization, Flexera • Ryan O’Leary • Senior Director, Product Management, Flexera Presenters
  • 3. ● Developing a cloud governance process ● How to maintain agility and flexibility of cloud use ● How to automate the remediation of policy violations ● 10 automated policies that should be your top priority Agenda 2
  • 4. Why Do Policies Need to Be “Multi-Cloud”? 3
  • 5. Top Initiatives: Optimize Cloud, More Cloud 4
  • 6. Few Organizations Are Automating Policies 5
  • 7. A Common Policy Engine RightScale Cloud Management Platform Orchestrate, automate and govern workloads across all your environments. VIRTUAL SERVERS PUBLIC CLOUDS ANY CLOUD SERVICE PRIVATE CLOUDS BARE METAL SERVERS CONTAINER CLUSTERS RightScale Optima Work collaboratively across the organization to manage and optimize clouds costs. RIGHTSCALE EXTENSIBLE ORCHESTRATION API Policy-Based Governance User access controls and policies
  • 8. Maturing Your Management of Cloud 7 Reactive Responsive PreventativeProactive Fire drill Manual policies and processes Automated policies and processes Prevent issues before they occur Automated Policies
  • 10. From Alert Only to Fully Automated Resolution 9 Alert only Alert Approval Automated resolution Fully automated resolution Move toward full automation as you gain confidence in policy conditions
  • 11. Policies Go Beyond Costs 10 Policies Define and enforce governance rules Cost Unattached volumes Old snapshots Unused RIs Underutilized VMs ...and more Security Unsecured storage Open security groups Disallowed ports Open IAM policies ...and more Compliance Untagged resources Invalid tags Disallowed configurations ...and more Operational No recent snapshots No DB backup No required alerts Upsize instances ...and more
  • 12. Customizing Out-of-the-Box Policies 11 Find untagged resources Apply default tags when possible Send an email alert/report Find untagged resources Apply default tags when possible Create a JIRA ticket Wait 48 hours and terminate/delete Out-of-the-Box Policy “Tag Checker” Customized Policy “Delete Untagged” Update resolution in JIRA ticket
  • 13. DEMO
  • 15. Policy: Reserved Instance Alerts 14 RI < 95% utilized? Y Email Alert/Report Pass N RI Alert Examples: -Expiration -Underutilized -Coverage
  • 16. Policy: Unattached Volumes (UAV) 15 Unattached > x days? Y Email Alert Pass Action: Delete volume User specified to delete? Y N Email Alert N
  • 17. Policy: Downsize Instances 16 < x% avg CPU and <y% max mem used Y Email Alert No action Action: Downsize User specified to downsize? Y N Email Alert N
  • 18. Policy: Instance Scheduling via Tags 17 After shutdown & before start time Action: Stop instance Y After start time & before shutdown Action: Start instance Y Tag Syntax Example (M-F 8-5): instance:schedule=8-17;MO,TU,WE,TH,FR;America/New_York
  • 19. Policy: Leverage Azure Hybrid Benefit 18
  • 21. Policy: Security Group Anomalies 20 SG Has Anomalies Y Email Alert Pass N SG Anomaly Examples: -High Open Ports -ICMP Enabled -Rules without Descriptions
  • 22. Policy: Open Storage Buckets 21 Public storage bucket? Y Email Alert Pass Action: Make private Check if public tag? N Y Pass Slack Alert N
  • 24. Policy: No Recent Volume Snapshots 23 Volume has no snapshots in last x days Y Email Alert No action Action: Take snapshot User specified to downsize? Y N Email Alert N
  • 26. Policy: Tag Checker 25 Has required tag? Has valid value? Y N Can auto-tag? Y N Email Alert Y N Fixed after x hours? Pass Pass Y Action: Terminate N
  • 27. Policy: Disallowed Region 26 Allowed region? N Alert with Approval Y Pass Action: Tag as allowed Y Action: Terminate Approved? N
  • 28. DEMO