SlideShare a Scribd company logo
1 of 43
Download to read offline
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Nazar Špak, Territory Manager, AWS
Vladimír Šimek, Sr. Solutions Architect, AWS
November, 2018
Jak vybudovat hybridní cloud v AWS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Housekeeping
• Who is the audience?
• Presentation – around 45 minutes
• Slides in English – talk in Czech & Slovak
• Questions – chat window and / or email
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Agenda
• Understand Hybrid Cloud architecture use cases
• Understand AWS portfolio of capabilities to support
Hybrid Cloud
• Understand AWS partnerships with VMWare, Microsoft
and other key enterprise players
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hybrid Cloud Strategy
of large
enterprises
run VMs in the
public cloud
(IDC)
60%
of organizations
have a hybrid
cloud strategy
today (IDC *)
65%
of workloads
are virtualized
today
(IDC )
83%
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What Do Customers Want in Hybrid?
Run workloads
on-premises
Run workloads
on the cloud
Tight integration Without buying
new hardware
$
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Global Infrastructure
https://aws.amazon.com/about-aws/global-infrastructure/
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hybrid Cloud Use Cases
• Integrated Network
• Integrated Identity and Access
• Data Integration
• Integrated resources and deployment management
• Integrated Devices and Edge Systems
• Cloud Bursting
• Data center extension
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Hybrid Cloud Solutions & Partners
VPC OpsWorksIAM Storage
Gateway
Direct
Connect
S3EC2 RDSSnowball Systems
Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The Foundation
Integrated Network
Integrated Identity and Access
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Virtual Private Network – Extension of your data center
172.31.0.0/16
Availability Zone Availability Zone Availability Zone
VPC subnet VPC subnet VPC subnet
172.31.0.0/24 172.31.1.0/24 172.31.2.0/24
eu-west-1a eu-west-1b eu-west-1c
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Connectivity Options
- Public IPs
- Elastic IPs
- Internet data out pricing
- IPsec authentication and
encryption
- Two main options
- AWS Managed VPN
- Software VPN (EC2)
- Launched in 2011
- Private connection
- Separate from the Internet
- Consistent network
experience
- Connect through 67 locations
- Port speeds of 1 Gbps, 10
Gbps or sub-1 Gbps
AWS Direct ConnectVPNPublic Internet
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
IAM Identities
Users and Groups
IAM user
 Entity created in AWS to represent
a person or service that uses it to
interact with AWS
IAM group
 Assign permissions to logical and
functional grouping of your
organization
 Bulk permissions management
(scalable)
 Easy to change permissions as
individuals change teams (portable)
AWS cloudAWS Management
Console
Password
[+MFA]
Access key
[+MFA]
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
IAM Identities
Identity Federation – Example for SAML 2.0 (Web Console)
Other protocol
supported:
OpenID Connect
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Options for AD-aware Cloud Workloads
On-premises
Windows Server
DC
AD
You manage
1
VPC
EC2 for Windows
Server DC
AD
You manage
2
VPC Endpoint
AWS Microsoft AD
AWS manages
3
AWS Directory Service
for Microsoft Active Directory
also known as AWS Managed Microsoft AD
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Data Integration
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Cold Standby – Cloud Gateways
Amazon EBS
snapshots
Amazon S3
Amazon Glacier
Application
server
AWS
Direct
Connect
Internet
Customer premises
Gateway
appliances
AWS
Storage Gateway
back-end
AMI
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hot Standby
Mirroring/replication
Application
data source
cut over
Elastic
load
balancerActive
Route 53
www.example.com
Corporate data center
Data
volume
Application
server
Subordinate
database
server
Reverse
proxy/
caching
server
AWS Region
Reverse
proxy/
caching
server
Application
server
Master
Database
server
Active
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Partnering to deliver a game-changing solution
 Leading private compute, storage, and
network virtualization capabilities
 Support for broad range of workloads
 De facto standard for the on-premises
enterprise
 Global scale and reach
 Flexible consumption economics
 Broadest set of cloud services
 Elastic infrastructure on demand
Uniting the leaders in private and public cloud services
+
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
DR as a Service with Site Recovery
Manager
Disaster recovery to VMware Cloud
Deliver as a service
Build on VMware established
disaster recovery solutions
Provide application-centric
DR runbook automation
Remove need for
dedicated DR data center
Integrate deeply with the
VMware Cloud on AWS
services
Overview of goals
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
VM
vSphere
(on premises)
VMware
Cloud on
AWS
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Integrated resources and
deployment management
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AMAZON EC2 SYSTEMS MANAGER
Systems Manager Service
EC2
Instance
Systems
Manager Agent
EC2
Instance
On-Prem
Instance
Systems
Manager Agent
Systems
Manager Agent
Manage your Amazon EC2 and on-premises instances
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Deliver scalable, resilient applications with less work
AWS OpsWorks (Chef and Puppet)
Supports any application
Supports existing EC2 instances
Supports servers running in on-premises
datacenters
Single platform to deploy and manage
applications across hybrid architectures
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Microservices on AWS using Kubernetes
Kubernetes is an open-source system for automating deployment,
scaling, and management of containerized applications
Integrated with
AWS Services
CloudTrail,
CloudWatch, ELB,
IAM, VPC,
PrivateLink
Highly available Automated
upgrades and
patches
Hybrid cloud
compatible
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
DevOps – Build on AWS and deploy on premise
Source Build Test Production
Third Party
Tooling
Software Release Steps:
AWS CodeCommit AWS CodeBuild AWS CodeDeploy
AWS CodePipeline
EC2On-Prem
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Integrated Devices and Edge
Systems
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Snowball Edge use cases
Offline
Staging Local Tiering
and Compute
IoT
Local
Transformation
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Moving to the Edge
Cloud
Storage & Compute
Intelligence
Insights & Logic → Action
Devices
Sense & Act
AWS IoT
Core
AWS
Greengrass AWS IoT
Analytics
Amazon
FreeRTOS
AWS IoT Device
Management
AWS IoT
Device
Defender
Things
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Greengrass ML Inference
Edge Cloud
Machine
inference
Inference Training
Use AWS Greengrass console to transfer models to your devices
Run Machine Learning at the edge
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Customer Success Story
Connects Growers, Data & Machines
manufactures agricultural, construction, and
forestry machinery, diesel engines, drivetrains
used in heavy equipment, and lawn care
equipment.
Using the AWS cloud, John Deere
can help farmers take action on real-
time developments on their farms,
plant more efficiently, and improve
the yield of their crops.
• John Deere’s mission: connect people,
technology, and insights to advance
agriculture in a sustainable fashion.
• Uses AWS to stream, analyze, store, and
share data collected by 200,000
telematics-enabled machines
• Provides growers with timely and
accurate data for optimal growing
conditions.
Patrick Pinkston
VP, Information Solutions, John Deere
”
“
John Deere: Video Case Study: http://aws.amazon.com/solutions/case-studies/john-deere/
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Cloud Bursting
(with EC2 Spot Instances)
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS EC2 Consumption Models
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What Are EC2 Spot Instances?
EC2 Spot Instances are
spare EC2 On-Demand capacity
with very simple rules
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The Very Simple Rules of Spot Instances
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Get the Best Value for EC2 Capacity
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Features introduced on re:Invent 2017
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Amazon EC2 Spot Instances Use Cases
Big Data
Containers &
Test/Dev
HPC & Batch
Stateless Web
Services
FINRA saved up to 50%
from its on premises solution,
increased elasticity and
scalability, and accelerated
reprocessing requests from
months to days with EC2
Spot Instances.
Yelp runs millions of tests
daily with EC2 Spot
Instances. It improved test
result response time from 2
days to 30 minutes and has
also delivered a large
reduction in execution costs.
TLG Aerospace saw a 75%
reduction in the cost per
CFD simulation with Amazon
EC2 Spot Instances. It
passed those savings to their
customers and are more
competitive.
AdRoll could seamlessly
scale their infrastructure,
better serve customers
across the globe, and
reduce their fixed costs by
75% and operational costs
by 83% with an AWS
solution, including EC2 Spot
Instances.
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Spot Integrated in Community & Partners
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Data center extension
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hybrid connectivity—split architecture
CORP
Web App Oracle
Database
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hybrid connectivity—split architecture (2)
CORP
Web/App Web/App
NLB / ALB
N E W !
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS global infrastructure
VMware Cloud on AWS
VMware Cloud on AWS
Customer
data center
AWS services
vCentervCenter
vSAN NSXvSphere
Hybrid
linked-mode
Amazon
EC2
Amazon
S3
Amazon
RDS
AWS Direct
Connect
Amazon
Dynamo
DB
Amazon
Redshift
Elastic
Network
Interface
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Links
https://aws.amazon.com/enterprise/hybrid/
https://aws.amazon.com/enterprise/
https://aws.amazon.com/professional-services/CAF/
https://aws.amazon.com/architecture/well-architected/
https://aws.amazon.com/migration-acceleration-program/
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Děkujeme za pozornost!
nazaspak@amazon.com
vladsim@amazon.com

More Related Content

More from Vladimir Simek

AWS Česko-Slovenský Webinár 03: Vývoj v AWS
AWS Česko-Slovenský Webinár 03: Vývoj v AWSAWS Česko-Slovenský Webinár 03: Vývoj v AWS
AWS Česko-Slovenský Webinár 03: Vývoj v AWSVladimir Simek
 
Artificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartArtificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartVladimir Simek
 
Artificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartArtificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartVladimir Simek
 
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduAWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduVladimir Simek
 
AWS Webinar CZSK Uvod do cloud computingu
AWS Webinar CZSK Uvod do cloud computinguAWS Webinar CZSK Uvod do cloud computingu
AWS Webinar CZSK Uvod do cloud computinguVladimir Simek
 
Introduction to EKS (AWS User Group Slovakia)
Introduction to EKS (AWS User Group Slovakia)Introduction to EKS (AWS User Group Slovakia)
Introduction to EKS (AWS User Group Slovakia)Vladimir Simek
 
Running Docker Containers on AWS
Running Docker Containers on AWSRunning Docker Containers on AWS
Running Docker Containers on AWSVladimir Simek
 
How to run your Hadoop Cluster in 10 minutes
How to run your Hadoop Cluster in 10 minutesHow to run your Hadoop Cluster in 10 minutes
How to run your Hadoop Cluster in 10 minutesVladimir Simek
 
CI&CD with AWS - AWS Prague User Group - May 2015
CI&CD with AWS - AWS Prague User Group - May 2015CI&CD with AWS - AWS Prague User Group - May 2015
CI&CD with AWS - AWS Prague User Group - May 2015Vladimir Simek
 

More from Vladimir Simek (11)

AWS Česko-Slovenský Webinár 03: Vývoj v AWS
AWS Česko-Slovenský Webinár 03: Vývoj v AWSAWS Česko-Slovenský Webinár 03: Vývoj v AWS
AWS Česko-Slovenský Webinár 03: Vývoj v AWS
 
Gaming with AWS
Gaming with AWSGaming with AWS
Gaming with AWS
 
Artificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartArtificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to Start
 
Artificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to StartArtificial Intelligence (Machine Learning) on AWS: How to Start
Artificial Intelligence (Machine Learning) on AWS: How to Start
 
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduAWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
 
AWS Webinar CZSK Uvod do cloud computingu
AWS Webinar CZSK Uvod do cloud computinguAWS Webinar CZSK Uvod do cloud computingu
AWS Webinar CZSK Uvod do cloud computingu
 
Introduction to EKS (AWS User Group Slovakia)
Introduction to EKS (AWS User Group Slovakia)Introduction to EKS (AWS User Group Slovakia)
Introduction to EKS (AWS User Group Slovakia)
 
Running Docker Containers on AWS
Running Docker Containers on AWSRunning Docker Containers on AWS
Running Docker Containers on AWS
 
Travel hackathon
Travel hackathonTravel hackathon
Travel hackathon
 
How to run your Hadoop Cluster in 10 minutes
How to run your Hadoop Cluster in 10 minutesHow to run your Hadoop Cluster in 10 minutes
How to run your Hadoop Cluster in 10 minutes
 
CI&CD with AWS - AWS Prague User Group - May 2015
CI&CD with AWS - AWS Prague User Group - May 2015CI&CD with AWS - AWS Prague User Group - May 2015
CI&CD with AWS - AWS Prague User Group - May 2015
 

Recently uploaded

What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 

Recently uploaded (20)

What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 

Cesko-Slovensky AWS Webinar 05 - Jak vybudovat hybridní cloud v AWS

  • 1. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Nazar Špak, Territory Manager, AWS Vladimír Šimek, Sr. Solutions Architect, AWS November, 2018 Jak vybudovat hybridní cloud v AWS
  • 2. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Housekeeping • Who is the audience? • Presentation – around 45 minutes • Slides in English – talk in Czech & Slovak • Questions – chat window and / or email
  • 3. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Agenda • Understand Hybrid Cloud architecture use cases • Understand AWS portfolio of capabilities to support Hybrid Cloud • Understand AWS partnerships with VMWare, Microsoft and other key enterprise players
  • 4. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid Cloud Strategy of large enterprises run VMs in the public cloud (IDC) 60% of organizations have a hybrid cloud strategy today (IDC *) 65% of workloads are virtualized today (IDC ) 83%
  • 5. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What Do Customers Want in Hybrid? Run workloads on-premises Run workloads on the cloud Tight integration Without buying new hardware $
  • 6. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Global Infrastructure https://aws.amazon.com/about-aws/global-infrastructure/
  • 7. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid Cloud Use Cases • Integrated Network • Integrated Identity and Access • Data Integration • Integrated resources and deployment management • Integrated Devices and Edge Systems • Cloud Bursting • Data center extension
  • 8. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Hybrid Cloud Solutions & Partners VPC OpsWorksIAM Storage Gateway Direct Connect S3EC2 RDSSnowball Systems Manager
  • 9. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The Foundation Integrated Network Integrated Identity and Access
  • 10. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Virtual Private Network – Extension of your data center 172.31.0.0/16 Availability Zone Availability Zone Availability Zone VPC subnet VPC subnet VPC subnet 172.31.0.0/24 172.31.1.0/24 172.31.2.0/24 eu-west-1a eu-west-1b eu-west-1c
  • 11. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Connectivity Options - Public IPs - Elastic IPs - Internet data out pricing - IPsec authentication and encryption - Two main options - AWS Managed VPN - Software VPN (EC2) - Launched in 2011 - Private connection - Separate from the Internet - Consistent network experience - Connect through 67 locations - Port speeds of 1 Gbps, 10 Gbps or sub-1 Gbps AWS Direct ConnectVPNPublic Internet
  • 12. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. IAM Identities Users and Groups IAM user  Entity created in AWS to represent a person or service that uses it to interact with AWS IAM group  Assign permissions to logical and functional grouping of your organization  Bulk permissions management (scalable)  Easy to change permissions as individuals change teams (portable) AWS cloudAWS Management Console Password [+MFA] Access key [+MFA]
  • 13. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. IAM Identities Identity Federation – Example for SAML 2.0 (Web Console) Other protocol supported: OpenID Connect
  • 14. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Options for AD-aware Cloud Workloads On-premises Windows Server DC AD You manage 1 VPC EC2 for Windows Server DC AD You manage 2 VPC Endpoint AWS Microsoft AD AWS manages 3 AWS Directory Service for Microsoft Active Directory also known as AWS Managed Microsoft AD
  • 15. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Data Integration
  • 16. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Cold Standby – Cloud Gateways Amazon EBS snapshots Amazon S3 Amazon Glacier Application server AWS Direct Connect Internet Customer premises Gateway appliances AWS Storage Gateway back-end AMI
  • 17. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hot Standby Mirroring/replication Application data source cut over Elastic load balancerActive Route 53 www.example.com Corporate data center Data volume Application server Subordinate database server Reverse proxy/ caching server AWS Region Reverse proxy/ caching server Application server Master Database server Active
  • 18. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Partnering to deliver a game-changing solution  Leading private compute, storage, and network virtualization capabilities  Support for broad range of workloads  De facto standard for the on-premises enterprise  Global scale and reach  Flexible consumption economics  Broadest set of cloud services  Elastic infrastructure on demand Uniting the leaders in private and public cloud services +
  • 19. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DR as a Service with Site Recovery Manager Disaster recovery to VMware Cloud Deliver as a service Build on VMware established disaster recovery solutions Provide application-centric DR runbook automation Remove need for dedicated DR data center Integrate deeply with the VMware Cloud on AWS services Overview of goals VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM VM vSphere (on premises) VMware Cloud on AWS
  • 20. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Integrated resources and deployment management
  • 21. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AMAZON EC2 SYSTEMS MANAGER Systems Manager Service EC2 Instance Systems Manager Agent EC2 Instance On-Prem Instance Systems Manager Agent Systems Manager Agent Manage your Amazon EC2 and on-premises instances
  • 22. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Deliver scalable, resilient applications with less work AWS OpsWorks (Chef and Puppet) Supports any application Supports existing EC2 instances Supports servers running in on-premises datacenters Single platform to deploy and manage applications across hybrid architectures
  • 23. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Microservices on AWS using Kubernetes Kubernetes is an open-source system for automating deployment, scaling, and management of containerized applications Integrated with AWS Services CloudTrail, CloudWatch, ELB, IAM, VPC, PrivateLink Highly available Automated upgrades and patches Hybrid cloud compatible
  • 24. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DevOps – Build on AWS and deploy on premise Source Build Test Production Third Party Tooling Software Release Steps: AWS CodeCommit AWS CodeBuild AWS CodeDeploy AWS CodePipeline EC2On-Prem
  • 25. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Integrated Devices and Edge Systems
  • 26. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Snowball Edge use cases Offline Staging Local Tiering and Compute IoT Local Transformation
  • 27. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Moving to the Edge Cloud Storage & Compute Intelligence Insights & Logic → Action Devices Sense & Act AWS IoT Core AWS Greengrass AWS IoT Analytics Amazon FreeRTOS AWS IoT Device Management AWS IoT Device Defender Things
  • 28. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Greengrass ML Inference Edge Cloud Machine inference Inference Training Use AWS Greengrass console to transfer models to your devices Run Machine Learning at the edge
  • 29. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Customer Success Story Connects Growers, Data & Machines manufactures agricultural, construction, and forestry machinery, diesel engines, drivetrains used in heavy equipment, and lawn care equipment. Using the AWS cloud, John Deere can help farmers take action on real- time developments on their farms, plant more efficiently, and improve the yield of their crops. • John Deere’s mission: connect people, technology, and insights to advance agriculture in a sustainable fashion. • Uses AWS to stream, analyze, store, and share data collected by 200,000 telematics-enabled machines • Provides growers with timely and accurate data for optimal growing conditions. Patrick Pinkston VP, Information Solutions, John Deere ” “ John Deere: Video Case Study: http://aws.amazon.com/solutions/case-studies/john-deere/
  • 30. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Cloud Bursting (with EC2 Spot Instances)
  • 31. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS EC2 Consumption Models
  • 32. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What Are EC2 Spot Instances? EC2 Spot Instances are spare EC2 On-Demand capacity with very simple rules
  • 33. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The Very Simple Rules of Spot Instances
  • 34. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Get the Best Value for EC2 Capacity
  • 35. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Features introduced on re:Invent 2017
  • 36. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. © 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved. Amazon EC2 Spot Instances Use Cases Big Data Containers & Test/Dev HPC & Batch Stateless Web Services FINRA saved up to 50% from its on premises solution, increased elasticity and scalability, and accelerated reprocessing requests from months to days with EC2 Spot Instances. Yelp runs millions of tests daily with EC2 Spot Instances. It improved test result response time from 2 days to 30 minutes and has also delivered a large reduction in execution costs. TLG Aerospace saw a 75% reduction in the cost per CFD simulation with Amazon EC2 Spot Instances. It passed those savings to their customers and are more competitive. AdRoll could seamlessly scale their infrastructure, better serve customers across the globe, and reduce their fixed costs by 75% and operational costs by 83% with an AWS solution, including EC2 Spot Instances.
  • 37. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Spot Integrated in Community & Partners
  • 38. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Data center extension
  • 39. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid connectivity—split architecture CORP Web App Oracle Database
  • 40. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid connectivity—split architecture (2) CORP Web/App Web/App NLB / ALB N E W !
  • 41. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS global infrastructure VMware Cloud on AWS VMware Cloud on AWS Customer data center AWS services vCentervCenter vSAN NSXvSphere Hybrid linked-mode Amazon EC2 Amazon S3 Amazon RDS AWS Direct Connect Amazon Dynamo DB Amazon Redshift Elastic Network Interface
  • 42. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Links https://aws.amazon.com/enterprise/hybrid/ https://aws.amazon.com/enterprise/ https://aws.amazon.com/professional-services/CAF/ https://aws.amazon.com/architecture/well-architected/ https://aws.amazon.com/migration-acceleration-program/
  • 43. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Děkujeme za pozornost! nazaspak@amazon.com vladsim@amazon.com