AWS Pace of Innovation » AWS Services in N. California » AWS Multi-Factor Authentication » AWS Management Console » AWS Economics Center » AWS in Education » AWS Security Center » SAS70 Type II Audit » More services in EU » Lower EC2 Pricing » Lower S3 Pricing » Lower pricing for Outbound Data Transfer » AWS Solution Provider Program » Amazon EC2 » Amazon S3 » Developer Portal & Forums » Amazon SQS » Amazon Mechanical Turk » Amazon SimpleDB » Amazon Flexible Payments Service » S3 in Europe » EC2 new instance types » AWS Start-Up Challenge » Amazon Simple Notification Service » RDS Multi-Availability Zone Support » S3 Reduced Redundancy Storage » New Locations and Features for CloudFront » S3 Bucket Policies » Cluster Instances for EC2 » Premium Support » Amazon CloudFront » EC2 Elastic IP addresses & Availability Zones » Windows Server, MySQL, Oracle, & JBoss on EC2 » Lower Data Transfer Costs » EC2 Reserved Instances » New SimpleDB Features » IBM on EC2 » Windows Server 2008 on EC2 » Amazon RDS » Amazon Virtual Private Cloud » Amazon Elastic MapReduce » EBS Shared Snapshots » Monitoring, Auto Scaling & Elastic Load Balancing for EC2 » AWS Import/Export » AWS Services in Singapore » RDS Reserved Database Instances » RDS Read Replicas & Lower Pricing » Lower Outbound Transfer Pricing » Data Transfer Usage Tiers » Consolidated Billing for AWS » Amazon S3 Versioning Feature » EC2 High Memory Instances » Micro Instances » Lower Pricing for EC2 High Mem Instances » Identity & Access Management » Amazon Linux AMI » Oracle on EC2 » New EC2 Features » SUSE Linux on EC2 » Public Data Sets » Elastic Block Store » EC2 SLA » EC2 in EU » S3 Tiered Pricing
Animoto and Amazon EC2 Number of EC2 Instances 4/12/2008 Launch of Facebook modification. Amazon EC2 easily scaled to handle additional traffic Peak of 5000 instances 4/14/2008 4/15/2008 4/16/2008 4/18/2008 4/19/2008 4/20/2008 4/17/2008 4/13/2008 Steady state of ~40 instances
The US Treasury needed to develop a new Treasury.gov website that could provide over 100 organizations within the Department the ability to manage and update their content. At the same time, they needed to roll out new Web 2.0 features to better engage with their constituents.
Treasury chose a cloud computing solution based on Amazon Web Services to support over 11 new websites from Treasury
Microsoft Sharepoint for web Content Management
Integration with Social Networking tools
Avoided Capital expense, and added capacity to scale up and down based on demand
Time to deployment
“ Treasury's decision to move its flagship site to a public cloud infrastructure reflects the Administration's commitment to closing the IT gap between the public and private sectors by leveraging the power of technology. Use of cloud computing increases cost effectiveness, improves efficiency and provides greater flexibility, as the private industry sector has proven. This is exactly the kind of game-changing technology required to do more with less." - Vivek Kundra, CIO, United States
USDA Food Nutrition Service was looking to build a service to help constituents locate nearest stores that would accept Supplemental Nutrition Assistance Program vouchers. Aggressive implementation schedule.
USDA FNS worked with ESRI to deploy a geo-location service, hosted on AWS.
Avoided the need to procure servers
Fast time to market/time to implementation
“ It’s a pretty complicated GIS solution and there’s lots of data involved. Instead of building the infrastructure to run this, we’re running it in the Amazon cloud. We were able to put it up there very quickly. We didn’t have to procure the servers. We were just buying a service from Amazon and it seems to be working very well. I think it’s a good model that we might follow again or other agencies can follow to host a fairly complex solution in a pretty short order.” - Jonathan Alboum, CIO, Food Nutrition Service (Federal News Radio Interview, July 28, 2010)
Because of the latency of data transmission from and to Mars, during a 2 hour window, it took mission planners 90 minutes to process telemetry data from the Mars Rover, 20 mins to decide where to move the Rover to, and 10 mins to up load the data.
NASA-JPL, loading their custom software application on EC2, was able to horizontally scale the number of virtual machines supporting the data processing.
Reduced data processing time from 90 minutes to 15 minutes using parallel processing
Increased mission planning time, resulting in high quality scientific observations
ST&E and Moderate Controls available now for incorporation into SSP
Actively pursuing FedRAMP
Includes DIACAP Mac II Sensitive
ISO 27001 Certification
Customers have deployed various compliant applications such as HIPAA (healthcare)
Amazon EC2 Instance Isolation Physical Interfaces Customer 1 Hypervisor Customer 2 Customer n … … Virtual Interfaces Firewall Customer 1 Security Groups Customer 2 Security Groups Customer n Security Groups
Multi-tier Security Architecture Web Tier Application Tier Database Tier EBS Volume Ports 80 and 443 only open to the Internet Engineering staff have ssh access to the App Tier, which acts as Bastion All other Internet ports blocked by default Authorized 3 rd parties can be granted ssh access to select AWS resources, such as the Database Tier Amazon EC2 Security Group Firewall AWS employs a private network with ssh support for secure access between tiers and is configurable to limit access between tiers
Amazon VPC Architecture Customer’s Network Amazon Web Services Cloud Secure VPN Connection over the Internet Subnets Customer’s isolated AWS resources Router VPN Gateway
Amazon EC2 Regions and Availability Zones Amazon EC2 Regions: US East (Northern Virginia) / US West (Northern California) / EU (Dublin) / Asia Pacific (Singapore) US West (Northern California) Availability Zone A Availability Zone B US East (Northern Virginia) Availability Zone A Availability Zone B Availability Zone C Availability Zone D
All traffic should be cryptographically controlled
Inbound and outbound traffic to corporate networks should be wrapped within industry standard VPN tunnels (option to use Amazon VPC)
Corporate Network Internet Traffic VPN
Designing Applications for Reliability Region Availability Zone Availability Zone Amazon CloudWatch Provides monitoring for AWS cloud resources. Elastic Load Balancing Automatically distributes incoming application traffic across multiple Amazon EC2 instances. Auto Scaling Automatically scales Amazon EC2 capacity up or down according to pre-defined conditions.