Highly Available Web Properties in Aws
Upcoming SlideShare
Loading in...5
×
 

Highly Available Web Properties in Aws

on

  • 4,668 views

 

Statistics

Views

Total Views
4,668
Views on SlideShare
4,469
Embed Views
199

Actions

Likes
11
Downloads
175
Comments
0

6 Embeds 199

http://www.newvem.com 169
http://www.scoop.it 22
http://www.linkedin.com 4
https://www.linkedin.com 2
https://twitter.com 1
http://info.zooppa.com 1

Accessibility

Upload Details

Uploaded via as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment
  • Elasticity is a fundamental property of the CloudThe difference between a classic architecture and a cloud architecture often resides in elasticity implementation
  • Ideally, you would need a cursor to dynamically adjust to the desired capacity level.It's exactly what EBK do … automatically.
  • Pour illustrer le launch early
  • 00:47:00
  • Is it open sourced yet ?
  • AUDITABILITY = No central location to track the status of a task
  • Montrerqu’apartir du moment oudoit faire des decisions, ilfaut considerer l’option SWFBubbles are steps, or activities. [workers]Arrows are control decisions, or coordination logic. [decider]
  • Activities, or steps
  • control decisions, or coordination logic
  • Writing a decider requires you to review the state of the workflow. The decider itself is stateless but SWF keeps the state and tells the decider about what has happened.[Point out that a decider can return several decisions in the same call. This allows for parallel processing.]To write workers and deciders you can use the SWF SDK (provided for Java, .NET, PHP) or call the API directly, but to make this easier [CUE NEXT SLIDE]
  • Compare this to what was required to write an SQS queue worker: Now the worker might have to send heartbeats; it also needs to take care of informing SWF if the work has been successful or not. This is required for SWF to keep track.
  • Create distinct Security Groups for each Amazon EC2 clusterUse group-based rules for controlling access between layersRestrict external access to specific IP rangesEncrypt data “at-rest”, encrypt data “in-transit” (SSL)Use Identity and Access Management (IAM)Rotate your AWS CredentialsUse Multi-Factor AuthenticationUse Amazon Virtual Private Cloud (VPC)
  • Filter by IP range, port range, security group, role
  • PCI DSS Level 1AWS satisfies the requirements under PCI DSS for shared hosting providers. AWS also has been successfully validated against standards applicable to a Level 1 service provider under PCI DSS Version 2.0. Merchants and other PCI service providers can use the AWS PCI-compliant technology infrastructure for storing, processing, and transmitting credit card information in the cloud, as long as those customers create PCI compliance for their part of the shared environment. Amazon Elastic Compute Cloud (EC2), Amazon Simple Storage Service (S3), Amazon Elastic Block Storage (EBS) and Amazon Virtual Private Cloud (VPC) were included as part of this validation. Under the same circumstances, other enterprises can also benefit by running their applications on other PCI-compliant technology infrastructure. AWS provides additional information and frequently asked questions about its PCI compliance on its web site.
  • cloud-hosted search service from AWSfully managed search service on the cloudscales automaticallyeliminates complex managementsupport structured or unstructured text documents. Why ?huge explosion on amount of data created everyday. structured or not. 
  • Amazon CloudSearch builds an index and picks the appropriate initial search instance type to ensure that your index can be stored in RAM. As your data volume grows, Amazon CloudSearch will scale your search domain to a larger search instance type (or partition your index across multiple instances if you are already on the largest search instance type).As with data volume, Amazon CloudSearch automatically scales your search domain to meet your traffic demands. When a search instance reaches over 80% CPU utilization, CloudSearch scales up your search domain by adding a search instance to handle the increased traffic. Conversely, when a search instance reaches below 30% CPU utilization, CloudSearch scales down your search domain by removing the additional search instances in order to minimize costs.
  • Pour illustrer le launch early

Highly Available Web Properties in Aws Highly Available Web Properties in Aws Presentation Transcript

  • Building HighlyAvailable, Scalable Web Properties with AWS Joe Ziegler │Technical Evangelist @jiyosub
  • 1. ELASTICITY2. DESIGN FOR FAILURE3. LOOSE COUPLING4. SECURITY5. PERFORMANCE
  • # 1ELASTICITY ●○○○○
  • AMAZON EC2ELASTIC COMPUTE CLOUD
  • AMAZON CLOUDWATCHMONITORING FOR AWS RESOURCES
  • AUTO SCALINGSCALE UP/DOWN EC2 CAPACITY
  • ELASTIC LOAD BALANCINGNETWORK TRAFFIC DISTRIBUTION
  • 6 am
  • 10 am
  • 10 am
  • 10 am
  • 7 pm
  • 7 pm
  • 7 pm
  • without elasticity you cant accelerate
  • what you really need is… …adjustable capacity
  • # 2DESIGN FOR FAILURE ●●○○○
  • « Everything fails all the time » Werner Vogels CTO of Amazon
  • YOUR GOALApplications should continue to function even if the underlying physical hardware fails or is removed or replaced
  • Avoid single points of failure.Assume everything fails, and designbackwards.
  • Avoid single points of failure.Assume everything fails, and designbackwards.
  • AMAZON RDSRELATIONAL DATABASE SERVICE
  • AMAZONROUTE 53DOMAIN NAME SERVICE
  • AMAZON RDSMULTI-AZDEPLOYMENT
  • AMAZON CLOUDWATCH ALARMS
  • AWS BUILDING BLOCKSInherently Fault-Tolerant Services Fault-Tolerant with the right architecture Amazon S3  Elastic Load Balancing  Amazon EC2 Amazon SimpleDB  AWS IAM  Amazon EBS Amazon DynamoDB  AWS Elastic  Amazon RDS Amazon CloudFront Beanstalk Amazon SWF  Amazon VPC  Amazon Amazon SQS ElastiCache Amazon SNS  Amazon EMR Amazon SES  Amazon CloudSearch Amazon Route53
  • NETFLIXCHAOS MONKEY
  • # 3 LOOSECOUPLING ●●●○○
  • BUILD LOOSELYCOUPLED SYSTEMS The looser the are coupled, the bigger they scale
  • Create independent components
  • Create independent componentsDesign everything as a Black Box
  • Create independent componentsDesign everything as a Black BoxThink in terms of services
  • TRANSCODERECEIVE & PUBLISH
  • TRANSCODERECEIVE & PUBLISH QUEUE
  • AMAZON SQSSIMPLE QUEUE SERVICE
  • START CHECK REJECT STOP VIDEO YES NO TOO SPAM PUBLISH SPAM? LONG? CHECK & NOTIFYYES NO SHORTEN TRANSCODE VIDEO
  • MAINTENANCEAUDITABILITYFLEXIBILITYLOW-LEVEL
  • WHAT ARE WETRYING TO DO?
  • START CHECK REJECT STOP VIDEO YES NO TOO SPAM PUBLISH SPAM? LONG? CHECK & NOTIFYYES NO SHORTEN TRANSCODE VIDEO
  • START CHECK REJECT STOP VIDEO YES NO TOO SPAM PUBLISH SPAM? LONG? CHECK & NOTIFYYES NO SHORTEN TRANSCODE VIDEO
  • START CHECK REJECT STOP VIDEO YES NO TOO SPAM PUBLISH SPAM? LONG? CHECK & NOTIFYYES NO SHORTEN TRANSCODE VIDEO
  • TASKSDECISIONS STATELESS ! HISTORY
  • STATELESS SCALES HORIZONTALLY
  • AMAZON SWF WORKFLOW SERVICE FORSCALABLE, RESILIENT APPLICATIONS
  • AMAZON SWF Keeps track of :  State  Executed tasks  Timeouts  Errors
  • WORKFLOWACTORS
  • DECIDERS COORDINATION LOGIC1. Poll for work on a decision list Long polling: 60 seconds2. Evaluate workflow execution history SWF sends full history in JSON format3. Return decision to Amazon SWF Usually scheduling another task
  • WORKERS COORDINATION LOGIC1. Poll for work on a specific task list Long polling: 60 seconds2. Execute works, send heartbeats SWF sends input data from deciders3. Return success / failure Detailed data can be provided to deciders
  • ALLHORIZONTAL SCALING PATTERNS APPLY
  • NO NEW LANGUAGE TO LEARNYOUR CODE IS YOUR WORKFLOW LANGUAGE SWF MAINTAINS STATE
  • AWS FLOW FRAMEWORKJava Library • Entire workflow can be expressed in sequential code • Integrated with Java Utils API
  • CHAINED TASKS WITHOUT DECISIONS?RECEIVE TRANSCODE NOTIFY use AMAZON SQS
  • TASK GRAPH WITH DECISIONS? GOOD OKRECEIVE CHECK SPAM TRANSCODE VIDEO LENGTH CHECK LONG SPAM SHORTEN PUBLISH REJECT VIDEO & NOTIFY use AMAZON SWF
  • # 4SECURITY ●●●●○
  • AWS IAMIDENTITY AND ACCESS MANAGEMENT
  • MULTI-MULTI-FACTORAUTHENTICATION
  • SECURITY GROUPS LAYERED SECURITY
  • CERTIFICATIONS& COMPLIANCE SAS 70 Type II audit ISO 27001 Certification Sarbanes-Oxley SOX HIPAA healthcare FISMA US Federal Government DIACAP MAC III Sensitive IATO
  •  PCI DSS Compliant LEVEL 1 SERVICE PROVIDER
  • # 5PERFORMANCE ●●●●●
  • VERTICALSCALING
  • CLUSTER COMPUTEEIGHT EXTRA LARGE 2x Intel Xeon E5-2670, eight-core Sandy Bridge architecture 60.5 GB of memory – 3.3 TB of storage
  • CLUSTER GPUQUADRUPLE EXTRA LARGE Intel Xeon X5570, quad-core 2x Nehalem architecture NVIDIA Tesla Fermi 2x M2050 GPUs 22 GB of memory – 1.7 TB of storage
  • AMAZONELASTICACHEMEMCACHED COMPATIBLE IN-MEMORY CACHE
  • SEARCHENGINES
  • Relevance & Ranking
  • Faceting
  • RangeSearching
  • AMAZONCLOUDSEARCHFULLY-MANAGED SEARCH SERVICE
  • +
  • DEMOCRATIZE SEARCH Amazon CloudSearch delivers a fully-managed search service in the cloudthat can be set up and running in less than 1 hour, with automatic scaling for data & traffic, at a price starting at less than $100 per month.
  • MEDIA SHARINGREFERENCE ARCHITECTURE
  • 1. ELASTICITY2. DESIGN FOR FAILURE3. LOOSE COUPLING4. SECURITY5. PERFORMANCE
  • « If youre not embarrassed when you ship your first version you waited too long » Matt Mullenweg CEO & Founder of WordPress
  • aws-apac-marketing@amazon.com
  • AWS ANZ Customer Appreciation DayIs Coming to Sydney November 13 th #AWSCADAU