SlideShare a Scribd company logo
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Design with Ops in mind
Nir Gomer
Director, R&D Group Manager
SundaySky
S K L 3 0 9
Shelly Dar
Sr. Technical Account Manager
Amazon Web Services
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent Detect Respond Learn
Agenda
Prevent repetition
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent
• Operational readiness
• Is everything ready?
• Situational awareness
• What are all the things?
• Anticipate failure
• What can go wrong?
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Operational readiness
https://aws.amazon.com/quickstart/architecture/compliance-cis-benchmark/
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Trusted Advisor
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Trusted Advisor
• 7 core Trusted Advisor checks - Available to all AWS
customers
• Business or Enterprise support plans:
• Access to the full set of Trusted Advisor checks
• Programmatic access
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Trusted Advisor tools
https://github.com/aws/Trusted-Advisor-Tools
AWS Step
Functions
Amazon
CloudWatch
Events
AWS Trusted
Advisor
AWS Lambda
AWS Lambda
AWS Lambda
AWS IAM
AWS CloudTrail
AWS SNS
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Config
• Aggregated view
• Across accounts
• Resources inventory
• Snapshots are saved on S3
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Config
https://aws.amazon.com/blogs/mt/aws-config-best-practices/
https://github.com/awslabs/aws-config-to-elasticsearch
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Tagging
General
• Name
• Owner
• Environment
• Product Project
• Business unit
Department
• Customer
Operational
• Build Release
Version
• Backup
• VPC
• OS version
Cost
• Cost center
budget
• RI Subscription id
• Auto start running
hours
• Expiration date
• License
• RI expiration
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Tag Editor
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Systems Manager
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent Detect Respond Learn
Agenda
Prevent repetition
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Detect
• Monitoring
• What is everything doing?
• Controls (security & governance)
• How do we protect our business?
• Raise alerts
• How do we know to act so we can reduce risk to the business?
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Monitoring
System
NOC
Support
Account
exec
Security
Budget
owner
Customer
vendors
Product
manager
DevOps
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Monitoring
Please don’t forget
VPC
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Log aggregation
Amazon Kinesis
Firehose
Amazon
CloudWatch Logs
Logstash
AWS IoT
Elasticsearch
data nodes
Kibana
Data Producers Buffer Transform Deliver
Amazon Elasticsearch Service
(includes managed Kibana)
Elasticsearch
master nodes
https://amzn.to/2NLKLcn
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Personal Health Dashboard
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GuardDuty
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GuardDuty- github samples
GuardDuty Amazon
CloudWatch Events
Lambda AWS WAF AWS WAF
Filtering rule
Amazon VPC Network
access
control list
Amazon
DynamoDB
Amazon Simple
Notification Service
https://github.com/aws-samples/amazon-guardduty-hands-on
https://github.com/aws-samples/amazon-guardduty-waf-acl
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent Detect Respond Learn
Agenda
Prevent repetition
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Respond
• Identify trends
• How do you know an event is coming before it leads to an incident?
• Respond with consistency
• Is there a documented process for responding to the event? (runbook/playbook)
• Automate proactive responses
• Can a scripted response be triggered automatically?
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Respond
• Identify trends
• Amazon GuardDuty, Amazon CloudWatch Logs Insights & Dashboards
• Respond with consistency
• AWS Systems Manager, AWS OpsWorks, AWS Config rules
• Automate responses
• AWS Auto Scaling, AWS Lambda
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent Detect Respond Learn
Prevent repetition
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Nir Gomer
Director, R&D Group Manager
SundaySky
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What is SundaySky
SundaySky delivers a powerful video marketing platform that enables personalized
storytelling across the consumer lifecycle
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
SundaySky Rendering Architecture
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Design for success, Architect for disaster
Tag checker
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Designing the service with Ops in mind
• Stop being reactive – think about security, cost, manageability, support and
availability from the design phase
• Monitoring is a great, but avoid over-monitoring
• Automation is the goal but you can start with manual switches (automate
the way things are done, leave the decision of what to do to a human at
first, and automate it later)
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Operational Tools used in SundaySky
CloudWatch PagerDuty
Cost Anomaly
Detector
Alarms
CloudTrail
Trusted
Advisor
Well-
Architected
GuardDuty Macie
Auto Scaling
Experiments
Tag
checker
GuardDuty
Cost Explorer
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Takeaways
• The benefits are huge! R&D velocity; cost; SLAs; Security levels; Operations FTEs
and more
• If this seems a lot, you’re right… it is…
• But… Rome was not built in a day…
• There is no ‘one playbook to rule them all’
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Prevent Detect Respond Learn
Prevent repetition
Thank you!
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Shelly Dar
shelldar@amazon.com
https://www.linkedin.com/in/shellydar
Nir Gomer
Director, R&D Group Manager
SundaySky
http://bit.ly/2SEvcEb

More Related Content

What's hot

Orchestrating containers on AWS | AWS Summit Tel Aviv 2019
Orchestrating containers on AWS  | AWS Summit Tel Aviv 2019Orchestrating containers on AWS  | AWS Summit Tel Aviv 2019
Orchestrating containers on AWS | AWS Summit Tel Aviv 2019
AWS Summits
 
利用 Fargate - 無伺服器的容器環境建置高可用的系統
利用 Fargate - 無伺服器的容器環境建置高可用的系統利用 Fargate - 無伺服器的容器環境建置高可用的系統
利用 Fargate - 無伺服器的容器環境建置高可用的系統
Amazon Web Services
 
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
AWS Summits
 
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS SummitOptimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
Amazon Web Services
 
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
Amazon Web Services
 
CI/CD for Modern Applications
CI/CD for Modern ApplicationsCI/CD for Modern Applications
CI/CD for Modern Applications
Amazon Web Services
 
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
Amazon Web Services
 
Optimize your Machine Learning workloads | AWS Summit Tel Aviv 2019
Optimize your Machine Learning workloads  | AWS Summit Tel Aviv 2019Optimize your Machine Learning workloads  | AWS Summit Tel Aviv 2019
Optimize your Machine Learning workloads | AWS Summit Tel Aviv 2019
AWS Summits
 
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
Amazon Web Services
 
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
AWS Summits
 
AWSome Day Brasil - Março 2020
AWSome Day Brasil - Março 2020AWSome Day Brasil - Março 2020
AWSome Day Brasil - Março 2020
Amazon Web Services LATAM
 
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Amazon Web Services
 
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
Amazon Web Services
 
從業人員指南-如何像技術專家一樣守護您的雲端安全
從業人員指南-如何像技術專家一樣守護您的雲端安全從業人員指南-如何像技術專家一樣守護您的雲端安全
從業人員指南-如何像技術專家一樣守護您的雲端安全
Amazon Web Services
 
Breaking down monoliths - DEM08-S - New York AWS Summit
Breaking down monoliths - DEM08-S - New York AWS SummitBreaking down monoliths - DEM08-S - New York AWS Summit
Breaking down monoliths - DEM08-S - New York AWS Summit
Amazon Web Services
 
AWS 如何協助客戶建立 DevOps 流程
AWS 如何協助客戶建立 DevOps 流程AWS 如何協助客戶建立 DevOps 流程
AWS 如何協助客戶建立 DevOps 流程
Amazon Web Services
 
Design with ops in mind | AWS Summit Tel Aviv 2019
Design with ops in mind | AWS Summit Tel Aviv 2019Design with ops in mind | AWS Summit Tel Aviv 2019
Design with ops in mind | AWS Summit Tel Aviv 2019
Amazon Web Services
 
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
Amazon Web Services
 
CI/CD best practices for building modern applications - MAD310 - New York AWS...
CI/CD best practices for building modern applications - MAD310 - New York AWS...CI/CD best practices for building modern applications - MAD310 - New York AWS...
CI/CD best practices for building modern applications - MAD310 - New York AWS...
Amazon Web Services
 

What's hot (19)

Orchestrating containers on AWS | AWS Summit Tel Aviv 2019
Orchestrating containers on AWS  | AWS Summit Tel Aviv 2019Orchestrating containers on AWS  | AWS Summit Tel Aviv 2019
Orchestrating containers on AWS | AWS Summit Tel Aviv 2019
 
利用 Fargate - 無伺服器的容器環境建置高可用的系統
利用 Fargate - 無伺服器的容器環境建置高可用的系統利用 Fargate - 無伺服器的容器環境建置高可用的系統
利用 Fargate - 無伺服器的容器環境建置高可用的系統
 
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
Solutions for Storage and Data Migrations | AWS Summit Tel Aviv 2019
 
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS SummitOptimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
Optimize data lakes with Amazon S3 - STG302 - Santa Clara AWS Summit
 
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
Budget management with Cloud Economics | AWS Summit Tel Aviv 2019
 
CI/CD for Modern Applications
CI/CD for Modern ApplicationsCI/CD for Modern Applications
CI/CD for Modern Applications
 
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
Architecting Digital Media Archive Migrations with AWS - STG301 - Anaheim AWS...
 
Optimize your Machine Learning workloads | AWS Summit Tel Aviv 2019
Optimize your Machine Learning workloads  | AWS Summit Tel Aviv 2019Optimize your Machine Learning workloads  | AWS Summit Tel Aviv 2019
Optimize your Machine Learning workloads | AWS Summit Tel Aviv 2019
 
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
Architecting Security & Governance across Your AWS Landing Zone - SEC301 - An...
 
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
AWS Core - Compute, Network, Storage and Security | AWS Summit Tel Aviv 2019
 
AWSome Day Brasil - Março 2020
AWSome Day Brasil - Março 2020AWSome Day Brasil - Março 2020
AWSome Day Brasil - Março 2020
 
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
Introduction to the Well-Architected Framework and Tool - SVC208 - Anaheim AW...
 
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
Making CI/CD pipelines safer with application monitoring and tracing - MAD202...
 
從業人員指南-如何像技術專家一樣守護您的雲端安全
從業人員指南-如何像技術專家一樣守護您的雲端安全從業人員指南-如何像技術專家一樣守護您的雲端安全
從業人員指南-如何像技術專家一樣守護您的雲端安全
 
Breaking down monoliths - DEM08-S - New York AWS Summit
Breaking down monoliths - DEM08-S - New York AWS SummitBreaking down monoliths - DEM08-S - New York AWS Summit
Breaking down monoliths - DEM08-S - New York AWS Summit
 
AWS 如何協助客戶建立 DevOps 流程
AWS 如何協助客戶建立 DevOps 流程AWS 如何協助客戶建立 DevOps 流程
AWS 如何協助客戶建立 DevOps 流程
 
Design with ops in mind | AWS Summit Tel Aviv 2019
Design with ops in mind | AWS Summit Tel Aviv 2019Design with ops in mind | AWS Summit Tel Aviv 2019
Design with ops in mind | AWS Summit Tel Aviv 2019
 
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
The evolution of continuous cloud security and compliance - DEM05-S - New Yor...
 
CI/CD best practices for building modern applications - MAD310 - New York AWS...
CI/CD best practices for building modern applications - MAD310 - New York AWS...CI/CD best practices for building modern applications - MAD310 - New York AWS...
CI/CD best practices for building modern applications - MAD310 - New York AWS...
 

More from AWS Summits

AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
AWS Summits
 
AWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
AWS Summit Singapore 2019 | Bridging Start-ups and EnterprisesAWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
AWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
AWS Summits
 
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and TricksAWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summits
 
AWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
AWS Summit Singapore 2019 | Five Common Technical Challenges for StartupsAWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
AWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
AWS Summits
 
AWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to ExitAWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summits
 
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics ServicesAWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summits
 
AWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
AWS Summit Singapore 2019 | Snowflake: Your Data. No LimitsAWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
AWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
AWS Summits
 
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement SolutionsAWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summits
 
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWSAWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summits
 
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
AWS Summits
 
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWSAWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summits
 
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summits
 
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
AWS Summits
 
AWS Summit Singapore 2019 | Operating Microservices at Hyperscale
AWS Summit Singapore 2019 | Operating Microservices at HyperscaleAWS Summit Singapore 2019 | Operating Microservices at Hyperscale
AWS Summit Singapore 2019 | Operating Microservices at Hyperscale
AWS Summits
 
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes WorkloadsAWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
AWS Summits
 
AWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business ValueAWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business Value
AWS Summits
 
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summits
 
AWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
AWS Summit Singapore 2019 | Transformation Towards a Digital Native EnterpriseAWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
AWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
AWS Summits
 
AWS Summit Singapore 2019 | Pragmatic Container Security
AWS Summit Singapore 2019 | Pragmatic Container SecurityAWS Summit Singapore 2019 | Pragmatic Container Security
AWS Summit Singapore 2019 | Pragmatic Container Security
AWS Summits
 
AWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
AWS Summit Singapore 2019 | Enterprise Migration Journey RoadmapAWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
AWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
AWS Summits
 

More from AWS Summits (20)

AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
AWS Summit Singapore 2019 | The Smart Way to Build an AI & ML Strategy for Yo...
 
AWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
AWS Summit Singapore 2019 | Bridging Start-ups and EnterprisesAWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
AWS Summit Singapore 2019 | Bridging Start-ups and Enterprises
 
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and TricksAWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
 
AWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
AWS Summit Singapore 2019 | Five Common Technical Challenges for StartupsAWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
AWS Summit Singapore 2019 | Five Common Technical Challenges for Startups
 
AWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to ExitAWS Summit Singapore 2019 | A Founder's Journey to Exit
AWS Summit Singapore 2019 | A Founder's Journey to Exit
 
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics ServicesAWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
 
AWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
AWS Summit Singapore 2019 | Snowflake: Your Data. No LimitsAWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
AWS Summit Singapore 2019 | Snowflake: Your Data. No Limits
 
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement SolutionsAWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
 
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWSAWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
 
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
AWS Summit Singapore 2019 | Big Data Analytics Architectural Patterns and Bes...
 
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWSAWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
 
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
 
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
AWS Summit Singapore 2019 | Accelerating Enterprise Cloud Transformation by M...
 
AWS Summit Singapore 2019 | Operating Microservices at Hyperscale
AWS Summit Singapore 2019 | Operating Microservices at HyperscaleAWS Summit Singapore 2019 | Operating Microservices at Hyperscale
AWS Summit Singapore 2019 | Operating Microservices at Hyperscale
 
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes WorkloadsAWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
AWS Summit Singapore 2019 | Autoscaling Your Kubernetes Workloads
 
AWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business ValueAWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business Value
 
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
 
AWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
AWS Summit Singapore 2019 | Transformation Towards a Digital Native EnterpriseAWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
AWS Summit Singapore 2019 | Transformation Towards a Digital Native Enterprise
 
AWS Summit Singapore 2019 | Pragmatic Container Security
AWS Summit Singapore 2019 | Pragmatic Container SecurityAWS Summit Singapore 2019 | Pragmatic Container Security
AWS Summit Singapore 2019 | Pragmatic Container Security
 
AWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
AWS Summit Singapore 2019 | Enterprise Migration Journey RoadmapAWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
AWS Summit Singapore 2019 | Enterprise Migration Journey Roadmap
 

Design with ops in mind | AWS Summit Tel Aviv 2019

  • 1.
  • 2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Design with Ops in mind Nir Gomer Director, R&D Group Manager SundaySky S K L 3 0 9 Shelly Dar Sr. Technical Account Manager Amazon Web Services
  • 3. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent Detect Respond Learn Agenda Prevent repetition
  • 4. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent • Operational readiness • Is everything ready? • Situational awareness • What are all the things? • Anticipate failure • What can go wrong?
  • 5. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 6. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational readiness https://aws.amazon.com/quickstart/architecture/compliance-cis-benchmark/
  • 7. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Trusted Advisor
  • 8. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Trusted Advisor • 7 core Trusted Advisor checks - Available to all AWS customers • Business or Enterprise support plans: • Access to the full set of Trusted Advisor checks • Programmatic access
  • 9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Trusted Advisor tools https://github.com/aws/Trusted-Advisor-Tools AWS Step Functions Amazon CloudWatch Events AWS Trusted Advisor AWS Lambda AWS Lambda AWS Lambda AWS IAM AWS CloudTrail AWS SNS
  • 10. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 11. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Config • Aggregated view • Across accounts • Resources inventory • Snapshots are saved on S3
  • 12. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Config https://aws.amazon.com/blogs/mt/aws-config-best-practices/ https://github.com/awslabs/aws-config-to-elasticsearch
  • 13. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Tagging General • Name • Owner • Environment • Product Project • Business unit Department • Customer Operational • Build Release Version • Backup • VPC • OS version Cost • Cost center budget • RI Subscription id • Auto start running hours • Expiration date • License • RI expiration
  • 14. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Tag Editor
  • 15. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 16. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Systems Manager
  • 17. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent Detect Respond Learn Agenda Prevent repetition
  • 18. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Detect • Monitoring • What is everything doing? • Controls (security & governance) • How do we protect our business? • Raise alerts • How do we know to act so we can reduce risk to the business?
  • 19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Monitoring System NOC Support Account exec Security Budget owner Customer vendors Product manager DevOps
  • 20. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Monitoring Please don’t forget VPC
  • 21. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Log aggregation Amazon Kinesis Firehose Amazon CloudWatch Logs Logstash AWS IoT Elasticsearch data nodes Kibana Data Producers Buffer Transform Deliver Amazon Elasticsearch Service (includes managed Kibana) Elasticsearch master nodes https://amzn.to/2NLKLcn
  • 22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Personal Health Dashboard
  • 23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty
  • 24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty- github samples GuardDuty Amazon CloudWatch Events Lambda AWS WAF AWS WAF Filtering rule Amazon VPC Network access control list Amazon DynamoDB Amazon Simple Notification Service https://github.com/aws-samples/amazon-guardduty-hands-on https://github.com/aws-samples/amazon-guardduty-waf-acl
  • 25. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent Detect Respond Learn Agenda Prevent repetition
  • 26. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Respond • Identify trends • How do you know an event is coming before it leads to an incident? • Respond with consistency • Is there a documented process for responding to the event? (runbook/playbook) • Automate proactive responses • Can a scripted response be triggered automatically?
  • 27. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Respond • Identify trends • Amazon GuardDuty, Amazon CloudWatch Logs Insights & Dashboards • Respond with consistency • AWS Systems Manager, AWS OpsWorks, AWS Config rules • Automate responses • AWS Auto Scaling, AWS Lambda
  • 28. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent Detect Respond Learn Prevent repetition
  • 29. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nir Gomer Director, R&D Group Manager SundaySky
  • 30. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. What is SundaySky SundaySky delivers a powerful video marketing platform that enables personalized storytelling across the consumer lifecycle
  • 31. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. SundaySky Rendering Architecture
  • 32. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Design for success, Architect for disaster Tag checker
  • 33. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Designing the service with Ops in mind • Stop being reactive – think about security, cost, manageability, support and availability from the design phase • Monitoring is a great, but avoid over-monitoring • Automation is the goal but you can start with manual switches (automate the way things are done, leave the decision of what to do to a human at first, and automate it later)
  • 34. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operational Tools used in SundaySky CloudWatch PagerDuty Cost Anomaly Detector Alarms CloudTrail Trusted Advisor Well- Architected GuardDuty Macie Auto Scaling Experiments Tag checker GuardDuty Cost Explorer
  • 35. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Takeaways • The benefits are huge! R&D velocity; cost; SLAs; Security levels; Operations FTEs and more • If this seems a lot, you’re right… it is… • But… Rome was not built in a day… • There is no ‘one playbook to rule them all’
  • 36. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 37. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Prevent Detect Respond Learn Prevent repetition
  • 38. Thank you! © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Shelly Dar shelldar@amazon.com https://www.linkedin.com/in/shellydar Nir Gomer Director, R&D Group Manager SundaySky http://bit.ly/2SEvcEb