SlideShare a Scribd company logo
1 of 44
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
NET204
AWS PrivateLink: Bringing SaaS Solutions into
Your VPCs and Your On-Premises Networks
N o v e m b e r 3 0 , 2 0 1 7
AWS re:INVENT
T i m L i , S e n i o r P r o d u c t M a n a g e r , A W S
S c o t t C l a r k , C E O , S i g o p t
R a n N a h m i a s , S e n i o r D i r e c t o r , A q u a S e c u r i t y
E r i c B r o w n , D e v O p s L e a d e r , A p p D y n a m i c s
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What to Expect
Introduction to AWS PrivateLink
Partner Use Cases
§ SigOpt
§ Aqua Security
§ AppDynamics
Final Thoughts
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Introduction to AWS PrivateLink
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Networking on the Cloud
Amazon EC2
APIs
Elastic Load
Balancing APIs
Amazon
Kinesis
10.1.0.0/16
10.2.0.0/16 10.3.0.0/16
10.4.0.0/16
VPC Peering
Connection
Connection using
public IP address
AWS Direct
Connect
SaaS
corporate data center
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink brings services into your VPC and your
on-premises networks
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The World with AWS PrivateLink
virtual private cloud
Application 1
corporate data center
AWS Direct
Connect
Application 2
Amazon
Kinesis
Streams
Elastic Load
Balancing API
AWS
Service Catalog
Amazon
EC2 API
Amazon EC2
Systems Manager
Your Own
Service in
Another VPC
Sample Partner
SaaS Solutions
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink—Service Provider
Proxy
Protocol V2
(Optional)
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink—Service User
virtual private cloud
Application 1
AWS Direct
Connect
Application 2
Endpoints to AWS
services
Endpoints to your own
services
Endpoints to AWS
partner services
Interface endpoints
DNS name on the endpoints
• Publicly resolvable regional and zonal DNS
name that maps to the local IP of the
endpoints
• NLB health check aware
Accessible over AWS Direct Connect
Security group integration
Local IP, no route table entry
Can span multiple Availability Zones
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink—End-to-End
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Marketplace Integration
Discoverability of the services when
customers purchase SaaS on AWS
Marketplace
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Enhancement for Marketplace Services:
Vanity DNS Names
vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com
Service Base DNS Name
Service ID Region Sub Domain
vpce-12345.vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com
Endpoints DNS Name on Client Side
VPC Endpoint ID
vpce-67890.vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Enhancement for Marketplace Services:
Vanity DNS Names
us-east-1.vpce.myexample.com
Service Vanity DNS Name
Region Sub Domain
vpce-12345.us-east-1.vpce.myexample.com
Endpoints DNS Name on Client Side
VPC Endpoint ID
vpce-67890.us-east-1.vpce.myexample.com
Easier Recognition of
Service Endpoints
Straight-forward TLS
Termination
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Enhancement for Marketplace Services:
Service Discoverability
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Enhancement for Marketplace Services:
Service Discoverability
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
SigOpt
Scott Clark, Co-founder and CEO
Using AWS PrivateLink to securely optimize
AI pipelines
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
SigOpt optimizes…
- Machine learning
- AI/Deep Learning
- Reinforcement learning
Resulting in…
- Better results
- Cheaper, faster tuning
- Faster development
Optimization-as-a-Service
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Deep Learning/AI is Expensive to Tune
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Black Box Optimizer Bolts on Top of Pipeline
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS-Based Optimization Framework
Web EC2
Instance
sigopt.com ELB
Customer Web EC2
Instance
api.sigopt.com
ELB
API EC2
Instance
API EC2
Instance
…
…
SQS Queue
RDS DB
Optimizer EC2
Instance
Optimizer EC2
Instance
…
CloudFront
CDN
Services
Service ELB Service EC2 Instance
…
Service EC2 Instance
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS-to-AWS Optimization Pre-PrivateLink
Training
EC2 Instance(s)
Data
S3 Buckets
Evaluation
EC2 Instance
Training
EC2 Instance
Data
S3 Buckets
Evaluation
EC2 Instance
Customer
api.sigopt.com
ELB
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS-to-AWS Optimization with PrivateLink
Training
EC2 Instance(s)
Data
S3 Buckets
Evaluation
EC2 Instance
Training
EC2 Instance
Data
S3 Buckets
Evaluation
EC2 Instance
Customer
SigOpt VPC
Endpoint
SigOpt API NLB
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
On-premise Optimization with PrivateLink
Customer
SigOpt VPC
Endpoint
SigOpt API NLB
Training
Resources
Data
Evaluation
Resources
Customer
On-premises
AWS Direct
Connect
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Aqua Security
Ran Nahmias, Aqua Security
Enabling Container Security
for VPC Users via PrivateLink
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
By 2019, more than 50% of enterprise
DevOps initiatives will have
incorporated application security *
By 2020, more than 50% of global
enterprises will be running
containerized applications in
production **
ALL new enterprise software
deployments will be cloud-native
* Gartner “DevSecOps: How to Seamlessly Integrate Security Into DevOps” Sept 2016
** Gartner “Evolution of Server Computing,” June 2017
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Full Lifecycle Trust & Security for Containers
Secure Pipeline Secure Deployment Secure Runtime
ECR
Image Scanning in
CI/CD
Image fingerprinting and
integrity assurance
Reduce Attack Surface Enforce Best Practices Prevent Attacks
Detect and stop
anomalous behavior
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Container Image Security Scanning
CI/CD Image
Registry (ECR)
Runtime
(ECS)
Cyber Center
• CVE and threat
database
• Updated daily
Scanner
DeployBuild
• Known
vulnerabilities
• Configuration issues
• Hard-coded
secrets
• Image
fingerprinting
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Container Runtime Security
ECS
Command Center
• Monitor all container actions
• Control network, file, OS access
• Set policies
• Log events
Trusted
Images
EC2 Instance
Enforcer
Docker engine
OSOS
EC2 Instance
Enforcer
Docker engine
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
4
4
Cyber
Center
Aqua Scanner on AWS with PrivateLink
Customer 1
Dev
Staging
Prod
VPC
Endpoint
AWS Region
NLB
Customer 2
Dev
Staging
Prod
VPC
Endpoint
Aqua Scanner
Aqua Scanner
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Aqua Customer Benefits
Modernize Security
Through Containers
Secure Once,
Deploy Anywhere
Automate
DevSecOps
Machine-learn and
whitelist good
behavior
Enforce immutable
infrastructure
Container-level firewall
to limit attack impact
Set security across
cloud and on-prem
Security follows the
application,
regardless of OS and
orchestrator
Shift left security to
identify issues early
Automate and
accelerate secure app
delivery
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Customer Benefits: PrivateLink with Aqua
Security Flexibility
• Remain entirely in VPC
• Uniform security
across on-prem and
cloud
• Separation between
dev and prod
environments
• Fully automated
process
• On-demand use
• Pay-as-you-go
consumption model
• Scalable across
regions
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
E r i c B r o w n , D e v O p s L e a d e r
AWS PrivateLink and AppDynamics
AppDynamics
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Auto-Discover and Map
No manual configuration
Baseline Every Metric
32
Production Monitoring
Low overhead
All user transactions
Unified Platform
One Consistent UI
Real-time context
Move Fast Focus on What
Matters Most
Follow Everything
Map iQ Baseline iQ Diagnostic iQ Enterprise iQ Business iQ
Application Performance Monitoring
End-User Monitoring
Business Performance Monitoring
Fastest
growing APM
companyMarket
Leadership
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AppD SaaS on AWS
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AppD VPC Design
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
VPC Design Issues
• C o m p l e x i t y o f r o u t e t a b l e s a n d V P C P e e r i n g
• C r o s s V P C / a c c o u n t c o n n e c t i o n s f o r s h a r e d s e r v i c e s
• S e c u r i t y q u e s t i o n s a r o u n d i n c o n s i s t e n t d e s i g n
• R e s t r i c t i o n s o f V P C d e s i g n
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
PrivateLink Benefits to AppDynamics
ü H i g h l y r e g u l a t e d e n t e r p r i s e s c a n n o w c o m m i t t o A p p D S a a S
ü S o l u t i o n f o r p r i v a t e l y c o n n e c t i n g A p p D y n a m i c s a g e n t t o S a a S V P C
ü P r i v a t e L i n k c a n b e s e c u r e l y w h i t e l i s t e d t o t a r g e t e d c u s t o m e r s
t h r o u g h m a r k e t p l a c e
ü U n i f i e s V P C d e s i g n a n d a d d s i n c r e a s e d s e c u r i t y
ü C o n s i s t e n t d e s i g n d r i v e s c o n s i s t e n t d e v e l o p m e n t
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AppD SaaS on AWS using PrivateLink
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Final Thoughts
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink—Use Cases
Centralized internal services such
as DB, logging, monitoring
workloads serving various VPCs
Micro-service implementation
SaaS serving your customers’
applications in other VPCs and
on-premises networks
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS PrivateLink enables customers to use unified stack
across on-premises networks and Amazon VPCs
AWS PrivateLink Benefits
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Benefits of AWS PrivateLink
AWS PrivateLink is highly reliable and horizontally scalable
on the service side and client side
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Benefits of AWS PrivateLink
AWS PrivateLink reduces operational overhead.
No more IP space planning and coordination and managing
multiple security devices.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Benefits of AWS PrivateLink
AWS PrivateLink is a secure model. The service owner is only
exposing a service concept and the connection is always
initiated by the service user.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Thank you!

More Related Content

What's hot

Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Amazon Web Services
 
CON203_Driving Innovation with Containers
CON203_Driving Innovation with ContainersCON203_Driving Innovation with Containers
CON203_Driving Innovation with ContainersAmazon Web Services
 
GPSTEC305-Machine Learning in Capital Markets
GPSTEC305-Machine Learning in Capital MarketsGPSTEC305-Machine Learning in Capital Markets
GPSTEC305-Machine Learning in Capital MarketsAmazon Web Services
 
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud Data
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud DataGPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud Data
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud DataAmazon Web Services
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Amazon Web Services
 
CON320_Monitoring, Logging and Debugging Containerized Services
CON320_Monitoring, Logging and Debugging Containerized ServicesCON320_Monitoring, Logging and Debugging Containerized Services
CON320_Monitoring, Logging and Debugging Containerized ServicesAmazon Web Services
 
DEV329_Cisco’s Journey from Monolith to Microservices
DEV329_Cisco’s Journey from Monolith to MicroservicesDEV329_Cisco’s Journey from Monolith to Microservices
DEV329_Cisco’s Journey from Monolith to MicroservicesAmazon Web Services
 
STG305_Deep Dive on Backup to the AWS Cloud
STG305_Deep Dive on Backup to the AWS CloudSTG305_Deep Dive on Backup to the AWS Cloud
STG305_Deep Dive on Backup to the AWS CloudAmazon Web Services
 
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdf
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdfDEV305_Manage Your Applications with AWS Elastic Beanstalk.pdf
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdfAmazon Web Services
 
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017Amazon Web Services
 
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...Amazon Web Services
 
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017Deep Dive on Amazon Glacier - STG303 - re:Invent 2017
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017Amazon Web Services
 
MCL306_Making IoT Smarter with AWS Rekognition.pdf
MCL306_Making IoT Smarter with AWS Rekognition.pdfMCL306_Making IoT Smarter with AWS Rekognition.pdf
MCL306_Making IoT Smarter with AWS Rekognition.pdfAmazon Web Services
 
GPSTEC324_STORAGE FOR HPC IN THE CLOUD
GPSTEC324_STORAGE FOR HPC IN THE CLOUDGPSTEC324_STORAGE FOR HPC IN THE CLOUD
GPSTEC324_STORAGE FOR HPC IN THE CLOUDAmazon Web Services
 
GPSTEC312-SAP HANA HA on AWS Preventing Production Facepalms
GPSTEC312-SAP HANA HA on AWS Preventing Production FacepalmsGPSTEC312-SAP HANA HA on AWS Preventing Production Facepalms
GPSTEC312-SAP HANA HA on AWS Preventing Production FacepalmsAmazon Web Services
 
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...Amazon Web Services
 
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...Amazon Web Services
 
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017Amazon Web Services
 

What's hot (19)

Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
 
CON203_Driving Innovation with Containers
CON203_Driving Innovation with ContainersCON203_Driving Innovation with Containers
CON203_Driving Innovation with Containers
 
GPSTEC305-Machine Learning in Capital Markets
GPSTEC305-Machine Learning in Capital MarketsGPSTEC305-Machine Learning in Capital Markets
GPSTEC305-Machine Learning in Capital Markets
 
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud Data
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud DataGPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud Data
GPSTEC315_GPS Optimizing Tips Amazon Redshift for Cloud Data
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
 
CON320_Monitoring, Logging and Debugging Containerized Services
CON320_Monitoring, Logging and Debugging Containerized ServicesCON320_Monitoring, Logging and Debugging Containerized Services
CON320_Monitoring, Logging and Debugging Containerized Services
 
SID402_An AWS Security Odyssey
SID402_An AWS Security OdysseySID402_An AWS Security Odyssey
SID402_An AWS Security Odyssey
 
DEV329_Cisco’s Journey from Monolith to Microservices
DEV329_Cisco’s Journey from Monolith to MicroservicesDEV329_Cisco’s Journey from Monolith to Microservices
DEV329_Cisco’s Journey from Monolith to Microservices
 
STG305_Deep Dive on Backup to the AWS Cloud
STG305_Deep Dive on Backup to the AWS CloudSTG305_Deep Dive on Backup to the AWS Cloud
STG305_Deep Dive on Backup to the AWS Cloud
 
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdf
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdfDEV305_Manage Your Applications with AWS Elastic Beanstalk.pdf
DEV305_Manage Your Applications with AWS Elastic Beanstalk.pdf
 
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017
NEW LAUNCH! AWS Serverless Application Repository - SRV215 - re:Invent 2017
 
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...
NEW LAUNCH! Infinitely Scalable Machine Learning Algorithms with Amazon AI - ...
 
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017Deep Dive on Amazon Glacier - STG303 - re:Invent 2017
Deep Dive on Amazon Glacier - STG303 - re:Invent 2017
 
MCL306_Making IoT Smarter with AWS Rekognition.pdf
MCL306_Making IoT Smarter with AWS Rekognition.pdfMCL306_Making IoT Smarter with AWS Rekognition.pdf
MCL306_Making IoT Smarter with AWS Rekognition.pdf
 
GPSTEC324_STORAGE FOR HPC IN THE CLOUD
GPSTEC324_STORAGE FOR HPC IN THE CLOUDGPSTEC324_STORAGE FOR HPC IN THE CLOUD
GPSTEC324_STORAGE FOR HPC IN THE CLOUD
 
GPSTEC312-SAP HANA HA on AWS Preventing Production Facepalms
GPSTEC312-SAP HANA HA on AWS Preventing Production FacepalmsGPSTEC312-SAP HANA HA on AWS Preventing Production Facepalms
GPSTEC312-SAP HANA HA on AWS Preventing Production Facepalms
 
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...
GPSWKS408-GPS Migrate Your Databases with AWS Database Migration Service and ...
 
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...
GPSTEC319-Build Once Deploy Many Architecting and Building Automated Reusable...
 
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017
NEW LAUNCH! Amazon EC2 Bare Metal Instances - CMP330 - re:Invent 2017
 

Similar to NEW LAUNCH! AWS PrivateLink: Bringing SaaS Solutions into Your VPCs and Your On-Premises Networks - NET204 - re:Invent 2017

AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAmazon Web Services
 
Building .NET-based Serverless Architectures and Running .NET Core Microservi...
Building .NET-based Serverless Architectures and Running .NET Core Microservi...Building .NET-based Serverless Architectures and Running .NET Core Microservi...
Building .NET-based Serverless Architectures and Running .NET Core Microservi...Amazon Web Services
 
Driving Innovation with Containers - CON203 - re:Invent 2017
Driving Innovation with Containers - CON203 - re:Invent 2017Driving Innovation with Containers - CON203 - re:Invent 2017
Driving Innovation with Containers - CON203 - re:Invent 2017Amazon Web Services
 
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...Extending Data Centers to the Cloud: Connectivity Options and Considerations ...
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...Amazon Web Services
 
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)Amazon Web Services
 
Devoxx: Building AI-powered applications on AWS
Devoxx: Building AI-powered applications on AWSDevoxx: Building AI-powered applications on AWS
Devoxx: Building AI-powered applications on AWSAdrian Hornsby
 
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...Amazon Web Services
 
SID301_Using AWS Lambda as a Security Team
SID301_Using AWS Lambda as a Security TeamSID301_Using AWS Lambda as a Security Team
SID301_Using AWS Lambda as a Security TeamAmazon Web Services
 
Containers on AWS - State of the Union - CON201 - re:Invent 2017
Containers on AWS - State of the Union - CON201 - re:Invent 2017Containers on AWS - State of the Union - CON201 - re:Invent 2017
Containers on AWS - State of the Union - CON201 - re:Invent 2017Amazon Web Services
 
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...Amazon Web Services
 
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017Amazon Web Services
 
DEV203_Launch Applications the Amazon Way
DEV203_Launch Applications the Amazon WayDEV203_Launch Applications the Amazon Way
DEV203_Launch Applications the Amazon WayAmazon Web Services
 
IOT311_Customer Stories of Things, Cloud, and Analytics on AWS
IOT311_Customer Stories of Things, Cloud, and Analytics on AWSIOT311_Customer Stories of Things, Cloud, and Analytics on AWS
IOT311_Customer Stories of Things, Cloud, and Analytics on AWSAmazon Web Services
 
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...Amazon Web Services
 
DEV204_Debugging Modern Applications Introduction to AWS X-Ray
DEV204_Debugging Modern Applications Introduction to AWS X-RayDEV204_Debugging Modern Applications Introduction to AWS X-Ray
DEV204_Debugging Modern Applications Introduction to AWS X-RayAmazon Web Services
 
Introduction to AWS Fargate & Amazon Elastic Container Service for Kubernetes
Introduction to AWS Fargate & Amazon Elastic Container Service for KubernetesIntroduction to AWS Fargate & Amazon Elastic Container Service for Kubernetes
Introduction to AWS Fargate & Amazon Elastic Container Service for KubernetesAmazon Web Services
 
What's New in Serverless - SRV305 - re:Invent 2017
What's New in Serverless - SRV305 - re:Invent 2017What's New in Serverless - SRV305 - re:Invent 2017
What's New in Serverless - SRV305 - re:Invent 2017Amazon Web Services
 
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...Amazon Web Services
 
GPSBUS202_Driving Customer Value with Big Data Analytics
GPSBUS202_Driving Customer Value with Big Data AnalyticsGPSBUS202_Driving Customer Value with Big Data Analytics
GPSBUS202_Driving Customer Value with Big Data AnalyticsAmazon Web Services
 
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Amazon Web Services
 

Similar to NEW LAUNCH! AWS PrivateLink: Bringing SaaS Solutions into Your VPCs and Your On-Premises Networks - NET204 - re:Invent 2017 (20)

AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
 
Building .NET-based Serverless Architectures and Running .NET Core Microservi...
Building .NET-based Serverless Architectures and Running .NET Core Microservi...Building .NET-based Serverless Architectures and Running .NET Core Microservi...
Building .NET-based Serverless Architectures and Running .NET Core Microservi...
 
Driving Innovation with Containers - CON203 - re:Invent 2017
Driving Innovation with Containers - CON203 - re:Invent 2017Driving Innovation with Containers - CON203 - re:Invent 2017
Driving Innovation with Containers - CON203 - re:Invent 2017
 
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...Extending Data Centers to the Cloud: Connectivity Options and Considerations ...
Extending Data Centers to the Cloud: Connectivity Options and Considerations ...
 
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)
透過最新的 AWS 服務在 2019 年為您的業務轉型 (Level 200)
 
Devoxx: Building AI-powered applications on AWS
Devoxx: Building AI-powered applications on AWSDevoxx: Building AI-powered applications on AWS
Devoxx: Building AI-powered applications on AWS
 
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
 
SID301_Using AWS Lambda as a Security Team
SID301_Using AWS Lambda as a Security TeamSID301_Using AWS Lambda as a Security Team
SID301_Using AWS Lambda as a Security Team
 
Containers on AWS - State of the Union - CON201 - re:Invent 2017
Containers on AWS - State of the Union - CON201 - re:Invent 2017Containers on AWS - State of the Union - CON201 - re:Invent 2017
Containers on AWS - State of the Union - CON201 - re:Invent 2017
 
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...
ARC306_High Resiliency & Availability Of Online Entertainment Communities Usi...
 
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017
Interstella 8888: Advanced Microservice Operations - CON407 - re:Invent 2017
 
DEV203_Launch Applications the Amazon Way
DEV203_Launch Applications the Amazon WayDEV203_Launch Applications the Amazon Way
DEV203_Launch Applications the Amazon Way
 
IOT311_Customer Stories of Things, Cloud, and Analytics on AWS
IOT311_Customer Stories of Things, Cloud, and Analytics on AWSIOT311_Customer Stories of Things, Cloud, and Analytics on AWS
IOT311_Customer Stories of Things, Cloud, and Analytics on AWS
 
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...
RET303_Drive Warehouse Efficiencies with the Same AWS IoT Technology that Pow...
 
DEV204_Debugging Modern Applications Introduction to AWS X-Ray
DEV204_Debugging Modern Applications Introduction to AWS X-RayDEV204_Debugging Modern Applications Introduction to AWS X-Ray
DEV204_Debugging Modern Applications Introduction to AWS X-Ray
 
Introduction to AWS Fargate & Amazon Elastic Container Service for Kubernetes
Introduction to AWS Fargate & Amazon Elastic Container Service for KubernetesIntroduction to AWS Fargate & Amazon Elastic Container Service for Kubernetes
Introduction to AWS Fargate & Amazon Elastic Container Service for Kubernetes
 
What's New in Serverless - SRV305 - re:Invent 2017
What's New in Serverless - SRV305 - re:Invent 2017What's New in Serverless - SRV305 - re:Invent 2017
What's New in Serverless - SRV305 - re:Invent 2017
 
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...
Verizon: Modernizing Enterprise Infrastructure with AWS - WIN307 - re:Invent ...
 
GPSBUS202_Driving Customer Value with Big Data Analytics
GPSBUS202_Driving Customer Value with Big Data AnalyticsGPSBUS202_Driving Customer Value with Big Data Analytics
GPSBUS202_Driving Customer Value with Big Data Analytics
 
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

NEW LAUNCH! AWS PrivateLink: Bringing SaaS Solutions into Your VPCs and Your On-Premises Networks - NET204 - re:Invent 2017

  • 1. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. NET204 AWS PrivateLink: Bringing SaaS Solutions into Your VPCs and Your On-Premises Networks N o v e m b e r 3 0 , 2 0 1 7 AWS re:INVENT T i m L i , S e n i o r P r o d u c t M a n a g e r , A W S S c o t t C l a r k , C E O , S i g o p t R a n N a h m i a s , S e n i o r D i r e c t o r , A q u a S e c u r i t y E r i c B r o w n , D e v O p s L e a d e r , A p p D y n a m i c s
  • 2. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What to Expect Introduction to AWS PrivateLink Partner Use Cases § SigOpt § Aqua Security § AppDynamics Final Thoughts
  • 3. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Introduction to AWS PrivateLink
  • 4. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Networking on the Cloud Amazon EC2 APIs Elastic Load Balancing APIs Amazon Kinesis 10.1.0.0/16 10.2.0.0/16 10.3.0.0/16 10.4.0.0/16 VPC Peering Connection Connection using public IP address AWS Direct Connect SaaS corporate data center
  • 5. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink brings services into your VPC and your on-premises networks
  • 6. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The World with AWS PrivateLink virtual private cloud Application 1 corporate data center AWS Direct Connect Application 2 Amazon Kinesis Streams Elastic Load Balancing API AWS Service Catalog Amazon EC2 API Amazon EC2 Systems Manager Your Own Service in Another VPC Sample Partner SaaS Solutions
  • 7. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink—Service Provider Proxy Protocol V2 (Optional)
  • 8. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink—Service User virtual private cloud Application 1 AWS Direct Connect Application 2 Endpoints to AWS services Endpoints to your own services Endpoints to AWS partner services Interface endpoints DNS name on the endpoints • Publicly resolvable regional and zonal DNS name that maps to the local IP of the endpoints • NLB health check aware Accessible over AWS Direct Connect Security group integration Local IP, no route table entry Can span multiple Availability Zones
  • 9. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink—End-to-End
  • 10. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Marketplace Integration Discoverability of the services when customers purchase SaaS on AWS Marketplace
  • 11. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Enhancement for Marketplace Services: Vanity DNS Names vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com Service Base DNS Name Service ID Region Sub Domain vpce-12345.vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com Endpoints DNS Name on Client Side VPC Endpoint ID vpce-67890.vpce-svc-1a2b3c4d.us-east-1.vpce.amazonaws.com
  • 12. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Enhancement for Marketplace Services: Vanity DNS Names us-east-1.vpce.myexample.com Service Vanity DNS Name Region Sub Domain vpce-12345.us-east-1.vpce.myexample.com Endpoints DNS Name on Client Side VPC Endpoint ID vpce-67890.us-east-1.vpce.myexample.com Easier Recognition of Service Endpoints Straight-forward TLS Termination
  • 13. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Enhancement for Marketplace Services: Service Discoverability
  • 14. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Enhancement for Marketplace Services: Service Discoverability
  • 15. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. SigOpt Scott Clark, Co-founder and CEO Using AWS PrivateLink to securely optimize AI pipelines
  • 16. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. SigOpt optimizes… - Machine learning - AI/Deep Learning - Reinforcement learning Resulting in… - Better results - Cheaper, faster tuning - Faster development Optimization-as-a-Service
  • 17. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Deep Learning/AI is Expensive to Tune
  • 18. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Black Box Optimizer Bolts on Top of Pipeline
  • 19. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS-Based Optimization Framework Web EC2 Instance sigopt.com ELB Customer Web EC2 Instance api.sigopt.com ELB API EC2 Instance API EC2 Instance … … SQS Queue RDS DB Optimizer EC2 Instance Optimizer EC2 Instance … CloudFront CDN Services Service ELB Service EC2 Instance … Service EC2 Instance
  • 20. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS-to-AWS Optimization Pre-PrivateLink Training EC2 Instance(s) Data S3 Buckets Evaluation EC2 Instance Training EC2 Instance Data S3 Buckets Evaluation EC2 Instance Customer api.sigopt.com ELB
  • 21. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS-to-AWS Optimization with PrivateLink Training EC2 Instance(s) Data S3 Buckets Evaluation EC2 Instance Training EC2 Instance Data S3 Buckets Evaluation EC2 Instance Customer SigOpt VPC Endpoint SigOpt API NLB
  • 22. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. On-premise Optimization with PrivateLink Customer SigOpt VPC Endpoint SigOpt API NLB Training Resources Data Evaluation Resources Customer On-premises AWS Direct Connect
  • 23. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Aqua Security Ran Nahmias, Aqua Security Enabling Container Security for VPC Users via PrivateLink
  • 24. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. By 2019, more than 50% of enterprise DevOps initiatives will have incorporated application security * By 2020, more than 50% of global enterprises will be running containerized applications in production ** ALL new enterprise software deployments will be cloud-native * Gartner “DevSecOps: How to Seamlessly Integrate Security Into DevOps” Sept 2016 ** Gartner “Evolution of Server Computing,” June 2017
  • 25. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Full Lifecycle Trust & Security for Containers Secure Pipeline Secure Deployment Secure Runtime ECR Image Scanning in CI/CD Image fingerprinting and integrity assurance Reduce Attack Surface Enforce Best Practices Prevent Attacks Detect and stop anomalous behavior
  • 26. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Container Image Security Scanning CI/CD Image Registry (ECR) Runtime (ECS) Cyber Center • CVE and threat database • Updated daily Scanner DeployBuild • Known vulnerabilities • Configuration issues • Hard-coded secrets • Image fingerprinting
  • 27. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Container Runtime Security ECS Command Center • Monitor all container actions • Control network, file, OS access • Set policies • Log events Trusted Images EC2 Instance Enforcer Docker engine OSOS EC2 Instance Enforcer Docker engine
  • 28. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 4 4 Cyber Center Aqua Scanner on AWS with PrivateLink Customer 1 Dev Staging Prod VPC Endpoint AWS Region NLB Customer 2 Dev Staging Prod VPC Endpoint Aqua Scanner Aqua Scanner
  • 29. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Aqua Customer Benefits Modernize Security Through Containers Secure Once, Deploy Anywhere Automate DevSecOps Machine-learn and whitelist good behavior Enforce immutable infrastructure Container-level firewall to limit attack impact Set security across cloud and on-prem Security follows the application, regardless of OS and orchestrator Shift left security to identify issues early Automate and accelerate secure app delivery
  • 30. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Customer Benefits: PrivateLink with Aqua Security Flexibility • Remain entirely in VPC • Uniform security across on-prem and cloud • Separation between dev and prod environments • Fully automated process • On-demand use • Pay-as-you-go consumption model • Scalable across regions
  • 31. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. E r i c B r o w n , D e v O p s L e a d e r AWS PrivateLink and AppDynamics AppDynamics
  • 32. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Auto-Discover and Map No manual configuration Baseline Every Metric 32 Production Monitoring Low overhead All user transactions Unified Platform One Consistent UI Real-time context Move Fast Focus on What Matters Most Follow Everything Map iQ Baseline iQ Diagnostic iQ Enterprise iQ Business iQ Application Performance Monitoring End-User Monitoring Business Performance Monitoring Fastest growing APM companyMarket Leadership
  • 33. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AppD SaaS on AWS
  • 34. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AppD VPC Design
  • 35. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC Design Issues • C o m p l e x i t y o f r o u t e t a b l e s a n d V P C P e e r i n g • C r o s s V P C / a c c o u n t c o n n e c t i o n s f o r s h a r e d s e r v i c e s • S e c u r i t y q u e s t i o n s a r o u n d i n c o n s i s t e n t d e s i g n • R e s t r i c t i o n s o f V P C d e s i g n
  • 36. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. PrivateLink Benefits to AppDynamics ü H i g h l y r e g u l a t e d e n t e r p r i s e s c a n n o w c o m m i t t o A p p D S a a S ü S o l u t i o n f o r p r i v a t e l y c o n n e c t i n g A p p D y n a m i c s a g e n t t o S a a S V P C ü P r i v a t e L i n k c a n b e s e c u r e l y w h i t e l i s t e d t o t a r g e t e d c u s t o m e r s t h r o u g h m a r k e t p l a c e ü U n i f i e s V P C d e s i g n a n d a d d s i n c r e a s e d s e c u r i t y ü C o n s i s t e n t d e s i g n d r i v e s c o n s i s t e n t d e v e l o p m e n t
  • 37. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AppD SaaS on AWS using PrivateLink
  • 38. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Final Thoughts
  • 39. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink—Use Cases Centralized internal services such as DB, logging, monitoring workloads serving various VPCs Micro-service implementation SaaS serving your customers’ applications in other VPCs and on-premises networks
  • 40. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS PrivateLink enables customers to use unified stack across on-premises networks and Amazon VPCs AWS PrivateLink Benefits
  • 41. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Benefits of AWS PrivateLink AWS PrivateLink is highly reliable and horizontally scalable on the service side and client side
  • 42. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Benefits of AWS PrivateLink AWS PrivateLink reduces operational overhead. No more IP space planning and coordination and managing multiple security devices.
  • 43. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Benefits of AWS PrivateLink AWS PrivateLink is a secure model. The service owner is only exposing a service concept and the connection is always initiated by the service user.
  • 44. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Thank you!