Skip to main content

Building a Well-Architected Cloud

Page 1

Building a WellArchitected Cloud AN E-BOOK BY ADAPTURE

2

ADAPTURE /// Building a Well-Architected Cloud


Contents

4

6

The Importance of a Strong Foundation in Cloud

8

Operational Excellence

10

Security

13

Reliability

16

Performance Efficiency

18

Cost Optimization

20

Build Your Way to Better Cloud

ADAPTURE /// Building a Well-Architected Cloud


6

ADAPTURE /// Building a Well-Architected Cloud


How do you know that you’re implementing best practices in your cloud environment? If you’re not measuring your cloud performance to industry standards, you could be leaving your environment open to inefficiencies and security risks, like shadow IT and rogue instances. Maybe you’re still in the planning stage of your big migration. Or perhaps you’ve already started building the foundations of your virtual environments (and you’re worried you haven’t done a good job). Either way, what are you using to benchmark your migration plans? A move to cloud is supposed to streamline your processes, optimize resource utilization, and accelerate your business initiatives. For cloud to be fully effective and secure, it must be meticulously well-built. Ultimately, you need standardized benchmarks to determine if your new environment is more … • agile

• flexible • secure • powerful • efficient

… than your old environment. The truth is, many organizations are falling short of industry standards in the cloud. In order to get an objective and globally accurate understanding of a well-built cloud environment, we recommend that you look at these five critical standardizations of cloud managed services.


The Importance of a Strong Foundation in the Cloud

When looking for quantitative standards to hold your virtual environments to, it’s best to start by studying how cloud providers— like AWS, Microsoft, and Google —have successfully harnessed the power of cloud. According to Amazon Web Services1, a well-architected cloud is built on the following pillars:

Operational Excellence

Security

Reliability

Performance Efficiency

Cost Optimization

If a cloud environment is not built on these pillars—or if it is missing one or several—it will be nearly impossible to establish a cloud that meets industry standards and your future needs. Before you can start building well (or remediating what you haven’t), it is important to understand what these pillars look like in functioning environments.

(2018). “THE 5 PILLARS OF THE AWS WELL-ARCHITECTED FRAMEWORK.” AMAZON WEB SERVICES. HTTPS://AWS.AMAZON.COM/BLOGS/APN/THE-5-PILLARS-OF-THE-AWS-WELLARCHITECTED-FRAMEWORK/ 1

8

ADAPTURE /// Building a Well-Architected Cloud


Operational Excellence

The Operational Excellence pillar represents the cultivated ability of your IT team to monitor existing systems, anticipate when components are going to fail, and how quickly and effectively they can respond to the issues at hand. But how do you enable your IT team to reach this level of readiness? Before you can establish operational excellence, you have to understand the nature of your workloads and of their anticipated performance and behaviors in cloud. Assign members of your IT team a specific role (or roles) in congruence with those workloads. Each member should know exactly what he or she is responsible for, and each should also have a firm grasp on other members’ duties in case of emergency. Don’t forget to consider external regulation and compliance requirements as you establish priorities within your in-house protocols and process-related determinations. Most importantly, learn from operational failures and be sure to share these lessons across the entire organization—don’t just limit these to your IT team. To maintain a healthy cloud environment, you have to continually improve on your cloud processes as you optimize your environments to accommodate for change and natural business growth.

10

ADAPTURE /// Building a Well-Architected Cloud


ADAPTURE CAN: Our team of cloud experts will help your IT team gather the pertinent cloud competencies and experience to better support and configure your future virtual environments. We will help you choose and implement an applicable visibility dashboard to give you greater insight into your systems. Using these dashboard and other APM tools, we will conduct a full cloud infrastructure audit to provide you with updated, actionable data on your server uptime and failure/downtime percentages as well as other vital information on the efficiency of your infrastructure. From there, we will counsel your IT team and walk you through how to remediate network concerns and optimize your environments for the future.


Security

The Security pillar represents your ability to protect your assets (without crippling your OPEX, thwarting production, or over-working your IT staff). Even when you are launching your applications on a public cloud platform with its own in-line security tools, it’s important to remember that the security burden is on your IT team alone. While the physical security of the public cloud infrastructure is kept secure, you can’t rely on the cloud provider to secure your digital assets without additional input on your end—that’s why it’s a shared responsibility model. This is also why the Security pillar is critical to get right from the start. Aside from implementing a strategic layering of quality security tools, focus on the following principles to strengthen your cloud security posture: Identity and Access Management: Establish and strictly manage granular protocols and hierarchies within your workforce—know at all times who has access to what data and resources. Detective Controls: Implement these controls and monitoring tools that alert you to potential threats and internal threat activity, provide overviews of connected devices and users, and generates forensic data after breaches occur.

12

ADAPTURE /// Building a Well-Architected Cloud


Infrastructure Protection: Standardize and require strict adherence to your company’s NIST2 -informed control methodologies and security protocols to meet industry best practices and compliance obligations. Data Protection: Establish a logical, compliance-driven protection and classification model to ensure that your critical data—both in transit and at rest—is properly secured and encrypted based on the data’s sensitivity level. You need redundancy and failover measures in place as you build towards cloud. Incident Response: Standardize company-specific incident response and mitigation protocols. Simulate different types of cyberattacks, data breaches, and social engineering campaigns to practice incident response as an entire organization.

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. U.S. DEPARTMENT OF COMMERCE. HTTPS://WWW.NIST.GOV 2


ADAPTURE CAN: Security is a fine balance between your workforce’s awareness and education, the effectiveness of your protocols, and the proper implementation and layering of the right security tools. From our initial cloud audit—and optional Vulnerability Scans and PEN testing— we will provide you with comprehensive vulnerability and security reports along with our industry recommendations to help you: • Decide on the right combination of monitoring and security tools for your specific needs • Train your staff how to configure these tools to your current and future cloud configurations • Organize, secure, and encrypt your critical data and other virtual resources according to their characteristics and sensitivity • Remediate the threat in case of breach, facilitate failover, and provide comprehensive threat reports to better prepare for the future

14

ADAPTURE /// Building a Well-Architected Cloud


Reliability

The Reliability pillar revolves around your ability to efficiently maintain a steady state, adapt to operational changes, and recover from:

Downtime

Misconfigurations

Network issues

As such, this pillar also represents the automation and self-healing measures you have taken to ensure the fastest and most comprehensive recovery from these disruptions. To bolster these initiatives, it is important to: • Conduct Test Recovery Procedures and systematically test how your system fails and recovers according to your remediation procedures and automation settings. Re-run past downtime scenarios to diagnose failure pathways and better prepare for the future. • Automatically Recover from Failures by installing a robust monitoring and notification system that tracks KPIs3. From there, optimize your automation settings to trigger when certain KPI thresholds are reached. • Scale Horizontally to Increase Aggregate System Availability by replacing overly large resources with numerous, smaller resources. These smaller iterations reduce the impact of single failures across your entire environment.

3

16

KEY PERFORMANCE INDICATORS ADAPTURE /// Building a Well-Architected Cloud


• Stop Guessing Capacity because resource saturation often allows the system demands to exceed the capacity of the system itself (almost like a self-inflicted DDoS attack). Monitor resource levels and demand— by adding or removing resources—to avoid over-or-under provisioning. • Manage Change in Automation. Any configuration or adjustments to your environments should be completed through automation; any manual changes that need to be done should be done to the automation protocols themselves.

ADAPTURE CAN: Whether your data is not backed up properly or you have “untouchable” server resources, our cloud experts will help you to build resiliency into your environments through: »» Mitigating and minimizing single points of failure »» Providing in-depth resource usage reports »» Updating cloud resource utilization protocols »» Optimizing automation protocols

We will facilitate system failure testing and help you establish more effective remediation protocols as well as preventative maintenance for future workloads and growth.


Performance Efficiency

The Performance Efficiency pillar refers to the utilization of your cloud resources across industry fluctuations (e.g. How well do your networks leverage cloud resources for spikes and lulls in demand?). In year’s past, IT teams were praised for having long uptimes because it meant that their systems had not crashed in weeks or months. However, modern cloud environments work most efficiently when their resources are only running for minutes or hours at a time—only using what is necessary to complete the current compute demand. In order to architect for performance efficiency: Democratize Advanced Technologies through your cloud provider. Not every IT team is equipped with engineers and specialists who can deploy machine learning initiatives or maintain NoSQL databases. However, you can still leverage these newer technologies by consuming them “as a service” through cloud (thus allowing your IT team to focus on what they do best). Go Global by taking advantage of your cloud provider’s intrinsic global footprint. You can provide lower latency (as well as built-in redundancy and failover) by deploying your systems in a variety of domestic and international cloud regions.

18

ADAPTURE /// Building a Well-Architected Cloud


Use Serverless Architecture to support unpredictable workloads; you pay for exactly what you need to run that code and nothing more. Unlike traditional deployment methods for dynamic workloads that are over-provisioned to account for unpredictable resource needs, these serverless workloads automatically grow and shrink based on their usage.

ADAPTURE CAN: Enable you to pay only for what you need when you need it: this is the beauty of a well-built cloud. After an initial audit—and after providing pertinent data around your company’s current utilization metrics—ADAPTURE experts will help you build an environment that scales to and meets the needs of your applications, without any extraneous additions or instances. In essence, we size your cloud correctly.


Cost Optimization

The Cost Optimization pillar’s primary focus is on cloud spend, but it shares quite a few similarities with the Performance Efficiency pillar. Both pillars, together, represent a continual process of refinement and optimization for the greatest output at the lowest cost. More specifically, cost optimization in cloud is your ability to reduce unnecessary costs and the over-provisioning of resources. A truly cost-optimized system will fully utilize all of its cloud resources while still meeting performance demand at the lowest price point. Key considerations for cost optimization include: • Analyzing and Attributing Expenditure: Cloud platforms provide tools that help you identify and diagnose the usage and cost of resource across your networks. Gather metrics company-wide to begin measuring ROI and optimizing your environments for greater cost savings. • Adopting a Consumption Model: Rather than rely on elaborate forecasting models for your dynamic workloads, pay only for the resources that you consume in real-time as you scale up or down according to demand by adopting a consumption model. Place your more predictable workloads on a Reserved Instances model. • Measuring Overall Efficiency of your systems by determining your business output and the correlated costs of delivering it. Use these metrics to find the optimal balance between output and expenditures. • No Longer Spending Money on Data Center Operations in-house because your cloud provider will be the one doing all of the physical 20

ADAPTURE /// Building a Well-Architected Cloud


labor and maintenance for the cloud hardware. In a similar way, you might no longer need to keep a DBA on staff (and other W2 positions like it) because of the data management services available in your public cloud platform. If you do maintain in-house resources, do so strategically (perhaps for competitive advantage and/or customization). • Using Managed Services to Reduce Cost of Ownership: For traditional workloads, alleviate operational burdens on your IT staff by outsourcing when cost-effective.

ADAPTURE CAN: ADAPTURE provides visibility and diagnostic tools to identify inefficiencies in your environments (e.g. what is running when it shouldn’t be, overprovisioned instances, etc.). From there, we will help you reconfigure your networks to keep your cloud bills under control—but never at the expense of performance. We will work with your IT team to determine: • Which workloads should be placed on reserved instances or an on-demand model • Whether you should keep your DBA team or rely on cloud database services (like RDS) • Which workloads should be outsourced to a managed services provider


Build Your Way to Better Cloud Quit building without a benchmark. You can’t fix what you don’t know is broken. ADAPTURE will partner with your IT team to audit, diagnose, and reconfigure your cloud to provide the greatest output for the lowest cost. We have the experience, the technology, and the workforce to ensure that your cloud is built firmly on the Five Pillars listed above.

22

ADAPTURE /// Building a Well-Architected Cloud


Need a better way to measure your progress in cloud? Contact ADAPTURE to build and run your cloud more effectively and efficiently.


Turn static files into dynamic content formats.

Create a flipbook
Building a Well-Architected Cloud by ADAPTURE - Issuu