Cloud Architecture Design
BCSE355L
Dr. SELVAM D
Course Outcomes
1. Demonstrate an in-depth understanding of AWS Cloud architecture,
services, and design patterns.
2. Apply security and compliance measures effectively in AWS architectures
using encryption, access controls, and monitoring.
3. Optimize cost and performance by selecting appropriate AWS services and
utilizing cost-effective resource management strategies.
4. Configure and manage advanced AWS networking features, storage
solutions, database technologies, and compute resources.
Syllabus
Module 1 -AWS Cloud Foundations & IAM
• Definition of Cloud Computing: Delivery of computing services
over the internet (the cloud) to offer faster innovation, flexible
resources, and economies of scale.
• Key Characteristics:
• On-demand self-service
• Broad network access
• Resource pooling
• Rapid elasticity
• Measured service
• Collaboration and productivity enhancement
Key Characteristics:
• On-demand self-service: Users can automatically provision computing resources
without human intervention, enabling faster resource management.
• Broad network access: Cloud services are accessible over the network through
standard mechanisms, supporting various platforms like mobile devices and
laptops.
• Resource pooling: Provider's computing resources are pooled to serve multiple
consumers, dynamically assigning resources according to demand for efficiency.
• Rapid elasticity: Cloud services can quickly scale resources up or down as needed,
allowing users to adapt to changing workloads.
• Measured service: Cloud systems automatically control and optimize resource use
through metering, enabling users to monitor consumption and manage costs.
• Collaboration and productivity enhancement: Cloud services provide tools for
real-time communication and document sharing, facilitating effective teamwork and
increased productivity.
Types of Cloud Services
• Infrastructure as a Service (IaaS): Provides virtualized computing
resources over the internet, allowing users to rent servers, storage, and
networking infrastructure on a pay-as-you-go basis.
• Platform as a Service (PaaS): Offers a platform allowing developers to
build, deploy, and manage applications without dealing with the
complexities of infrastructure management, streamlining the
development process.
• Software as a Service (SaaS): Delivers software applications over the
internet on a subscription basis, enabling users to access applications
from any device without needing to install or maintain them locally.
Deployment Models:
• Public Cloud: Cloud resources are owned and operated by third-
party providers and made available to the general public, offering
scalability and cost-effectiveness without the need for on-site
infrastructure.
• Private Cloud: Cloud infrastructure is exclusively used by a single
organization, providing greater control, security, and
customization options, often hosted on-premises or by a third-
party provider.
• Hybrid Cloud: Combines public and private clouds, allowing data
and applications to be shared between them, providing flexibility
and greater deployment options to meet varying business needs.
Benefits:
• Cost efficiency: Reduces capital expenses by allowing organizations to pay
only for what they use, eliminating the need for significant upfront
investments in hardware and infrastructure.
• Scalability: Enables organizations to easily scale resources up or down
based on demand, ensuring they can adapt to changing workloads without
overcommitting resources.
• Disaster recovery: Provides robust data backup and recovery solutions in
the cloud, ensuring business continuity and minimizing downtime in case of
unexpected events.
• Mobility: Allows users to access applications and data from any location
with internet connectivity, enhancing flexibility and enabling remote work.
• Collaboration and productivity enhancement: Facilitates real-time
collaboration through shared tools and resources, improving teamwork and
overall productivity among users.
Virtualization
• Virtualization is the process of creating a virtual version of Key Aspects
a resource, such as a server, storage device, network, or
operating system, allowing multiple instances to exist and • Abstraction: Virtualization abstracts the physical
operate independently on a single physical hardware hardware, allowing software to interact with virtual
system. resources rather than directly with physical components.
• This technology enables improved resource utilization, • Isolation: Each virtual instance operates in its own
isolation, and flexibility, making it easier to manage and environment, ensuring that applications and workloads
deploy IT resources. are isolated from one another, which enhances security
and stability.
• Resource Optimization: By allowing multiple virtual
instances to run on a single physical machine,
virtualization maximizes resource utilization and reduces
hardware costs.
• Scalability and Flexibility: Virtualization makes it easier
to scale resources up or down as needed and to deploy
new services rapidly without the need for additional
physical hardware.
• Management Simplification: Centralized management
tools can oversee virtual resources, leading to easier
administration and monitoring of IT environments.
Types
• Server Virtualization • Network Virtualization
• Definition: Abstracts physical hardware to • Definition: Creates a virtualized network
create multiple virtual machines (VMs). environment that separates network
• Examples: VMware, Hyper-V, KVM. resources and services from the hardware.
• Examples: VMware NSX, Cisco ACI.
• Storage Virtualization
• Application Virtualization • Definition: Pools storage resources from
• Definition: Runs applications in a virtual multiple physical devices into a single virtual
environment, separating them from the storage unit.
underlying OS. • Examples: VMware vSAN, IBM Spectrum
• Examples: Citrix Virtual Apps, Microsoft App- Virtualize.
V.
• Desktop Virtualization
• Definition: Allows desktop environments to
be hosted on a central server and accessed
remotely.
• Examples: VMware Horizon, Citrix Virtual
Desktops.
Virtualization - Types
Server Virtualization Storage Virtualization
Virtualization - Types
Application Virtualization Network Virtualization
Software Defined Data Center (SDDC)
• An SDDC refers to a data center where all elements are • Key features of SDDC include:
virtualized and delivered as a service.
• Virtualization: SDDC employs virtualization technologies
• This encompasses computing, storage, networking, and to abstract the hardware layer, providing flexibility and
security resources, which are managed through software scalability. Resources can be allocated and managed
rather than hardware. dynamically based on demand.
• Automation: Automation tools are used to manage data
center operations, which reduces the need for manual
intervention and enhances operational efficiency.
• Resource Optimization: By using software to manage
resources, SDDC can optimize resource usage, enabling
better performance and reducing costs.
• Agility: SDDC allows organizations to deploy applications
and services faster, adapting to changing business needs
without the constraints of physical hardware.
• Flexibility: With SDDC, organizations can easily scale
their resources up or down based on demand, which is
essential for businesses with fluctuating workloads.
AWS - Overview
Aws Global Presence
AWS Infrastructure
Components of AWS Infrastructure
Components of AWS Global Infrastructure
•Regions: Geographically separated areas that enable the deployment of AWS services across the
globe for redundancy and resilience.
•Availability Zones (AZs): Isolated locations within a region that ensure high availability and fault
tolerance for applications and services.
•Local Zones: Extend AWS services closer to large population centers, reducing latency for
applications that require immediate responsiveness.
•Edge Locations: Caches content for fast delivery to users through Amazon CloudFront, enhancing
performance and reducing load times.
•Regional Edge Caches: Improve content delivery efficiency by minimizing the need to retrieve data
from the origin server.
•Wavelength Zones: Allow the deployment of applications with ultra-low latency on 5G networks,
ideal for real-time applications.
Understanding the Backbone of Cloud Services
AWS Shared Responsibility Model:
• Definition: The AWS Shared • AWS Responsibilities
Responsibility Model outlines (Security of the Cloud):
the responsibilities of AWS and • Physical security of data centers
its customers in securing • Network and hardware security
cloud services. • Hypervisor security
• Global infrastructure security
• Compliance with various
regulatory standards
The AWS Global Infrastructure consists of
Regions and Availability Zones.
• Your choice of a Region is typically based on
compliance requirements or to reduce latency.
• Each Availability Zone is physically separate from
other Availability Zones and has redundant
power, networking, and connectivity.
• Edge locations, and Regional edge caches
improve performance by caching content closer
to users.
AWS services and service
category overview
Multi-objective ____1_____ based VM Placement (VMP) optimisation using ____2______ in Cloud Data Center (CDC)
Resource Type Optimization Objectives Description
Performance vs. Cost, Energy vs. Load Allocation of CPU cycles for compute-
CPU (vCPU Cores)
Balance intensive tasks.
GPU/TPU Throughput vs. Energy, Speed vs. Cost Optimized for parallel workloads like AI/ML.
RAM (Memory) Memory Utilization vs. Energy Efficiency Critical for real-time and big data workloads.
Access Latency vs. Storage Cost, Availability Input/output operations per second for data-
Storage IOPS
vs. Performance intensive applications.
Compute-Based Multi-Objective Resources in Cloud Computing
Choice of storage medium based on workload
Disk Type (SSD/HDD) Speed vs. Cost, Reliability vs. Lifespan
needs.
Performance vs. Cost, Scalability vs. Resource Optimally selecting VM flavors (compute-
VM Types/Sizes
Waste optimized, memory-optimized, etc.).
Container Resources Deployment Speed vs. Resource Isolation Used for microservices-based architecture.
Energy-aware scheduling to minimize power
Energy Consumption Performance vs. Energy Cost
usage.
Important for sustainable data center
Thermal Constraints Performance vs. Cooling Requirements
operation.
Scheduling tasks to meet deadlines and
Execution Time Latency vs. Throughput
minimize waiting time.
Data movement between compute and
Bandwidth Usage Data Transfer Speed vs. Network Congestion
storage nodes.
Optimizing task ordering across compute
Task Scheduling Makespan vs. Resource Utilization
nodes.
QoS Parameters (SLA) Response Time vs. Cost vs. Availability Meeting Service Level Agreements (SLAs).
Redundancy vs. Cost, Reliability vs. Resource Ensuring compute resilience via replication or
Fault Tolerance
Usage migration.
Dynamic selection of local (edge) or
Edge vs. Cloud Node Latency vs. Compute Capacity
centralized (cloud) compute resources.
Ensuring fair and secure allocation among
Multi-Tenant Isolation Security vs. Resource Efficiency
multiple users.
1. Amazon S3 (Simple Storage Service) 3. Amazon EFS (Elastic File System)
•Purpose: Object storage for the internet. •Purpose: Fully managed shared file storage.
•Why Used: •Why Used:
• Scalable and durable storage for files, backups, • Ideal for workloads requiring concurrent access
static websites, media, logs. (e.g., web servers, containers).
• Easy integration with data analytics, serverless, and • Scales automatically with usage.
CDN services. • NFS-compatible and supports Linux workloads.
• Pay-as-you-go model.
2. Amazon EBS (Elastic Block Store) 4. Amazon S3 Glacier
•Purpose: Block-level storage for EC2 instances. •Purpose: Archival storage for long-term data retention.
•Why Used: •Why Used:
• Provides high-performance volumes for • Extremely low-cost storage for infrequently
databases and transaction-heavy workloads. accessed data.
• Persistent storage even after EC2 shutdown. • Best for compliance, regulatory archives, or digital
• Snapshot and encryption support for backup and preservation.
security. • Supports retrieval within minutes to hours
depending on the tier.
1. Amazon EC2 (Elastic Compute Cloud) 5. AWS Elastic Beanstalk
•Use: Provides resizable virtual servers. •Use: Deploy and manage web applications.
•Purpose: Run applications on virtual machines (instances) •Purpose: Automatically handles deployment, from
in the cloud. capacity provisioning to load balancing.
•Key Benefit: Full control over OS, storage, and •Key Benefit: Supports multiple languages and frameworks
configuration. (Java, Python, [Link], etc.).
2. Amazon EC2 Auto Scaling 6. AWS Lambda
•Use: Automatically adjusts the number of EC2 instances. •Use: Run code without provisioning servers.
•Purpose: Maintain application performance and reduce •Purpose: Execute backend logic in response to events
cost by scaling based on demand. (e.g., S3 upload, API call).
•Key Benefit: Ensures availability and cost-efficiency. •Key Benefit: Serverless architecture — pay only for
runtime.
3. Amazon ECS (Elastic Container Service) 7. Amazon EKS (Elastic Kubernetes Service)
•Use: Run and manage Docker containers. •Use: Run Kubernetes workloads on AWS.
•Purpose: Container orchestration without managing your •Purpose: Manage containerized applications using
own cluster. Kubernetes without needing to install or manage the control
•Key Benefit: Deep integration with AWS services like EC2, plane.
•Key Benefit: Scalable and secure container orchestration.
IAM, and CloudWatch.
4. Amazon EC2 Container Registry (ECR) 8. AWS Fargate
•Use: Store, manage, and deploy Docker container images. •Use: Run containers without managing servers or clusters.
•Purpose: Acts as a secure, scalable repository for •Purpose: Works with ECS and EKS to launch containers without
container images used in ECS or Kubernetes. managing EC2 instances.
•Key Benefit: Fully managed, integrated with IAM for access •Key Benefit: Serverless container hosting.
control.
4. AWS Transit Gateway
1. Amazon VPC (Virtual Private Cloud)
•Use: Connect multiple VPCs and on-premises networks via a
•Use: Create isolated cloud networks within AWS. central hub.
•Purpose: Control your virtual networking environment, •Purpose: Simplify large-scale network architecture by avoiding
including IP address ranges, subnets, route tables, and point-to-point connections.
gateways. •Key Benefit: Scalable and efficient network routing.
•Key Benefit: Enhanced security and network
5. Amazon Route 53
segmentation.
•Use: Domain Name System (DNS) web service.
2. Elastic Load Balancing (ELB) •Purpose: Translates domain names into IP addresses and routes
end users to Internet applications.
•Use: Distribute incoming application traffic across
•Key Benefit: High availability, low latency DNS service with traffic
multiple targets (like EC2 instances). routing policies.
•Purpose: Automatically scales to handle varying load,
improving fault tolerance. 6. AWS Direct Connect
•Use: Establish a dedicated network connection from your premises
•Key Benefit: Increases availability and reliability of
to AWS.
applications. •Purpose: Provides high-bandwidth, low-latency connectivity,
bypassing the public internet.
3. Amazon CloudFront •Key Benefit: Secure and consistent network performance.
•Use: Deliver content (websites, videos, APIs) globally
with low latency. 7. AWS VPN
•Purpose: Content Delivery Network (CDN) that •Use: Establish secure site-to-site or client-to-site encrypted
connections to AWS.
caches copies of content closer to users.
•Purpose: Extend on-premises networks securely to the AWS cloud.
•Key Benefit: Improves user experience through fast •Key Benefit: Ensures secure data transmission over public internet
content delivery. using IPsec tunnels.
AWS Shared Responsibility Model
• AWS secures the infrastructure, while customers are responsible
for securing their data and applications within the cloud.
• Security and Compliance is a shared responsibility between AWS
and the customer.
• This shared model can help relieve the customer’s operational
burden as AWS operates, manages and controls the components
from the host operating system and virtualization layer down to
the physical security of the facilities in which the service operates.
• The customer assumes responsibility and management of the
guest operating system (including updates and security patches),
other associated application software as well as the configuration
of the AWS provided security group firewall.
AWS responsibility “Security of the Cloud” - AWS is responsible for
protecting the infrastructure that runs all of the services offered in
the AWS Cloud. This infrastructure is composed of the hardware,
software, networking, and facilities that run AWS Cloud services.
• Customer responsibility “Security in the Cloud” – Customer
responsibility will be determined by the AWS Cloud services that a
customer selects. This determines the amount of configuration
work the customer must perform as part of their security
responsibilities.
• Inherited Controls- Controls which a customer fully inherits from
AWS.
• Shared Controls-Controls which apply to both the infrastructure
layer and customer layers.
• Customer Specific – Controls which are solely the responsibility of
the customer based on the application they are deploying within
AWS services.
AWS Identity and Access Management (IAM)
• Use IAM to manage access to AWS resources –
• A resource is an entity in an AWS account that you can work with
• Example resources; An Amazon EC2 instance or an Amazon S3 bucket.
• Example – Control who can terminate Amazon EC2 instances
• Create and manage AWS users and groups: Define who can
access resources and what permissions they have.
• Set permissions: Grant specific privileges to users, groups, and
roles using policies.
• Multi-factor authentication (MFA): Add an extra layer of security by
requiring MFA for sensitive operations.
• Role-based access control: Assign roles to users or services for
temporary access to resources.
• Define fine-grained access rights –
• Who can access the resource
• Which resources can be accessed and what can the user do to the resource
• How resources can be accessed
AWS Shared Responsibility Model:
AWS Shared Responsibility Model:
• Customer Responsibilities • Shared Services: Certain
(Security in the Cloud): services have shared
• Data classification and responsibilities, such as:
management • Amazon RDS (Relational Database
• Identity and access management Service) – AWS manages the
(IAM) infrastructure, while customers
• Application security manage database configurations
and security settings.
• Operating system and network
configuration
• Security of data in transit and at
rest
AWS Shared Responsibility Model:
• Customer Control: • Continuous Monitoring:
Customers have the ability to Customers are encouraged to
control their security continuously monitor their
configurations, including: environment for threats and
• Encryption settings vulnerabilities.
• Security group and firewall • Compliance and
settings Governance: AWS provides
• User permissions and roles tools and resources to help
customers meet compliance
requirements.
AWS Identity and Access
Management (AWS IAM)
• User Management: Enables you to • Temporary Security Credentials:
create and manage AWS users and Provides temporary security
groups, allowing you to control credentials for users and
access to AWS resources. applications, allowing for secure
• Permissions: Uses policies to and controlled access to AWS
define permissions for AWS services.
resources, ensuring that users have • Integration with Other AWS
the minimum necessary access. Services: Works seamlessly with
• Multi-Factor Authentication (MFA): other AWS services, enabling you to
Supports MFA for an added layer of manage permissions across your
security, requiring users to provide entire AWS environment.
not just a password but also a • Audit and Compliance: Offers
second form of identification. logging and monitoring capabilities
through AWS CloudTrail, helping you
to track and audit IAM activities.
IAM: Users & Groups
IAM: Permissions
IAM Policies inheritance
IAM Policies Structure
IAM – Password Policy
Multi Factor Authentication - MFA
How can users access AWS ?
IAM Roles for Services
IAM Guidelines & Best Practices
IAM Section – Summary