SlideShare ist ein Scribd-Unternehmen logo
1 von 23
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Estate and Patch Management
Infrastructure and Operations as Code
Nirav Kothari,
Principal Consultant
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
What is the Operational Excellence Pillar?
“The operational excellence pillar includes the ability to run and monitor systems
to deliver business value and to continually improve supporting processes and
procedures. The operational excellence pillar provides an overview of design
principles, best practices, and questions.”
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Design Principles
• Perform operations as code
• Annotated documentation
• Make frequent, small, reversible changes
• Refine operations procedures frequently
• Anticipate failure
• Learn from all operational failures
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
What is the Operational Excellence Pillar?
PREPARE EVOLVEOPERATE
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
How do you design your workload to enable operability?
• Shared design standards
• Design for cloud operations
• Mitigate deployment risks
PREPARE
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
How do you know that you are ready to support a workload?
• Documented accessible governance and guidance
• Runbooks PREPARE
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Why are we here?
• The increased speed and agility of the cloud is best
supported using the same engineering discipline and
practices that you apply to code.
• Dynamic and elastic access to resources increases
the speed and agility of your organization and
benefits from equally dynamic operations.
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Setting Up Your Lab Environment
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Requirements
1. Your own device for console access
2. An AWS account that you are able to use for testing,
that is not used for production or other purposes.
3. An available region within your account with capacity
to add 2 additional VPCs
4. Download the Lab Guide at https://bit.ly/2rnSUdi
• https://s3-us-west-2.amazonaws.com/aws-well-architected-
labs/Operations/100+-+Estate+&+Patch+management+Lab+guide.html
Amazon VPC*
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Lab Setup
1. Create an Administrator IAM user and group
2. Log in with your IAM Administrator user
3. Create an EC2 Key Pair IAM
Amazon EC2
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Deploying an Environment using Infrastructure as Code
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Deploy the lab environment
1. Deploy the Lab CloudFormation template
• https://s3-us-west-2.amazonaws.com/aws-well-architected-
labs/Operations/OE_Single_VPC+_2-Tier_Application_Lab.json
2. Examine the environment in CloudFormation Designer
3. Deploy your stack
template
AWS
CloudFormation
stack
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Estate Management Systems Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Understanding the Resources in your Environment
1. Set up Systems Manager
2. Create a second CloudFormation stack
2. Track your resources using Inventory
3. Review associations with State Manager
Amazon EC2
Systems Manager
stack
Inventory
State Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Patch Management
Systems Manager Patch Manager
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Patch Management
1. Create a Patch Baseline
2. Assign a Patch Group
3. Scan your instances
4. Patch your instances
Patch
Manager
documents
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Removing lab resources
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Removing lab resources
1. Delete your CloudFormation stacks
2. Delete your State Manager association
• If you created a…
• S3 bucket, delete it
• SNS Topic, delete it
• Maintenance window, delete it
• If you don’t plan to use your Administrator user,
delete it
• If you do plan to use your Administrator user, we
recommend you enable MFA
stack
Maintenance
Windows
bucket
State Manager
IAM
topic
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Thank you!
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Bonus Content:
Creating Maintenance Windows and Scheduling Automated Operations Activities
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
Automating Patching with Maintenance Windows
1. Set up Maintenance Windows
2. Create a Patch Maintenance Window
3. Assign Targets
4. Assign Tasks
5. After the maintenance window review the results
Maintenance
Windows
Patch Manager
Amazon
EC2

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Container Scheduling
Container SchedulingContainer Scheduling
Container Scheduling
 
How Enterprises Are Modernizing Their Security, Risk Management, & Compliance...
How Enterprises Are Modernizing Their Security, Risk Management, & Compliance...How Enterprises Are Modernizing Their Security, Risk Management, & Compliance...
How Enterprises Are Modernizing Their Security, Risk Management, & Compliance...
 
Too Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational ModelsToo Many Tools - How AWS Systems Manager Bridges Operational Models
Too Many Tools - How AWS Systems Manager Bridges Operational Models
 
Build a Vulnerability Management Program Using AWS for AWS (SEC337-R1) - AWS ...
Build a Vulnerability Management Program Using AWS for AWS (SEC337-R1) - AWS ...Build a Vulnerability Management Program Using AWS for AWS (SEC337-R1) - AWS ...
Build a Vulnerability Management Program Using AWS for AWS (SEC337-R1) - AWS ...
 
Introducing AWS Firewall Manager - AWS Online Tech Talks
Introducing AWS Firewall Manager - AWS Online Tech TalksIntroducing AWS Firewall Manager - AWS Online Tech Talks
Introducing AWS Firewall Manager - AWS Online Tech Talks
 
Up and Running with Amazon Linux WorkSpaces (BAP207-R1) - AWS re:Invent 2018
Up and Running with Amazon Linux WorkSpaces (BAP207-R1) - AWS re:Invent 2018Up and Running with Amazon Linux WorkSpaces (BAP207-R1) - AWS re:Invent 2018
Up and Running with Amazon Linux WorkSpaces (BAP207-R1) - AWS re:Invent 2018
 
Keynote - Chaos Engineering: Why breaking things should be practiced
Keynote - Chaos Engineering: Why breaking things should be practicedKeynote - Chaos Engineering: Why breaking things should be practiced
Keynote - Chaos Engineering: Why breaking things should be practiced
 
Amazon EC2 Spot Instances
Amazon EC2 Spot InstancesAmazon EC2 Spot Instances
Amazon EC2 Spot Instances
 
Accelerate Innovation and Maximize Business Value with Serverless Application...
Accelerate Innovation and Maximize Business Value with Serverless Application...Accelerate Innovation and Maximize Business Value with Serverless Application...
Accelerate Innovation and Maximize Business Value with Serverless Application...
 
Amazon WorkSpaces for Regulated Industries (BAP211) - AWS re:Invent 2018
Amazon WorkSpaces for Regulated Industries (BAP211) - AWS re:Invent 2018Amazon WorkSpaces for Regulated Industries (BAP211) - AWS re:Invent 2018
Amazon WorkSpaces for Regulated Industries (BAP211) - AWS re:Invent 2018
 
End Extra Spending Hunting for Increased Value through Cost Optimization (ENT...
End Extra Spending Hunting for Increased Value through Cost Optimization (ENT...End Extra Spending Hunting for Increased Value through Cost Optimization (ENT...
End Extra Spending Hunting for Increased Value through Cost Optimization (ENT...
 
AWS Storage and Edge Processing
AWS Storage and Edge ProcessingAWS Storage and Edge Processing
AWS Storage and Edge Processing
 
Your road to a Well Architected solution in the Cloud - Tel Aviv Summit 2018
Your road to a Well Architected solution in the Cloud - Tel Aviv Summit 2018Your road to a Well Architected solution in the Cloud - Tel Aviv Summit 2018
Your road to a Well Architected solution in the Cloud - Tel Aviv Summit 2018
 
DEM07 Best Practices for Monitoring Amazon ECS Containers Launched with Fargate
DEM07 Best Practices for Monitoring Amazon ECS Containers Launched with FargateDEM07 Best Practices for Monitoring Amazon ECS Containers Launched with Fargate
DEM07 Best Practices for Monitoring Amazon ECS Containers Launched with Fargate
 
DEM20 Protecting Your Data in Amazon S3
DEM20 Protecting Your Data in Amazon S3DEM20 Protecting Your Data in Amazon S3
DEM20 Protecting Your Data in Amazon S3
 
[NEW LAUNCH!] Introducing AWS Ground Station – Fully managed Ground Station a...
[NEW LAUNCH!] Introducing AWS Ground Station – Fully managed Ground Station a...[NEW LAUNCH!] Introducing AWS Ground Station – Fully managed Ground Station a...
[NEW LAUNCH!] Introducing AWS Ground Station – Fully managed Ground Station a...
 
Automate & Audit Cloud Governance & Compliance in Your Landing Zone (ENT315-R...
Automate & Audit Cloud Governance & Compliance in Your Landing Zone (ENT315-R...Automate & Audit Cloud Governance & Compliance in Your Landing Zone (ENT315-R...
Automate & Audit Cloud Governance & Compliance in Your Landing Zone (ENT315-R...
 
Amazon SageMaker and Chainer: Tips & Tricks (AIM329-R1) - AWS re:Invent 2018
Amazon SageMaker and Chainer: Tips & Tricks (AIM329-R1) - AWS re:Invent 2018Amazon SageMaker and Chainer: Tips & Tricks (AIM329-R1) - AWS re:Invent 2018
Amazon SageMaker and Chainer: Tips & Tricks (AIM329-R1) - AWS re:Invent 2018
 
Migrating Workloads from Oracle to Amazon Redshift: Best Practices with Pfize...
Migrating Workloads from Oracle to Amazon Redshift: Best Practices with Pfize...Migrating Workloads from Oracle to Amazon Redshift: Best Practices with Pfize...
Migrating Workloads from Oracle to Amazon Redshift: Best Practices with Pfize...
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
 

Ähnlich wie Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf

New AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your WorkloadNew AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your Workload
Amazon Web Services
 

Ähnlich wie Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf (20)

Inventory and Patch Management Using AWS Systems Manager (ARC332) - AWS re:In...
Inventory and Patch Management Using AWS Systems Manager (ARC332) - AWS re:In...Inventory and Patch Management Using AWS Systems Manager (ARC332) - AWS re:In...
Inventory and Patch Management Using AWS Systems Manager (ARC332) - AWS re:In...
 
Design with Ops in Mind.pdf
Design with Ops in Mind.pdfDesign with Ops in Mind.pdf
Design with Ops in Mind.pdf
 
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
Operational Excellence for Identity & Access Management (SEC334) - AWS re:Inv...
 
Set Up a CI/CD Pipeline for Deploying Containers Using the AWS Developer Tool...
Set Up a CI/CD Pipeline for Deploying Containers Using the AWS Developer Tool...Set Up a CI/CD Pipeline for Deploying Containers Using the AWS Developer Tool...
Set Up a CI/CD Pipeline for Deploying Containers Using the AWS Developer Tool...
 
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
Designing for Operability: Getting the Last Nines in Five-Nines Availability ...
 
Remove Undifferentiated Heavy Lifting from CI/CD Toolsets with Corteva Agrisc...
Remove Undifferentiated Heavy Lifting from CI/CD Toolsets with Corteva Agrisc...Remove Undifferentiated Heavy Lifting from CI/CD Toolsets with Corteva Agrisc...
Remove Undifferentiated Heavy Lifting from CI/CD Toolsets with Corteva Agrisc...
 
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
 
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
Operationalizing Microsoft Workloads (WIN320) - AWS re:Invent 2018
 
Workshop: Architecting a Serverless Data Lake
Workshop: Architecting a Serverless Data LakeWorkshop: Architecting a Serverless Data Lake
Workshop: Architecting a Serverless Data Lake
 
Build Your Own Log Analytics Solutions on AWS (ANT323-R) - AWS re:Invent 2018
Build Your Own Log Analytics Solutions on AWS (ANT323-R) - AWS re:Invent 2018Build Your Own Log Analytics Solutions on AWS (ANT323-R) - AWS re:Invent 2018
Build Your Own Log Analytics Solutions on AWS (ANT323-R) - AWS re:Invent 2018
 
AWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_Singapore
 
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
Gaining Better Observability of Your VMs with Amazon CloudWatch - AWS Online ...
 
AWS Lambda use cases and best practices - Builders Day Israel
AWS Lambda use cases and best practices - Builders Day IsraelAWS Lambda use cases and best practices - Builders Day Israel
AWS Lambda use cases and best practices - Builders Day Israel
 
DevOps, CI/CD, cost management, and security on AWS
DevOps, CI/CD, cost management, and security on AWSDevOps, CI/CD, cost management, and security on AWS
DevOps, CI/CD, cost management, and security on AWS
 
AWS Well-Architected Workshop
AWS Well-Architected WorkshopAWS Well-Architected Workshop
AWS Well-Architected Workshop
 
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
 
Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops
 
New AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your WorkloadNew AWS Security Solutions to Protect Your Workload
New AWS Security Solutions to Protect Your Workload
 
AWSome Day - Solutions Architecture Best Practices
AWSome Day - Solutions Architecture Best PracticesAWSome Day - Solutions Architecture Best Practices
AWSome Day - Solutions Architecture Best Practices
 
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
CI CD using AWS Developer Tools @ AWS Community Day Bengaluru 2018
 

Mehr von Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Mehr von Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Nirav Kothari: Well-Architected - Operational Excellence Instructor Led Lab.pdf

  • 1. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Estate and Patch Management Infrastructure and Operations as Code Nirav Kothari, Principal Consultant
  • 2. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved What is the Operational Excellence Pillar? “The operational excellence pillar includes the ability to run and monitor systems to deliver business value and to continually improve supporting processes and procedures. The operational excellence pillar provides an overview of design principles, best practices, and questions.”
  • 3. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Design Principles • Perform operations as code • Annotated documentation • Make frequent, small, reversible changes • Refine operations procedures frequently • Anticipate failure • Learn from all operational failures
  • 4. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved What is the Operational Excellence Pillar? PREPARE EVOLVEOPERATE
  • 5. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved How do you design your workload to enable operability? • Shared design standards • Design for cloud operations • Mitigate deployment risks PREPARE
  • 6. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved How do you know that you are ready to support a workload? • Documented accessible governance and guidance • Runbooks PREPARE
  • 7. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
  • 8. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Why are we here? • The increased speed and agility of the cloud is best supported using the same engineering discipline and practices that you apply to code. • Dynamic and elastic access to resources increases the speed and agility of your organization and benefits from equally dynamic operations.
  • 9. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Setting Up Your Lab Environment
  • 10. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Requirements 1. Your own device for console access 2. An AWS account that you are able to use for testing, that is not used for production or other purposes. 3. An available region within your account with capacity to add 2 additional VPCs 4. Download the Lab Guide at https://bit.ly/2rnSUdi • https://s3-us-west-2.amazonaws.com/aws-well-architected- labs/Operations/100+-+Estate+&+Patch+management+Lab+guide.html Amazon VPC*
  • 11. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Lab Setup 1. Create an Administrator IAM user and group 2. Log in with your IAM Administrator user 3. Create an EC2 Key Pair IAM Amazon EC2
  • 12. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Deploying an Environment using Infrastructure as Code
  • 13. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Deploy the lab environment 1. Deploy the Lab CloudFormation template • https://s3-us-west-2.amazonaws.com/aws-well-architected- labs/Operations/OE_Single_VPC+_2-Tier_Application_Lab.json 2. Examine the environment in CloudFormation Designer 3. Deploy your stack template AWS CloudFormation stack
  • 14. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Estate Management Systems Manager
  • 15. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Understanding the Resources in your Environment 1. Set up Systems Manager 2. Create a second CloudFormation stack 2. Track your resources using Inventory 3. Review associations with State Manager Amazon EC2 Systems Manager stack Inventory State Manager
  • 16. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved
  • 17. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Patch Management Systems Manager Patch Manager
  • 18. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Patch Management 1. Create a Patch Baseline 2. Assign a Patch Group 3. Scan your instances 4. Patch your instances Patch Manager documents
  • 19. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Removing lab resources
  • 20. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Removing lab resources 1. Delete your CloudFormation stacks 2. Delete your State Manager association • If you created a… • S3 bucket, delete it • SNS Topic, delete it • Maintenance window, delete it • If you don’t plan to use your Administrator user, delete it • If you do plan to use your Administrator user, we recommend you enable MFA stack Maintenance Windows bucket State Manager IAM topic
  • 21. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Thank you!
  • 22. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Bonus Content: Creating Maintenance Windows and Scheduling Automated Operations Activities
  • 23. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved Automating Patching with Maintenance Windows 1. Set up Maintenance Windows 2. Create a Patch Maintenance Window 3. Assign Targets 4. Assign Tasks 5. After the maintenance window review the results Maintenance Windows Patch Manager Amazon EC2