8. Public Cloud
● Amazon Web Services
● Google Cloud Platform
● Microsoft Azure
Private Cloud
● On-Premise
● VMware vSphere / vCloud
● Not really cloud
vs
19. IaaS vs PaaS
Infrastructure as a Service
● Building blocks of the cloud
● VMs and Storage
● AWS EC2 & S3
● Most similar to data center
Platform as a Service
● Managed Services
● Databases or Cache
● On-prem MySql vs Amazon RDS
● On-prem Memcached vs AWS
ElastiCache
● Minor architectural adjustments
25. Encryption Everywhere - S3
● Server Side Encryption
○ S3-Managed Keys
○ KMS-Managed Keys
○ Customer Provided Keys
● Client Side Encryption
○ AWS SDK
● AES-256
26. S3: Efficiency Sidebar
● 11-nines durability (99.999999999%)
● Store 100 billion objects (files) without loss
● Designed to withstand the loss of 2 data centers
● Infinitely scalable
27. Encryption Everywhere - EC2
● One-Click Full Disk Encryption
● Data encrypted at rest ...
● … and moving to and from the VM
● AES-256
28. Encryption Everywhere - RDS
● One-Click Full Database Encryption
● Data encrypted at rest
● Data in motion depends on implementation
● AES-256