Urgent.News

What's breaking now, across thousands of outlets.

Tech

AWS optimization always looks cleaner from the outside

AWS optimization always looks cleaner from the outside than it is from the inside Here are the things that slow down or stop work that looks straightforward on paper IAM and permission boundaries In organizations with mature security posture, the engineer doing the optimization work often doesn't have permission to make the changes. They can see the problem. They can define the solution. They…

Optimization efforts in AWS often appear simpler from an external perspective than they are internally. A key challenge arises from IAM and permission boundaries. In organizations with a robust security stance, the engineer proposing the optimization may lack the necessary permissions to implement the changes. They can identify the issue and outline a solution, but executing the changes requires navigating an access request process that can take several days.

This becomes even more intricate in multi-account settings. The permissions structure within AWS Organizations implies that even if an engineer possesses appropriate access within one account, cross-account actions necessitate separate configurations. A straightforward move of a workload to a different account entails managing IAM roles, resource policies, and organizational SCPs that must all be synchronized.

It's crucial to account for permission lead time, as it frequently surpasses the technical work required. Furthermore, reserved instances and Savings Plans complexity can arise when AWS accounts are part of an organization with consolidated billing. Reserved instances and Savings Plans acquired in one account can be shared across the entire organization, which is advantageous.

However, this also means that optimization decisions in one team's account can impact the economics of another team's account. Before procuring any commitment-based discounts in an organizational context, it's essential to understand who controls the payer account, the current allocation of reservations, and whether there is an existing RI management process.

Failing to do so could result in conflicts with existing commitments or the loss of opportunities for better terms. Lastly, compliance and data residency constraints significantly influence optimization decisions. Optimizations often entail relocating data or workloads. For instance, moving a database to a less expensive region.

However, data with residency requirements, such as GDPR, financial regulations, or healthcare data requirements, may have limitations on where it can be stored. In such cases, the cheaper alternative might not be compliant. Consequently, it's vital to be aware of these constraints before designing the solution. Discovering a compliance obstacle midway through a migration proves more costly than inquiring about potential limitations beforehand.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 7 October →