Andrew May: Things AWS could learn from Azure (and things it shouldn't)

awschicago 18 views 21 slides Jun 13, 2024
Slide 1
Slide 1 of 21
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21

About This Presentation

AWS Community Day Midwest 2024 | Things AWS could learn from Azure (and things it shouldn't) | Andrew May


Slide Content

MIDWEST | OHIO

Things AWS Could Learn from Azure (and things it shouldn’t) Andrew May

Andrew May Senior Solutions Architect Cloud / DevOps Specialist 7 years of AWS experience 1* year of Azure experience

Why this talk? Completed major Azure project in the last 9 months Rebuilt all Azure infrastructure to use best practices and Infrastructure as Code

AWS Resource Hierarchy

Azure Resource Hierarchy

Azure Resource Hierarchy

Azure Resource Hierarchy

Azure Resource Hierarchy

Since 2015

REST API ARM Template

Audit Deny Append / Modify Deploy if not exists

What’s the benefit? Compare to AWS Config and Organization Service Control Policies Enforce policies at any level of the resource hierarchy Works against Azure Resource Manager, supporting any resource type Define rules against any attribute in request Automatically modify or create additional resources

IAM permissions: Action vs. Data Action Reader Storage Blob Data Reader

How much could AWS actually change?

Now for some things that annoy me about Azure 😠

SKU SKU SKU SKU SKU SKU SKU SKU SKU * SKU = Stock Keeping Unit

AzureWebJobStorage

Questions?