Appearance
AWS Storage Extras — Theory (Bản gốc slide / Original slide)
1. AWS Snowball — Tổng quan (Overview)
- Thiết bị portable, bảo mật cao để thu thập & xử lý dữ liệu tại edge, và di chuyển dữ liệu vào/ra khỏi AWS
- Hỗ trợ di chuyển tới hàng Petabyte dữ liệu
| Device | Compute | Memory | Storage (SSD) |
|---|---|---|---|
| Snowball Edge Storage Optimized | 104 vCPU | 416 GB | 210 TB |
| Snowball Edge Compute Optimized | 104 vCPU | 416 GB | 28 TB |
- Highly-secure, portable devices to collect and process data at the edge, and migrate data into and out of AWS
- Helps migrate up to Petabytes of data
| Device | Compute | Memory | Storage (SSD) |
|---|---|---|---|
| Snowball Edge Storage Optimized | 104 vCPUs | 416 GB | 210 TB |
| Snowball Edge Compute Optimized | 104 vCPUs | 416 GB | 28 TB |
2. Data Migrations với Snowball
Thời gian truyền dữ liệu qua mạng (Time to Transfer):
| 100 Mbps | 1 Gbps | 10 Gbps | |
|---|---|---|---|
| 10 TB | 12 ngày | 30 giờ | 3 giờ |
| 100 TB | 124 ngày | 12 ngày | 30 giờ |
| 1 PB | 3 năm | 124 ngày | 12 ngày |
Thách thức khi truyền qua mạng:
- Kết nối hạn chế, băng thông hạn chế
- Chi phí mạng cao
- Băng thông chia sẻ (không tận dụng tối đa được đường truyền)
- Kết nối không ổn định
💡 Quy tắc: nếu truyền qua mạng mất hơn 1 tuần, hãy dùng thiết bị Snowball!
Time to Transfer:
| 100 Mbps | 1 Gbps | 10 Gbps | |
|---|---|---|---|
| 10 TB | 12 days | 30 hours | 3 hours |
| 100 TB | 124 days | 12 days | 30 hours |
| 1 PB | 3 years | 124 days | 12 days |
Challenges:
- Limited connectivity, limited bandwidth
- High network cost
- Shared bandwidth (can't maximize the line)
- Connection stability
💡 Rule of thumb: if it takes more than a week to transfer over the network, use Snowball devices!
3. Edge Computing là gì? (What is Edge Computing?)
- Xử lý dữ liệu ngay khi nó được tạo ra tại một vị trí edge — ví dụ: một xe tải trên đường, một con tàu ngoài biển, một trạm khai thác dưới lòng đất…
- Những vị trí này có thể có Internet hạn chế và không có sẵn compute power
- Dùng thiết bị Snowball Edge để thực hiện edge computing:
- Snowball Edge Compute Optimized (dành riêng cho use case này) & Storage Optimized
- Chạy EC2 instance hoặc Lambda function ngay tại edge
- Use cases: tiền xử lý dữ liệu (preprocess), machine learning, transcoding media
- Process data while it's being created at an edge location — e.g., a truck on the road, a ship on the sea, a mining station underground...
- These locations may have limited internet and no access to computing power
- Set up a Snowball Edge device to do edge computing:
- Snowball Edge Compute Optimized (dedicated for that use case) & Storage Optimized
- Run EC2 Instances or Lambda functions at the edge
- Use cases: preprocess data, machine learning, transcoding media
4. Kiến trúc: Snowball vào Glacier
- Snowball KHÔNG THỂ import trực tiếp vào Glacier
- Phải đi qua Amazon S3 trước, kết hợp với một S3 Lifecycle Policy để tự động chuyển dữ liệu sang Glacier
Luồng: Snowball → (import) → Amazon S3 → (S3 lifecycle policy) → Amazon Glacier
- Snowball cannot import to Glacier directly
- You must use Amazon S3 first, in combination with an S3 lifecycle policy
Flow: Snowball → (import) → Amazon S3 → (S3 lifecycle policy) → Amazon Glacier
5. Amazon FSx — Tổng quan (Overview)
- Cho phép launch các file system hiệu năng cao của bên thứ 3 trên AWS
- Là fully managed service
- 4 loại:
- FSx for Windows File Server
- FSx for Lustre
- FSx for NetApp ONTAP
- FSx for OpenZFS
- Launch 3rd party high-performance file systems on AWS
- Fully managed service
- 4 kinds:
- FSx for Windows File Server
- FSx for Lustre
- FSx for NetApp ONTAP
- FSx for OpenZFS
6. Amazon FSx for Windows (File Server)
- Là Windows file system share drive được quản lý hoàn toàn (fully managed)
- Hỗ trợ giao thức SMB và Windows NTFS
- Tích hợp Microsoft Active Directory, ACL, user quota
- Có thể mount trên Linux EC2 instance
- Hỗ trợ Microsoft's Distributed File System (DFS) Namespaces (nhóm file across nhiều file system)
- Scale tới hàng chục GB/s, hàng triệu IOPS, hàng trăm PB dữ liệu
- Tuỳ chọn storage:
- SSD — workload nhạy cảm độ trễ (database, media processing, data analytics…)
- HDD — dải workload rộng (home directory, CMS…)
- Có thể truy cập từ hạ tầng on-premises (VPN hoặc Direct Connect)
- Có thể cấu hình Multi-AZ (high availability)
- Dữ liệu được backup hằng ngày sang S3
- A fully managed Windows file system share drive
- Supports SMB protocol & Windows NTFS
- Microsoft Active Directory integration, ACLs, user quotas
- Can be mounted on Linux EC2 instances
- Supports Microsoft's Distributed File System (DFS) Namespaces (group files across multiple FS)
- Scale up to 10s of GB/s, millions of IOPS, 100s PB of data
- Storage Options:
- SSD — latency-sensitive workloads (databases, media processing, data analytics…)
- HDD — broad spectrum of workloads (home directory, CMS…)
- Can be accessed from your on-premises infrastructure (VPN or Direct Connect)
- Can be configured to be Multi-AZ (high availability)
- Data is backed up daily to S3
7. Amazon FSx for Lustre
- Lustre là một loại parallel distributed file system cho tính toán quy mô lớn
- Tên "Lustre" bắt nguồn từ "Linux" + "cluster"
- Use cases: Machine Learning, High Performance Computing (HPC), Video Processing, Financial Modeling, Electronic Design Automation
- Scale tới hàng trăm GB/s, hàng triệu IOPS, độ trễ dưới mili-giây
- Tuỳ chọn storage:
- SSD — độ trễ thấp, workload nặng IOPS, thao tác file nhỏ & ngẫu nhiên
- HDD — workload nặng throughput, thao tác file lớn & tuần tự
- Tích hợp liền mạch với S3:
- Có thể "đọc S3" như một file system (thông qua FSx)
- Có thể ghi kết quả tính toán ngược lại S3 (thông qua FSx)
- Có thể dùng từ server on-premises (VPN hoặc Direct Connect)
Tuỳ chọn triển khai (Deployment Options):
| Scratch File System | Persistent File System | |
|---|---|---|
| Lưu trữ | Tạm thời (temporary) | Dài hạn (long-term) |
| Replication | Không replicate — mất dữ liệu nếu file server lỗi | Replicate trong cùng AZ — thay file lỗi trong vài phút |
| Hiệu năng | Burst cao (nhanh gấp 6x, 200MBps/TiB) | Ổn định |
| Dùng cho | Xử lý ngắn hạn, tối ưu chi phí | Xử lý dài hạn, dữ liệu nhạy cảm |
- Lustre is a type of parallel distributed file system, for large-scale computing
- The name "Lustre" is derived from "Linux" and "cluster"
- Use cases: Machine Learning, High Performance Computing (HPC), Video Processing, Financial Modeling, Electronic Design Automation
- Scales up to 100s GB/s, millions of IOPS, sub-ms latencies
- Storage Options:
- SSD — low-latency, IOPS intensive workloads, small & random file operations
- HDD — throughput-intensive workloads, large & sequential file operations
- Seamless integration with S3:
- Can "read S3" as a file system (through FSx)
- Can write the output of computations back to S3 (through FSx)
- Can be used from on-premises servers (VPN or Direct Connect)
Deployment Options:
| Scratch File System | Persistent File System | |
|---|---|---|
| Storage | Temporary | Long-term |
| Replication | Not replicated — doesn't persist if file server fails | Replicated within the same AZ — replace failed files within minutes |
| Performance | High burst (6x faster, 200MBps per TiB) | Steady |
| Usage | Short-term processing, cost optimization | Long-term processing, sensitive data |
8. Amazon FSx for NetApp ONTAP
- NetApp ONTAP được quản lý (managed) trên AWS
- File system tương thích giao thức NFS, SMB, iSCSI
- Giúp di chuyển workload đang chạy trên ONTAP hoặc NAS sang AWS
- Hoạt động với: Linux, Windows, MacOS, VMware Cloud on AWS, Amazon WorkSpaces & AppStream 2.0, EC2/ECS/EKS
- Storage tự động co giãn (shrink/grow)
- Hỗ trợ snapshot, replication, chi phí thấp, compression & data de-duplication
- Point-in-time instantaneous cloning (hữu ích để test workload mới)
- Managed NetApp ONTAP on AWS
- File System compatible with NFS, SMB, iSCSI protocols
- Move workloads running on ONTAP or NAS to AWS
- Works with: Linux, Windows, MacOS, VMware Cloud on AWS, Amazon WorkSpaces & AppStream 2.0, EC2/ECS/EKS
- Storage shrinks or grows automatically
- Snapshots, replication, low-cost, compression and data de-duplication
- Point-in-time instantaneous cloning (helpful for testing new workloads)
9. Amazon FSx for OpenZFS
- OpenZFS file system được quản lý (managed) trên AWS
- File system tương thích NFS (v3, v4, v4.1, v4.2)
- Giúp di chuyển workload đang chạy trên ZFS sang AWS
- Hoạt động với: Linux, Windows, MacOS, VMware Cloud on AWS, Amazon WorkSpaces & AppStream 2.0, EC2/ECS/EKS
- Tới 1,000,000 IOPS với độ trễ < 0.5ms
- Hỗ trợ snapshot, compression, chi phí thấp
- Point-in-time instantaneous cloning (hữu ích để test workload mới)
- Managed OpenZFS file system on AWS
- File System compatible with NFS (v3, v4, v4.1, v4.2)
- Move workloads running on ZFS to AWS
- Works with: Linux, Windows, MacOS, VMware Cloud on AWS, Amazon WorkSpaces & AppStream 2.0, EC2/ECS/EKS
- Up to 1,000,000 IOPS with < 0.5ms latency
- Snapshots, compression, low-cost
- Point-in-time instantaneous cloning (helpful for testing new workloads)
10. Hybrid Cloud cho Storage & Storage Cloud Native Options
- AWS đang thúc đẩy mô hình "hybrid cloud": một phần hạ tầng ở cloud, một phần ở on-premises
- Lý do phổ biến: di trú (migration) kéo dài, yêu cầu bảo mật, yêu cầu compliance, chiến lược IT
- S3 là công nghệ lưu trữ độc quyền (khác EFS/NFS) — vậy làm sao expose dữ liệu S3 ra on-premises?
- → AWS Storage Gateway!
- AWS is pushing for "hybrid cloud": part of your infrastructure on the cloud, part on-premises
- Common reasons: long cloud migrations, security requirements, compliance requirements, IT strategy
- S3 is a proprietary storage technology (unlike EFS/NFS) — so how do you expose S3 data on-premises?
- → AWS Storage Gateway!
11. AWS Storage Gateway — Tổng quan (Overview)
- Là cầu nối giữa dữ liệu on-premises và dữ liệu trên cloud
- Use cases: disaster recovery, backup & restore, tiered storage, cache on-premises & truy cập file độ trễ thấp
- 3 loại Storage Gateway:
- S3 File Gateway
- Volume Gateway
- Tape Gateway
- A bridge between on-premises data and cloud data
- Use cases: disaster recovery, backup & restore, tiered storage, on-premises cache & low-latency file access
- Types of Storage Gateway:
- S3 File Gateway
- Volume Gateway
- Tape Gateway
12. Amazon S3 File Gateway
- Các S3 bucket đã cấu hình truy cập được qua giao thức NFS và SMB
- Dữ liệu được dùng gần đây nhất được cache ngay tại file gateway
- Hỗ trợ S3 Standard, S3 Standard-IA, S3 One Zone-IA, S3 Intelligent-Tiering
- Chuyển sang S3 Glacier bằng Lifecycle Policy
- Truy cập bucket dùng IAM role cho từng File Gateway
- Giao thức SMB tích hợp với Active Directory (AD) để xác thực user
- Configured S3 buckets are accessible using the NFS and SMB protocol
- Most recently used data is cached in the file gateway
- Supports S3 Standard, S3 Standard-IA, S3 One Zone-IA, S3 Intelligent-Tiering
- Transition to S3 Glacier using a Lifecycle Policy
- Bucket access using IAM roles for each File Gateway
- SMB Protocol has integration with Active Directory (AD) for user authentication
13. Volume Gateway
- Block storage dùng giao thức iSCSI, được lưu trữ trên S3
- Được backing bởi EBS snapshot — có thể giúp khôi phục volume on-premises!
- Cached volumes: truy cập độ trễ thấp tới dữ liệu gần nhất, toàn bộ dataset vẫn ở S3
- Stored volumes: toàn bộ dataset ở on-premises, backup theo lịch (scheduled) sang S3
- Block storage using iSCSI protocol, backed by S3
- Backed by EBS snapshots which can help restore on-premises volumes!
- Cached volumes: low latency access to most recent data, entire dataset stays in S3
- Stored volumes: entire dataset is on-premises, scheduled backups to S3
14. Tape Gateway
- Một số công ty vẫn dùng quy trình backup bằng tape vật lý (!)
- Với Tape Gateway, họ có thể dùng cùng quy trình đó nhưng trên cloud
- Virtual Tape Library (VTL) được backing bởi Amazon S3 và Glacier
- Backup dữ liệu bằng quy trình tape hiện có (qua giao diện iSCSI)
- Hoạt động với các nhà cung cấp phần mềm backup hàng đầu
- Some companies have backup processes using physical tapes (!)
- With Tape Gateway, companies use the same processes but in the cloud
- Virtual Tape Library (VTL) backed by Amazon S3 and Glacier
- Back up data using existing tape-based processes (via iSCSI interface)
- Works with leading backup software vendors
15. AWS Storage Gateway — Kiến trúc tổng thể
Tổng hợp 3 loại gateway theo local cache trên EC2/on-premises và đích lưu trữ trên AWS:
| Gateway | Giao thức on-premises | Local cache | Đích lưu trên AWS |
|---|---|---|---|
| File Gateway | NFS/SMB | Có | Mọi S3 storage class (trừ Glacier & Glacier Deep Archive) |
| Volume Gateway | iSCSI | Có | S3 + AWS EBS (snapshot) |
| Tape Gateway | iSCSI VTL | Có | S3 Tape Library + Glacier & Glacier Deep Archive (archived tapes) |
- Kết nối qua Internet hoặc Direct Connect, có mã hoá khi truyền (encryption in transit)
- Deployment: chạy dưới dạng VM (VMware, Hyper-V, KVM) tại on-premises
Summary of the 3 gateway types by on-premises local cache and AWS storage destination:
| Gateway | On-premises protocol | Local cache | AWS destination |
|---|---|---|---|
| File Gateway | NFS/SMB | Yes | Any S3 storage class (excluding Glacier & Glacier Deep Archive) |
| Volume Gateway | iSCSI | Yes | S3 + AWS EBS (snapshot) |
| Tape Gateway | iSCSI VTL | Yes | S3 Tape Library + Glacier & Glacier Deep Archive (archived tapes) |
- Connects over Internet or Direct Connect, with encryption in transit
- Deployment: runs as a VM (VMware, Hyper-V, KVM) on-premises
16. AWS Transfer Family
- Dịch vụ fully-managed cho việc truyền file vào/ra Amazon S3 hoặc Amazon EFS dùng giao thức họ FTP
- Giao thức hỗ trợ:
- AWS Transfer for FTP (File Transfer Protocol)
- AWS Transfer for FTPS (FTP over SSL)
- AWS Transfer for SFTP (Secure File Transfer Protocol)
- Hạ tầng được quản lý, có thể scale, đáng tin cậy, highly available (multi-AZ)
- Tính phí theo endpoint đã cấp phát/giờ + data transfer theo GB
- Lưu trữ & quản lý credential của user ngay trong dịch vụ
- Tích hợp với hệ thống xác thực có sẵn: Microsoft Active Directory, LDAP, Okta, Amazon Cognito, custom
- Use case: chia sẻ file, public dataset, CRM, ERP…
- A fully-managed service for file transfers into and out of Amazon S3 or Amazon EFS using the FTP protocol family
- Supported Protocols:
- AWS Transfer for FTP (File Transfer Protocol)
- AWS Transfer for FTPS (FTP over SSL)
- AWS Transfer for SFTP (Secure File Transfer Protocol)
- Managed infrastructure, Scalable, Reliable, Highly Available (multi-AZ)
- Pay per provisioned endpoint per hour + data transfers in GB
- Store and manage users' credentials within the service
- Integrate with existing authentication systems: Microsoft Active Directory, LDAP, Okta, Amazon Cognito, custom
- Usage: sharing files, public datasets, CRM, ERP…
17. AWS DataSync
- Di chuyển lượng lớn dữ liệu vào/ra:
- On-premises / cloud khác → AWS (NFS, SMB, HDFS, S3 API…) — cần agent
- AWS → AWS (giữa các storage service khác nhau) — không cần agent
- Có thể đồng bộ tới:
- Amazon S3 (mọi storage class — kể cả Glacier)
- Amazon EFS
- Amazon FSx (Windows, Lustre, NetApp, OpenZFS…)
- Task replication có thể lên lịch hằng giờ, hằng ngày, hằng tuần
- File permission và metadata được giữ nguyên (NFS POSIX, SMB…)
- Một agent task có thể dùng tới 10 Gbps, có thể giới hạn bandwidth
- Move large amounts of data to and from:
- On-premises / other cloud → AWS (NFS, SMB, HDFS, S3 API…) — needs an agent
- AWS → AWS (different storage services) — no agent needed
- Can synchronize to:
- Amazon S3 (any storage classes — including Glacier)
- Amazon EFS
- Amazon FSx (Windows, Lustre, NetApp, OpenZFS...)
- Replication tasks can be scheduled hourly, daily, weekly
- File permissions and metadata are preserved (NFS POSIX, SMB…)
- One agent task can use 10 Gbps, can set up a bandwidth limit
Ngoài chiều on-premises → AWS, DataSync còn hỗ trợ đồng bộ trực tiếp giữa các AWS storage service với nhau (S3 ↔ S3, EFS ↔ EFS, FSx ↔ FSx…) mà không cần agent — sao chép cả dữ liệu lẫn metadata.
Besides the on-premises → AWS direction, DataSync also supports direct synchronization between AWS storage services (S3 ↔ S3, EFS ↔ EFS, FSx ↔ FSx…) with no agent needed — copying both data and metadata.
18. Storage Comparison
| Dịch vụ | Vai trò |
|---|---|
| S3 | Object Storage |
| S3 Glacier | Object Archival |
| EBS volumes | Network storage cho một EC2 instance tại một thời điểm |
| Instance Storage | Storage vật lý gắn với EC2 instance (IOPS cao) |
| EFS | Network File System cho Linux instance, POSIX filesystem |
| FSx for Windows | Network File System cho Windows server |
| FSx for Lustre | Linux file system cho High Performance Computing |
| FSx for NetApp ONTAP | Khả năng tương thích OS cao |
| FSx for OpenZFS | Managed ZFS file system |
| Storage Gateway | S3 & FSx File Gateway, Volume Gateway (cached & stored), Tape Gateway |
| Transfer Family | Giao diện FTP, FTPS, SFTP trên nền Amazon S3 hoặc Amazon EFS |
| DataSync | Lên lịch đồng bộ dữ liệu on-premises → AWS, hoặc AWS → AWS |
| Snowcone / Snowball / Snowmobile | Di chuyển lượng lớn dữ liệu vật lý lên cloud |
| Database | Cho các workload cụ thể, thường có indexing và query |
| Service | Role |
|---|---|
| S3 | Object Storage |
| S3 Glacier | Object Archival |
| EBS volumes | Network storage for one EC2 instance at a time |
| Instance Storage | Physical storage for your EC2 instance (high IOPS) |
| EFS | Network File System for Linux instances, POSIX filesystem |
| FSx for Windows | Network File System for Windows servers |
| FSx for Lustre | High Performance Computing Linux file system |
| FSx for NetApp ONTAP | High OS Compatibility |
| FSx for OpenZFS | Managed ZFS file system |
| Storage Gateway | S3 & FSx File Gateway, Volume Gateway (cache & stored), Tape Gateway |
| Transfer Family | FTP, FTPS, SFTP interface on top of Amazon S3 or Amazon EFS |
| DataSync | Schedule data sync on-premises → AWS, or AWS → AWS |
| Snowcone / Snowball / Snowmobile | Move large amounts of data to the cloud, physically |
| Database | For specific workloads, usually with indexing and querying |