feat(dpvp): add backup-solution architecture notes from 2026-07-17 thread review

- New file: workstreams/backup-solution.md
  - DLM explanation: what it is, how it works, vs AWS Backup
  - EC2/compute backup Q&A: AMI vs EBS snapshot, stateful vs stateless matrix
  - Document gaps checklist (rename, DLM policy spec, golden AMI strategy, etc.)
- Updated vssa-dpvp.md: note linking to backup-solution.md
- Updated README.md: added backup-solution to workstreams index
This commit is contained in:
2026-07-17 10:11:45 +00:00
parent ce18208cdb
commit 68fc65e685
3 changed files with 104 additions and 0 deletions
+1
View File
@@ -8,6 +8,7 @@
| # | Workstream | File | | # | Workstream | File |
|---|-----------|------| |---|-----------|------|
| 🔵 | VSSA — Digital Platform Value Proposition | [workstreams/vssa-dpvp.md](workstreams/vssa-dpvp.md) | | 🔵 | VSSA — Digital Platform Value Proposition | [workstreams/vssa-dpvp.md](workstreams/vssa-dpvp.md) |
| 🔵 | AWS Backup Solution (DPVP) | [workstreams/backup-solution.md](workstreams/backup-solution.md) |
| 🟡 | VSSA — Enterprise Architect Consultancy | [workstreams/vssa-enterprise-architect.md](workstreams/vssa-enterprise-architect.md) | | 🟡 | VSSA — Enterprise Architect Consultancy | [workstreams/vssa-enterprise-architect.md](workstreams/vssa-enterprise-architect.md) |
| 🟢 | Cognitive Architect | [workstreams/cognitive-architect.md](workstreams/cognitive-architect.md) | | 🟢 | Cognitive Architect | [workstreams/cognitive-architect.md](workstreams/cognitive-architect.md) |
| 🟣 | SAP Delivery Powered By AI | [workstreams/sap-delivery.md](workstreams/sap-delivery.md) | | 🟣 | SAP Delivery Powered By AI | [workstreams/sap-delivery.md](workstreams/sap-delivery.md) |
+102
View File
@@ -0,0 +1,102 @@
# AWS Backup Solution — Architecture Notes
> **Workstream:** VSSA — DPVP
> **Source:** Thread `#vssa-dpvp-storm` (2026-07-17) — Lego review + Q&A
> **Status:** 🔵 In progress — questions answered, doc gaps identified
> **Last updated:** 2026-07-17
---
## Document Rename
`aws backup-solutions` (plural) → **`backup-solution`** (singular)
---
## Q&A — Key Learnings from Thread Review
### 1. What is AWS DLM and how does it work?
**AWS Data Lifecycle Manager (DLM)** is a native AWS service that **automates creation, retention, and deletion of EBS snapshots and AMIs**. No Lambda, no cron jobs — it's built into AWS.
#### Flow
```
EC2 / EBS Volume
│
▼
DLM Policy ──► Tag-based targeting (e.g. tag: backup=true)
│
▼
Schedule ──► Snapshot/AMI on cron (hourly / daily / weekly)
│
▼
Retention ──► Count-based (keep last N) or age-based (keep X days)
│
▼
Cross-Region Copy (optional) ──► DR region replication
│
▼
Cross-Account Copy (optional) ──► Isolated backup account
```
#### DLM vs AWS Backup
| | DLM | AWS Backup |
|---|---|---|
| Scope | EBS + AMIs only | Multi-service (RDS, EFS, EKS, DynamoDB, FSx, EC2…) |
| Complexity | Simple, low-level | Central console, Vault Lock, compliance policies |
| Best for | Fine-grained EBS snapshot control | Enterprise-wide unified backup strategy |
| Coexistence | ✅ — run alongside each other |
> **Recommendation:** Use DLM for granular EBS/AMI control + AWS Backup for everything else.
---
### 2. Can compute resources (EC2) be backed up?
**Yes.** Two approaches:
#### A — AMI (Full Instance Backup)
Captures the entire EC2 instance: OS, software, config, and all attached EBS volumes.
- Automate with: **DLM** (AMI schedule) or **AWS Backup** (EC2 resource type)
- Supports cross-region copy for DR
#### B — EBS Snapshots (Volume-level)
For data volumes only — faster and cheaper than full AMIs.
- Automate with: **DLM** snapshot policies or **AWS Backup**
#### Compute Backup Decision Matrix
| Resource | Backup Mechanism | RPO | Notes |
|---|---|---|---|
| EC2 — stateful | AMI via DLM or AWS Backup | 1h–24h | Schedule determines RPO |
| EBS data volumes | EBS snapshot | 1h–24h | Faster/cheaper than full AMI |
| EC2 — stateless (app tier) | ⚠️ Skip — redeploy from golden AMI/IaC | Minutes | Backing up stateless = wasted cost |
| Auto Scaling Groups | Launch template + IaC | Minutes (redeploy) | No snapshot needed |
| EC2 user data / config | CloudFormation / Terraform | N/A | IaC is the backup |
> **Key design principle:** Stateless/immutable EC2 = redeploy from golden AMI or IaC. Only stateful EC2 needs AMI backup. This is a major cost driver.
---
## Gaps to Address in the Solution Document
Identified during the thread review on 2026-07-17:
- [ ] **Rename** document from `aws backup-solutions` → `backup-solution`
- [ ] **DLM policy spec** — which EC2/EBS resources are stateful and DLM-targeted
- [ ] **AMI vs EBS snapshot decision matrix** — per workload type (table above is a starting point)
- [ ] **Stateful vs stateless EC2 classification** — explicit list of instances by tier
- [ ] **Compute rows in RPO/RTO table** — ensure EC2/EBS are alongside RDS, EFS, DynamoDB, EKS PVs
- [ ] **Golden AMI strategy** — how base AMIs are built, versioned, and rotated for stateless tiers
- [ ] **Cross-region AMI copy** — DR coverage for stateful EC2 workloads
---
## Related
- DPVP workstream: [vssa-dpvp.md](vssa-dpvp.md)
- Thread: `#vssa-dpvp-storm`, Discord guild `1518726359512387766`, thread `1527604713074458745`
+1
View File
@@ -27,3 +27,4 @@
## Notes ## Notes
- Julius Sulcas was on time off — follow up when back - Julius Sulcas was on time off — follow up when back
- AWS Backup Solution doc under review — see [backup-solution.md](backup-solution.md) for architecture notes, DLM/compute Q&A, and doc gaps (2026-07-17)