Files
jarvis-at-skic 68fc65e685 feat(dpvp): add backup-solution architecture notes from 2026-07-17 thread review
- New file: workstreams/backup-solution.md
  - DLM explanation: what it is, how it works, vs AWS Backup
  - EC2/compute backup Q&A: AMI vs EBS snapshot, stateful vs stateless matrix
  - Document gaps checklist (rename, DLM policy spec, golden AMI strategy, etc.)
- Updated vssa-dpvp.md: note linking to backup-solution.md
- Updated README.md: added backup-solution to workstreams index
2026-07-17 10:11:45 +00:00

103 lines
3.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# AWS Backup Solution — Architecture Notes
> **Workstream:** VSSA — DPVP
> **Source:** Thread `#vssa-dpvp-storm` (2026-07-17) — Lego review + Q&A
> **Status:** 🔵 In progress — questions answered, doc gaps identified
> **Last updated:** 2026-07-17
---
## Document Rename
`aws backup-solutions` (plural) → **`backup-solution`** (singular)
---
## Q&A — Key Learnings from Thread Review
### 1. What is AWS DLM and how does it work?
**AWS Data Lifecycle Manager (DLM)** is a native AWS service that **automates creation, retention, and deletion of EBS snapshots and AMIs**. No Lambda, no cron jobs — it's built into AWS.
#### Flow
```
EC2 / EBS Volume
│
▼
DLM Policy ──► Tag-based targeting (e.g. tag: backup=true)
│
▼
Schedule ──► Snapshot/AMI on cron (hourly / daily / weekly)
│
▼
Retention ──► Count-based (keep last N) or age-based (keep X days)
│
▼
Cross-Region Copy (optional) ──► DR region replication
│
▼
Cross-Account Copy (optional) ──► Isolated backup account
```
#### DLM vs AWS Backup
| | DLM | AWS Backup |
|---|---|---|
| Scope | EBS + AMIs only | Multi-service (RDS, EFS, EKS, DynamoDB, FSx, EC2…) |
| Complexity | Simple, low-level | Central console, Vault Lock, compliance policies |
| Best for | Fine-grained EBS snapshot control | Enterprise-wide unified backup strategy |
| Coexistence | ✅ — run alongside each other |
> **Recommendation:** Use DLM for granular EBS/AMI control + AWS Backup for everything else.
---
### 2. Can compute resources (EC2) be backed up?
**Yes.** Two approaches:
#### A — AMI (Full Instance Backup)
Captures the entire EC2 instance: OS, software, config, and all attached EBS volumes.
- Automate with: **DLM** (AMI schedule) or **AWS Backup** (EC2 resource type)
- Supports cross-region copy for DR
#### B — EBS Snapshots (Volume-level)
For data volumes only — faster and cheaper than full AMIs.
- Automate with: **DLM** snapshot policies or **AWS Backup**
#### Compute Backup Decision Matrix
| Resource | Backup Mechanism | RPO | Notes |
|---|---|---|---|
| EC2 — stateful | AMI via DLM or AWS Backup | 1h–24h | Schedule determines RPO |
| EBS data volumes | EBS snapshot | 1h–24h | Faster/cheaper than full AMI |
| EC2 — stateless (app tier) | ⚠️ Skip — redeploy from golden AMI/IaC | Minutes | Backing up stateless = wasted cost |
| Auto Scaling Groups | Launch template + IaC | Minutes (redeploy) | No snapshot needed |
| EC2 user data / config | CloudFormation / Terraform | N/A | IaC is the backup |
> **Key design principle:** Stateless/immutable EC2 = redeploy from golden AMI or IaC. Only stateful EC2 needs AMI backup. This is a major cost driver.
---
## Gaps to Address in the Solution Document
Identified during the thread review on 2026-07-17:
- [ ] **Rename** document from `aws backup-solutions` → `backup-solution`
- [ ] **DLM policy spec** — which EC2/EBS resources are stateful and DLM-targeted
- [ ] **AMI vs EBS snapshot decision matrix** — per workload type (table above is a starting point)
- [ ] **Stateful vs stateless EC2 classification** — explicit list of instances by tier
- [ ] **Compute rows in RPO/RTO table** — ensure EC2/EBS are alongside RDS, EFS, DynamoDB, EKS PVs
- [ ] **Golden AMI strategy** — how base AMIs are built, versioned, and rotated for stateless tiers
- [ ] **Cross-region AMI copy** — DR coverage for stateful EC2 workloads
---
## Related
- DPVP workstream: [vssa-dpvp.md](vssa-dpvp.md)
- Thread: `#vssa-dpvp-storm`, Discord guild `1518726359512387766`, thread `1527604713074458745`