- New file: workstreams/backup-solution.md - DLM explanation: what it is, how it works, vs AWS Backup - EC2/compute backup Q&A: AMI vs EBS snapshot, stateful vs stateless matrix - Document gaps checklist (rename, DLM policy spec, golden AMI strategy, etc.) - Updated vssa-dpvp.md: note linking to backup-solution.md - Updated README.md: added backup-solution to workstreams index
103 lines
3.6 KiB
Markdown
103 lines
3.6 KiB
Markdown
# AWS Backup Solution — Architecture Notes
|
||
|
||
> **Workstream:** VSSA — DPVP
|
||
> **Source:** Thread `#vssa-dpvp-storm` (2026-07-17) — Lego review + Q&A
|
||
> **Status:** 🔵 In progress — questions answered, doc gaps identified
|
||
> **Last updated:** 2026-07-17
|
||
|
||
---
|
||
|
||
## Document Rename
|
||
|
||
`aws backup-solutions` (plural) → **`backup-solution`** (singular)
|
||
|
||
---
|
||
|
||
## Q&A — Key Learnings from Thread Review
|
||
|
||
### 1. What is AWS DLM and how does it work?
|
||
|
||
**AWS Data Lifecycle Manager (DLM)** is a native AWS service that **automates creation, retention, and deletion of EBS snapshots and AMIs**. No Lambda, no cron jobs — it's built into AWS.
|
||
|
||
#### Flow
|
||
|
||
```
|
||
EC2 / EBS Volume
|
||
│
|
||
▼
|
||
DLM Policy ──► Tag-based targeting (e.g. tag: backup=true)
|
||
│
|
||
▼
|
||
Schedule ──► Snapshot/AMI on cron (hourly / daily / weekly)
|
||
│
|
||
▼
|
||
Retention ──► Count-based (keep last N) or age-based (keep X days)
|
||
│
|
||
▼
|
||
Cross-Region Copy (optional) ──► DR region replication
|
||
│
|
||
▼
|
||
Cross-Account Copy (optional) ──► Isolated backup account
|
||
```
|
||
|
||
#### DLM vs AWS Backup
|
||
|
||
| | DLM | AWS Backup |
|
||
|---|---|---|
|
||
| Scope | EBS + AMIs only | Multi-service (RDS, EFS, EKS, DynamoDB, FSx, EC2…) |
|
||
| Complexity | Simple, low-level | Central console, Vault Lock, compliance policies |
|
||
| Best for | Fine-grained EBS snapshot control | Enterprise-wide unified backup strategy |
|
||
| Coexistence | ✅ — run alongside each other |
|
||
|
||
> **Recommendation:** Use DLM for granular EBS/AMI control + AWS Backup for everything else.
|
||
|
||
---
|
||
|
||
### 2. Can compute resources (EC2) be backed up?
|
||
|
||
**Yes.** Two approaches:
|
||
|
||
#### A — AMI (Full Instance Backup)
|
||
Captures the entire EC2 instance: OS, software, config, and all attached EBS volumes.
|
||
|
||
- Automate with: **DLM** (AMI schedule) or **AWS Backup** (EC2 resource type)
|
||
- Supports cross-region copy for DR
|
||
|
||
#### B — EBS Snapshots (Volume-level)
|
||
For data volumes only — faster and cheaper than full AMIs.
|
||
|
||
- Automate with: **DLM** snapshot policies or **AWS Backup**
|
||
|
||
#### Compute Backup Decision Matrix
|
||
|
||
| Resource | Backup Mechanism | RPO | Notes |
|
||
|---|---|---|---|
|
||
| EC2 — stateful | AMI via DLM or AWS Backup | 1h–24h | Schedule determines RPO |
|
||
| EBS data volumes | EBS snapshot | 1h–24h | Faster/cheaper than full AMI |
|
||
| EC2 — stateless (app tier) | ⚠️ Skip — redeploy from golden AMI/IaC | Minutes | Backing up stateless = wasted cost |
|
||
| Auto Scaling Groups | Launch template + IaC | Minutes (redeploy) | No snapshot needed |
|
||
| EC2 user data / config | CloudFormation / Terraform | N/A | IaC is the backup |
|
||
|
||
> **Key design principle:** Stateless/immutable EC2 = redeploy from golden AMI or IaC. Only stateful EC2 needs AMI backup. This is a major cost driver.
|
||
|
||
---
|
||
|
||
## Gaps to Address in the Solution Document
|
||
|
||
Identified during the thread review on 2026-07-17:
|
||
|
||
- [ ] **Rename** document from `aws backup-solutions` → `backup-solution`
|
||
- [ ] **DLM policy spec** — which EC2/EBS resources are stateful and DLM-targeted
|
||
- [ ] **AMI vs EBS snapshot decision matrix** — per workload type (table above is a starting point)
|
||
- [ ] **Stateful vs stateless EC2 classification** — explicit list of instances by tier
|
||
- [ ] **Compute rows in RPO/RTO table** — ensure EC2/EBS are alongside RDS, EFS, DynamoDB, EKS PVs
|
||
- [ ] **Golden AMI strategy** — how base AMIs are built, versioned, and rotated for stateless tiers
|
||
- [ ] **Cross-region AMI copy** — DR coverage for stateful EC2 workloads
|
||
|
||
---
|
||
|
||
## Related
|
||
|
||
- DPVP workstream: [vssa-dpvp.md](vssa-dpvp.md)
|
||
- Thread: `#vssa-dpvp-storm`, Discord guild `1518726359512387766`, thread `1527604713074458745`
|