An AWS Region is coming to France
allthingsdistributed.com
allthingsdistributed.com
Currently Ireland vs. Frankfurt is (more data needed of course)[2]:
Europe (Ireland): 25 ms 27 ms 24 ms
Europe (Frankfurt): 39 ms 39 ms 42 ms
And Frankfurt is about 100 miles further than Dublin.But for a quick test, this looks like a good tool: http://www.cloudping.info/
Will be interested to test this once released to see UK / Paris vs. Dublin.
[1] Article states UK region "due in coming months". No location announced?
[2] Hitting ec2.eu-west-1.amazonaws.com vs. ec2.eu-central-1.amazonaws.com.
At the bottom of the English section it says it's London
The new European region, coupled with the existing AWS Regions in Dublin and Frankfurt, and a future one in London,
It's not a great situation, having everything so centralised on London, but it's a small enough country that it doesn't have a huge effect on latency. It would make no sense for AWS to locate in a non-London region when everything would then have to be backhauled to London.
"Each availability zone is designed as an independent failure zone. This means that availability zones are physically separated within a typical metropolitan region and are located in lower risk flood plains (specific flood zone categorization varies by Region). In addition to discrete uninterruptable power supply (UPS) and onsite backup generation facilities, they are each fed via different grids from independent utilities to further reduce single points of failure. Availability zones are all redundantly connected to multiple tier-1 transit providers."
[1] https://d0.awsstatic.com/whitepapers/aws-security-whitepaper...
Does inter-AZ traffic traverse only fiber that you wholly own? Does AWS send traffic over some shared links in some cases? If only some cases, which cases?
Of course later on the IRA bombed the building next door to us - we survived ok the modems just rest them selves
Locating outside London would be a lot cheaper, for labour, land and power.
If you run a data heavy service, PoP inside the UK or Ireland is a must if you want to avoid throttling and heavy-handed traffic shapping.
(To Ireland) --- dynamodb.eu-west-1.amazonaws.com ping statistics --- 100 packets transmitted, 100 packets received, 0.0% packet loss round-trip min/avg/max/stddev = 15.306/22.425/63.455/9.655 ms
To Softlayer Paris: --- speedtest.par01.softlayer.com ping statistics --- 100 packets transmitted, 100 packets received, 0.0% packet loss round-trip min/avg/max/stddev = 12.082/16.196/54.741/7.652 ms
https://aws.amazon.com/blogs/aws/coming-in-2017-new-aws-regi...
[0] https://unop.uk/azure-eu-regions-naming-confusion
[1] https://www.digitalocean.com/company/blog/introducing-our-lo...
[2] https://aws.amazon.com/about-aws/global-infrastructure
[3] http://www.allthingsdistributed.com/2015/11/aws-announces-uk...
I expect Microsoft are using the UN region names for Europe, where Britain are Ireland are part of Northern Europe.
https://en.wikipedia.org/wiki/United_Nations_geoscheme_for_E...
The UK names still aren't great, even if they sound reasonable in isolation (Cardiff - West, London - South). They have fixed the map though.
This might also allow for mixing critical server roles hosted in other Paris data centers with AWS.
I'm thinking about connecting a web server (in AWS) with a DB server (in another Paris DC) while keeping the latency at a low level.
For bonus points, choose the same DC that AWS is actually in http://www.equinix.com/locations/france-colocation/france-da...
Shouldn't it at least be mentioned in the announcement that the french government can pretty much ask Amazon for any of your data without a warrant. Or is the situation better than a year ago?
EDIT: Warrant is apparently needed as noplay said.
But it's probably not a good idea to host in France if you have not reason to do that. Like NSA, french secret service just don't care about laws. But if you target french customer that's good news you have one more alternative for hosting without trouble with regulation about data.
I guess "government" interprets to different things in different countries, what I wrote above is a very american viewpoint.
In my country (SE), a member of government can be relieved of her duties if she even mentions that an agency should act in a certain way (as the government only should make up policies and not interfere in the daily businesses of the agencies).
The last extension is effective since 2016-07-26 and is supposed to last 6 months.
> Today, I am excited to add the United Kingdom to that list! The AWS UK region will be our third in the European Union (EU), and we're shooting to have it ready by the end of 2016 (or early 2017). This region will provide even lower latency and strong data sovereignty to local users.
[1] http://www.allthingsdistributed.com/2015/11/aws-announces-uk...
https://aws.amazon.com/blogs/aws/coming-in-2017-new-aws-regi...
> This will be the fourth AWS Region in Europe. We currently have two other Regions in Europe — EU (Ireland) and EU (Frankfurt) and an additional Region in the UK expected to launch in the coming months.
Currently it is an incredibly inefficient design of a service management trying to do everything yet many are dependent for using it.
Ansible, for example, can easily manage stuff like security groups (http://docs.ansible.com/ansible/ec2_group_module.html) , load balancing (http://docs.ansible.com/ansible/ec2_elb_lb_module.html), IAM users and roles (http://docs.ansible.com/ansible/iam_module.html), etc., and it does them in repeatable, auditable, version-controllable, self-documenting fashion.
Is the suggestion to recreate what Amazon Console has done (using APIs) in every large organisation using AWS because Amazon Console is not good enough?
If you're using AWS then Cloudformation (maybe with an abstraction like troposphere), will do what you need.
If you are pressing the big blue 'launch instance' button, you are doing it wrong.
Agreed. Advantage is clear and understood.
My point here is: there exists something called 'Amazon Console'. I argue it is a good thing to have if done properly easing the service management as visualized management is more human friendly and APIs more computer friendly. If there exists a bad visualized service management (e.g. Amazon Console) it is the lack of skills of the humans developing it not because managing a vast complex clusters is easier through APIs/CLI and impossible/wrong via UI.
What's your suggestion for improving the UX?
I believe the current sub-categorizing of services:
API Gateway, AppStream, AWS IoT, Certificate Manager, CloudFormation, CloudFront, CloudSearch, CloudTrail, CloudWatch, CodeCommit, CodeDeploy, CodePipeline, Cognito, Config, Data Pipeline, Device Farm, Direct Connect, Directory Service, DMS, DynamoDB, EC2, EC2 Container Service, Elastic Beanstalk, Elastic File System, Elastic Transcoder, ElastiCache, Elasticsearch Service, EMR, GameLift, Glacier, IAM, Inspector, Kinesis, Lambda, Machine Learning, Mobile Analytics, Mobile Hub, OpsWorks, RDS, Redshift, Route 53, S3, Service Catalog, SES, Snowball, SNS, SQS, Storage Gateway, SWF, Trusted Advisor, VPC, WAF, WorkDocs, WorkMail, WorkSpaces.
is not helpful and confusing for new users. This is because all the mentioned services are a mix of dependent (e.g. ECS depends on EC2), independent(e.g. IAM & EC2), security, services acting like plugins.
The documents for all of these services can be a sequel novel. If you have been with AWS since 2012 you may have gradually been updated by each service that was getting blindly added but for a new user or a startup aiming to setup something or test the scalability of their application ASAP it is a nightmare.
The other day I found out (in a hard way) that you cannot launch an EC2 instance with an AWS container agent from the default launch page but you need to go to the launch page via the document link which puts extra parameters in the url...
Having said all that I believe the improvement needs to be more fundamental than couple of bullet points.
Our platform is very mature now I wish more folks would give it a shot.
p.s. we also take EU people data privacy very seriously. https://www.thefastmode.com/technology-solutions/9077-micros...
Hmmm. I find that very hard to believe.
MS is going to have to be _very_ good for a _long_ time to overcome firing the late Caspar Bowden (then MS' chief privacy adviser) for telling regional managers that the NSA can pwn their customers' data. https://twitter.com/casparbowden/status/542588420611379201
In a U.S. AWS data center, I am very confident (right now) that my encryption keys and encrypted data will never be given out to any governmental agency. Even with a warrant, they can not access my data unencrypted.
What will Amazon do when the French government says hand us all of your keys or else...
As our data is all extremely sensitive financial information, we really can not even take that chance until we know.
Clarification: We send all data over HTTPS with AES 256 encryption. If authorities have a warrant for data, can we hand them the encrypted data and say the keys are in the U.S. and we can't give them to you?
1) Keeping keys to extremely sensitive financial data on a cloud server
2) Confident that the US government won't request this information through warrant or national security letter
3) Asking for advice about this on a message board?
2) Well lately, I'm not. The Apple/FBI case was somewhat assuring. And I believe that to date, AWS has not handed over any data or keys without permission.
3) More theoretical advice about the new French region. What are the laws about privacy and how will that work. We just saw what Germany ruled on with WhatsApp. And really just asking the question because it needs to be asked. I don't actually expect an ultimate answer, just discussion about it.
How would you know? The NSL would prevent Amazon from being able to say anything about it.
If you're that concerned about your security, you shouldn't be using a cloud provider.
Comparing with the US I don't remember that France has any gag laws.
All Internet traffic in and out of Israel goes through three undersea cables connecting the country with Turkey, Greece, and Italy, and as such suffer from the kind of lag that happens when you're separated from your destination server by a couple thousand kilometers, usually more. There are no local cloud providers and the local entrepreneurial culture (which is MASSIVE for such a small country) either has to pay for cloud resources in Europe or has to pay for local non-cloud hosting, which is orders of magnitude more expensive and running on relatively ancient hardware (the local VPS shops have little incentive to upgrade).
Do we have to beg for Amazon to come here?!
> (the local VPS shops have little incentive to upgrade)
> Do we have to beg for Amazon to come here?!
I'm surprised nobody has stepped in and built out their own cloud offering.
https://en.wikipedia.org/wiki/List_of_countries_by_GDP_(PPP)
In the Middle East there are several markets larger than Israel, and putting a region in Israel will probably not be tenable for Egypt, Saudi Arabia and the like.
There is no region in Africa...
Russia & Eastern Europe is not that well served...
Fast connections there are also few and far between in the Middle East and Africa. In Israel, LTE is ubiquitous in urban areas, most residences have either DOCSIS 3.0 or Fiber-to-the-curb, and a nationwide FTTH infrastructure is being built out currently. Domestic connections are great - the problem is just that almost nothing is hosted domestically.
Eastern Europe / Western Russia sounds like a good idea to me, although I'm not familiar with their local Internet topologies.