Contents
Best Practices for Cloud Deployments .........................................................................................................................3
What is Cloud .......................................................................................................................... ................................................................................ 3
Operating systems (Windows VS Linux) .......................................................................................................................... ..................................4
Linux - Which Linux? ..................................................................................................................................................................................... 4
VM Configurations ...........................................................................................................................................................5
Ram ........................................................................................................................................................................................................................... 5
Storage...................................................................................................................................................................................................................... 5
File Systems .......................................................................................................................... ................................................................................... 5
NTFS - Windows .......................................................................................................................... .......................................................................... 6
XFS – RedHat Linux ............................................................................................................................................................................................... 6
ZFS - OpenZFS ....................................................................................................................................................................................................... 6
Numa!!! - Do not overprovision! ......................................................................................................................................................................... 7
Ulimits – Large systems need tuning based on loads .................................................................................................................................... 7
Connectivity .......................................................................................................................................................................8
SSH vs Telnet ........................................................................................................................................................................................................... 8
AccuTerm/IO (Sockets)........................................................................................................................................................................................... 9
VPNs .......................................................................................................................................................................................................................... 9
Web Based security controls ............................................................................................................................................................................... 9
Token based/per IP based controls .......................................................................................................................... ........................................... 10
Good access Controls ............................................................................................................................................................................................ 10
Good tracking. Watch for attacks ....................................................................................................................................................................... 10
Access Controls ....................................................................................................................................................................................................... 10
Other Services ......................................................................................................................................................................................................... 10
FTP .................................................................................................................................................................................................................... 10
Email – SendGrid/Cloud/Trellio/etc. .......................................................................................................................... ................................ 11
Storage – Usually PDFs, CSV files, etc. Move away from Windows Shares ..................................................................................... 11
Deployment techniques – Git vs Windows shares to move code around for example ................................................................. 11
Web services (MVConnect, MVIS, U2 Web DE, Bluefinitty, RDM, homegrown, etc.) ................................................................... 11
HA/DR and Backups .......................................................................................................................................................12
Backups/Restores - MV systems are databases. .............................................................................................................................................12
Snapshots ................................................................................................................................................................................................................. 12
HA/TF/Restores ...................................................................................................................................................................................................... 12
Logging – watching disk space, etc. .................................................................................................................................................................... 12
Security ...............................................................................................................................................................................13
SELinux/Other kernel level tools ......................................................................................................................................................................... 13
Windows Security tools ........................................................................................................................................................................................ 13
User Permissions (Root/Admin vs users) ........................................................................................................................................................... 13
Logging – Watching activity ................................................................................................................................................................................. 13
Encrypted files ......................................................................................................................................................................................................... 14
Encrypted transmissions (SSH vs Telnet, https vs http, etc.) ......................................................................................................................... 14
Keep software and Operating Systems up to date! DevOps ................................................................................................................ 14