AWS Data Protection - Ken Hui VMware Explore 2022
Transcript
>> Welcome to VMware Explore 2022 with the CTO Advisor Studio. Come on in and consume some content. >> Welcome back to coverage of VMworld 2022. We're going to have quite a bit of a controversial conversation. I have with me a good friend from the industry, Ken Hoy, Service Solutions Architect at AWS. Ken, first we're going to get into that title. >> Sure. >> That's an unusual title, but I've made this controversial statement over on the queue. I said that there's been to the detriment of IT infrastructure this overshift to application or the, that's fine.
Yeah, that's fine. Yeah. To the detriment of IT infrastructure, we've overshifted the conversation to the developer experience. Controversial, Ken. >> Could be, for sure. Yeah. >> My thought process is that there's a lot of work that needs to be done to make this nirvana a developer experience with their just contributing compute, networking, storage, etcetera, via in the abstraction. In the public clouds, that's very much a option. >> Right. >> If you're a AWS customer, you don't think about any of that, but if you're a hybrid IT customer, you're thinking about your AS/400.
You're thinking about your mainframes. You're thinking about your SAP running on HP-UX. As you're transitioned to the public cloud, you're thinking about your VMware vSphere running in the public cloud. My argument is that there's a lot of plumbing that needs to happen for the developer experience to be fully enabled in the way that we are painting. >> Okay. >> And when there's a cool solution like the NetApp FSN Service that now supports VMworld cloud on AWS. >> Yes. >> Directly attaching storage to it, I kind of looked at that announcement and shrug my shoulders.
It is technically amazing. >> Yeah. >> But I'm thinking about developer experience. >> Yeah. So, first of all, thanks for having me on, you know, in VMware Explore and talking with you about IT. It's great because we try to have these private conversations before so it's great to have it kind of on camera. So in a certain sense I agree with you. I think there is obviously a very heavy focus right now on developers within the VMware ecosystem, but I think, you know, that's kind of natural in the sense that there's been so much talk about DevOps and bringing developers and operations together and companies like NetApp or VMware have been so, that customer base is so filled with operators that they need to kind of reach out to developers to kind of bring them into the conversation.
And I think where that fits in here with VMware cloud and AWS or just AWS in general is, while it's true that we do the cloud, we are doing the managed service part. We're taking care of a lot of that plumbing and infrastructure, there is also the shared responsibility model where yes, we'll manage the underlying infrastructure, but what's sitting on the infrastructure? Workloads, data, and that is something that developers should care about, but that's not necessarily been something they have been aligned to in the past.
So I think what NetApp and us are trying to say let's bring the depth developer and operate a community together so they can address that, share the responsibility for data. >> So at some point I'll have someone from NetApp on or somebody from the FSx team specifically- >> Yeah. >> To talk about that solution and why it's important. >> Yeah. >> But we brought you on to talk about a natural combination of environments. AWS famously a few years ago started to meet IT infrastructure professionals and IT infrastructure where they were which is- >> Yep.
>> I have workloads that make sense- >> Yes. >> On VMware vSphere, and I don't need EC2 or S3 or any of the AWS native services itself, but I want the power in the elasticity of the AWS underlay. So over the past few years, VMware and AWS has done the hard work of delivering VMC on AWS. A next logical progression is your role within AWS which is talking about the newish service announced AWS backup, but first I want to hit on your title.
>> Yeah. >> That's an unusual title, Ken. >> Sure. So the Service Solutions Architect, a couple of the things that differentiate us is I actually work as part of a service team in this case is the AWS Data Protection Service Team, and we're very focused. Our charter really is to help customers protect their data wherever it's sitting, whether it's in AWS or even on prem. And my role as an SA is really to be the voice of the customer back to our product manager and engineering team.
I lead a team right now. All of us on this team not only have vendor experience, but we have operator experience dealing with infrastructure and dealing with data and backup and protecting that data. So our job is to go to the product management and engineering team and go, this is what customers need in order to be able to protect their data in a scalable way. So yeah, so that is kind of the, that's why it's a Service SA role because it's really we're functioning on behalf of the customer back to a specific service team.
>> Okay. That makes sense. Walk me through the customer journey- >> Yeah. >> When it comes to data protection. >> Sure. >> Especially on AWS, I've decided that I'm going to move to the public cloud, and I'm going to initially do a lift and shift. I'm going to go from VMware vSphere on premises to VMC on AWS. I need to back that up. >> Yep. >> I need to protect that data. Where does AWS data protection come in with that customer?
>> Sure. So I talked about the share responsibility model when it comes to security and also protecting your environment. So, again, AWS, along with VMware, we're protecting say the configuration, right, of your infrastructure, but for the customer they are still responsible for protecting the data itself. And what we want to do is provide all the tools you need, the customers need to be able to do that. So one of the first service that came out with the AW, for the Data Protection Team was AWS Backup.
And the idea is we, Kelsey just came to us and said, we, you know, we like the fact that there are, you have all these services, all these places that can store your data, but what happens if there's an outage? What happens if there's a problem or corruption? How do I make sure that I can recover that data in an easy way? So in response to that, the Data Protection Team was formed and we created a solution, first a solution that would help customers backup and recover their data on any service in AWS.
We're starting, right now we actually support 15 services in AWS, and that list will continue to grow over time. >> So help me out with that overall capability and think this through. So I'm hoping- >> Yeah. >> VMs on, let's say it's the FSx Service on NetApps or even I'm extending the VM storage to the non-NetApp. >> Yeah. >> Version, on tap version of the service. How, am I able to natively back that up and is that now independent of my VMC on AWS deployment?
>> So a couple of things there, and I'm glad we're talking about FSx and VMC because like you said, that was announced at VMware Explore, and we support both services in terms of backing up and protecting those environments so with AW's backup, we really think about three pillars based on customer discussions. And the first pillar is data resiliency, right, across as many services as possible so and that means being able to recover data wherever it sits when it needs to be, but also means it has to be some kind of separation, right, where if someone was to able, so for example, to hack into the production environment, they should not be able to then have the permission to go in and delete all your backups for the type of the backups.
So that was something that we've built into AWS backup as a core feature is we have the service that can protect 15 data across 15 services. And the way we store those backups, even if someone compromised the production account, they cannot actually do anything to the backups themselves. So that's one way to, again, a tool to give customers a way to protect their data in, you know, against not only corruption, but, again, against hackers. And the second pillar is the customers will say is that's great.
We actually know that in services like EBS and RDS, there is already data protection built in natively, but a customer would have to be able to go to each of those consoles, right, and set up backup policies for each of those. So one of the core value problems of data is backup is we simplify and unify backup management across all services within one dashboard and one set of ATIs. So you can, for example, create a policy for how you want, how long, when backup should be taking, how long they should be retained, things like that.
And you can do that across all those services and apply them to either one, two, three or 15 services, if you want for whatever reason to have the same policy across all services. And then kind of the third pillar is customer said, hey, I'm back now and I'm back in with this data, how do I have visibility to know I'm compliant, right? What if something over time drifts and now I cannot, and now I thought I was backing up this data, but it actually isn't happening.
So we provide that through a tool called Backup Auto Manager where you can actually, we'll actually be able tell a customer, hey, you have all these VMs, and you initially set them to be, have a certain backup policy. Now over time for some reason they've drifted or maybe or more likely you've created some new VMs and you forgot to make sure that they've been, they're following this backup policy. So those are kind of the three ways that we're helping customers kind of manage their backup data protection across- >> So let, I think I'm starting to understand the value of those three pillars.
Let's walk through kind of that typical lift and expand. >> Yep. >> Lift, shift, and expand- >> Yep. >> Motion that customers are in. >> Yeah. >> So I've lifted my VMware environment from my private data center >> Yep. >> Into VMC on AWS. >> Yep. >> I may continue to use my existing Data Protected Solutions. >> Sure. >> And then I decide that we're going to move forward. We're going to break up an application that currently uses a Oracle database to that's running in a VM.
>> Yep. >> To provide the persistent layer of data. And I'm going to move that to RDS. >> Yes. >> And now when I look at my existing backup solution, that backup solution doesn't protect RDS directly. >> Right. >> It protects my VMs, but not my RDS data set. >> Exactly. >> Now I can, if I'm hearing you correctly, I can move to AWS backup or data protection, have one policy for the application VM. >> Yep.
>> And the same policy for RDS in a single solution. >> Yeah. And that extends beyond even, you know, another use case for customers have so maybe they have that database that's sending an RDS and now they want to do some analytics on the data. So maybe they export that out to an S3 bucket, and they want to be able to do analytics on that, but they want, they also want to make sure that that data's protected as well, and we enable that.
So now, as you said, they can do it across all these services and instead of having to match the backups for each one separately, they can match under one unified interface. >> So I know my audience. >> Yep. >> And this is VMware Explore 2022. >> Yes. >> They're going to ask the question. Okay. That's great. But one of the big selling points for VMC on AWS is that connection between my VMware environment whether it's transient or it's a permanent relationship where I have my vSphere located on premises, and I have VMC on AWS and the AWS infrastructure.
Now I have two different backup solutions. >> Right. And, first of all, I do want to say there may be use cases where that actually make sense. >> Right. >> Especially in a hybrid environment where a customer maybe not just have VMware, but maybe they have Solaris, right? HP-UX even, right? >> Yes. >> That they are bare metal Windows that they're protecting on premises. And so in that situation, it makes sense for them to keep what they have, but it is also the case that we do have customers that maybe want to use a native solution.
And like you said, they want to protect their VMware environment both on premises and in the cloud. So one of the side benefits of building something for VMware cloud and AWS is the methodology we follow to be able to backup that environment. It's actually infrastructure agnostic in the sense that we can actually back up VMware wherever it sits as long as you have a vCenter environment. (host laughing) And that you're leveraging the vSphere APIs for data protection, we can actually back that up.
>> Yeah. I don't know if there's too many EX SI only customers looking to leverage VMC on AWS and- >> Right. >> And AWS backup. That would be, if you have that use case, I would love to hear from you. (Ken laughing) That's really unique- >> Yeah. >> In this case. >> So in that case, again, there's a certain use case where a customer goes, so I'm back. I'm going to use AWS backup to protect VMware cloud on AWS.
And because I want to use a single interface, they may choose to then also backup their on prem environment. >> So you walked right into kind of my next question which is I might have other stuff. >> Yes. >> I may need, I might decide that I want to use AWS backup to back up native AWS services because there's 15 services that you backup. >> Yeah. >> And I haven't ran into another data protection company that can make that claim.
>> No, right. >> For AWS that they back up 15 different services. So that's compelling, but there's features and needs beyond those AWS services. So talk to me about that relationship with the other data protection companies. >> Sure. So, you know, first and foremost, I want to say, you know, AWS actually has a very deep and wide partner program. So we really value our backend recovery partners, you know, the Veeams, the CommVault, the Veritas, Flumios, N2WS. I'm sure, I'm probably forgetting a few more, but we value all those partners, and we want to work with them.
So we feel that our product, our solution and theirs is actually complimentary in a couple of ways. One is that for certain customers, it may, like you say, if they have workloads that they require of the, for example, or CommVault to protect, they can keep that. And they can also use AWS backup, but we have customers that also want to say, you know what? I want to be able to backup all the services in AWS. And I also want to back to everything on prem, and I want to use the tool that I already been using for the last 10 years.
We completely respect that. So one of the things that I'm doing as a Service SA is trying to work with these partners and basically allow them to leverage our ATIs so that they can gain all the benefits of AWS backup but as they integrate it with their tool. >> So in theory, if the relationships develop- >> Yeah. >> As you are describing it, I'll have a combo that's able to back up my Solaris, my AIX, my HP-UX, my AS/400 and through the same console where I can backup my RDS, my EC2.
>> Exactly. >> Even my VMC on AWS, if I can choose. And then I could use my combo policies that call the AWS APIs. >> Exactly. And the clear benefit there for those partners is we've and since then done a lot of the hard work of integrating with all these other services, like let's say 15 in all. And right now if each of our partners, they're doing a great job, but they have to integrate each service separately, and it takes time to do that, right.
We've already done that hard work. So where we want go to the partner and say, instead of you doing that, just write to the AWS backup APIs, and you basically gain all the benefits of the work that we've done already with those other service teams to integrate with their services. >> So we can't have this conversation, and my friend, Cory Quinn, will slap me on a risk if I don't talk- >> Sure >> About costing. >> Yeah. >> How much does this cost?
How do I pay for this? >> Yeah. So the, either it's backup service itself. There's no cost to it. What customers do pay for is the storage capacity used to store their backups, and the cost, yeah. And the cost, you know, is strictly on what we call our data plan where we're storing the backups. And there's a, you know, a typical monthly charge just like you would with any other service. >> So let's talk about the last piece which is cross AZ, disaster recovery.
>> Yeah. >> Or high availability, however you want to look at it. If the data lives in AWS, there's a couple of questions, one around cost, and then two around where I can restore to. >> Yeah. >> How does that work from both a technical perspective like how do I backup a solution from one AZ to another AZ? >> Right. >> Or even is that concept exposed to the end user? >> Yeah. So the way we want to think about backing up resources, it's really more at a regional level, right.
It doesn't matter where the AZ, which AZ you are because we can back that up when it's part of that region. What we want to do obviously we have do have customers that have workloads across multiple regions, and they want to back those up. We certainly enable that, but also we have certain cases where customers say so if you're familiar with the backup world, there's a concept called the 321 rule, you know, three copies of every data, two copies, at least two copies that are in some completely separate system then your production, and at least one copy that's in a totally different location.
S. east one. S. east one. >> Right. >> Makes perfect sense. So one of the things we are able to do is we can actually, customers can actually copy their backups across regions or even across accounts so that they in that sense is almost like a virtual air gap, right, from their production environment. So that's kind of one way that people do leveraging our services to be able to protect cross region cross account. The other thing we want to do, and I'll talk about this from a management perspective is sometimes you have different accounts, different regions, and there's backup policies that you need to have, you want to have across the entire state.
>> Right. It doesn't matter if I have eight different backup. I mean, AWS accounts. >> Yeah. >> I have one backup policy. >> Right. So traditionally you would have to manage that completely separately, every account. >> Right. >> One of the things we have done, though, with AWS backups we actually integrated with AWS organizations. So now from the top level admin organization, you can create a standard backup policy that says, hey, I'm going to protect all my VMware, my VMs.
And, by the way, I'm going to retain them for 30 days or to a year. And I want them all to get copied to a different region. You can dictate that at that admin level. And then you can push that down across all the accounts in that organization. >> So, Ken, I really appreciate you taking out the time to talk to me about AWS data protection. When I looked at, you know, the announcement that you moved to the team. >> Yeah.
>> I kind of scratched my head. >> Yeah. >> Like AWS data protection, how would that even work? >> Yep. >> We've answered that question. >> Sure. >> And I also really was curious about the relationships across backup vendors because if I do have other clouds, were it VMware Explore and the cross cloud conversation is there I'm thinking from, you know, the superset of a CommVault or a Veritas. >> Yep. >> Or Cohesivity, Rubrik, go down a list of how I need to go, yes, I need to go deep into AWS with the 15 services, but what about everything else?
And I think you've answered those questions. >> Yeah. >> If you have other questions for Ken, he's pretty prolific on Twitter. You can generally tweet at him, and he'll answer the question. >> Yes. >> But if you're too shy, you can DM me @ctoadvisor on Twitter. I'm more than happy to answer this question or anything else about data protection. You want to follow the CTO Advisor. com. Stay tuned for more coverage from VMware Explore 2022. Okay.
Thank you, Keith.