Once upon a time in a Migration from Legacy to OCI Public Cloud
In my previous experience with AWS, Alibaba, Google and PTCL Public cloud I have been working with mostly green field deployment for in house solution with all in and out clear. This time I get challenge with a brown field migration from on-prem to OCI Public cloud for a big public service company. As I always say go with the basic and build from the scratch we start a kick-off meeting with the customer and ask about their plan for this migration and what they are planning for it after discussing we get to know that whole environment need to be migrated so at that time, we bring the most tough ask on the table as plan was that customer want to perform migration in phases with more than 20 application on-boarded in current environment as i studied during my AWS exam preparation it's never suggested to use same IPs across different environments to avoid complicity and better plan for the migration we ask for the change of IPs for the instances that includes Web, Application and DB tier which currently hosting the services eventually application owners need to be on-boarded so from the first day of planning we had this alignment that this migration will not be only depends on the infrastructure planning only we need to on-board the application team as main stake holder while doing the migration aim was to achieve micro-segmentation and enhance the security after initial kick-off meeting and gathering customer information we took our time and come up with our solution design for the implementation after getting the require approval from all the stake holders.
We build Hub and spoke topology using DRG services while building the proposed solution we kept both solution from our end as one was consisting of in-build OCI solution like OCI Firewall and OCI Load balancer with WAF Policy, second one which was consisting of the OEM solutions for Firewall and load balancing and WAF services after approval we did the deployment as per our plan and start the migration from on-prem to cloud i will not say it went easily all teams work really hard to achieve it but only thing which we were able to do without impacting the current production was testing and make sure that all services was working fine still many integration came out on the night of migration as they were too much but not enough to make a major impact on our migration plan and at the end it went fine.
Lesson learns from this migration always bring all the possibilities on the tables so other teams can understand the thought process, don't over promise and make sure that all parties understand their responsibilities and roles and at the end don't thing that after migrating workload to cloud it will be secure by default it need to be plan and then implement accordingly to make sure its fully secure.
Raja Shajeel Ahmad
Hybrid Data Center Network & Security Operations and Planning
Happy Learning
The limit is the sky.
Comments