A Canadian-based automotive manufacturer approached Curious Orbit to help build, develop and manage a centralized solution that would allow them to reduce management overhead while improving the overall security of a growing number of public-facing applications used by their extensive network of partners.
As the customer continued to move more applications to AWS, they faced several challenges. First, they needed a cost-effective solution capable of handling the current workload and scaling to handle the anticipated future throughput requirements as more applications moved to AWS.
In addition to scalability, the customer needed a solution that could help them meet their compliance requirements with a small operations staff who are not directly responsible for each AWS account used by the various product teams.
Curious Orbit engaged with the operations, application, and security teams to design, build, and manage a container-based solution to handle Internet-based traffic for a growing number of public-facing applications.
The final solution meets the customers' scaling requirements while helping to manage costs by leveraging running reverse proxy containers on Fargate. By running containers on Fargate, we shift much of the day-to-day infrastructure management to AWS, which allows the operations team to focus on more essential tasks like rule management and monitoring.
The new centralized WAF solution delivered by Curious Orbit provides our customer with a cost-effective, flexible solution that scales to meet their current and future requirements while shifting responsibility for much of the day-to-day management to AWS by leveraging AWS-managed services where appropriate.
By leveraging AWS-managed services, the operations team efficiently manages WAF rules and network connectivity for multiple AWS accounts, on-premise solutions, and third-party applications. Thanks to a combination of AWS and customer-managed rules, the WAF can easily handle 10K client requests/minute. The reverse proxy running on Fargate seamlessly scales from two to twenty containers, depending on the number of client requests.
The security team can quickly analyze access logs, generate reports and send outbound notifications from a central account. Centralizing the logs ensures their integrity while reducing the management overhead commonly associated with distributed logging solutions.
Tell me what you're trying to do on AWS and what "good" would look like. I'll come back with how I'd approach it.