SlideShare a Scribd company logo
Techniques for Scaling Application
with Security and Visibility
in Cloud
Akshay Mathur
@akshaymathu of @appcito
Let’s Know Each Other
• Do you Manage applications?
• Hosting providers?
• Priorities?
• Tools?
• Why are you attending?
• What are your Goal?
• Happy Users, Happy DevOps, Happy Servers
2@akshaymathu
Akshay Mathur
• 15+ years in IT industry
• Currently Product Manager at Appcito
• Mostly worked with Startups
• From Conceptualization to Stabilization
• At different functions i.e. development, testing, release, marketing, devops
• With multiple technologies
• Founding Team Member of
• ShopSocially (Enabling “social” for retailers)
• AirTight Neworks (Global leader of WIPS)
@akshaymathu 3
Ground Rules
• Tweet now: #TechNext @akshaymathu @appcito
• Disturb Everyone later
• Not by phone rings
• Not by local talks
• By more information and questions
@akshaymathu 4
How Applications are Changing
Traditional Application
• Monolithic components
• All application layers in a box
• Complex objects
• Box specific sessions
• Designed for vertical scale
• Self managed deployment
@akshaymathu 6
New Age Scalability
@akshaymathu 7
Cloud Computing Landscape
@akshaymathu 8
Architectural Mind-shift
@akshaymathu 9
Modern Application
• Light weight services
• Application layers designed for
network communication
• Cloud deployment
• Designed for horizontal scale
@akshaymathu 10
@akshaymathu 11
Growing Applications
Growth Phase 1: Load Balancing
• Replicate the box
• Have a load balancer
@akshaymathu 13
Questions before Growing Further
• About Insights:
• Are all server instances healthy?
• When should I add more servers?
• What is the traffic volume and its
pattern?
• What areas of application are used
most?
• What are problematic areas?
• Who access my application?
• What devices, browsers, apps are in
use?
• About Optimization:
• How can I serve more traffic using
existing servers?
• Does all the serves must be of same
type, running same code?
• Can the content be compressed,
cached?
• What to do for optimizing content for
various devices?
• Do I really need to redirect traffic to a
different URLs for specific servings?
• Does managing so many URLs for same
functionality makes sense?
• Can someone take care of SSL
termination?
@akshaymathu 14
Growth Phase 2: Insights
• Google Analytics, Statcounter etc. only provide
information after page load
• Information about programmatic access is missing
• Access logs provide true information about traffic
• Logs are typically in each box rather than a central place
• Difficult to read; log parsers also provide minimal
information
• Need to push logs to some analytics engine and
configure analytics engine for getting meaningful
information out
@akshaymathu 15
Growth Phase 3: Content Optimization
• Compressing the response
• Optimizing images
• In-lining the external resources
• JS
• CSS
• Images as base64
• Caching (as needed)
• Prefetching (if possible)
• Google’s PageSpeed does it well for HTML pages
@akshaymathu 16
Growth Phase 4: Offloading
• SSL Handshake
• Encryption and Decryption
• Connection handling
• Content optimization
• Anything that can be done asynchronously
e.g. sending email, tweets etc.
• Point solutions are available for each of
these
@akshaymathu 17
App Servers
Apache + Pylons
Message Queue
RabbitMQ
Background
Worker Nodes
Celery
SSL Terminator
Content Optimizer
Growth Phase 5: Content Switching
• Serve different content from different servers (reverse proxy)
• Static files (JS, CSS, Images) may be served from a web server; App server is not
needed
• High frequency requests may be served from different server
• Different app servers may be used for the use case they are optimized for
• Have different set of servers for different geographies
• Dedicate a few servers for specific customer
• Dedicate servers for specific functions e.g. authentication, API serving etc.
• HA Proxy is most popular tool here
• NginX is also used as reverse proxy
@akshaymathu 18
Web Servers
NginX
App Servers
Mongral + Brubeck
App Servers
Apache + Pylons
Web Servers
Apache + Wordpress
NoSql Datastore
Redis
NoSql Datastore
MongoDB
Sql Datastore
MySql
Corporate
website
Main dynamic
content
High frequency
requests
High speed storage Main Storage
Content Switching
Reverse Proxy
Growth Phase 6: Denying BOT Traffic
• Traffic from bad BOTs is about 30%
• Amounts to 30% wastage of server
resources
• Various fingerprinting techniques
are there for identifying the BOTs
• IP reputation
• UA analysis
• Pattern analysis
• JS insertion
• Advance algorithms
@akshaymathu 20
Growth Phase 7: Preventing Data Theft
• Typical ways are:
• SQL/object injection
• Cross Site Scripting (XSS)
• File include
• Malware inclusion
• Exploiting vulnerabilities of coding, framework,
language, platform
• Scan the deployment regularly
• Fix any vulnerability by applying patches
• Use Web Application Firewall (WAF)
@akshaymathu 21
Growth Phase 8: Preventing from DDoS Attack
• Volumetric attack
• Many clients make connections with
server
• Clients send huge traffic to the server
• Traffic is typically bogus
• Prevention
• Rapidly increase scale to consume
connections/traffic
• Rate limit connections/requests
• Delay/Deny bogus traffic
• Blacklist BAD clients
• Protocol exploits
• Attacker crafts traffic knowing the
timeouts and limits of protocol
• Slow moving bogus traffic hogs
resources of server
• Prevention
• Setup policy to apply aggressive limits
and timeouts in case of heavy load
• Terminate connection when unusual
behavior is observed
• Blacklist BAD client
@akshaymathu 22
Growth Phase 7: Continuous Delivery
• Upgrade the system without disturbing availability
• Why Continuous Delivery?
@akshaymathu 23
Continuous Delivery
• Considerations:
• Zero down time
• Even a little downtime means a lot for
high volume applications
• Seamless re-orientation of live traffic
from old to new deployment
• User experience has to be smooth
• Easy roll back
• Minimize the impact in case something
goes wrong
• Technique: Blue Green deployments
• Deploy old and new version in parallel
and switch the traffic
• Switch using DNS
• Switch using fixed NATed IP addresses
• Switch using external tools like load
balancer or reverse proxy
25@akshaymathu
App & Traffic
Metrics
What is Needed Overall?
26
Availability Performance Security DevOps
Advanced Load
Balancing
Content Switching
Application Fluency
Elastic & Self-Scaling
Continuous
Deployment
Request Mirroring
Request Replay
Programmable
Policies
Per Application
Control
Front-End
Optimization
Mobile and Web
Client App
optimization
Caching &
compression
Predictive API
caching
Application & Server
offloading
Application Firewall
Elastic SSL
Anomaly Detection
DDoS Prevention
BOT Protection
Trends &
Correlations Anomalies
Policy
Recommendations
Analytics & Insights
CDN
Custom Scripts, Rules, Alert Management Aggregation across instances
Application Front-End Architecture
• Spaghetti of point solutions
• Multiple points of failure, redundancy difficult to setup
• Not elastic and cloud native
@akshaymathu 27
CDN
Application Front-End Architecture with CAFE
• All services for application under one consolidated product
• Easy Activation of capabilities closer to application
• Application policy is coordinated across services and policy enforced
@akshaymathu 28
Availability Security Performance Continuous
Deployment
Appcito Cloud Application Front-End (CAFE)
Cloud Application Front End
(CAFE)
Taking Cloud Applications from Good to Great
Appcito CAFE Service
Insights &
Analytics
Content
Optimization
Application
Security & DDoS
Prevention
Unified Functionality Available As
SaaS Delivery
Simple Activation
No Code Change
For
Dev /Ops
Cloud-agnostic
App Owner
Elastic
Continuous
Delivery
Availability &
Elasticity
Typical Deployment
Customer’s Cloud
Customer’s
End Users
app
server
app
server
Load
Balancer
app
server
DNS
Network Subnet
Availability Zone
Deployment with CAFE
Customer’s Cloud
Customer’s
End Users
app
server
app
server
Load
Balancer
app
server
Appcito Cloud
CAFE Barista
Management, Control, Analytics
DNS
CAFE
PEP
Network Subnet
Availability Zone
CAFE Configuration Model
• Think Out of the box (literally)
• Think in terms of
• Applications
• Traffic flow
• Request patterns
• Forget about
• Box provisioning
• Box configuration
• Networking flow
• L2/L3 access control
@akshaymathu 33
Production A (Blue)
Production B (Green)
Launch
Upgrade
Traffic Splitting
80% 20%
Appcito CAFE
80%
20%
CAFE Blue/Green Technique
• Steer traffic NOT switch
• Test with production traffic
• Move with confidence
• Compare performance and take informed
decisions
App & Traffic
Metrics
Appcito CAFE Service Capabilities
35
Availability Performance Security DevOps
Advanced Load
Balancing
Content
Switching
Application
Fluency
Elastic & Self-
Scaling
Continuous
Deployment
Request
Mirroring
Request Replay
Programmable
Policies
Per Application
Control
Front-End
Optimization
Optimization for
client
Caching &
compression
Predictive caching
Application &
Server offloading
Application
Firewall
Elastic SSL
Anomaly
Detection
DDoS
BOT Protection
Trends &
Correlations
Anomalies
Detection
Policy
Recommendation
Analytics & Insights
Thanks
@akshaymathu 36
@akshaymathu
akshay@appcito.com

More Related Content

PPTX
Cloud Bursting with A10 Lightning ADS
PPTX
Kubernetes as Orchestrator for A10 Lightning Controller
PDF
Overcoming 5 Common Docker Challenges: How We Do It at RightScale
PPTX
Server Monitoring from the Cloud
PDF
Project Sherpa: How RightScale Went All in on Docker
PPTX
Tokyo azure meetup #8 - Azure Update, August
PDF
Monitoring Your AWS Cloud Infrastructure
PDF
Better, faster, cheaper infrastructure with apache cloud stack and riak cs redux
Cloud Bursting with A10 Lightning ADS
Kubernetes as Orchestrator for A10 Lightning Controller
Overcoming 5 Common Docker Challenges: How We Do It at RightScale
Server Monitoring from the Cloud
Project Sherpa: How RightScale Went All in on Docker
Tokyo azure meetup #8 - Azure Update, August
Monitoring Your AWS Cloud Infrastructure
Better, faster, cheaper infrastructure with apache cloud stack and riak cs redux

What's hot (19)

PPTX
Tokyo azure meetup #9 azure update, october
PPTX
Tokyo Azure Meetup #9 - Azure Update, september
PPTX
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
PPTX
Launch and Scale Your E-commerce Website with Magento
PPTX
[Webinar] AWS Monitoring with Site24x7
PPTX
Discovering Cloud Networking: VPC, VPN, Express Connect & Server Load Balancer
PDF
Azure Service Endpoints vs. Private Links
PPTX
Grails in the Cloud (2013)
PPTX
NextGen IBM Cloud Monitoring and Logging
PPTX
Tokyo azure meetup #12 service fabric internals
PPTX
Greetings from AWS User Group Taiwan
PDF
Pivoting Spring XD to Spring Cloud Data Flow with Sabby Anandan
PDF
Load Balancers vs IIS ARR or a Web Application Proxy (WA) for HA
PDF
Intro to Serverless
PDF
Lessons from the field: Catalog of Kafka Deployments | Joseph Niemiec, Cloudera
PPTX
Importance of ‘Centralized Event collection’ and BigData platform for Analysis !
PDF
Scala Security: Eliminate 200+ Code-Level Threats With Fortify SCA For Scala
PDF
Network security with Azure PaaS services by Erwin Staal from 4DotNet at Azur...
PPTX
Serverless Patterns
Tokyo azure meetup #9 azure update, october
Tokyo Azure Meetup #9 - Azure Update, september
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Launch and Scale Your E-commerce Website with Magento
[Webinar] AWS Monitoring with Site24x7
Discovering Cloud Networking: VPC, VPN, Express Connect & Server Load Balancer
Azure Service Endpoints vs. Private Links
Grails in the Cloud (2013)
NextGen IBM Cloud Monitoring and Logging
Tokyo azure meetup #12 service fabric internals
Greetings from AWS User Group Taiwan
Pivoting Spring XD to Spring Cloud Data Flow with Sabby Anandan
Load Balancers vs IIS ARR or a Web Application Proxy (WA) for HA
Intro to Serverless
Lessons from the field: Catalog of Kafka Deployments | Joseph Niemiec, Cloudera
Importance of ‘Centralized Event collection’ and BigData platform for Analysis !
Scala Security: Eliminate 200+ Code-Level Threats With Fortify SCA For Scala
Network security with Azure PaaS services by Erwin Staal from 4DotNet at Azur...
Serverless Patterns
Ad

Viewers also liked (7)

PPTX
Shared Security Responsibility Model of AWS
PPTX
Azure Cloud Application Design and Implementation Guidance の紹介
PPTX
Introduction to Azure Service Fabric
PPTX
Object Oriented Programing in JavaScript
PDF
DDoS Attack Detection & Mitigation in SDN
PPTX
Introduction to Node js
PPT
F5 link controller
Shared Security Responsibility Model of AWS
Azure Cloud Application Design and Implementation Guidance の紹介
Introduction to Azure Service Fabric
Object Oriented Programing in JavaScript
DDoS Attack Detection & Mitigation in SDN
Introduction to Node js
F5 link controller
Ad

Similar to Techniques for scaling application with security and visibility in cloud (20)

PPTX
Building a Real-Time Security Application Using Log Data and Machine Learning...
PDF
Cloud-native Data
PDF
Cloud-Native-Data with Cornelia Davis
PDF
Out With the Old, in With the Open-source: Brainshark's Complete CMS Migration
PDF
NUS-ISS Learning Day 2018- Designing software to make the most of cloud platf...
PDF
UI Dev in Big data world using open source
PPTX
Global Azure 2022 - Architecting Modern Serverless APIs with Azure Functions ...
PDF
Gcp intro-20160721
PPTX
In-Stream Processing Service Blueprint, Reference architecture for real-time ...
PPTX
Comparing Legacy and Modern e-commerce solutions
PPTX
Migrating Lotus Notes Applications to Sharepoint Online with Nintex
PDF
Making Cloud Deployment A Reality For End-To-End Policy Administration
PPTX
Using Google App Engine Python
PPTX
Потоковая обработка больших данных
PDF
Serverless: Market Overview and Investment Opportunities
PDF
Making the Transition from Suite to the Hub
DOC
PDF
MuleSoft Manchester Meetup #4 slides 11th February 2021
PPTX
Do I Need A Service Mesh.pptx
PPTX
Re-Platforming Applications for the Cloud
Building a Real-Time Security Application Using Log Data and Machine Learning...
Cloud-native Data
Cloud-Native-Data with Cornelia Davis
Out With the Old, in With the Open-source: Brainshark's Complete CMS Migration
NUS-ISS Learning Day 2018- Designing software to make the most of cloud platf...
UI Dev in Big data world using open source
Global Azure 2022 - Architecting Modern Serverless APIs with Azure Functions ...
Gcp intro-20160721
In-Stream Processing Service Blueprint, Reference architecture for real-time ...
Comparing Legacy and Modern e-commerce solutions
Migrating Lotus Notes Applications to Sharepoint Online with Nintex
Making Cloud Deployment A Reality For End-To-End Policy Administration
Using Google App Engine Python
Потоковая обработка больших данных
Serverless: Market Overview and Investment Opportunities
Making the Transition from Suite to the Hub
MuleSoft Manchester Meetup #4 slides 11th February 2021
Do I Need A Service Mesh.pptx
Re-Platforming Applications for the Cloud

More from Akshay Mathur (15)

PPTX
Documentation with Sphinx
PPTX
Kubernetes Journey of a Large FinTech
PPTX
Security and Observability of Application Traffic in Kubernetes
PPTX
Enhanced Security and Visibility for Microservices Applications
PPTX
Considerations for East-West Traffic Security and Analytics for Kubernetes En...
PPTX
Getting Started with Angular JS
PDF
Releasing Software Without Testing Team
PPTX
Getting Started with jQuery
PPTX
CoffeeScript
PPTX
Creating Single Page Web App using Backbone JS
PPTX
Getting Started with Web
PPTX
Getting Started with Javascript
PPTX
Working with GIT
PPTX
Testing Single Page Webapp
PPTX
Mongo db
Documentation with Sphinx
Kubernetes Journey of a Large FinTech
Security and Observability of Application Traffic in Kubernetes
Enhanced Security and Visibility for Microservices Applications
Considerations for East-West Traffic Security and Analytics for Kubernetes En...
Getting Started with Angular JS
Releasing Software Without Testing Team
Getting Started with jQuery
CoffeeScript
Creating Single Page Web App using Backbone JS
Getting Started with Web
Getting Started with Javascript
Working with GIT
Testing Single Page Webapp
Mongo db

Recently uploaded (20)

PDF
KodekX | Application Modernization Development
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Big Data Technologies - Introduction.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Smarter Business Operations Powered by IoT Remote Monitoring
PDF
SAP855240_ALP - Defining the Global Template PUBLIC.pdf
PPTX
Cloud computing and distributed systems.
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
cuic standard and advanced reporting.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
PDF
Modernizing your data center with Dell and AMD
PDF
NewMind AI Monthly Chronicles - July 2025
KodekX | Application Modernization Development
GamePlan Trading System Review: Professional Trader's Honest Take
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
Review of recent advances in non-invasive hemoglobin estimation
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
20250228 LYD VKU AI Blended-Learning.pptx
Big Data Technologies - Introduction.pptx
MYSQL Presentation for SQL database connectivity
“AI and Expert System Decision Support & Business Intelligence Systems”
Smarter Business Operations Powered by IoT Remote Monitoring
SAP855240_ALP - Defining the Global Template PUBLIC.pdf
Cloud computing and distributed systems.
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
AI And Its Effect On The Evolving IT Sector In Australia - Elevate
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
cuic standard and advanced reporting.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
Modernizing your data center with Dell and AMD
NewMind AI Monthly Chronicles - July 2025

Techniques for scaling application with security and visibility in cloud

  • 1. Techniques for Scaling Application with Security and Visibility in Cloud Akshay Mathur @akshaymathu of @appcito
  • 2. Let’s Know Each Other • Do you Manage applications? • Hosting providers? • Priorities? • Tools? • Why are you attending? • What are your Goal? • Happy Users, Happy DevOps, Happy Servers 2@akshaymathu
  • 3. Akshay Mathur • 15+ years in IT industry • Currently Product Manager at Appcito • Mostly worked with Startups • From Conceptualization to Stabilization • At different functions i.e. development, testing, release, marketing, devops • With multiple technologies • Founding Team Member of • ShopSocially (Enabling “social” for retailers) • AirTight Neworks (Global leader of WIPS) @akshaymathu 3
  • 4. Ground Rules • Tweet now: #TechNext @akshaymathu @appcito • Disturb Everyone later • Not by phone rings • Not by local talks • By more information and questions @akshaymathu 4
  • 6. Traditional Application • Monolithic components • All application layers in a box • Complex objects • Box specific sessions • Designed for vertical scale • Self managed deployment @akshaymathu 6
  • 10. Modern Application • Light weight services • Application layers designed for network communication • Cloud deployment • Designed for horizontal scale @akshaymathu 10
  • 13. Growth Phase 1: Load Balancing • Replicate the box • Have a load balancer @akshaymathu 13
  • 14. Questions before Growing Further • About Insights: • Are all server instances healthy? • When should I add more servers? • What is the traffic volume and its pattern? • What areas of application are used most? • What are problematic areas? • Who access my application? • What devices, browsers, apps are in use? • About Optimization: • How can I serve more traffic using existing servers? • Does all the serves must be of same type, running same code? • Can the content be compressed, cached? • What to do for optimizing content for various devices? • Do I really need to redirect traffic to a different URLs for specific servings? • Does managing so many URLs for same functionality makes sense? • Can someone take care of SSL termination? @akshaymathu 14
  • 15. Growth Phase 2: Insights • Google Analytics, Statcounter etc. only provide information after page load • Information about programmatic access is missing • Access logs provide true information about traffic • Logs are typically in each box rather than a central place • Difficult to read; log parsers also provide minimal information • Need to push logs to some analytics engine and configure analytics engine for getting meaningful information out @akshaymathu 15
  • 16. Growth Phase 3: Content Optimization • Compressing the response • Optimizing images • In-lining the external resources • JS • CSS • Images as base64 • Caching (as needed) • Prefetching (if possible) • Google’s PageSpeed does it well for HTML pages @akshaymathu 16
  • 17. Growth Phase 4: Offloading • SSL Handshake • Encryption and Decryption • Connection handling • Content optimization • Anything that can be done asynchronously e.g. sending email, tweets etc. • Point solutions are available for each of these @akshaymathu 17 App Servers Apache + Pylons Message Queue RabbitMQ Background Worker Nodes Celery SSL Terminator Content Optimizer
  • 18. Growth Phase 5: Content Switching • Serve different content from different servers (reverse proxy) • Static files (JS, CSS, Images) may be served from a web server; App server is not needed • High frequency requests may be served from different server • Different app servers may be used for the use case they are optimized for • Have different set of servers for different geographies • Dedicate a few servers for specific customer • Dedicate servers for specific functions e.g. authentication, API serving etc. • HA Proxy is most popular tool here • NginX is also used as reverse proxy @akshaymathu 18
  • 19. Web Servers NginX App Servers Mongral + Brubeck App Servers Apache + Pylons Web Servers Apache + Wordpress NoSql Datastore Redis NoSql Datastore MongoDB Sql Datastore MySql Corporate website Main dynamic content High frequency requests High speed storage Main Storage Content Switching Reverse Proxy
  • 20. Growth Phase 6: Denying BOT Traffic • Traffic from bad BOTs is about 30% • Amounts to 30% wastage of server resources • Various fingerprinting techniques are there for identifying the BOTs • IP reputation • UA analysis • Pattern analysis • JS insertion • Advance algorithms @akshaymathu 20
  • 21. Growth Phase 7: Preventing Data Theft • Typical ways are: • SQL/object injection • Cross Site Scripting (XSS) • File include • Malware inclusion • Exploiting vulnerabilities of coding, framework, language, platform • Scan the deployment regularly • Fix any vulnerability by applying patches • Use Web Application Firewall (WAF) @akshaymathu 21
  • 22. Growth Phase 8: Preventing from DDoS Attack • Volumetric attack • Many clients make connections with server • Clients send huge traffic to the server • Traffic is typically bogus • Prevention • Rapidly increase scale to consume connections/traffic • Rate limit connections/requests • Delay/Deny bogus traffic • Blacklist BAD clients • Protocol exploits • Attacker crafts traffic knowing the timeouts and limits of protocol • Slow moving bogus traffic hogs resources of server • Prevention • Setup policy to apply aggressive limits and timeouts in case of heavy load • Terminate connection when unusual behavior is observed • Blacklist BAD client @akshaymathu 22
  • 23. Growth Phase 7: Continuous Delivery • Upgrade the system without disturbing availability • Why Continuous Delivery? @akshaymathu 23
  • 24. Continuous Delivery • Considerations: • Zero down time • Even a little downtime means a lot for high volume applications • Seamless re-orientation of live traffic from old to new deployment • User experience has to be smooth • Easy roll back • Minimize the impact in case something goes wrong • Technique: Blue Green deployments • Deploy old and new version in parallel and switch the traffic • Switch using DNS • Switch using fixed NATed IP addresses • Switch using external tools like load balancer or reverse proxy
  • 26. App & Traffic Metrics What is Needed Overall? 26 Availability Performance Security DevOps Advanced Load Balancing Content Switching Application Fluency Elastic & Self-Scaling Continuous Deployment Request Mirroring Request Replay Programmable Policies Per Application Control Front-End Optimization Mobile and Web Client App optimization Caching & compression Predictive API caching Application & Server offloading Application Firewall Elastic SSL Anomaly Detection DDoS Prevention BOT Protection Trends & Correlations Anomalies Policy Recommendations Analytics & Insights
  • 27. CDN Custom Scripts, Rules, Alert Management Aggregation across instances Application Front-End Architecture • Spaghetti of point solutions • Multiple points of failure, redundancy difficult to setup • Not elastic and cloud native @akshaymathu 27
  • 28. CDN Application Front-End Architecture with CAFE • All services for application under one consolidated product • Easy Activation of capabilities closer to application • Application policy is coordinated across services and policy enforced @akshaymathu 28 Availability Security Performance Continuous Deployment Appcito Cloud Application Front-End (CAFE)
  • 29. Cloud Application Front End (CAFE) Taking Cloud Applications from Good to Great
  • 30. Appcito CAFE Service Insights & Analytics Content Optimization Application Security & DDoS Prevention Unified Functionality Available As SaaS Delivery Simple Activation No Code Change For Dev /Ops Cloud-agnostic App Owner Elastic Continuous Delivery Availability & Elasticity
  • 31. Typical Deployment Customer’s Cloud Customer’s End Users app server app server Load Balancer app server DNS Network Subnet Availability Zone
  • 32. Deployment with CAFE Customer’s Cloud Customer’s End Users app server app server Load Balancer app server Appcito Cloud CAFE Barista Management, Control, Analytics DNS CAFE PEP Network Subnet Availability Zone
  • 33. CAFE Configuration Model • Think Out of the box (literally) • Think in terms of • Applications • Traffic flow • Request patterns • Forget about • Box provisioning • Box configuration • Networking flow • L2/L3 access control @akshaymathu 33
  • 34. Production A (Blue) Production B (Green) Launch Upgrade Traffic Splitting 80% 20% Appcito CAFE 80% 20% CAFE Blue/Green Technique • Steer traffic NOT switch • Test with production traffic • Move with confidence • Compare performance and take informed decisions
  • 35. App & Traffic Metrics Appcito CAFE Service Capabilities 35 Availability Performance Security DevOps Advanced Load Balancing Content Switching Application Fluency Elastic & Self- Scaling Continuous Deployment Request Mirroring Request Replay Programmable Policies Per Application Control Front-End Optimization Optimization for client Caching & compression Predictive caching Application & Server offloading Application Firewall Elastic SSL Anomaly Detection DDoS BOT Protection Trends & Correlations Anomalies Detection Policy Recommendation Analytics & Insights

Editor's Notes

  • #31: (RGB)
R=1 G=66 B=135 (RGB)
R=132 G=194 B=37