Month: July 2022

Cloudemy

I have been thinking about an online platform which can help the cloud enthusiast in kicking off the the cloud journey. To serve that, cloudemy.xyz domain has been registered. All the courses will be in localized language (Bangla). The development of the platform is in progress. Expected date of release is 1st August 2022. A place holder is there for now till the platform is released. Expecting to create an significant impact in cloud adaptability over here in Bangladesh.

Moodle LMS in AWS

Brain Station 23 is the only solution partner of Moodle in Bangladesh. We have been working with both local and global clients in development and consultancy capacity.

We have already done good amount of opensource contribution (https://moodle.org/plugins/browse.php?list=contributor&id=3524295) specially the ”Moodle Proctoring plugin which has been downloaded 1K+.

Regarding deploying Moodle in AWS, a recommended architecture given below which can ensure high availability:

AWS User Group Bangladesh reached 6K+ members

AWS User Group Bangladesh (https://www.facebook.com/groups/AWSBangladesh) was created in both Facebook and LinkedIn to have a strong community of AWS enthusiast. It was established more than 5 years ago and new members are joining to support each other. I am the co-founder of this group and community leader. We have a vision to play a key role in adopting cloud over here. We have been arranging lots of workshop, seminar all these years. Before pandemic, it was all physical event, now we are more into virtual event considering the participants safety. We are continuously contributing in solving different problems by the community members to strengthen the cloud adaptation.

Speaker in AWS Community Day 2021

AWS Community Day South Asia 2021 (https://communityday.awsug.asia/) happened in last October where both speakers and audiences from Bangladesh, India and Srilanka participated. I was the only Bangladeshi participated as speaker in this event.

My topic of the session was “Cutting an eCommerce application cloud costing by 70%“. Amazing speakers were sharing their knowledge which were really helpful.

I have shared the presentation deck below:

The recorded session can be found below for both track:

Track 01:

Track 02:

BS23 in AWS India Partner GameDay 2022

We, Brain Station 23 have participated in AWS Partner GameDay 2022 on 20th May 2022 for the first time. I was one of the members of the team. Brain Station 23 secured the 19th position amongst 76 teams; the only #Bangladeshi team got the invitation to participate on such an energetic event with different gigantic cloud teams like Infosys, Deloitte, Capgemini, Rapyder. It was a great opportunity to compete, learn & hone our skills at this #AWS event.

Brain Station 23 in Dubai

We have recently visited Dubai to have strong presence over there. Since Dubai is the hub of global major multinational companies, we see good traction of our service offerings. We had a very good discussion with local partner and met with different concerns who are interested to support us in expanding our services strongly over there. I have shared few of the snaps during our visit over there.

AWS Site-2-Site VPN with 3rd party ISP

Telco is a highly regulated industry in Bangladesh. The solution mentioned was for a major telco in Bangladesh. We were in process to migrate a number of on-premise workload to AWS cloud. One of the compliances from their end was not to connect to the internet directly from their infrastructure rather through a third part ISP which includes high availability. The solution got successfully deployed and working fine for more than 4 months without any downtime. As it is a common ask from many enterprises, this architecture would be helpful to be followed by others.

To comply with the company, we had to implement site-2-site VPN for one of the telco companies in Bangladesh. Here one of the constraints is there needs to have a 3rd party provider between AWS and client infrastructure along with fault tolerant. Considering the scope, we came up with the following architecture which might be helpful for others.

Migration of a Fintech application in AWS

We worked on a fintech application recently to receive the remittance from foreign countries people by one of the top banks in Bangladesh.

Since the solution is in on-premise capacity, the shared architecture was proposed in migrating to AWS cloud. Having the solution on-premise was a major challenge to be accessible in global capacity. Cloud migration will be helping them to resolve that bottleneck and be global with following fintech compliance in a short time.

We wanted to make sure that the architecture of the infrastructure is aligned with the compliance.

I have shared the overall AWS architecture below:

I have shared about few relevant services below:
Security in AWS Cloud

Considering the City Bank remittance application to be a public internet facing application, we recommend the following security guiding principles to be applied :

Security groups: Security groups act as a firewall for associated Amazon EC2 instances, controlling both inbound and outbound traffic at the instance level. When you launch an instance, you can associate it with one or more security groups that you’ve created. Each instance in your VPC could belong to a different set of security groups. If you don’t specify a security group when you launch an instance, the instance is automatically associated with the default security group for the VPC. For more information, see Security groups for your VPC.
Network access control lists (ACLs): Network ACLs act as a firewall for associated subnets, controlling both inbound and outbound traffic at the subnet level. For more information, see Network ACLs.
VPC Flow logs: Flow logs capture information about the IP traffic going to and from network interfaces in your VPC. You can create a flow log for a VPC, subnet, or individual network interface. Flow log data is published to CloudWatch Logs or Amazon S3, and it can help you diagnose overly restrictive or overly permissive security group and network ACL rules. For more information, see VPC Flow Logs.
Traffic mirroring: You can copy network traffic from an elastic network interface of an Amazon EC2 instance. You can then send the traffic to out-of-band security and monitoring appliances. For more information, see the Traffic Mirroring Guide.
Next Generation Firewall(NGFW) – Fortinet Fortigate VM
AWS IAM – Identity and Access Management with granular access control policies and RBAC
Amazon GuardDuty – Machine Learning based Threat Detection service based on VPC Flow Logs, DNS Logs

Fortinet FortiGate Next-Generation Firewall features

Application Control
Web Filtering
FortiCloud Sandbox
Antivirus
Intrusion Prevention
Virus Outbreak Protection Service
Content Disarm & Reconstruction
IP Reputation & Anti-botnet Security