Skip to content
This repository has been archived by the owner on Apr 30, 2021. It is now read-only.

Latest commit

 

History

History
32 lines (17 loc) · 1.93 KB

gsp-architecture-cloud-infrastructure.md

File metadata and controls

32 lines (17 loc) · 1.93 KB

GDS Supported Platform Infrastructure

overview of the GDS Supported Platform infrastructure

  1. A GSP cluster resides in an AWS account within the London region (eu-west-2)

  2. The infrastructure is deployed across three availability zones (eu-west-2a, eu-west-2b, eu-west-2c)

  3. The cluster makes use of Global Accellerator to manage static IP addresses.

  4. Load balancing is achieved through the use of an application load balancer.

  5. External egress access is via a NAT gateway in each availability zone.

  6. The kubernetes control plane is managed by AWS EKS

  7. The cluster relies on AWS IAM for identity and authorisation

  8. The cluster contains an autoscaling group containing a continuous integration service based on ConcourseCI

  9. By default there are three kubernetes worker nodes for the cluster split across the three availability zones

  10. All accounts benefit from AWS Shield protection against distributed denial of service attacks

  11. The cluster aggregates selected log events to AWS CloudWatch for ongoing processing by the Cyber Security team

  12. CloudWatch logs are shipped externally to Splunk using AWS Lambda