Book Image

AWS FinOps Simplified

By : Peter Chung
Book Image

AWS FinOps Simplified

By: Peter Chung

Overview of this book

Much like how DevOps is a combination of cultural philosophies, practices, and tools that advocate a collaborative working relationship between development and IT operations, FinOps encourages the same collaboration between technology and finance team, making it key relationship to establish and maintain for any thriving business. This book will help you understand how organizations with a mature FinOps practice can decentralize cost ownership to developer teams and encourage cross-functional collaboration between business, finance, and technology, enabling speed, innovation, and business growth. You’ll focus on structuring your organization to form the right FinOps team, including a Cloud Center of Excellence, and learn how to implement practical cost savings measures with AWS tools to optimize costs in both the short as well as long term. By the end of this cloud FinOps book, you’ll be ready to implement a successful Cloud FinOps practice for your organization to get the best value from the AWS cloud for your workloads.
Table of Contents (18 chapters)
Free Chapter
2
Part 1: Managing Your AWS Inventory
7
Part 2: Optimizing Your AWS Resources
12
Part 3: Operationalizing FinOps

Creating a multi-account environment

All resources and services on AWS require an AWS account. After you create an account, you can deploy AWS resources to that account. Hence, the AWS account is the fundamental container that holds your resources. Every month, AWS aggregates usage for each account, and the account holder is responsible for those charges. However, most organizations using AWS have multiple accounts that run their workloads.

Securing your business assets is the primary reason for using multiple accounts. An AWS account provides a natural security boundary for organizations with multiple accounts. Say you were to deploy your entire business’ production workload in a single AWS account. If a malicious actor were to obtain certain privileges to that account, that may lead to a large security breach in your business. However, if the threat affects just one account out of many, this significantly limits the threat or blast radius.

Isolating resources by attributing...