Book Image

AWS FinOps Simplified

By : Peter Chung
Book Image

AWS FinOps Simplified

By: Peter Chung

Overview of this book

Much like how DevOps is a combination of cultural philosophies, practices, and tools that advocate a collaborative working relationship between development and IT operations, FinOps encourages the same collaboration between technology and finance team, making it key relationship to establish and maintain for any thriving business. This book will help you understand how organizations with a mature FinOps practice can decentralize cost ownership to developer teams and encourage cross-functional collaboration between business, finance, and technology, enabling speed, innovation, and business growth. You’ll focus on structuring your organization to form the right FinOps team, including a Cloud Center of Excellence, and learn how to implement practical cost savings measures with AWS tools to optimize costs in both the short as well as long term. By the end of this cloud FinOps book, you’ll be ready to implement a successful Cloud FinOps practice for your organization to get the best value from the AWS cloud for your workloads.
Table of Contents (18 chapters)
Free Chapter
2
Part 1: Managing Your AWS Inventory
7
Part 2: Optimizing Your AWS Resources
12
Part 3: Operationalizing FinOps

Summary

Governance is a crucial part of your FinOps implementation. Without governance, all you have is good intent. Governance provides guardrails for your FinOps practices to be executed in a standardized and scalable way.

Authentication and authorization are both required for any activity within AWS, FinOps-related or otherwise. It’s important to streamline cross-account access via roles and IAM policies that adhere to the principle of least privilege.

You can use SCPs and tagging policies to enforce compliance for the accounts and OUs. All accounts and associated entities are subject to any SCPs. Thus, the allowed permissions are the union between the permission boundary and IAM policy for an entity.

For day-to-day operations, AWS Config, AWS Service Catalog, and AWS CloudTrail are governance-focused services that help with enforcing compliance and auditing account activity.

We have established the right foundation by setting up a multi-account environment, analyzing...