Time
14 hours 28 minutes
Difficulty
Intermediate
CEU/CPE
15

Video Transcription

00:00
Hello, Siberians. Welcome to Lesson 3.5. Off Monetary Off discussed stated Microsoft Azure Arctic design
00:08
so we'll continue from where we left off in the last video.
00:11
Well, carry on Talking about sequel in Hajer. But from a performance perspective and this goes beyond just as juicy Quote Database will actually be covering the different sequel options in Hajar from a performance perspective.
00:25
Then we'll cover just sequel from a security perspective
00:29
and finally will cover as a sequel for me. Cost perspective.
00:34
Let's get into this. Let's talk about sequel in Hajer design decisions as it relates to performance on in this particular slight I won't just be covering as your sequel. I'll also be extending that this discussion to seek well in a virtual machine in Hajer because they're set in
00:52
concentrations that we have tohave when it comes to performance.
00:56
When it comes to, I just seek well, and I just think we'll manage instance. We want to select the right steer fire workload. So you know how we have the different T has the pendant
01:06
on the deployment model that you have. You have different tiers where we have the general propose you have the business critical. And then you have the iPods killed, just insured. I used to like the right city, every walk look.
01:19
Also, it's a good practice to deploy year database workload as close as possible to the application on the client that uses it. This is to avoid as much as possible network latency
01:34
when it comes to Sequel seven Measure of virtual Machines.
01:38
Just continue to use the same database performance tune in options that I play cable to see course ever in an on premises environment on. By the way, this is not just only for sick, well seven Nigel Virtual machines. This also applies to Azure sequel Best practices When it comes to performance, tune in for sick or still applies.
01:57
So factors such as the size of the veteran machine that you're deploying I'm sequel to the configuration off the data disk. Whether you're using standard disco premium discs, definitely have an IMP activation sequel. Sava in Nigel Virtual Machine.
02:14
One of the things that I want to call out when it's related to the data disks off the veteran mission that's running sequel in Hajer East that you can configure cash in for the disks. Now he has the best practice. Read only cash in configured on disks that old Austin your data
02:32
and when it comes to the disc that Austin your logs enable no cash in. In other words, there's no cash in for discussed in the logs. Read Only cash in for Disco Austin The data. This would give you the best performance for sequel server in Nigel Virtual machines.
02:51
Now let's talk about security. So when it comes to security there multiple, Leah's the friends, and that is always a good strategy.
02:59
And that is what is covered in this light. You have security as it relates to identity and access security at it as it relates to data protection, network security, monitoring and logging, which we talked about in the previous video on then other things like security management and ensuring that you have visibility into what's going on.
03:16
I'll just emphasize some key best practices in the upcoming slight
03:23
as it comes in network security. You want to use I P Firewall rolls off Vinod service endpoint to restrict network access
03:31
as you're sick. Whoa! Unlike Jessica, managed instance, is not applied within a virtual network, which means that it can be reached directly over the Internet. Now we can use something called under the firewall and virtual Networks configuration of that service
03:47
we can restrict with I P addresses can connect to our just sequel
03:53
over the network on. We can also use something called Vinet service endpoint to ensure that connective it can only be made to the platform. Sequel from Service is off resources that are running within an isolated network.
04:09
Hi p Firewall votes can become figured at a server level. Are the data base level. In some cases,
04:16
when it comes to access management, you want to use robots access control to restrict management access. So if you think about it, for example, you want to be ableto restrict was ableto get to the service and make configuration changes.
04:32
Also, when it comes to the databases that are running within the server
04:39
data basis, the supports two types of authentication sequel authentication, which is the default on as your 80 authentication. So we can actually integrate as your Haiti directly with a sequel databases so that we manage identity from a central point that also as the added advantage of being able to use face like
04:59
multi factor authentication.
05:02
Database. Auto Physician can be a signed using transact sequel
05:08
when it comes to a data protection. Transparent data encryption is enabled by default, so that means you're dead eyes encrypted at rest.
05:16
Now we can and as the encryption by using our own case.
05:20
The defaulting prefer that enabled The keys are automatically managed when Microsoft, but maybe for complaints reasons. Who wants to bid? Once managing the key, we can griet and integrate key votes that we talked about in previous lessons. We can integrate key vote with just sequel on Be able to use our keys
05:41
as it relates to trade protection. This is talking about identifying the different attacks or different anomalies that may be going on within sicko so we can enable a service called Advance Straight Protection, which is gonna analyze the sequel logs and look for anomalies or indicators off compromise or indicators of attacks.
06:01
It's gonna help us to detect unusual behavior and potentially harmful attempt, tow, exploit our data basis.
06:09
It's concentrated protection mentioned this earlier. Transparent Did. Our encryption is enabled by default on. We can announce it is in our own keys
06:20
when it comes to cost
06:23
with just a quote design.
06:26
We need to understand what exactly are we charged for when we use this service? So here's what we attach for were charged for the computer, and I includes the memory that we're using would pay for that when we select the different service tear that we want to use.
06:41
We also charge for the stoppage, which, in the case, off using the vehicle approaches and model. We have more flexibility in controlling that.
06:48
We chat for the back off storage. So if we're gonna be doing back after the back of that a start, there's gonna be a cost to that. And then we also charge for long time backup retention strategy that's going to be starting a Nigel storage account. And that's gonna in Kiersten and costs,
07:06
as we've discussed earlier there to protest in models the vehicle based on the ditty you based model.
07:14
When it comes to building option, we can either pay us you go. In other words, you just paper how for what you're using or, in the case off, several issue even paying per second,
07:25
we can do something called a reserved instance, so reserved instance means, if you know that this is a database walker that's not going anywhere, it's a database workload that's gonna be online for a long period. You probably wants to pay for it or agree to reserve it upfront, and that's going to give you
07:43
potentially up to 28% savings. If you reserved for
07:46
after three years,
07:49
pay as you go your paper. How are for the computer you're using one year or three years reserved Mr Paper year with 18% or 20% savings now makes of us has introduced more flexibility to where you can reserve the instances but pay monthly. So that's good.
08:07
If you're isn't Vic approaches and model, we have the option off using hybrid benefit, which allows us to be able to use our sequel. Several licenses in Hajer on that's gonna result in significant savings also,
08:22
So if we want to get up to 86% cost savings, we can use a combination of what I bred benefit regions in our existence. Sicko. Several licenses which reserved instances and that can result in significant cost savings.
08:39
So that's it for this particular lesson. I hope you've enjoyed it, and I'll see you in the next lesson

Up Next

AZ-301 Microsoft Azure Architect Design

This AZ-301 training covers the skills that are measured in the Microsoft Azure Architect Design certification exam. Learn strategies to plan for the exam, target your areas of study, and gain hands-on experience to prepare for the real world.

Instructed By

Instructor Profile Image
David Okeyode
Cloud Security Architect
Instructor