How Expert Thinking helped one of the world’s leading satellite operators make their development process more transparent, robust and efficient.
Requirements
Aerospace is an industry with high demands and the design, build and operation of satellites is one of its most complex challenges. The sector is increasingly competitive, with ever-increasing customer expectations across shipping, agriculture, aviation and government. A competitive edge requires operators to design, build, and deploy ever more effective software to deliver more specialised, reliable, and economical services.
The value of satellites is ultimately realised on the ground, through the software platforms that process their data. To achieve this, the development process must balance integrity, security and speed, enabled by the right internal developer platform (IDP). While new features and speed of deployment are key, the consequences of downtime or security breaches could be severe, with data that is influencing real-world decisions on issues including the climate crisis and national security.
One of the key players in this sector engaged Expert Thinking to create a new Internal Developer Platform on AWS to help maintain its leading position in the industry and prepare it for the next stage of growth.
The company’s requirements were:
The Criteria
The key success factors for the project were:
- Speed of deployment
In a fast-moving sector, there was no time for a lengthy project, and it was vital that the new platform could be operational quickly, without disruption to the development team’s work. - Fitness for purpose
In a highly specialised industry, it was important that the new platform could be developed in sympathy with the customer’s unique needs, to ensure the team’s specific requirements were met. - Economy
While a very high quality of work was required, the budget for this project was tight, with no scope for waste or overrun.
Our Solution
Figure 1OU Heirachy allows SCPs to be applied to appropriate accounts. AWS Config compliance pack helps detect non-compliant infrastructure.
Figure 2 – Shared public subnet means all ingress/egress is enough AWS Network Firewall. SCP prevents NAT Gateway creation in spoke accounts.
AWS Network Firewall supported NIST 800-171 compliance, by providing enforceable network controls and detailed visibility into network activity. AWS Network Firewall enables centrally managed, stateful inspection and filtering of traffic, enforcing approved communications paths and blocking unauthorised or potentially malicious traffic. Firewall logs and Amazon Virtual Private Cloud (VPC) flow logs help ensure that evidence of data flows is stored, helping meet NIST audit requirements.
Figure 3 Logs metrics, traces and cost data made available in centralised location with fine grained access control achieved using Self Hosted Grafana Enterprise.
Observability is a core capability of the platform. Logs, metrics and traces are collected across the stack, from applications, infrastructure and traffic. Logs are consolidated using Amazon OpenSearch Service, whilst Mimir and Tempo store metrics and traces, all of which can be visualised and alerted on from Grafana, aiding both operations and compliance requirements.
By building such controls into the platform itself, compliance becomes a default property of every deployed application, rather than a manual per-project effort.
In addition to compliance, the new IDP was built so that even major new business requirements can be affected quickly, with changes that previously would have taken months now achievable in days thanks to configurable Terraform modules. This includes onboarding customers in new regions or updating customer workflows, with the new system designed to make it easy to ensure isolation between customer workloads – a vital attribute for customers in the government and security sectors.
The Benefits
- Key Benefit 1: Visibility and observability
The new IDP’s observability stack draws together logs, traces and metrics from all the various testing, staging and production environments and consolidates them to provide ‘single pane of glass’ visibility of the whole operation. This enables engineering teams to quickly detect anomalies, assess impact and respond to incidents in a controlled and reliable manner. - Key Benefit 2: Compliance and security
The new IDP enforces compliance with the vital NIST 800-171 standard, ensuring the company’s place as one of the first choices for government, defence and security contracts, in the US and elsewhere. Having this compliance built into the platform reduces the operational burden on both development and infrastructure teams by providing predefined security guardrails that ensure workloads are designed, deployed and operated in line with NIST 800—171 by default. - Key Benefit 3: Streamlining and efficiency
Well defined reusable Terraform modules, along with CICD templates mean that developers working on the new IDP can push code from their local machines to testing, to staging, and then to production, with a single, secure and integrated process. This means development velocity is increased, and timelines are far more predictable. Developers have access to a registry of pre-approved and pre-tested modules within the platform, allowing them to quickly access and use proven code, propagating best practices and raising quality incrementally across the team.
Talk to the
cloud experts.
Whether you are considering using cloud for the first time or have already embraced it, you need to work with a specialist – contact us today.