5 ms·
A couple jobs ago we had to take our entire SaaS offering (security product) and reproduce it in the EU for GDPR. This exercise evolved into my Systems team bei
by jdoss 4y ago
A couple jobs ago we had to take our entire SaaS offering (security product) and reproduce it in the EU for GDPR. This exercise evolved into my Systems team being asked to create private deployments for a handful of Fortune 500 / Fortune 10 sales opportunities. The private deployment enabled Sales to land these Enterprise deals that were very risk adverse to having their data in a multi-tenant SaaS product. We ended up with around 10 of these private deployments and some very large big name customers.
We did it entirely with Ansible on AWS or GCP on accounts owned by us. This was before Terraform was 1.0 and Ansible enabled us to quickly reproduce our deployments. It wasn't sexy or pretty. It worked well enough to get the job done. The best aspect of using this model is it gives your engineering team total control over the private SaaS deployment and unlimited access. Where as On-Prem or Customer Cloud deployments are an entire other bag of cats. It is great middle ground for Enterprise customers that won't do multi-tenant SaaS.
I am only sharing this anecdote because I have seen this single-tenant SaaS model work in the past and I think more engineering teams should strive be able to reproduce their whole environments for private deployments.
- wara23arish 4y agoif you were to do this again today do you think terraform would be a better fit or maybe even something like pulumni?
- jdoss 4y agoI would use Pulumi if I had to do it over again. I use the Pulumi Python SDK for some internal things at my work currently and it's so much better of a DX than fighting HCL all day. We actually tried to adopt Terraform early in 2015 but we hit some of the nasty state bugs back in version .05 or .06 IIRC and we hosed one of our deployments and couldn't recover. That burned the Terraform bridge for us and we just used Ansible to automate everything.
- croes 4y agoWouldn't it nowadays be a violation of the GDPR? I mean AWS and GCP still are affected by the CloudAct, and if your company is US based they are too. I guess your anecdote happened during Safe Harbor or Privacy Shield.
- jdoss 4y agoGood question. Our EU deployment was on AWS in eu-central-1. TBH I don't know. I was told it was for GDPR and other compliance reasons and as long as it was being hosted in the EU it checked the boxes for our EU customers.
- jcims 4y agoWhat part says violation to you? Just the fact that re-homing was the only thing mentioned?
- nijave 4y agoI worked at a company that did this with Python and Terraform. Another great benefit is being able to rollout product changes based on customers risk tolerance. Some customers will be more interested in new features while others will prefer stability. On the engineering side, you can do canary-style rollouts to each isolated environment Some enterprise customers will want special features or configurations that might not make sense for everyone else this setup also makes a lot easier (special network connectivity like IP allowlisting, network peering, VPN tunnels, cipher selection)