...
draw.io source: direct-connect-migration-process.v2.drawio
Anchor | ||||
---|---|---|---|---|
|
Phase | Stage | Timeframe | Status | Activity | Impact on Cornell AWS Account VPC Networks |
---|---|---|---|---|---|
Preparation | Data Collection | November 2022 |
| none | |
Resource Tagging |
|
| none | ||
Resource Groups |
| none | |||
Customer Input #1 | - |
| none | ||
Migration | Transit Gateway Attachments | - |
| none | |
Customer Input #2 | - |
| none | ||
VPC Routing Updated | Originally Jan 16, but that is MLK day. So,
|
| VPC-to-campus traffic will be routed through the v2 architecture | ||
Campus Direct Connect Routes Updated |
|
| campus-to-VPC traffic will be routed through the V2 architecture | ||
Cleanup | Customer Account Cleanup | - |
| none | |
Campus Direct Connect Cleanup |
| none |
Anchor | ||||
---|---|---|---|---|
|
Customers have the option to request that migration for their VPC(s) occur during the week of Jan 9-13 instead of the default migration dates of January 17 and 18. This is especially encouraged for customers that have a separate sandbox or development VPC that needs to be migrated. We can also support taking both migration steps on the same alternate day, but we'd like to leave a 1-4 hour gap between migration steps to confirm that the "VPC Routing Updated" step was successful before continuing to the "Campus Direct Connect Routes Updates" step.
Anchor | ||||
---|---|---|---|---|
|
Both the "VPC Routing Updated" and the "Campus Direct Connect Routes Updated" steps have simple rollback stepsmechanism. If you discover problems with networking in your VPC after either step and think the change needs to be rolled back, send an email to cloud-incident@cornell.edu and ping Paul Allen (pea1) on Teams.
FAQs
How do I tell if my AWS account will be affected by this change?
The list of AWS accounts affected by this migration is here: Cornell AWS Accounts Affected by 2023 Direct Connect Architecture Migration
You will receive multiple emails to the email address associated with the root user of your Cornell AWS account. These emails will make announcements and ask for your input during the migration process.
Will there be any interruption in Direct Connect connectivity during this migration?
As of , our testing indicates that we should be able to complete this migration without any interruption in overall Direct Connect connectivity. However we cannot guarantee this for individual VPCs. If interruptions occur, they should be brief (minutes, not hours).
How will this change affect my AWS account costs?
Cornell AWS accounts will not experience substantive differences in charges between v1 and v2 architecture. A new $36/mo charge for each VPC connected to the v2 architecture is billed directly to a CIT KFS account.
For more details, please see the Costs section above.
- The rollback for the "VPC Routing Updated" step is to reassign the original Route Tables to the public and private subnets. This will rollback takes effect immediately.
- The rollback for the "Campus Direct Connect Routes Updated" step is to the cancel the failover of the Direct Connect Virtual Interfaces that we triggered to initial the campus routing updates. This rollback takes 5-20 minutes to complete.
FAQs
How do I tell if my AWS account will be affected by this change?
The list of AWS accounts affected by this migration is here: Cornell AWS Accounts Affected by 2023 Direct Connect Architecture Migration
You will receive multiple emails to the email address associated with the root user of your Cornell AWS account. These emails will make announcements and ask for your input during the migration process.
Will there be any interruption in Direct Connect connectivity during this migration?
As of , our testing indicates that we should be able to complete this migration without any interruption in overall Direct Connect connectivity. However we cannot guarantee this for individual VPCs. If interruptions occur, they should be brief (minutes, not hours).
How will this change affect my AWS account costs?
Cornell AWS accounts will not experience substantive differences in charges between v1 and v2 architecture. A new $36/mo charge for each VPC connected to the v2 architecture is billed directly to a CIT KFS account.
For more details, please see the Costs section above.
Does this Does this change affect VPC peering?
...
When, specifically, will this migration occur?
...
See detailed schedule above.
Is there any flexibility in migration dates?
Yes. See Alternate Migration Days above.
Can the migration be rolled back?
Yes. Each of the two active migration steps ("VPC Routing Updated" and "Campus Direct Connect Routes Updated") can be individually rolled back for each migrating AWS VPC. See Rollback above.
What if I use Terraform or a similar tool to manage the network resources in my AWS account?
...