EG334S . HyEnt Multi-Cloud Project

On-prem VPC ↔ AWS public VPC ↔ Azure VNet, joined by two IPSec tunnels

Decommission deadline
--
Sun 30 Aug 2026, 23:59 SGT . marks deducted if late
Project week
1 / 5
Plan & set up (ahead: AWS build already live)
Milestones done
2 / 6
M1 CIDR + M3 VPN #1 . tick below to update
Overall progress
33%
AWS cells built + first tunnel passing traffic

Live status . VPN #1 (on-prem us-east-1 ↔ AWS public eu-west-1)

OPERATIONAL . M3 ✓
Tunnel statusTunnel 1 UP (accepted route 1) . Tunnel 2 standby
End-to-end testping → 10.1.1.32 0% loss, ttl 254, ~68 ms
Routing10.0.0.0/16 propagated to Ireland VGW (active)
DesignAWS-managed VGW + strongSwan customer gateway, static routing
Deployed24 Jul 2026 . CloudFormation, both regions
Evidencetunnel telemetry + ping capture saved for report §5/§6

ttl 254 (decremented) proves traffic routed through the tunnel, not short-circuited. Next on the chain: VPN #2 (AWS ↔ Azure) → M4 multi-cloud.

Cost monitoring . guardrails active (Bernard . Security/Monitoring)

MTD AWS spend
~$5.16
snapshot 24 Jul . not live
Cost driver
VPC / VPN #1
$2.83 MTD . ~$2.40/day while up
Monthly budget
$40
alerts 50 / 80 / 100% + forecast
Daily tripwire
$3
catches "left running" within a day
AWS Budgetsactive . EG334S-Monthly-40 + EG334S-Daily-Tripwire-3 → email
Cost Anomaly Detectionactive . service-level, alerts on ≥ $5 spike → email
Daily still-running checkscheduled . 09:00 SGT, push + email, teardown commands attached
Auto-stop on breachnot available . lab IAM blocks Budget Actions (alert-only)
Cost-allocation tagProject tag not activatable . linked account (payer-only); budgets are account-wide

Guardrails are alert-only: AWS emails you, you (or the daily check) act. Cheapest guardrail is still teardown . delete-stack both regions between work sessions.

Critical path . protect this chain, cut everything else first

Green = done. Amber = AWS side done, Azure pending. Grey = not started. Anything off this chain (bonus, report polish, slides) is parallel work you sacrifice first if time runs short.

Assessment . official weighting (Project Information §4)

Checkpoint
30%
Individual . problem-solving, ownership, attendance
Presentation
30%
Individual . delivery, slides, Q&A
System demo
20%
Technical / team . completeness & troubleshooting
Report
20%
Group . neatness, clarity, logical flow

60% is individual (Checkpoint + Presentation). Build the system as a team; own and defend your own section alone.

Presentation rubric . what assessors score (individual, 30%)

Performance indicatorExcellent (top band)What it takes
Organisation & Content (60)
Organisation & supporting materials; Content
Agenda exists, coherent & interesting sequence; supporting materials used innovatively & explained in context; can explain all details, constraints and work-arounds. Have a clear agenda; every diagram/screenshot explained in context; be able to explain the whole project's details, limits and how you worked around them.
Presentation Skills (40)
Delivery; Q&A
Interesting, eloquent, enthusiastic delivery (not heavily scripted); handles all Q&A well and anticipates questions. Rehearse so you're not reading slides; pre-empt likely assessor questions and prepare answers.

Report rubric . what assessors score (group, 20%)

Performance indicatorExcellent (top band)What it takes
Report Presentation (20)
Writing; Presentation & supporting materials
Exceptionally clear, precise, concise English; few typos; professional layout; all illustrations well formatted. Proofread hard; consistent styles/margins; clean, labelled figures and screenshots.
Technical Content (30)
Organisation & structure; Literature survey; Quality of analysis
Structure entirely correct, all sections placed; exemplary range of references; well-informed, authoritative discussion of a complex problem with depth. Follow the required section order; cite real references (not just www); show reasoned technical analysis, not just description.

Report requirements & structure (Project Information §5)

Required section order

  • 1 . Introduction
  • 2 . Project Objectives
  • 3 . Schedule, Milestones & Deliverables
  • 4 . Project Team & Organization
  • 5 . AWS Infrastructure Design & Implementation
  • 6 . Problems Encountered & Solutions
  • 7 . Test Results
  • 8 . Conclusion
  • Annex A . Bibliography

Must include

  • start Responsibility Assignment Table (name, admin no., role, topic, section, remarks)
  • evidence Diagrams, screenshots, YAML files & configuration
  • refs Bibliography of all references cited (incl. URLs)
  • format Cover page + content page
  • submit Softcopy uploaded to PoliteMall by due date

Scope & tasks (Project Information §3) . built with Amazon Q → CloudFormation YAML

Networks & compute

    IPSec site-to-site VPN

      Bonus marks (only after M4 . core working)

      High availability & load balancing of web servers Auto-scaling + simulated load test CloudWatch + CloudTrail + VPC Flow Logs (Bernard's slice)

      Team & responsibilities

      Casper

      Team Lead . Cloud Architect

      Architecture, exec summary, conclusion. CIDR sign-off.

      Chief Editor . §1, §7

      Jeff

      Network Engineer

      VPC/VNet build + both IPSec tunnels. VGW Ireland, customer gateway Virginia.

      Editor . §3, §5

      Bernard PM

      Technical PM + Security/Monitoring

      Delivery, critical path, risk & teardown. CloudWatch, CloudTrail, VPC Flow Logs.

      PM . Editor §3, §5.1

      Adeline

      Web & Database Engineer

      IP addressing scheme, routing, web-server instance in public subnet.

      Editor . §4

      Soo Fern

      DC Ops Manager

      EC2 (Virginia private server), DNS/DHCP, problems & solutions log.

      Researcher/Editor . §2, §6

      Milestones . tick to update the counter

        Architecture . 3 cells, 2 tunnels

        On-prem DC
        AWS VPC 1 . us-east-1
        N. Virginia . 10.0.0.0/16
        built
        IPSec UP
        cross-region
        AWS public
        AWS VPC 2 . eu-west-1
        Ireland . 10.1.0.0/16
        built
        IPSec pending
        VPN #2
        Azure VNet
        N. Europe (TBC)
        10.2.0.0/16
        to build

        Cross-region: the on-prem↔public tunnel spans us-east-1 and eu-west-1. Teardown must clear both AWS regions + Azure separately.

        5-week plan . back-planned from teardown

        Week 1
        24 Jul – 2 Aug
        Plan & set up . roles + CIDR + AWS/Azure/Q access. CIDR done AWS build + VPN #1 done (ahead)
        Week 2
        3 – 9 Aug
        Network + compute . CloudFormation for 3 networks. Deploy VPCs + VNet. Web + private servers.
        Week 3
        10 – 16 Aug
        VPN #1: on-prem ↔ AWS . already passing traffic
        Week 4
        17 – 23 Aug
        VPN #2 + integration . Azure ↔ AWS IPSec. End-to-end multi-cloud test. Log problems + fixes.
        Week 5
        24 – 30 Aug
        Bonus, report, demo, TEARDOWN . demo to assessors → decommission all by 30 Aug 23:59.

        Teardown checklist . run in every region before 30 Aug 23:59

        On-prem sim AWS us-east-1

        • EC2 private server
        • Customer gateway + VPN connection
        • VPC, subnets, route tables, IGW
        • Elastic IPs released
        • Security groups + key pairs
        • CloudFormation stack deleted

        AWS public AWS eu-west-1

        • EC2 web server
        • Virtual private gateway + VPN conn
        • CloudWatch / CloudTrail / Flow Logs
        • VPC, subnets, route tables, IGW
        • Elastic IPs released
        • CloudFormation stack deleted

        Azure North Europe

        • VM + managed disks
        • VPN gateway + public IPs
        • VNet + NSGs
        • Delete the resource group
        • Billing shows nothing running
        • Console empty in all regions

        Note: an orphaned IAM role from the locked-down lab account (eg334s-vpn1-onprem-SsmRole-*) can't be self-deleted . flag to lab admin. IAM is global, not regional.

        Risk watch . the things that actually bite

        !
        Overlapping CIDR ranges . #1 cause of "tunnel up, traffic won't route". Locked non-overlapping at M1 (10.0 / 10.1 / 10.2).
        !
        Decommission slippage . real mark penalty past 30 Aug 23:59. Rehearse teardown via CloudFormation delete-stack.
        !
        Cross-region teardown . resources are per-region across us-east-1 + eu-west-1 + Azure. Clear each separately or orphans survive and cost marks.
        Gold-plating . don't start bonus (HA, auto-scaling, monitoring) until M4 done.
        Evidence debt . screenshot + save YAML as you build. Can't capture a resource after teardown.

        Interactive tracker . milestone ticks are per-session. Times in Asia/Singapore. Built for EG334S. Updated 24 Jul 2026 . VPN #1 operational.