All applications hosted by WSP Digital are housed in a fully redundant, managed infrastructure provided by Rackspace in a secure data centre in the USA. Rackspace’s data centres are protected by key card protocols, biometric scanning protocols and round-the-clock interior and exterior surveillance monitoring. The data centre’s HVAC (Heating Ventilation Air Conditioning) system is N+1 redundant, ensuring that a duplicate system immediately comes online should there be an HVAC system failure.
In the event of a total utility power failure, the data centres’ power systems are designed to run uninterrupted, with every server receiving conditioned UPS (Uninterruptible Power Supply) power. All UPS power subsystem are N+1 redundant, with instantaneous failover if the primary UPS fails. If an extended utility power outage occurs, on-site diesel generators can run indefinitely.
The data centre’s internet connectivity is fully redundant, with nine different network providers providing internet access via fibre optic cables entering the data centre from separate physical points in the building.
A secondary backup environment is housed with Amazon EC2 in the West Coast Data Centre, USA. In the event of a failure at the primary host in the USA, all services will be switched to the backup infrastructure at Amazon EC2 – resulting in minimal disruption and downtime to users.
The backup server is configured as a replication slave, providing instantaneous backup for all data stored in the primary production environment. Archives are also produced on a daily, weekly, monthly and yearly rotation on both the primary and secondary environments.
Both the primary and secondary environments are pro-actively monitored. A WSP Technician is on-call at all times in case of any failure at either environment. The primary environment is also monitored by Rackspace, with technicians at WSP notified in person by Rackspace in the event of any failure. In addition, SMS and email notifications are triggered in the event of any failure at either environment.
SMS and email notifications are provided by Host-Tracker.com which utilises a network of over 60 servers worldwide to provide uptime and monitoring alerts for hosted environments.
Security
The production environment is protected by a fully managed Cisco PIX firewall. Only ports 80 (HTTP) and 443 (HTTPS) are open to users. All other ports are either blocked or available only to WSP authenticated users. All communication between the server and the web browser is conducted under SSL 128 encryption.
SSH is used for maintenance on all infrastructures, with password authentication disabled. Only users with trusted public-keys on authenticated WSP machines can access the production and backup environments.
Copyright © 2010 - WSP Digital