Data Escrow Environment Reference Architecture
Publication date: May 13, 2022 (Diagram history)
This architecture shows how to build a data escrow environment. You can securely store, share, and access data between publishers and advertisers.
Data Escrow Environment Reference Architecture
-
The publisher account stores data specific to each advertiser in Amazon S3 object storage.
-
Transformed data stores in transformed Amazon S3 object storage.
-
Data goes through transformation processes by using services such as Amazon EMR or AWS Glue.
-
The local governance and monitoring system governs and catalogs these S3 buckets. This uses AWS Glue catalog, Lake Formation, CloudTrail, and CloudWatch.
-
The local governance and monitoring system catalogs and governs transformed S3 buckets.
-
Resource sharing occurs between the central governance account and the publisher account holding advertiser data. The publisher controls the central governance account.
-
The central governance account provides access to the publisher account. The publisher account transforms Amazon S3 objects to different advertisers' accounts.
-
The advertiser client application starts a process to integrate data from publishers.
-
Amazon Managed Workflows for Apache Airflow creates Airflow DAGs for transformations.
-
The transformation process extracts data from local S3 buckets containing advertiser data.
-
The transformation process gets access to related data from the publisher account. It uses central governance and the metadata access layer.
-
Transformed and joined data from both accounts store in final S3 buckets.
-
Amazon S3 data exports to Amazon Redshift or queries directly with or Amazon Redshift Spectrum.
-
Amazon Quick Sight accesses the tables created in or Amazon Redshift Spectrum.
-
Analysts access dashboards and insights.
Further reading
For additional information, refer to
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | May 13, 2022 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.