Hey Rob, 

This is potentially a minority opinion, but if security is a particular concern I have made the case on the CloudBioLinux list (https://groups.google.com/forum/?fromgroups=#!topic/cloudbiolinux/9R_X5Ww00b4) that CloudMan out of the box on Amazon is sort of fundamentally insecure. I think the small act of enabling SSL would go a long way with respect to this.

I have some documentation on building "production" cloudman instances here and part of that includes enabling SSL:
http://bit.ly/prodcloudman

I have also put together a corresponding prezi (http://bit.ly/prodcloudman-slides) to sort of complement that documentation. The prezi lays this out in the context of OpenStack, but I think it is just as valid on Amazon. Here is a recording of me giving the presentation to a Galaxy Admins meeting (http://bit.ly/prodcloudman-recording).

Hope this helps,
-John



On Mon, Mar 25, 2013 at 2:35 PM, Rob Leclerc <robert.leclerc@gmail.com> wrote:
I need a comprehensive understanding of the Best Practices for a Galaxy Production Server. 

(i) I've read "Running Galaxy in a Production Environment" and associated wikis
(ii) I saw the presentations "Building Scalable Galaxy (2010)", "Deploying Galaxy on the Cloud (2010)", and "Cloudman: Galaxy on the Cloud". 
(iii) I've searched the mailing list.


Are there any other undocumented pitfalls/tips that we should be aware of for a Cloudman/Amazon install? Security would be a high priority for this list.



Below are a list of references I've compiled for my own list:

Running Galaxy in a Production Environment

Sildes: Building Scalable Galaxy 2010

Deploying Galaxy on the Cloud, 2010

Configure Apache Proxy to Galaxy

Configure nginx Proxy to Galaxy

Running Tests

Presentation: CloudMan: Galaxy on the Cloud, 2011

Cloudman Capacity Planning for AWS

Using Amazon EBS Volumes

Copying an Amazon EBS Snapshot


Rob Leclerc, PhD
P: (Shanghai) +86-1-(861)-612-5469
Personal Email: rob.leclerc@aya.yale.edu

___________________________________________________________
Please keep all replies on the list by using "reply all"
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:
  http://lists.bx.psu.edu/

To search Galaxy mailing lists use the unified search at:
  http://galaxyproject.org/search/mailinglists/