Asterrr's Handbook

Server migration

Rehosting servers with Application Migration Service, one-off image imports with VM Import/Export, and the options for VMware estates.

Exam tasks: 4.2 (determine a new architecture for existing workloads when rehosting, select a migration tool for servers, plan cutover with minimal downtime)

The decision: do you need continuous replication with a cutover window of minutes, a one-time image import, or a way to keep running VMware without converting VMs at all?

Choosing a tool

Application Migration ServiceVM Import/ExportAmazon EVS
StrategyRehostRehost, one server at a timeRelocate
SourcesPhysical, any hypervisor, other clouds, other AWS RegionsVMDK, VHD/VHDX, OVA or raw images in S3VMware vSphere estates
ReplicationContinuous, block levelNone: point-in-time imageUses VMware tools such as HCX
Downtime at cutoverMinutesHours: shut down, export, upload, importMinutes with live migration tooling
ResultNative EC2 instancesAMI, EC2 instance or EBS snapshotVMs on VMware Cloud Foundation in your VPC
At scaleBuilt for thousands of servers, grouped in applications and wavesScripted per imageWhole clusters

Name change

AWS Application Migration Service (MGN) now appears in AWS documentation as AWS Transform MGN. It's the same service and console, and the exam may use either name.

Application Migration Service (MGN)

Install the AWS Replication Agent on each source server, Windows or Linux. For VMware there's also an agentless option that replicates through a vCenter client, for servers where you can't install software.

Initial sync, then continuous replication. The agent copies every disk to replication servers in a staging subnet, then streams block-level changes. The staging area uses small instances and cheap EBS, so it costs little while you wait.

Configure launch settings. An EC2 launch template per server defines instance type, subnet, security groups and tags. MGN can right-size the instance type from the source's CPU and RAM.

Launch test instances. The conversion server makes the replicated disks bootable on EC2, with the right drivers and boot loader. Replication keeps running during tests, and you can test as often as you like.

Cut over. Stop the application on the source, wait for the last changes to replicate, launch cutover instances and switch DNS. Then finalize the cutover, which stops replication and cleans up the staging resources.

Post-launch actions run SSM documents on the new instances after launch, for test instances, cutover instances or both. Predefined actions cover installing the SSM Agent and CloudWatch agent, installing the Elastic Disaster Recovery agent for DR in another Region, license conversion and OS-level changes. You can add your own SSM documents, for example to join a domain or swap a hostname in config files.

TCP 1500
Replication traffic from source servers to replication servers in the staging subnet.
TCP 443
Source servers and replication servers to the MGN service endpoint.
Minutes
Typical cutover downtime, because only the final changes need to sync.

Private replication path

If a question says replication must not use the public internet, configure the replication settings so the staging servers use private IP addresses, and route over Direct Connect or VPN. Add a VPC interface endpoint for MGN if the sources must reach the service endpoint privately too.

Forgetting the test launch

The cutover instance comes from the same replicated disks as the test instance. Answers that skip test launches, or that stop replication to test, miss the point: MGN lets you test repeatedly with no impact on the source or on replication.

MGN for DR

MGN is for migration. For ongoing disaster recovery with the same replication model, the answer is Elastic Disaster Recovery (DRS). See disaster recovery.

VM Import/Export

  • Upload a disk image to S3, then call the import API to get an AMI, an instance or an EBS snapshot.
  • Export turns an EC2 instance or AMI back into a VMDK, VHD or OVA image in S3, for on-premises or another cloud.
  • Needs a service role, usually vmimport, that lets the service read the S3 bucket.
  • No replication. The server is down, or diverging, from when you take the image until the import finishes.

Choose it for a handful of servers where downtime of hours is fine, for importing a golden image built on premises, or when you have to export an instance.

VMware estates

OptionWhat it isWhen it fits
Amazon Elastic VMware Service (EVS)VMware Cloud Foundation deployed on EC2 bare metal, inside your own VPC. You bring VCF licensesRelocate quickly while keeping vSphere, NSX and vSAN skills and tooling, with AWS-native networking
VMware Cloud on AWSVMware-operated service on AWS infrastructure, now sold through Broadcom and partnersExisting VMC customers, or where VMware should operate the stack
AWS Transform for VMwareAI-assisted discovery, network conversion and wave planning that rehosts VMs onto EC2 through MGNLeaving VMware entirely

Relocate vs rehost for VMware

"No changes to the VMs", "keep using vCenter" or "exit the data center in weeks without converting images" points to relocate on EVS. "Reduce VMware licensing cost" or "run natively on EC2" points to rehost with MGN.

Legacy: use Application Migration Service instead

AWS Server Migration Service (SMS), which scheduled incremental VM snapshot replication through a connector, was discontinued in 2022. CloudEndure Migration was also discontinued, and its technology became MGN. CloudEndure Disaster Recovery became Elastic Disaster Recovery.

Scenarios

Scenario
A manufacturer must migrate 350 Windows and Linux servers, a mix of physical machines and Hyper-V VMs, to EC2. Each application may be down for no more than 30 minutes at cutover, and teams need to test each server on AWS several times before cutover. Which approach meets the requirements with the LEAST effort?
Scenario · choose 2
A company is migrating servers with Application Migration Service. Security requires that replication data never traverses the public internet, and every migrated instance must have the CloudWatch agent and join the corporate domain. Which TWO actions should the architect take?
Scenario
A financial firm runs 1,200 VMs on vSphere. Its data center contract ends in 10 weeks. Operations wants to keep vCenter, NSX policies and existing runbooks, and there's no budget for re-testing converted VMs. Which option fits?

Further reading

On this page