Home / Case Studies / Cloud infrastructure
Cloud infrastructure

Recording a 60-camera live studio straight to AWS.

A live-dealer studio with no storage on site now records every camera to AWS over encrypted tunnels, with playback on managed desktops and tamper-proof evidence storage.

Live-dealer studio · Client name withheld under NDA

60

Cameras: recorded straight to AWS.

4

Encrypted IPsec tunnels: across two internet providers.

0

Video stored on site: by design.

AWS Site-to-Site VPNAmazon EC2Amazon EBSAmazon WorkSpacesAWS Managed Microsoft ADAmazon S3AWS KMSAWS CloudTrailAmazon CloudWatchTerraform

The challenge

A live-dealer studio runs about 60 cameras into network video recorders that have no disks of their own. The requirement was strict: nothing is stored on site, every frame is encrypted in transit, and the local internet providers must never see video or internal traffic.

The constraints

  • The recorders accept network disks of up to about 8 TB each.
  • The studio link is lossy, with around 65 ms round-trip time to the AWS region.
  • Two internet providers, so encrypted tunnels on both.
  • Cost at this volume: a Transit Gateway would have added roughly $500 a month in data processing alone.

Decisions & tradeoffs

We tested the heavier options first and chose the simplest one the recorders support natively.

  • Evaluated and dropped: Amazon FSx for OpenZFS, FSx for NetApp ONTAP over iSCSI and NFS, a separate video-management recording server, and a custom web viewer.
  • Chosen: each recorder writes to its own iSCSI disk on an EC2 host, backed by an 8 TB gp3 EBS volume.
  • A Virtual Private Gateway with Site-to-Site VPN instead of a Transit Gateway, which keeps data charges down.
  • Playback on Amazon WorkSpaces, signed in through AWS Managed Microsoft AD with MFA and reachable only from the studio.

The implementation

Everything is Terraform: KMS keys, a private network with one NAT gateway, the Site-to-Site VPN (two customer gateways, four IPsec tunnels with IKEv2 and AES-256), one recording host per recorder, the WorkSpaces directory, storage, and monitoring.

The iSCSI timeouts were tuned for the lossy link so a short drop does not disconnect a recorder. Exported clips go to an S3 evidence bucket with Object Lock, encrypted with a customer-managed KMS key, with CloudTrail auditing and a CloudWatch dashboard for recording health.

The rollout plan was a pilot of 3 cameras for 72 hours, then all 60 for 72 hours, with no recording gaps as the pass criterion.

Cameras feed recorders in the studio; through a firewall and four IPsec tunnels, each recorder writes over iSCSI to an EC2 host with an 8 TB EBS volume; the risk team plays footage back on Amazon WorkSpaces with Managed Microsoft AD; exported clips go to S3 with Object Lock.
Studio CCTV on AWS. Highlighted: the recording path.

Outcomes

Video leaves the building encrypted and there is nothing on site to steal or tamper with. The risk team reviews footage from managed desktops, and evidence clips cannot be altered or deleted once stored. At about 1.6 TB a day with H.265, the AWS Pricing Calculator estimate for the setup was about $3,400 a month.

Handover & ongoing ownership

Terraform for every component, a runbook for the VPN and recorders, and the recording-health dashboard.

Planning something similar? Talk to an AWS partner in Armenia that has built it before.

What’s next for
your business?

Let’s talk