SlideShare une entreprise Scribd logo
1  sur  33
The Move to Hybrid Cloud
Benefits and challenges to IT Service Management
Matt Johnson, April 2015
Agenda
• Recap – what is cloud anyway?
• Deployment, Service models
• Essential characteristics
• The Hybrid cloud model
• Service Management in a hybrid cloud world
• Service Design: Capacity, InfoSec, Supplier Mgmt
• Service Transition: Change, Asset/Config, Release Mgmt
• Service Improvement: Service Measurement & Reporting
• Recommendations
Recap:
What is Cloud, anyway?
Recap: What is Cloud anyway?
Cloud Models
• Cloud Deployment models
• Public – multi-tenanted Internet-based service (AWS)
• Private – single-tenanted, closed-network service (vCloud)
• Community – multi-tenanted service aimed at a specific user group
• Hybrid – Combination of 2 (or more) cloud infrastructures
• Today’s focus is on Hybrid Cloud models
Cloud Models
• Cloud Service Models
• IaaS – compute, storage, networking services
• PaaS – managed platform that supports app development
• SaaS – managed software delivered via a web browser
• Today’s focus is on IaaS service models
Cloud Characteristics
• Essential Characteristics
• Broad Network Access
• Resource Pooling
• Rapid Elasticity
• Measured Service
• On Demand Self-Service
Essential Characteristics
Broad Access – addressing usability
• Traditional IT has historically been “siloed”
• Vertical deployments of application stacks for specific purposes
• Access to these silos is controlled independently
• Integration across services is limited
• This isn’t always a bad thing!
• Security, accountability, control are all increased
• But this approach…
• …has resulted in “planning blight”, and
• Leads to the use of “Shadow IT”
Broad access – more than one way…
Cloud
Service
Web console
Command
Line
REST API
Development
SDK
3rd party
integration
Resource pooling – addressing efficiency
• Consolidation of workloads
• More efficient use of infrastructure
• Higher availability (through HA)
• Lower infrastructure costs
• Comes at a price
• Less spare capacity to scale,
unless you purchase “spare”
• Failure of physical servers impact
more services
Resource pooling – benefits at scale
Organisation with
200 physical servers:
~ $6,500 per server
Cloud provider with
20k+ physical servers:
~ $1,000 per server
• Traditional architecture design
requires adopting one of two
approaches:
• Design for peak load – results in
unused capacity
• Design for average load – results
in over-subscribed capacity
• Virtualisation can help solve
compute capacity, but not:
• Network / storage capacity
• Scaling automation
Elasticity – addressing capacity
Elasticity (rapid scalability)
• Public cloud provides “infinite”
(from a typical customer’s
viewpoint) scalability
• Deals with the “hard” stuff that
virtualisation doesn’t:
• Scaling network/bandwidth
• Scaling storage
• Scaling automation
Measured Service – addressing purchasing
• IT has traditionally been a cost centre
• Pressure to reduce costs
• Expenditure linked to budget cycles
• Typically high CapEx for new projects
• IT increasingly adds value to business
• Showback / Chargeback are attempts to
represent this value to individual business
units
• Very difficult to apportion core infrastructure
costs (switching, network, etc.)
Measured Service – pay as you go
• Cloud services charge based on use
• Discount levels for bulk usage
• No minimum contract periods
• Detailed metrics, which can be categorised as required
The Hybrid Cloud model
Private + Public = Hybrid
Hybrid Cloud
• At its simplest, Hybrid cloud simply connects two (or more)
cloud services via defined mechanism(s)
• In practice, there are two distinct patterns for service delivery:
• Discrete – individual services reside on a single, specific cloud
• Integrated – individual services are managed & delivered
transparently across the hybrid cloud infrastructure
• Management services are similar:
• Discrete – each cloud is managed individually
• Integrated – combined management stack
Why Hybrid?
• Allows you to make best use of the strengths of each type
of cloud platform:
• Public Cloud (such as AWS):
• Scale, pace of innovation, elasticity, additional functionality, price
• Private Cloud (such as vCloud):
• Security, customisation, compliance, control
• Provides a transition path from fully on-premise services
• Great for pilot / PoC / development / DR service provision
• Lots of different justifications; in practice, it comes down to:
• Public cloud = agility
• Private cloud = control
Public cloud capability (AWS)
Private Cloud control (Eduserv)
• Secure Compute Cloud
• Government-accredited infrastructure (“IL2”, “IL3”)
• UK data sovereignty – UK owned and operated datacentre
• Specialist network connectivity (PSN, Janet, WAN, etc.)
• Capability for external audits
Hybrid Cloud – Management considerations
• Infrastructure
• Deployment tools are likely to be different to on-premise IT
• Be aware of subtle differences, esp. if you are used to vSphere
• Network connectivity
• Fast, low-latency links are important where services are integrated
• OS & application management
• Existing tools should be compatible, but…
• …may not be able to handle “cloud-native” designs
• Think about how you architect directory services across clouds
• Start simple!
Hybrid Cloud Service Management
Some considerations
Capacity Management
• Hybrid “Cloud Bursting” is (in most cases) a myth
• Scaling a service tier across a hybrid cloud is complex and costly
• Keep tiers within a single cloud (i.e. web on public, app on private)
• Try to place “bursty” services onto public cloud infrastructure
• Long-term stable services are a good fit for private cloud
• There’s no such thing as “spare” capacity on a public cloud
• You pay for anything that is running / being used
• Turn on when you need it, off when you don’t
• Public cloud is great for off-site storage (object/tape storage)
• Push (encrypted) backup data, with retention/lifecycle policies
Supplier Management
• One of the most important hybrid cloud
processes to understand
• Understand cloud providers T&Cs
• Unlikely you will be able to modify the terms
• Understand data retention, termination,
payment requirements
• Understand cloud provider service levels
• What SLAs are offered? What are the
exclusions?
• Typically SLAs are against the entire
infrastructure, NOT single VMs
Information Security
• Not always as clear-cut as private > public re. security
• Cloud providers existence depend on delivering secure services
• However legal compliance is sometimes out of their control
• For IaaS service models, OS responsibility is still yours
• Patching, AV, IDS/IPS, hardening, etc.
• Key aspect of hybrid cloud is integrated monitoring
• Similar tools across public/private clouds to protect OS and apps
• Control access to Cloud provider APIs / user accounts
• Enforce strong passwords, 2FA, access controls
• Difficult to overstate the importance of this requirement
Change Management
• Make use of cloud service tools
• Audit logs (such as AWS CloudTrail, Config)
• See if your existing toolsets can integrate with your public cloud
• Remember that some changes are cloud-initiated
• e.g. Auto-scaling of instances due to load / bandwidth capacity
• As with configuration management, it’s the auto-scaling policy
that should be under change control, not the instances
themselves
Asset & Configuration Management
• Cloud assets are often transient
• Created and destroyed based on demand requirements
• Auto-scaling instances are identical
• Cattle v Pets analogy
• Asset manage the template,
not the instance
• Disable management connectivity to
individual instances
• Version your templates/config
Release Management
• Approach depends on architectural design
• Cloud-native application:
• Continuous integration / deployment
• Blue / green deployment
• Rolling upgrades
• Enterprise applications
• Existing approaches can be used
• Beware of public cloud limitations (snapshots, rollbacks)
• DevOps approach is worth investigation
• Combine Development and Operations skills within a team
Service Reporting
• Public clouds provide great metrics
• But you have to work to integrate them with your systems
• And decide how much of them you want to share with end-users
• If you haven’t already, invest in a centralised data repository
• Lots of options:
• Open-source, such as Elasticsearch
• COTS, such as MS SQLAnalytics
• Cloud-based, such as SumoCloud or Splunk
• The benefits far outweigh the costs of implementation
Conclusions
Cloud is not just hype…
• …done right, Public cloud provides:
• Scale, elasticity, self-service, metered usage
• The agility to deploy new services rapidly with no CapEx
• However, Private cloud is still vital for:
• Sensitive services that are required to be hosted locally
• Stable, long-running service with known workloads
• Hybrid cloud allows you the best of both worlds
• But requires you to adapt your processes to accommodate both
• How far those adaptations go depend on how “bought-in” you are
• Lots of good practice in the market – make use of it!
QUESTIONS?
Thank you!
Matt Johnson
Principal Infrastructure Architect, Eduserv
Web: http://www.eduserv.org.uk/services/cloud/
Twitter: @mhj_work
LinkedIn: https://uk.linkedin.com/in/mhjwork

Contenu connexe

Tendances

Cloud + Soa: Enterprise Service Platform
Cloud + Soa: Enterprise Service PlatformCloud + Soa: Enterprise Service Platform
Cloud + Soa: Enterprise Service Platform
victorlbrown
 
Group 39 presentation cloud computing
Group 39 presentation cloud computingGroup 39 presentation cloud computing
Group 39 presentation cloud computing
Deepak Shukla
 
2109 mobile cloud integrating your mobile workloads with the enterprise
2109 mobile cloud  integrating your mobile workloads with the enterprise2109 mobile cloud  integrating your mobile workloads with the enterprise
2109 mobile cloud integrating your mobile workloads with the enterprise
Todd Kaplinger
 
Cloudcomputing.072110
Cloudcomputing.072110Cloudcomputing.072110
Cloudcomputing.072110
Maxwell Pearl
 
Salesforce.com
Salesforce.comSalesforce.com
Salesforce.com
Rohit Bedi
 
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
WSO2
 

Tendances (20)

Cloud + Soa: Enterprise Service Platform
Cloud + Soa: Enterprise Service PlatformCloud + Soa: Enterprise Service Platform
Cloud + Soa: Enterprise Service Platform
 
Cloud enablement
Cloud enablementCloud enablement
Cloud enablement
 
Group 39 presentation cloud computing
Group 39 presentation cloud computingGroup 39 presentation cloud computing
Group 39 presentation cloud computing
 
OS Migration
OS MigrationOS Migration
OS Migration
 
Community IT Webinar - Cloud Migration Planning
Community IT Webinar - Cloud Migration PlanningCommunity IT Webinar - Cloud Migration Planning
Community IT Webinar - Cloud Migration Planning
 
2109 mobile cloud integrating your mobile workloads with the enterprise
2109 mobile cloud  integrating your mobile workloads with the enterprise2109 mobile cloud  integrating your mobile workloads with the enterprise
2109 mobile cloud integrating your mobile workloads with the enterprise
 
Basic cloud
Basic cloudBasic cloud
Basic cloud
 
Virtualization and High Availability
Virtualization and High AvailabilityVirtualization and High Availability
Virtualization and High Availability
 
Free VMware Presentation: The Power to Change
Free VMware Presentation:  The Power to ChangeFree VMware Presentation:  The Power to Change
Free VMware Presentation: The Power to Change
 
SAP Teched 2012 Session Tec3438 Automate IaaS SAP deployments
SAP Teched 2012 Session Tec3438 Automate IaaS SAP deploymentsSAP Teched 2012 Session Tec3438 Automate IaaS SAP deployments
SAP Teched 2012 Session Tec3438 Automate IaaS SAP deployments
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
Messaging: Harnessing The Cloud
Messaging: Harnessing The CloudMessaging: Harnessing The Cloud
Messaging: Harnessing The Cloud
 
Private cloud for_partners
Private cloud for_partnersPrivate cloud for_partners
Private cloud for_partners
 
Migration into cloud
Migration into cloud Migration into cloud
Migration into cloud
 
Cloud Enablement - IT Services Model
Cloud Enablement - IT Services Model Cloud Enablement - IT Services Model
Cloud Enablement - IT Services Model
 
Cloudcomputing.072110
Cloudcomputing.072110Cloudcomputing.072110
Cloudcomputing.072110
 
Serverless microservices
Serverless microservicesServerless microservices
Serverless microservices
 
Softlayer 07.nov.2014 en
Softlayer 07.nov.2014 enSoftlayer 07.nov.2014 en
Softlayer 07.nov.2014 en
 
Salesforce.com
Salesforce.comSalesforce.com
Salesforce.com
 
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
Roadmap to the Clouds - How to Easily Migrate to the Cloud Platform Using WSO...
 

Similaire à The move-to-hybrid-cloud-itsmf-april2015

Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012
Agora Group
 
CloudComputing
CloudComputingCloudComputing
CloudComputing
Adi Challa
 
Cloud computing presentation
Cloud computing presentationCloud computing presentation
Cloud computing presentation
Akash Tripathi
 

Similaire à The move-to-hybrid-cloud-itsmf-april2015 (20)

Cloud computing
Cloud computing Cloud computing
Cloud computing
 
Cloud computing(ppt)
Cloud computing(ppt)Cloud computing(ppt)
Cloud computing(ppt)
 
CLOUD COMPUTING.ppt
CLOUD COMPUTING.pptCLOUD COMPUTING.ppt
CLOUD COMPUTING.ppt
 
cloud computing
 cloud computing cloud computing
cloud computing
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Cloud Computing and Services | PPT
Cloud Computing and Services | PPTCloud Computing and Services | PPT
Cloud Computing and Services | PPT
 
12458003.ppt
12458003.ppt12458003.ppt
12458003.ppt
 
Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012Radu crahmaliuc 23feb2012
Radu crahmaliuc 23feb2012
 
Cloud computing Fundamentals - behind the hood of cloud platforms
Cloud computing Fundamentals - behind the hood of cloud platformsCloud computing Fundamentals - behind the hood of cloud platforms
Cloud computing Fundamentals - behind the hood of cloud platforms
 
Cloud computing Fundamentals - behind the hood of cloud platforms
Cloud computing Fundamentals - behind the hood of cloud platformsCloud computing Fundamentals - behind the hood of cloud platforms
Cloud computing Fundamentals - behind the hood of cloud platforms
 
Unit iii virtualitation
Unit iii   virtualitationUnit iii   virtualitation
Unit iii virtualitation
 
Cloud Computing basic concept to understand
Cloud Computing basic concept to understandCloud Computing basic concept to understand
Cloud Computing basic concept to understand
 
Financial impact of Cloud Computing
Financial impact of Cloud ComputingFinancial impact of Cloud Computing
Financial impact of Cloud Computing
 
CloudComputing
CloudComputingCloudComputing
CloudComputing
 
Cloud computing and data security
Cloud computing and data securityCloud computing and data security
Cloud computing and data security
 
Cloud Computing.pptx
Cloud Computing.pptxCloud Computing.pptx
Cloud Computing.pptx
 
Cloud Computing.pptx
Cloud Computing.pptxCloud Computing.pptx
Cloud Computing.pptx
 
Cloud Storage and Cloud Computing.pptx
Cloud Storage and  Cloud Computing.pptxCloud Storage and  Cloud Computing.pptx
Cloud Storage and Cloud Computing.pptx
 
Virtualization vs. Cloud Computing: What's the Difference?
Virtualization vs. Cloud Computing: What's the Difference?Virtualization vs. Cloud Computing: What's the Difference?
Virtualization vs. Cloud Computing: What's the Difference?
 
Cloud computing presentation
Cloud computing presentationCloud computing presentation
Cloud computing presentation
 

Plus de Eduserv

Plus de Eduserv (20)

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
 
Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources
 
Lightning talk - EBSCO
Lightning talk - EBSCOLightning talk - EBSCO
Lightning talk - EBSCO
 
Lightning talk - Boopsie
Lightning talk - BoopsieLightning talk - Boopsie
Lightning talk - Boopsie
 
Lightning talk - Softlink
Lightning talk - SoftlinkLightning talk - Softlink
Lightning talk - Softlink
 
Lightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineLightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZine
 
Lightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsLightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest Agreements
 
Phase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionPhase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolution
 
Key considerations when mapping your end user experience
Key considerations when mapping your end user experienceKey considerations when mapping your end user experience
Key considerations when mapping your end user experience
 
Our product development methodology
Our product development methodologyOur product development methodology
Our product development methodology
 
How Readers Discover Content
How Readers Discover ContentHow Readers Discover Content
How Readers Discover Content
 
OpenAthens product update
OpenAthens product updateOpenAthens product update
OpenAthens product update
 
OpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressOpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome address
 
Generating leads with content marketing
Generating leads with content marketingGenerating leads with content marketing
Generating leads with content marketing
 
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
 
Mobius from Maplesoft
Mobius from MaplesoftMobius from Maplesoft
Mobius from Maplesoft
 
QSR NVivo
QSR NVivo QSR NVivo
QSR NVivo
 
How Eduserv are helping local government organisations
How Eduserv are helping local government organisationsHow Eduserv are helping local government organisations
How Eduserv are helping local government organisations
 
Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Is cloud the right fit for your needs?
Is cloud the right fit for your needs?
 
Planning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsPlanning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing Councils
 

Dernier

Dernier (20)

FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
 
Powerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaPowerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara Laskowska
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 
Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024Enterprise Knowledge Graphs - Data Summit 2024
Enterprise Knowledge Graphs - Data Summit 2024
 
IESVE for Early Stage Design and Planning
IESVE for Early Stage Design and PlanningIESVE for Early Stage Design and Planning
IESVE for Early Stage Design and Planning
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdfHow Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
 
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya HalderCustom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2
 
UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1
 
WebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM PerformanceWebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM Performance
 
ECS 2024 Teams Premium - Pretty Secure
ECS 2024   Teams Premium - Pretty SecureECS 2024   Teams Premium - Pretty Secure
ECS 2024 Teams Premium - Pretty Secure
 

The move-to-hybrid-cloud-itsmf-april2015

  • 1. The Move to Hybrid Cloud Benefits and challenges to IT Service Management Matt Johnson, April 2015
  • 2. Agenda • Recap – what is cloud anyway? • Deployment, Service models • Essential characteristics • The Hybrid cloud model • Service Management in a hybrid cloud world • Service Design: Capacity, InfoSec, Supplier Mgmt • Service Transition: Change, Asset/Config, Release Mgmt • Service Improvement: Service Measurement & Reporting • Recommendations
  • 4. Recap: What is Cloud anyway?
  • 5. Cloud Models • Cloud Deployment models • Public – multi-tenanted Internet-based service (AWS) • Private – single-tenanted, closed-network service (vCloud) • Community – multi-tenanted service aimed at a specific user group • Hybrid – Combination of 2 (or more) cloud infrastructures • Today’s focus is on Hybrid Cloud models
  • 6. Cloud Models • Cloud Service Models • IaaS – compute, storage, networking services • PaaS – managed platform that supports app development • SaaS – managed software delivered via a web browser • Today’s focus is on IaaS service models
  • 7. Cloud Characteristics • Essential Characteristics • Broad Network Access • Resource Pooling • Rapid Elasticity • Measured Service • On Demand Self-Service
  • 9. Broad Access – addressing usability • Traditional IT has historically been “siloed” • Vertical deployments of application stacks for specific purposes • Access to these silos is controlled independently • Integration across services is limited • This isn’t always a bad thing! • Security, accountability, control are all increased • But this approach… • …has resulted in “planning blight”, and • Leads to the use of “Shadow IT”
  • 10. Broad access – more than one way… Cloud Service Web console Command Line REST API Development SDK 3rd party integration
  • 11. Resource pooling – addressing efficiency • Consolidation of workloads • More efficient use of infrastructure • Higher availability (through HA) • Lower infrastructure costs • Comes at a price • Less spare capacity to scale, unless you purchase “spare” • Failure of physical servers impact more services
  • 12. Resource pooling – benefits at scale Organisation with 200 physical servers: ~ $6,500 per server Cloud provider with 20k+ physical servers: ~ $1,000 per server
  • 13. • Traditional architecture design requires adopting one of two approaches: • Design for peak load – results in unused capacity • Design for average load – results in over-subscribed capacity • Virtualisation can help solve compute capacity, but not: • Network / storage capacity • Scaling automation Elasticity – addressing capacity
  • 14. Elasticity (rapid scalability) • Public cloud provides “infinite” (from a typical customer’s viewpoint) scalability • Deals with the “hard” stuff that virtualisation doesn’t: • Scaling network/bandwidth • Scaling storage • Scaling automation
  • 15. Measured Service – addressing purchasing • IT has traditionally been a cost centre • Pressure to reduce costs • Expenditure linked to budget cycles • Typically high CapEx for new projects • IT increasingly adds value to business • Showback / Chargeback are attempts to represent this value to individual business units • Very difficult to apportion core infrastructure costs (switching, network, etc.)
  • 16. Measured Service – pay as you go • Cloud services charge based on use • Discount levels for bulk usage • No minimum contract periods • Detailed metrics, which can be categorised as required
  • 17. The Hybrid Cloud model Private + Public = Hybrid
  • 18. Hybrid Cloud • At its simplest, Hybrid cloud simply connects two (or more) cloud services via defined mechanism(s) • In practice, there are two distinct patterns for service delivery: • Discrete – individual services reside on a single, specific cloud • Integrated – individual services are managed & delivered transparently across the hybrid cloud infrastructure • Management services are similar: • Discrete – each cloud is managed individually • Integrated – combined management stack
  • 19. Why Hybrid? • Allows you to make best use of the strengths of each type of cloud platform: • Public Cloud (such as AWS): • Scale, pace of innovation, elasticity, additional functionality, price • Private Cloud (such as vCloud): • Security, customisation, compliance, control • Provides a transition path from fully on-premise services • Great for pilot / PoC / development / DR service provision • Lots of different justifications; in practice, it comes down to: • Public cloud = agility • Private cloud = control
  • 21. Private Cloud control (Eduserv) • Secure Compute Cloud • Government-accredited infrastructure (“IL2”, “IL3”) • UK data sovereignty – UK owned and operated datacentre • Specialist network connectivity (PSN, Janet, WAN, etc.) • Capability for external audits
  • 22. Hybrid Cloud – Management considerations • Infrastructure • Deployment tools are likely to be different to on-premise IT • Be aware of subtle differences, esp. if you are used to vSphere • Network connectivity • Fast, low-latency links are important where services are integrated • OS & application management • Existing tools should be compatible, but… • …may not be able to handle “cloud-native” designs • Think about how you architect directory services across clouds • Start simple!
  • 23. Hybrid Cloud Service Management Some considerations
  • 24. Capacity Management • Hybrid “Cloud Bursting” is (in most cases) a myth • Scaling a service tier across a hybrid cloud is complex and costly • Keep tiers within a single cloud (i.e. web on public, app on private) • Try to place “bursty” services onto public cloud infrastructure • Long-term stable services are a good fit for private cloud • There’s no such thing as “spare” capacity on a public cloud • You pay for anything that is running / being used • Turn on when you need it, off when you don’t • Public cloud is great for off-site storage (object/tape storage) • Push (encrypted) backup data, with retention/lifecycle policies
  • 25. Supplier Management • One of the most important hybrid cloud processes to understand • Understand cloud providers T&Cs • Unlikely you will be able to modify the terms • Understand data retention, termination, payment requirements • Understand cloud provider service levels • What SLAs are offered? What are the exclusions? • Typically SLAs are against the entire infrastructure, NOT single VMs
  • 26. Information Security • Not always as clear-cut as private > public re. security • Cloud providers existence depend on delivering secure services • However legal compliance is sometimes out of their control • For IaaS service models, OS responsibility is still yours • Patching, AV, IDS/IPS, hardening, etc. • Key aspect of hybrid cloud is integrated monitoring • Similar tools across public/private clouds to protect OS and apps • Control access to Cloud provider APIs / user accounts • Enforce strong passwords, 2FA, access controls • Difficult to overstate the importance of this requirement
  • 27. Change Management • Make use of cloud service tools • Audit logs (such as AWS CloudTrail, Config) • See if your existing toolsets can integrate with your public cloud • Remember that some changes are cloud-initiated • e.g. Auto-scaling of instances due to load / bandwidth capacity • As with configuration management, it’s the auto-scaling policy that should be under change control, not the instances themselves
  • 28. Asset & Configuration Management • Cloud assets are often transient • Created and destroyed based on demand requirements • Auto-scaling instances are identical • Cattle v Pets analogy • Asset manage the template, not the instance • Disable management connectivity to individual instances • Version your templates/config
  • 29. Release Management • Approach depends on architectural design • Cloud-native application: • Continuous integration / deployment • Blue / green deployment • Rolling upgrades • Enterprise applications • Existing approaches can be used • Beware of public cloud limitations (snapshots, rollbacks) • DevOps approach is worth investigation • Combine Development and Operations skills within a team
  • 30. Service Reporting • Public clouds provide great metrics • But you have to work to integrate them with your systems • And decide how much of them you want to share with end-users • If you haven’t already, invest in a centralised data repository • Lots of options: • Open-source, such as Elasticsearch • COTS, such as MS SQLAnalytics • Cloud-based, such as SumoCloud or Splunk • The benefits far outweigh the costs of implementation
  • 32. Cloud is not just hype… • …done right, Public cloud provides: • Scale, elasticity, self-service, metered usage • The agility to deploy new services rapidly with no CapEx • However, Private cloud is still vital for: • Sensitive services that are required to be hosted locally • Stable, long-running service with known workloads • Hybrid cloud allows you the best of both worlds • But requires you to adapt your processes to accommodate both • How far those adaptations go depend on how “bought-in” you are • Lots of good practice in the market – make use of it!
  • 33. QUESTIONS? Thank you! Matt Johnson Principal Infrastructure Architect, Eduserv Web: http://www.eduserv.org.uk/services/cloud/ Twitter: @mhj_work LinkedIn: https://uk.linkedin.com/in/mhjwork