1.0 Introduction & Core Concepts
1.1 Definition and Evolution of Cloud Computing
-
Definition (NIST): A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
-
Core Characteristics (NIST):
-
On-Demand Self-Service: Provision resources automatically without human interaction.
-
Broad Network Access: Available over the network via standard mechanisms.
-
Resource Pooling: Multi-tenant model with pooled physical/virtual resources.
-
Rapid Elasticity: Resources can be scaled outward/inward quickly.
-
Measured Service: Resource usage monitored, controlled, and billed.
-
-
Evolution:
-
Cluster Computing: Group of loosely coupled computers working together.
-
Grid Computing: Distributed computing for large-scale, collaborative tasks (e.g., SETI@home).
-
Utility Computing: Pay-per-use model for computing resources (precursor to cloud billing).
-
Cloud Computing: Integrated service model (IaaS/PaaS/SaaS) with full abstraction and management.
-
[!TIP] Exam Focus: "Computing on Demand" is synonymous with On-Demand Self-Service. Be ready to explain how it enables dynamic provisioning via APIs/portals.
1.2 Grid Computing vs. Cloud Computing
| Feature | Grid Computing | Cloud Computing |
|---|---|---|
| Goal | Solve large, complex scientific problems | Deliver on-demand IT services & applications |
| Architecture | Decentralized, heterogeneous resources | Centralized/Orchestrated, homogeneous pools |
| Resource Mgmt. | Distributed scheduling, job-based | Centralized orchestration, VM/container-based |
| Ownership | Multiple administrative domains | Single provider (public) or single org (private) |
| Scalability | Scale out for batch jobs | Scale elastically for variable workloads |
| Business Model | Often non-commercial, collaborative | Commercial, pay-per-use |
| Example | SETI@home, CERN LHC computing grid | AWS, Azure, Google Cloud Platform |
Similarities: Both use distributed resources, aim for high utilization, and support parallel processing.
[!TIP] Common Pitfall: Grid focuses on collaborative problem-solving across organizations; Cloud focuses on service delivery to end-users/applications.
2.0 Cloud Service Models (SPI Model)
2.1 Infrastructure as a Service (IaaS)
-
Definition: Provides fundamental computing resources—processing, storage, networks—over the internet. Users install OS and applications.
-
Core Offerings: Virtual Machines (VMs), Virtual Networks, Block Storage (EBS), Object Storage.
-
Examples: Amazon EC2, Google Compute Engine, Microsoft Azure VMs.
-
User Control: OS, middleware, runtime, applications, data.
2.2 Platform as a Service (PaaS)
-
Definition: Provides a platform allowing customers to develop, run, and manage applications without infrastructure complexity.
-
Core Offerings: Runtime environment, middleware, development tools (SDKs, databases), OS.
-
Examples: Google App Engine, Heroku, Microsoft Azure App Services, AWS Elastic Beanstalk.
-
User Control: Applications and data only.
2.3 Software as a Service (SaaS)
-
Definition: Delivers complete, ready-to-use software applications over the internet, typically via a web browser.
-
Core Offerings: Complete application, data, configuration.
-
Examples: Gmail, Salesforce, Microsoft 365, Dropbox.
-
User Control: Minimal configuration and data.
2.4 Comparative Analysis of SPI Models
Control vs. Convenience Spectrum:
IaaS <---(More Control, Less Convenience)--- PaaS <---(Less Control, More Convenience)--- SaaS
Shared Responsibility Model:
| Service Model | Provider Responsibility | Customer Responsibility |
|---|---|---|
| IaaS | Physical infrastructure, hypervisor, network core | OS, middleware, apps, data, access |
| PaaS | Infrastructure, OS, middleware, runtime | Apps, data, configuration |
| SaaS | Everything up to the application | Data, user access, configuration |
[!TIP] Exam Question: "Define SaaS, PaaS, and IaaS models and explain their differences." Use the spectrum diagram and responsibility table in your answer.
3.0 Cloud Deployment Models
| Model | Definition | Ownership/Operation | Benefits | Limitations | Use Cases |
|---|---|---|---|---|---|
| Public Cloud | Services offered over the public internet by third-party providers. | Third-party (e.g., AWS, Azure) | Cost-effective (OpEx), no CapEx, high scalability, managed. | Less control, security/compliance concerns, potential vendor lock-in. | Web apps, dev/test, variable workloads, startups. |
| Private Cloud | Cloud infrastructure operated solely for a single organization. | Organization (on-prem/outsourced) | Maximum control, security, customization, compliance. | High CapEx/OpEx, management overhead, limited elasticity. | Regulated industries (finance, govt), sensitive data, legacy apps. |
| Hybrid Cloud | Orchestration between two or more distinct cloud models (public + private). | Combined (org + provider) | Flexibility, workload optimization, compliance, avoids lock-in. | Complex integration, management challenges, network latency. | Cloud bursting, phased migration, data sovereignty. |
| Community Cloud | Shared infrastructure for a specific community with common concerns. | Community orgs or 3rd party | Cost-sharing, compliance with community standards. | Limited scale, community governance complexity. | Government agencies, universities, industry consortiums. |
Selecting a Deployment Model:
Decision Framework: Evaluate based on Cost (CapEx vs OpEx), Control & Customization needs, Security & Compliance requirements (e.g., GDPR, HIPAA), Scalability needs, and Organizational Constraints (skills, legacy systems).
[!TIP] Exam Focus: "Public vs. Private Clouds" and "Hybrid Cloud benefits/challenges" are recurring 7-mark questions. Use the table for structured answers.
4.0 Virtualization: The Foundational Technology
4.1 Introduction to Virtualization
-
Definition: The creation of a virtual (rather than actual) version of something, including virtual hardware platforms, storage devices, and network resources.
-
Enables: Efficient hardware utilization (consolidation), multi-tenancy, isolation, and rapid provisioning—core to cloud computing.
4.2 Types of Virtualization
-
Server Virtualization: Multiple OS instances on a single physical server.
-
Full Virtualization: Complete hardware simulation (VMware, Hyper-V).
-
Para-virtualization: Guest OS modified to use hypervisor API for better perf (Xen).
-
Hardware-Assisted Virtualization (HVM): CPU extensions (Intel VT-x, AMD-V) for efficient virtualization.
-
-
Storage Virtualization:
-
Block-level (SAN): Presents logical disks (LUNs) from a storage pool.
-
File-level (NAS): Presents shared file systems (NFS, CIFS).
-
Concept: Abstracts physical storage into a single logical pool.
-
-
Network Virtualization: Combines physical network resources into a virtual network.
-
VLANs: Segregate broadcast domains.
-
SDN: Separates control plane (controller) from data plane (switches).
-
4.3 Hypervisors (Virtual Machine Monitors - VMM)
| Type | Architecture | Examples | Key Points |
|---|---|---|---|
| Type 1 (Bare-Metal) | Runs directly on host hardware. | VMware ESXi, Microsoft Hyper-V, Xen (with dom0) | High performance, used in data centers & clouds. |
| Type 2 (Hosted) | Runs on top of a host OS. | VMware Workstation, Oracle VirtualBox | Easy setup, used for desktop/development. |
Functions: Resource allocation (CPU, memory, I/O), isolation between VMs, hardware emulation.
4.4 Virtual Machine (VM) Concepts
-
Lifecycle: Create → Start/Stop → Suspend/Resume → Migrate (live) → Destroy.
-
VM Image/Template: Pre-configured OS + apps, used for rapid provisioning.
-
Security Risks:
-
VM Escape: Breaking out of VM to host.
-
VM Sprawl: Uncontrolled VM proliferation.
-
Image Security: Malicious/outdated images, insecure credentials.
-
4.5 Logical Partitioning (LPAR)
-
Definition: Firmware-level partitioning of a physical server into independent logical partitions (LPARs), each with dedicated resources (CPU, memory, I/O).
-
Advantages: Strong isolation, predictable performance, security, flexible resource allocation.
-
Disadvantages: Complexity, potential resource fragmentation, less flexible than full virtualization (no VMotion).
-
vs. Full Virtualization: LPAR uses hardware partitioning (no hypervisor overhead), but lacks features like live migration and dynamic resource reallocation.
4.6 Virtualized Data Center Architecture
[[DIAGRAM: CANVAS: A layered diagram showing:
-
Physical Layer: Rack servers, SAN/NAS storage, physical switches/routers.
-
Virtualization Layer: Hypervisors on servers, virtual switches (vSwitch), virtual storage (vSAN).
-
Management Layer: vCenter/System Center for orchestration.
-
Cloud Portal/API Layer: End-user interface for self-service.
]] Components:
-
Virtualized Servers (Compute): Hypervisor hosts running VMs.
-
Virtualized Storage: Storage pools presented as virtual disks.
-
Virtualized Networking: Virtual switches, VLANs, virtual firewalls.
-
Management Layer: Central console (e.g., VMware vCenter) for provisioning, monitoring, automation. Benefits: Server consolidation, agility, automated provisioning, improved disaster recovery.
[!TIP] Exam Question: "Explain how virtualization enables efficient utilization..." Focus on consolidation (multiple VMs on one server), isolation, and dynamic resource allocation.
5.0 Cloud Architecture & Design Patterns
5.1 Cloud Computing Reference Model
[[DIAGRAM: CANVAS: A layered model from top to bottom:
-
Client Layer ( browsers, mobile apps)
-
Application Layer ( SaaS apps)
-
Platform Layer (PaaS runtime, middleware)
-
Infrastructure Layer (IaaS: VMs, storage, network)
-
Management Layer (orchestration, billing, security) - spans all layers.
]]
-
Layers: Client → Application → Platform → Infrastructure → Management.
-
Management Layer is cross-cutting, providing orchestration, provisioning, metering, security, and compliance across all service layers.
5.2 Service-Oriented Architecture (SOA) in Cloud
-
Core Principles: Loose coupling, reusability, interoperability, contract-based interactions.
-
Role in Cloud: Enables composition of cloud services (from different providers) into business processes. Facilitates integration between on-premise and cloud apps.
-
Technologies: Web Services (SOAP/XML for enterprise, REST/JSON for web/mobile), APIs (public/private), Enterprise Service Bus (ESB).
-
Example: A retail app using AWS (compute), Salesforce (CRM), and a payment gateway API—all integrated via SOA/REST.
5.3 Cloud Stack
-
Conceptual Layered Model: The SPI stack built on virtualization.
SaaS (Applications) PaaS (Runtime, Middleware) IaaS (VMs, Storage, Network) Virtualization Layer Physical Hardware -
Example Stacks:
-
OpenStack: Open-source IaaS cloud operating system (Nova, Swift, Neutron).
-
Cloud Foundry: Open-source PaaS (buildpack-based deployment).
-
Proprietary Stack: AWS (IaaS/PaaS) + SaaS apps.
-
[!TIP] Exam Focus: "Cloud Stack" and "SOA in Cloud" are direct past questions. Draw the stack diagram and explain SOA's role with a concrete example.
6.0 Cloud Security
6.1 Importance and Unique Challenges
-
Shared Responsibility Model: Provider secures the cloud (infrastructure). Customer secures in the cloud (data, apps, access).
-
Challenges: Multi-tenancy risks (data leakage), data residency/sovereignty, compliance (GDPR, HIPAA), API vulnerabilities, account hijacking, insider threats.
6.2 Core Security Aspects
| Aspect | Key Technologies/Concepts |
|---|---|
| Data Security | Encryption (At Rest: AES-256; In Transit: TLS 1.3), Key Management (KMS), Data Loss Prevention (DLP), tokenization. |
| Network Security | Virtual Firewalls (Security Groups/NACLs), IDS/IPS, DDoS mitigation (AWS Shield), VPNs/Direct Connect, micro-segmentation. |
| Identity & Access Mgmt (IAM) | Authentication (MFA, SSO, Federation via SAML/OIDC), Authorization (policies), Principle of Least Privilege. |
| Role-Based Access Control (RBAC) | Permissions assigned to roles (e.g., Admin, Developer, Viewer), users assigned to roles. Centralized policy management. |
6.3 Secure Execution Environments & Communications
-
Secure Bootstrapping: Verified boot process, measured boot (TPM).
-
Trusted Platform Module (TPM): Hardware-based security for key storage/attestation (cloud TPMs available).
-
Encrypted VM Disks & Memory: VM-level encryption (e.g., AWS EBS encryption), confidential computing (encrypted memory).
6.4 Securing Virtual Machines (VMs)
-
Use Hardened/Trusted Images: CIS Benchmarks, minimal OS, patched.
-
Network Segmentation (Micro-segmentation): Apply security groups at NIC/VM level.
-
VM Activity Monitoring & Logging: Centralized logging (CloudWatch, Azure Monitor), audit trails.
-
VM Sprawl Management: Automated de-provisioning, tagging, lifecycle policies.
[!TIP] Exam Question: "Discuss the importance of information security..." Structure: 1) Shared Responsibility, 2) Multi-tenancy risks, 3) Cover Data, Network, IAM aspects, 4) Compliance. Use RBAC and encryption as key examples.
7.0 Supporting Technologies & Concepts
7.1 Utility Computing
-
Pay-per-use model: Resources metered and billed based on consumption (compute hours, GB stored, network I/O).
-
Analogy: Like electricity—plug in, use, pay bill.
7.2 Quality of Service (QoS)
-
Definition: Metrics defining service performance: Availability (uptime %), Performance (throughput, latency), Reliability (MTBF).
-
Key Issues:
-
Network Latency: Delay in data transmission (critical for real-time apps).
-
Bandwidth Guarantees: Reserved bandwidth for critical apps.
-
Service Level Agreements (SLAs): Formal contracts specifying QoS metrics and penalties.
-
Noisy Neighbor: One tenant's resource hogging affecting others.
-
7.3 Storage Clouds
-
Object Storage (S3): Unstructured data (blobs), REST API, massive scale, eventual consistency (e.g., AWS S3).
-
Block Storage (EBS): Raw block devices for VMs, high IOPS, persistent.
-
File Storage (EFS/FSx): Shared file systems (NFS/SMB), hierarchical.
-
STaaS: Storage delivered as a service with pay-per-use.
7.4 Cloud Infrastructure Benchmarks
-
Purpose: Compare performance, scalability, cost of cloud platforms/vendors.
-
Common Metrics:
-
Compute: vCPUs, GHz, benchmarks (SPECint).
-
Storage: IOPS (Input/Output Operations Per Second), throughput (MB/s), latency (ms).
-
Network: Bandwidth (Gbps), latency, jitter.
-
Cost: $/VM-hour, $/GB-month, total cost of ownership (TCO).
-
7.5 Independent Software Vendors (ISVs)
-
Role: Develop enterprise/business applications (e.g., SAP, Oracle) that run on cloud platforms.
-
Cloud Adaptation: Re-architect for cloud (multi-tenancy, elasticity), create cloud-native versions.
-
Certification Programs: AWS ISV Accelerate, Azure Marketplace—test and certify apps for cloud deployment, ensuring compatibility and best practices.
[!TIP] Exam Focus: "QoS" and "Storage Clouds" are direct past questions. Define QoS, list latency, bandwidth, SLA as key issues. For storage, differentiate Object vs Block vs File with one example each.
8.0 Open-Source & Proprietary Cloud Platforms (Briefing)
8.1 OpenNebula
-
Overview: Open-source cloud management platform for IaaS.
-
Key Features: VM orchestration, hybrid cloud support (AWS, Azure, vCenter), simple architecture, focuses on stability and interoperability.
-
Use Cases: Enterprise private clouds, research, education.
8.2 Nimbus
-
Overview: Open-source IaaS toolkit for cloud computing, originally from scientific community.
-
Key Features: Contextualization (injecting user data/config into VMs), supports EC2-compatible APIs, lightweight.
-
Use Cases: Scientific clouds, testbeds, research infrastructure.
8.3 Comparative Context
| Platform | Type | Primary Use | vs. AWS/Azure/GCP |
|---|---|---|---|
| OpenNebula | Open-source IaaS | Private/Hybrid cloud management | More lightweight, less feature-rich than AWS, but avoids vendor lock-in. |
| Nimbus | Open-source IaaS Toolkit | Scientific/Research clouds | Niche, API-compatible with AWS (EC2), simpler than full suites. |
| AWS/Azure/GCP | Proprietary Public Cloud | Full-stack public cloud services | Comprehensive global services, massive scale, integrated ecosystem. |
| VMware | Proprietary (Private/Hybrid) | Enterprise private cloud (vSphere) | Mature, enterprise-grade, but licensing costs. |
[!TIP] Exam Focus: "How OpenNebula used in cloud computing?" Explain its role as an IaaS manager for building private/hybrid clouds, contrasting with public cloud providers. Mention EC2 compatibility and contextualization for Nimbus.