Skip to content
AL-604 (A) · Cloud Computing/Quick Revision Short Notes

Cloud Computing (AL-604 (A)) - Unit 2 Short Notes

UNIT 2: CLOUD COMPUTING - SHORT NOTES

1.0 FOUNDATIONAL CONCEPTS & EVOLUTION

1.1 Computing on Demand (CoD) / Utility Computing

  • Definition: A business model where computing resources (processing power, storage, network) are provided as a metered service, similar to traditional utilities (electricity, water). Users pay only for the resources they consume.

  • Core Principle: On-demand self-service with pay-per-use billing.

  • Enables Dynamic Provisioning:

    • Scalability: Ability to increase or decrease resource capacity to meet workload demands.

    • Elasticity: Rapid, automatic scaling (both up and down) in response to real-time demand.

    • Resource Pooling: Provider's computing resources are pooled to serve multiple consumers using a multi-tenant model.

[!TIP] Exam Focus: CoD is the foundational economic model for cloud computing. Link it directly to the NIST essential characteristics of "measured service" and "rapid elasticity."

1.2 Grid Computing vs. Cloud Computing

Feature Grid Computing Cloud Computing
Primary Goal Solve large, complex problems by aggregating resources from multiple administrative domains. Deliver on-demand, scalable IT resources as a service.
Architecture Decentralized, heterogeneous, often geographically dispersed. Centralized, standardized, large data centers.
Resource Management Complex, often batch-oriented, with focus on job scheduling. Centralized, automated, with self-service portals and APIs.
Ownership Resources belong to different organizations (federated). Resources are owned and managed by a single provider (or a private entity).
Scalability Scales by adding more nodes to the grid. Scales seamlessly within a pooled infrastructure.
Use Case Scientific computing (e.g., SETI@home, climate modeling). Enterprise IT, web applications, SaaS.
Similarity Both involve distributed computing and resource sharing.

[!TIP] Common Pitfall: Do not confuse them. Grid is about collaborative problem-solving across boundaries; Cloud is about centralized service delivery with a utility model.

1.3 Cloud Computing Reference Model

A layered architectural model defining functional components and their relationships.

  • Client Layer: Devices and interfaces (web browsers, thin clients, mobile apps) used to access cloud services.

  • Application Layer: Cloud-based software applications (SaaS).

  • Platform Layer: Development and runtime environments (PaaS - OS, middleware, DBMS).

  • Infrastructure Layer: Virtualized hardware resources - compute, storage, network (IaaS).

  • Management/Security Layer: Cross-cutting functions (orchestration, provisioning, security, compliance, billing) that span all other layers.

DiagramSEARCH: "cloud computing reference model nist layer diagram"

2.0 CLOUD SERVICE MODELS (SPI MODEL)

2.1 Infrastructure as a Service (IaaS)

  • Definition: Provides fundamental computing resources (virtual machines, storage, networks) over the internet. Users have control over OS, storage, and deployed applications.

  • Characteristics: Virtualized hardware, on-demand provisioning, pay-as-you-go, high scalability.

  • Examples: Amazon EC2 (VMs), Google Compute Engine, Microsoft Azure VMs, virtual private clouds (VPCs).

2.2 Platform as a Service (PaaS)

  • Definition: Provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the underlying infrastructure.

  • Characteristics: Includes OS, programming language execution environment, database, web server. Focuses on application development lifecycle.

  • Examples: Heroku, Google App Engine, Microsoft Azure App Services, AWS Elastic Beanstalk.

2.3 Software as a Service (SaaS)

  • Definition: Delivers complete, ready-to-use software applications over the internet, typically via a web browser.

  • Characteristics: No infrastructure/platform management for user. Multi-tenant architecture, automatic updates, subscription-based.

  • Examples: Gmail, Salesforce, Microsoft 365, Dropbox, Slack.

2.4 Comparative Analysis of IaaS, PaaS, SaaS

Aspect IaaS PaaS SaaS
Control Level Highest (OS, middleware, runtime, app, data). Medium (app, data). Lowest (configuration only).
Management Responsibility User manages OS, apps, data. Provider manages physical infra. User manages app & data. Provider manages OS, runtime, infra. Provider manages everything. User just uses the app.
Customization Very high (full OS control). Moderate (within platform constraints). Low (configuration within app settings).
Target User IT admins, DevOps, architects. Application developers. End-users, business units.
Analogy Renting a raw plot of land & construction tools. Renting a pre-built house with utilities. Renting a fully furnished apartment.

[!TIP] Exam Tip: Remember the " Responsibility Pyramid": User responsibility decreases from IaaS -> PaaS -> SaaS. Provider responsibility increases.


3.0 CLOUD DEPLOYMENT MODELS

3.1 Public Cloud

  • Definition: Cloud infrastructure made available to the general public or a large industry group, owned and operated by a cloud service provider (e.g., AWS, Azure, GCP).

  • Characteristics: Multi-tenancy, massive scale, no capital expenditure (OpEx model), high scalability.

  • Advantages: Cost-effective, no maintenance, high reliability, global reach.

  • Disadvantages: Less control, potential security/compliance concerns, possible vendor lock-in.

3.2 Private Cloud

  • Definition: Cloud infrastructure operated solely for a single organization. Can be managed internally or by a third party, hosted on-premise or off-site.

  • Characteristics: Single-tenancy, greater control, enhanced security/customization.

  • Advantages: Superior control, security, and compliance for sensitive data. Customizable.

  • Disadvantages: High capital cost (CapEx), requires management expertise, less elastic than public cloud.

3.3 Hybrid Cloud

  • Definition: Composition of two or more distinct cloud models (private and public) that remain unique entities but are bound together by standardized or proprietary technology enabling data and application portability.

  • Architecture: Uses APIs, VPNs, and dedicated connections to link private and public clouds.

  • Key Use Cases:

    • Cloud Bursting: Run normal workload in private cloud; burst to public cloud during demand spikes.

    • Data Sovereignty/Compliance: Keep sensitive data on-premise (private), use public cloud for less-sensitive processing.

    • Gradual Migration: Move legacy apps to cloud incrementally.

3.4 Community Cloud

  • Definition: Cloud infrastructure shared by several organizations with shared concerns (e.g., security requirements, compliance, policy). It may be managed by the organizations or a third party.

  • Example: A cloud shared by multiple government agencies for a specific project.

3.5 Selecting the Optimal Deployment Model

Decision factors to evaluate:

  1. Cost: TCO analysis (CapEx vs. OpEx).

  2. Security & Compliance: Regulatory requirements (GDPR, HIPAA), data sensitivity.

  3. Control: Need for customization and administrative access.

  4. Scalability Needs: Predictability of workload patterns.

  5. Legacy Systems: Integration complexity with existing on-premise infrastructure.

  6. Performance & Latency: Geographic location of users vs. data centers.

[!TIP] Exam Framework: For "selecting the best model" questions, structure your answer around these six factors. Use a scenario (e.g., a bank, a startup, a research lab) to illustrate.


4.0 VIRTUALIZATION - THE CORE ENABLING TECHNOLOGY

4.1 Fundamentals of Virtualization

  • Definition: The creation of a virtual (rather than actual) version of something, including virtual hardware platforms, storage devices, and network resources. It abstracts physical hardware from the software running on it.

  • Enables Efficient Utilization:

    • Consolidation: Multiple virtual machines (VMs) run on a single physical server, increasing utilization from ~15% to 60-80%.

    • Isolation: VMs are isolated from each other; a crash in one doesn't affect others.

    • Encapsulation: A VM is a single file (or set of files), making it easy to save, copy, and migrate.

4.2 Hypervisors (Virtual Machine Monitors - VMM)

  • Definition: Software, firmware, or hardware that creates and runs VMs. It sits between the physical hardware and the guest OS, allocating resources.
Type Type-1 (Native/Bare-Metal) Type-2 (Hosted)
Architecture Runs directly on the physical hardware (replaces the host OS). Runs on top of a conventional host OS (like an application).
Performance High (direct hardware access). Lower (hardware access via host OS).
Use Case Enterprise data centers, cloud infrastructure. Desktop virtualization, development/testing.
Examples VMware ESXi, Microsoft Hyper-V, Xen, KVM. Oracle VirtualBox, VMware Workstation, Parallels Desktop.
  • Paravirtualization: Guest OS is modified to be aware of the hypervisor, enabling more efficient communication (e.g., Xen in paravirt mode).

  • Hardware-Assisted Virtualization (HVM): CPU extensions (Intel VT-x, AMD-V) provide hardware support for running unmodified guest OSes securely. Modern standard for Type-1 hypervisors.

[!TIP] Key Distinction: Type-1 is for production clouds/servers. Type-2 is for desktop users/developers.

4.3 Logical Partitioning (LPAR)

  • Definition: A hardware-level virtualization technique (primarily on IBM POWER, mainframes) where a single physical server is divided into multiple isolated logical partitions. Each LPAR has its own dedicated resources (CPU, memory, I/O).

  • Architecture: Firmware/hypervisor layer (e.g., PowerVM, PR/SM) directly manages physical resources and assigns them to LPARs.

  • Advantages:

    • Strong isolation and security (hardware-enforced).

    • Predictable, guaranteed resource allocation (no "noisy neighbor").

    • High flexibility; resources can be dynamically moved between LPARs.

    • Supports multiple OS types (AIX, Linux, IBM i) on same server.

  • Disadvantages/Challenges:

    • Complex management.

    • Less flexible than full virtualization (e.g., cannot run arbitrary OS without support).

    • Typically tied to specific high-end hardware (proprietary).

4.4 Virtualized Data Center Architecture

A modern data center where physical components are abstracted and managed as software-defined entities.

  • Virtualized Servers (Compute): Physical servers run a hypervisor to host multiple VMs.

  • Storage Virtualization: Pool of physical storage devices presented as a single logical storage unit (see 4.5).

  • Network Virtualization (SDN): Separation of network control plane (SDN Controller) from data plane (switches). Enables creation of virtual networks (overlays like VXLAN) independent of physical topology.

  • Management Layer (Orchestration): Software (e.g., OpenStack, vRealize) that automates provisioning, monitoring, and lifecycle management of all virtualized resources.

4.5 Storage Virtualization

  • Definition: Abstraction of physical storage devices (from different vendors) into a single, pooled logical storage resource.

  • Types:

    • Block-Level: Presents raw storage blocks (LUNs) to hosts. Used by databases, VMs. (e.g., SAN).

    • File-Level: Provides a shared file system with folders/files. Used for NAS, home directories. (e.g., NFS, CIFS).

  • SAN vs. NAS:

    | Feature | SAN (Storage Area Network) | NAS (Network Attached Storage) | | :--- | :--- | :--- | | Access Method | Block-level (via Fibre Channel, iSCSI). | File-level (via NFS, SMB/CIFS over IP). | | Protocol | SCSI, Fibre Channel, iSCSI. | NFS, SMB/CIFS. | | Appearance to OS | Appears as a local disk drive. | Appears as a network file share. | | Use Case | High-performance DB, VM storage, enterprise apps. | File sharing, backups, content repositories. | | Example | EMC VMAX, NetApp FAS (block mode). | NetApp FAS (file mode), Isilon. |

  • Benefits: Increased utilization, simplified management, non-disruptive data migration, improved availability (mirroring across pools).

4.6 Requirements of a Virtualization Platform for Cloud Implementation

  1. Performance: Low overhead, near-native I/O performance (especially for network/storage).

  2. Scalability: Support for thousands of VMs per cluster, linear performance scaling.

  3. Security: Strong isolation between VMs, secure VM migration, support for security policies.

  4. Management APIs: Robust APIs for automation and integration with cloud management platforms (CMPs).

  5. Live Migration: Ability to move running VMs between physical hosts with zero downtime (e.g., vMotion, Live Migration).

  6. High Availability (HA): Automatic VM restart on other hosts in case of host failure.

  7. Resource Scheduling (DRS): Intelligent load balancing of VMs across hosts.


5.0 CLOUD SECURITY

5.1 Importance and Challenges

  • Importance: Protects sensitive data, ensures service availability, maintains compliance (GDPR, HIPAA), preserves customer trust, and prevents financial/reputational loss.

  • Challenges:

    • Shared Responsibility Model: Confusion over who secures what (Provider: security of the cloud; Customer: security in the cloud).

    • Multi-tenancy: Risk of data leakage between tenants sharing the same physical infrastructure.

    • Data Breaches: Unauthorized access to data stored in the cloud.

    • Compliance: Meeting regulatory requirements in a shared, dynamic environment.

    • Insider Threats: Malicious or negligent actions by employees of provider or customer.

    • Visibility & Control: Limited customer insight into provider's physical/logical security.

5.2 Comprehensive Scope of Cloud Security

  1. Data Security: Encryption (at rest, in transit), Data Loss Prevention (DLP), data classification, secure deletion.

  2. Network Security: Virtual firewalls, IDS/IPS, network segmentation (micro-segmentation), DDoS protection.

  3. Identity & Access Management (IAM): Centralized user management, authentication (MFA), authorization (RBAC), auditing.

  4. Compliance & Governance: Audit trails, logging, reporting, adherence to standards (ISO 27001, SOC 2).

5.3 Secure Execution Environments & Communications

  • Secure Bootstrapping: Mechanisms to ensure a VM starts with a known, trusted software stack (measured boot, trusted platform module - TPM).

  • Encryption:

    • In Transit: TLS/SSL for web traffic, VPNs (IPsec) for site-to-site.

    • At Rest: Encryption of storage volumes, databases, object storage (using provider-managed or customer-managed keys).

  • Secure Protocols: Use of SSH instead of Telnet, SFTP instead of FTP.

  • Trusted Platform Module (TPM): Hardware-based security chip that can be virtualized (vTPM) to provide attestation and key storage for VMs.

5.4 Virtual Machine (VM) Security

  • Risks:

    • VM Escape: Exploit allowing code in a VM to break out and interact with the hypervisor/host.

    • VM Hopping: Attacking one VM to gain access to another on the same host.

    • Snapshot/Analysis Attacks: Accessing sensitive data from VM snapshots or memory dumps.

    • Resource Exhaustion (DoS): Consuming all host resources (CPU, memory, disk I/O) from within a VM.

  • Recommendations/Benefits:

    • Hardened Images: Use minimal, patched OS images from trusted sources.

    • Network Segmentation: Place VMs in separate security groups/VLANs based on function.

    • VM Activity Monitoring: Monitor for anomalous behavior (CPU spikes, network traffic).

    • Anti-malware for VMs: Install endpoint protection inside guest OS.

    • Secure VM Lifecycle Management: Enforce policies for provisioning, de-provisioning, and patching.

5.5 Role-Based Access Control (RBAC)

  • Definition: A non-discretionary access control model where permissions are assigned to roles, not directly to users. Users are assigned to roles, inheriting the permissions of that role.

  • Model Components:

    • Users (Subjects): Individuals or systems.

    • Roles: Job functions (e.g., Admin, Developer, ReadOnly).

    • Permissions (Privileges): Specific actions on resources (e.g., vm:start, storage:delete).

    • Sessions: A user activates a subset of their assigned roles during a session.

  • Implementation in Cloud IAM: Central to AWS IAM, Azure RBAC, Google Cloud IAM. Policies (JSON/YAML) define which roles have which permissions on which resources.

  • Benefits over DAC: Simplifies administration (manage roles, not individual users), enforces least privilege, supports separation of duties.

[!TIP] Key Concept: In cloud, RBAC is the primary mechanism for implementing the "least privilege" security principle.


6.0 ENABLING TECHNOLOGIES & ARCHITECTURAL STYLES

6.1 Service-Oriented Architecture (SOA)

  • Core Principles:

    • Service: A self-contained unit of functionality (e.g., "Check Credit Score").

    • Loose Coupling: Services interact via well-defined interfaces (contracts), minimizing dependencies.

    • Interoperability: Services use standard protocols (HTTP, SOAP, REST) to work across platforms.

  • Role in Cloud: SOA is the architectural foundation for building cloud-native applications. It facilitates:

    • Integration: Combining multiple cloud-based and on-premise services.

    • Composition: Orchestrating finer-grained services into business processes.

    • Reusability: Services can be reused across different applications.

  • Implementation: Primarily through Web Services:

    • SOAP: Protocol-heavy, XML-based, with strict standards (WS-*). Used for enterprise integration.

    • REST: Architectural style using HTTP verbs (GET, POST), lightweight, JSON/XML. Dominant for public APIs and web-scale apps.

6.2 Role of Independent Software Vendors (ISVs)

  • Definition: Companies that develop and sell software applications that run on platforms provided by others (e.g., cloud providers, OS vendors).

  • In Cloud Context:

    • Developing SaaS Applications: ISVs build applications designed from the ground up for the cloud (multi-tenant, elastic).

    • Platform Certification: ISVs certify their software to run on specific cloud platforms (e.g., "AWS Ready," "Azure Certified") for compatibility and support.

    • Marketplace Distribution: Cloud providers (AWS Marketplace, Azure Marketplace, Salesforce AppExchange) offer ISV applications as one-click deployments, creating new revenue channels.

    • e-Business Apps: Focus on CRM, ERP, collaboration tools delivered via SaaS model.


7.0 ADVANCED TOPICS & SPECIALIZED AREAS

7.1 Quality of Service (QoS) & Cloud Infrastructure Benchmarks

  • QoS in Cloud: A set of measurable service attributes (Service Level Objectives - SLOs) that define the performance and reliability of a cloud service.

  • Key QoS Issues:

    1. Availability: Uptime percentage (e.g., 99.9%).

    2. Reliability: Probability of failure-free operation.

    3. Performance: Throughput, response time, latency.

    4. Scalability: Ability to handle growth.

    5. Security: Confidentiality, integrity, availability.

    6. Interoperability: Ability to work with other systems.

    7. Portability: Ease of moving apps/data between clouds.

  • Benchmarking Tools/Metrics: Standardized tests to measure and compare cloud performance.

    • SPEC Cloud IaaS: Industry-standard benchmarks for IaaS performance (CPU, memory, storage, network).

    • CloudHarmony (now part of Gartner): Historical performance data for cloud services.

    • Key Metrics: IOPS (storage), network throughput, VM boot time, scalability curve.

7.2 Storage Cloud / Cloud Storage Models

  • Object Storage (e.g., Amazon S3):

    • Model: Data is stored as objects (data + metadata + unique ID) in a flat namespace (buckets).

    • Access: HTTP/HTTPS APIs (REST). Highly scalable, durable, cost-effective for unstructured data (images, videos, backups).

  • Block Storage (e.g., Amazon EBS):

    • Model: Raw storage volumes (like virtual hard drives) that can be attached to VMs.

    • Access: Via protocols like iSCSI/Fibre Channel. Low latency, high performance. Used for OS, databases, file systems.

  • File Storage (e.g., Amazon EFS, Azure Files):

    • Model: Hierarchical file system (folders/files) accessible via standard protocols (NFS, SMB).

    • Access: Shared file system for multiple VMs/instances. Used for content management, home directories.

7.3 Cloud Management & Orchestration Tools

  • OpenNebula:

    • Architecture: Modular. Core (Sunstone, CLI) interacts with Hypervisors (KVM, LXC, vCenter), Storage (NFS, Ceph), Networking (Open vSwitch), and Authentication (LDAP, Active Directory).

    • Components: oned (main daemon), sunstone (web UI), CLI, drivers for infrastructure.

    • Use: Open-source cloud management platform for building and managing private/hybrid clouds and virtualized data centers. Focuses on simplicity and stability.

  • Nimbus:

    • Architecture: Client-server. Nimbus IaaS provides a cloud controller (cc) and a compute controller (nc). Uses Xen or KVM hypervisors.

    • Components: cloud-client (submit VM requests), cloud-controller (orchestration), compute-controller (per-node agent).

    • Use: Lightweight, open-source toolkit for deploying IaaS clouds, often used in scientific/research communities (e.g., for cloud bursting to public resources).

7.4 Cloud-Based Data Processing - OLAP

  • OLAP (Online Analytical Processing): Technology for organizing large databases to support complex analytical queries quickly, used in business intelligence and data warehousing.

  • Functionality: Enables users to analyze multidimensional data from multiple perspectives (e.g., sales by product, region, time).

  • Core OLAP Operations:

    1. Roll-up (Drill-up): Aggregating data to a higher level (e.g., city -> country).

    2. Drill-down: Navigating to more detailed data (e.g., quarter -> month).

    3. Slice: Selecting a single dimension (e.g., all data for "2023").

    4. Dice: Selecting a sub-cube by specifying ranges on multiple dimensions (e.g., sales in Q1 2023 for Product A in Region X).

    5. Pivot (Rotate): Reorienting the cube to view data from a different perspective (swapping rows and columns).

  • Relevance in Cloud: Cloud data warehouses (Amazon Redshift, Google BigQuery, Snowflake) are built on OLAP principles, offering scalable, managed platforms for large-scale analytics.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in