UNIT 2: CLOUD COMPUTING - SHORT NOTES
1.0 FOUNDATIONAL CONCEPTS & EVOLUTION
1.1 Computing on Demand (CoD) / Utility Computing
-
Definition: A business model where computing resources (processing power, storage, network) are provided as a metered service, similar to traditional utilities (electricity, water). Users pay only for the resources they consume.
-
Core Principle: On-demand self-service with pay-per-use billing.
-
Enables Dynamic Provisioning:
-
Scalability: Ability to increase or decrease resource capacity to meet workload demands.
-
Elasticity: Rapid, automatic scaling (both up and down) in response to real-time demand.
-
Resource Pooling: Provider's computing resources are pooled to serve multiple consumers using a multi-tenant model.
-
[!TIP] Exam Focus: CoD is the foundational economic model for cloud computing. Link it directly to the NIST essential characteristics of "measured service" and "rapid elasticity."
1.2 Grid Computing vs. Cloud Computing
| Feature | Grid Computing | Cloud Computing |
|---|---|---|
| Primary Goal | Solve large, complex problems by aggregating resources from multiple administrative domains. | Deliver on-demand, scalable IT resources as a service. |
| Architecture | Decentralized, heterogeneous, often geographically dispersed. | Centralized, standardized, large data centers. |
| Resource Management | Complex, often batch-oriented, with focus on job scheduling. | Centralized, automated, with self-service portals and APIs. |
| Ownership | Resources belong to different organizations (federated). | Resources are owned and managed by a single provider (or a private entity). |
| Scalability | Scales by adding more nodes to the grid. | Scales seamlessly within a pooled infrastructure. |
| Use Case | Scientific computing (e.g., SETI@home, climate modeling). | Enterprise IT, web applications, SaaS. |
| Similarity | Both involve distributed computing and resource sharing. |
[!TIP] Common Pitfall: Do not confuse them. Grid is about collaborative problem-solving across boundaries; Cloud is about centralized service delivery with a utility model.
1.3 Cloud Computing Reference Model
A layered architectural model defining functional components and their relationships.
-
Client Layer: Devices and interfaces (web browsers, thin clients, mobile apps) used to access cloud services.
-
Application Layer: Cloud-based software applications (SaaS).
-
Platform Layer: Development and runtime environments (PaaS - OS, middleware, DBMS).
-
Infrastructure Layer: Virtualized hardware resources - compute, storage, network (IaaS).
-
Management/Security Layer: Cross-cutting functions (orchestration, provisioning, security, compliance, billing) that span all other layers.
2.0 CLOUD SERVICE MODELS (SPI MODEL)
2.1 Infrastructure as a Service (IaaS)
-
Definition: Provides fundamental computing resources (virtual machines, storage, networks) over the internet. Users have control over OS, storage, and deployed applications.
-
Characteristics: Virtualized hardware, on-demand provisioning, pay-as-you-go, high scalability.
-
Examples: Amazon EC2 (VMs), Google Compute Engine, Microsoft Azure VMs, virtual private clouds (VPCs).
2.2 Platform as a Service (PaaS)
-
Definition: Provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the underlying infrastructure.
-
Characteristics: Includes OS, programming language execution environment, database, web server. Focuses on application development lifecycle.
-
Examples: Heroku, Google App Engine, Microsoft Azure App Services, AWS Elastic Beanstalk.
2.3 Software as a Service (SaaS)
-
Definition: Delivers complete, ready-to-use software applications over the internet, typically via a web browser.
-
Characteristics: No infrastructure/platform management for user. Multi-tenant architecture, automatic updates, subscription-based.
-
Examples: Gmail, Salesforce, Microsoft 365, Dropbox, Slack.
2.4 Comparative Analysis of IaaS, PaaS, SaaS
| Aspect | IaaS | PaaS | SaaS |
|---|---|---|---|
| Control Level | Highest (OS, middleware, runtime, app, data). | Medium (app, data). | Lowest (configuration only). |
| Management Responsibility | User manages OS, apps, data. Provider manages physical infra. | User manages app & data. Provider manages OS, runtime, infra. | Provider manages everything. User just uses the app. |
| Customization | Very high (full OS control). | Moderate (within platform constraints). | Low (configuration within app settings). |
| Target User | IT admins, DevOps, architects. | Application developers. | End-users, business units. |
| Analogy | Renting a raw plot of land & construction tools. | Renting a pre-built house with utilities. | Renting a fully furnished apartment. |
[!TIP] Exam Tip: Remember the " Responsibility Pyramid": User responsibility decreases from IaaS -> PaaS -> SaaS. Provider responsibility increases.
3.0 CLOUD DEPLOYMENT MODELS
3.1 Public Cloud
-
Definition: Cloud infrastructure made available to the general public or a large industry group, owned and operated by a cloud service provider (e.g., AWS, Azure, GCP).
-
Characteristics: Multi-tenancy, massive scale, no capital expenditure (OpEx model), high scalability.
-
Advantages: Cost-effective, no maintenance, high reliability, global reach.
-
Disadvantages: Less control, potential security/compliance concerns, possible vendor lock-in.
3.2 Private Cloud
-
Definition: Cloud infrastructure operated solely for a single organization. Can be managed internally or by a third party, hosted on-premise or off-site.
-
Characteristics: Single-tenancy, greater control, enhanced security/customization.
-
Advantages: Superior control, security, and compliance for sensitive data. Customizable.
-
Disadvantages: High capital cost (CapEx), requires management expertise, less elastic than public cloud.
3.3 Hybrid Cloud
-
Definition: Composition of two or more distinct cloud models (private and public) that remain unique entities but are bound together by standardized or proprietary technology enabling data and application portability.
-
Architecture: Uses APIs, VPNs, and dedicated connections to link private and public clouds.
-
Key Use Cases:
-
Cloud Bursting: Run normal workload in private cloud; burst to public cloud during demand spikes.
-
Data Sovereignty/Compliance: Keep sensitive data on-premise (private), use public cloud for less-sensitive processing.
-
Gradual Migration: Move legacy apps to cloud incrementally.
-
3.4 Community Cloud
-
Definition: Cloud infrastructure shared by several organizations with shared concerns (e.g., security requirements, compliance, policy). It may be managed by the organizations or a third party.
-
Example: A cloud shared by multiple government agencies for a specific project.
3.5 Selecting the Optimal Deployment Model
Decision factors to evaluate:
-
Cost: TCO analysis (CapEx vs. OpEx).
-
Security & Compliance: Regulatory requirements (GDPR, HIPAA), data sensitivity.
-
Control: Need for customization and administrative access.
-
Scalability Needs: Predictability of workload patterns.
-
Legacy Systems: Integration complexity with existing on-premise infrastructure.
-
Performance & Latency: Geographic location of users vs. data centers.
[!TIP] Exam Framework: For "selecting the best model" questions, structure your answer around these six factors. Use a scenario (e.g., a bank, a startup, a research lab) to illustrate.
4.0 VIRTUALIZATION - THE CORE ENABLING TECHNOLOGY
4.1 Fundamentals of Virtualization
-
Definition: The creation of a virtual (rather than actual) version of something, including virtual hardware platforms, storage devices, and network resources. It abstracts physical hardware from the software running on it.
-
Enables Efficient Utilization:
-
Consolidation: Multiple virtual machines (VMs) run on a single physical server, increasing utilization from ~15% to 60-80%.
-
Isolation: VMs are isolated from each other; a crash in one doesn't affect others.
-
Encapsulation: A VM is a single file (or set of files), making it easy to save, copy, and migrate.
-
4.2 Hypervisors (Virtual Machine Monitors - VMM)
- Definition: Software, firmware, or hardware that creates and runs VMs. It sits between the physical hardware and the guest OS, allocating resources.
| Type | Type-1 (Native/Bare-Metal) | Type-2 (Hosted) |
|---|---|---|
| Architecture | Runs directly on the physical hardware (replaces the host OS). | Runs on top of a conventional host OS (like an application). |
| Performance | High (direct hardware access). | Lower (hardware access via host OS). |
| Use Case | Enterprise data centers, cloud infrastructure. | Desktop virtualization, development/testing. |
| Examples | VMware ESXi, Microsoft Hyper-V, Xen, KVM. | Oracle VirtualBox, VMware Workstation, Parallels Desktop. |
-
Paravirtualization: Guest OS is modified to be aware of the hypervisor, enabling more efficient communication (e.g., Xen in paravirt mode).
-
Hardware-Assisted Virtualization (HVM): CPU extensions (Intel VT-x, AMD-V) provide hardware support for running unmodified guest OSes securely. Modern standard for Type-1 hypervisors.
[!TIP] Key Distinction: Type-1 is for production clouds/servers. Type-2 is for desktop users/developers.
4.3 Logical Partitioning (LPAR)
-
Definition: A hardware-level virtualization technique (primarily on IBM POWER, mainframes) where a single physical server is divided into multiple isolated logical partitions. Each LPAR has its own dedicated resources (CPU, memory, I/O).
-
Architecture: Firmware/hypervisor layer (e.g., PowerVM, PR/SM) directly manages physical resources and assigns them to LPARs.
-
Advantages:
-
Strong isolation and security (hardware-enforced).
-
Predictable, guaranteed resource allocation (no "noisy neighbor").
-
High flexibility; resources can be dynamically moved between LPARs.
-
Supports multiple OS types (AIX, Linux, IBM i) on same server.
-
-
Disadvantages/Challenges:
-
Complex management.
-
Less flexible than full virtualization (e.g., cannot run arbitrary OS without support).
-
Typically tied to specific high-end hardware (proprietary).
-
4.4 Virtualized Data Center Architecture
A modern data center where physical components are abstracted and managed as software-defined entities.
-
Virtualized Servers (Compute): Physical servers run a hypervisor to host multiple VMs.
-
Storage Virtualization: Pool of physical storage devices presented as a single logical storage unit (see 4.5).
-
Network Virtualization (SDN): Separation of network control plane (SDN Controller) from data plane (switches). Enables creation of virtual networks (overlays like VXLAN) independent of physical topology.
-
Management Layer (Orchestration): Software (e.g., OpenStack, vRealize) that automates provisioning, monitoring, and lifecycle management of all virtualized resources.
4.5 Storage Virtualization
-
Definition: Abstraction of physical storage devices (from different vendors) into a single, pooled logical storage resource.
-
Types:
-
Block-Level: Presents raw storage blocks (LUNs) to hosts. Used by databases, VMs. (e.g., SAN).
-
File-Level: Provides a shared file system with folders/files. Used for NAS, home directories. (e.g., NFS, CIFS).
-
-
SAN vs. NAS:
| Feature | SAN (Storage Area Network) | NAS (Network Attached Storage) | | :--- | :--- | :--- | | Access Method | Block-level (via Fibre Channel, iSCSI). | File-level (via NFS, SMB/CIFS over IP). | | Protocol | SCSI, Fibre Channel, iSCSI. | NFS, SMB/CIFS. | | Appearance to OS | Appears as a local disk drive. | Appears as a network file share. | | Use Case | High-performance DB, VM storage, enterprise apps. | File sharing, backups, content repositories. | | Example | EMC VMAX, NetApp FAS (block mode). | NetApp FAS (file mode), Isilon. |
-
Benefits: Increased utilization, simplified management, non-disruptive data migration, improved availability (mirroring across pools).
4.6 Requirements of a Virtualization Platform for Cloud Implementation
-
Performance: Low overhead, near-native I/O performance (especially for network/storage).
-
Scalability: Support for thousands of VMs per cluster, linear performance scaling.
-
Security: Strong isolation between VMs, secure VM migration, support for security policies.
-
Management APIs: Robust APIs for automation and integration with cloud management platforms (CMPs).
-
Live Migration: Ability to move running VMs between physical hosts with zero downtime (e.g., vMotion, Live Migration).
-
High Availability (HA): Automatic VM restart on other hosts in case of host failure.
-
Resource Scheduling (DRS): Intelligent load balancing of VMs across hosts.
5.0 CLOUD SECURITY
5.1 Importance and Challenges
-
Importance: Protects sensitive data, ensures service availability, maintains compliance (GDPR, HIPAA), preserves customer trust, and prevents financial/reputational loss.
-
Challenges:
-
Shared Responsibility Model: Confusion over who secures what (Provider: security of the cloud; Customer: security in the cloud).
-
Multi-tenancy: Risk of data leakage between tenants sharing the same physical infrastructure.
-
Data Breaches: Unauthorized access to data stored in the cloud.
-
Compliance: Meeting regulatory requirements in a shared, dynamic environment.
-
Insider Threats: Malicious or negligent actions by employees of provider or customer.
-
Visibility & Control: Limited customer insight into provider's physical/logical security.
-
5.2 Comprehensive Scope of Cloud Security
-
Data Security: Encryption (at rest, in transit), Data Loss Prevention (DLP), data classification, secure deletion.
-
Network Security: Virtual firewalls, IDS/IPS, network segmentation (micro-segmentation), DDoS protection.
-
Identity & Access Management (IAM): Centralized user management, authentication (MFA), authorization (RBAC), auditing.
-
Compliance & Governance: Audit trails, logging, reporting, adherence to standards (ISO 27001, SOC 2).
5.3 Secure Execution Environments & Communications
-
Secure Bootstrapping: Mechanisms to ensure a VM starts with a known, trusted software stack (measured boot, trusted platform module - TPM).
-
Encryption:
-
In Transit: TLS/SSL for web traffic, VPNs (IPsec) for site-to-site.
-
At Rest: Encryption of storage volumes, databases, object storage (using provider-managed or customer-managed keys).
-
-
Secure Protocols: Use of SSH instead of Telnet, SFTP instead of FTP.
-
Trusted Platform Module (TPM): Hardware-based security chip that can be virtualized (vTPM) to provide attestation and key storage for VMs.
5.4 Virtual Machine (VM) Security
-
Risks:
-
VM Escape: Exploit allowing code in a VM to break out and interact with the hypervisor/host.
-
VM Hopping: Attacking one VM to gain access to another on the same host.
-
Snapshot/Analysis Attacks: Accessing sensitive data from VM snapshots or memory dumps.
-
Resource Exhaustion (DoS): Consuming all host resources (CPU, memory, disk I/O) from within a VM.
-
-
Recommendations/Benefits:
-
Hardened Images: Use minimal, patched OS images from trusted sources.
-
Network Segmentation: Place VMs in separate security groups/VLANs based on function.
-
VM Activity Monitoring: Monitor for anomalous behavior (CPU spikes, network traffic).
-
Anti-malware for VMs: Install endpoint protection inside guest OS.
-
Secure VM Lifecycle Management: Enforce policies for provisioning, de-provisioning, and patching.
-
5.5 Role-Based Access Control (RBAC)
-
Definition: A non-discretionary access control model where permissions are assigned to roles, not directly to users. Users are assigned to roles, inheriting the permissions of that role.
-
Model Components:
-
Users (Subjects): Individuals or systems.
-
Roles: Job functions (e.g.,
Admin,Developer,ReadOnly). -
Permissions (Privileges): Specific actions on resources (e.g.,
vm:start,storage:delete). -
Sessions: A user activates a subset of their assigned roles during a session.
-
-
Implementation in Cloud IAM: Central to AWS IAM, Azure RBAC, Google Cloud IAM. Policies (JSON/YAML) define which roles have which permissions on which resources.
-
Benefits over DAC: Simplifies administration (manage roles, not individual users), enforces least privilege, supports separation of duties.
[!TIP] Key Concept: In cloud, RBAC is the primary mechanism for implementing the "least privilege" security principle.
6.0 ENABLING TECHNOLOGIES & ARCHITECTURAL STYLES
6.1 Service-Oriented Architecture (SOA)
-
Core Principles:
-
Service: A self-contained unit of functionality (e.g., "Check Credit Score").
-
Loose Coupling: Services interact via well-defined interfaces (contracts), minimizing dependencies.
-
Interoperability: Services use standard protocols (HTTP, SOAP, REST) to work across platforms.
-
-
Role in Cloud: SOA is the architectural foundation for building cloud-native applications. It facilitates:
-
Integration: Combining multiple cloud-based and on-premise services.
-
Composition: Orchestrating finer-grained services into business processes.
-
Reusability: Services can be reused across different applications.
-
-
Implementation: Primarily through Web Services:
-
SOAP: Protocol-heavy, XML-based, with strict standards (WS-*). Used for enterprise integration.
-
REST: Architectural style using HTTP verbs (GET, POST), lightweight, JSON/XML. Dominant for public APIs and web-scale apps.
-
6.2 Role of Independent Software Vendors (ISVs)
-
Definition: Companies that develop and sell software applications that run on platforms provided by others (e.g., cloud providers, OS vendors).
-
In Cloud Context:
-
Developing SaaS Applications: ISVs build applications designed from the ground up for the cloud (multi-tenant, elastic).
-
Platform Certification: ISVs certify their software to run on specific cloud platforms (e.g., "AWS Ready," "Azure Certified") for compatibility and support.
-
Marketplace Distribution: Cloud providers (AWS Marketplace, Azure Marketplace, Salesforce AppExchange) offer ISV applications as one-click deployments, creating new revenue channels.
-
e-Business Apps: Focus on CRM, ERP, collaboration tools delivered via SaaS model.
-
7.0 ADVANCED TOPICS & SPECIALIZED AREAS
7.1 Quality of Service (QoS) & Cloud Infrastructure Benchmarks
-
QoS in Cloud: A set of measurable service attributes (Service Level Objectives - SLOs) that define the performance and reliability of a cloud service.
-
Key QoS Issues:
-
Availability: Uptime percentage (e.g., 99.9%).
-
Reliability: Probability of failure-free operation.
-
Performance: Throughput, response time, latency.
-
Scalability: Ability to handle growth.
-
Security: Confidentiality, integrity, availability.
-
Interoperability: Ability to work with other systems.
-
Portability: Ease of moving apps/data between clouds.
-
-
Benchmarking Tools/Metrics: Standardized tests to measure and compare cloud performance.
-
SPEC Cloud IaaS: Industry-standard benchmarks for IaaS performance (CPU, memory, storage, network).
-
CloudHarmony (now part of Gartner): Historical performance data for cloud services.
-
Key Metrics: IOPS (storage), network throughput, VM boot time, scalability curve.
-
7.2 Storage Cloud / Cloud Storage Models
-
Object Storage (e.g., Amazon S3):
-
Model: Data is stored as objects (data + metadata + unique ID) in a flat namespace (buckets).
-
Access: HTTP/HTTPS APIs (REST). Highly scalable, durable, cost-effective for unstructured data (images, videos, backups).
-
-
Block Storage (e.g., Amazon EBS):
-
Model: Raw storage volumes (like virtual hard drives) that can be attached to VMs.
-
Access: Via protocols like iSCSI/Fibre Channel. Low latency, high performance. Used for OS, databases, file systems.
-
-
File Storage (e.g., Amazon EFS, Azure Files):
-
Model: Hierarchical file system (folders/files) accessible via standard protocols (NFS, SMB).
-
Access: Shared file system for multiple VMs/instances. Used for content management, home directories.
-
7.3 Cloud Management & Orchestration Tools
-
OpenNebula:
-
Architecture: Modular. Core (Sunstone, CLI) interacts with Hypervisors (KVM, LXC, vCenter), Storage (NFS, Ceph), Networking (Open vSwitch), and Authentication (LDAP, Active Directory).
-
Components:
oned(main daemon),sunstone(web UI),CLI, drivers for infrastructure. -
Use: Open-source cloud management platform for building and managing private/hybrid clouds and virtualized data centers. Focuses on simplicity and stability.
-
-
Nimbus:
-
Architecture: Client-server. Nimbus IaaS provides a cloud controller (
cc) and a compute controller (nc). Uses Xen or KVM hypervisors. -
Components:
cloud-client(submit VM requests),cloud-controller(orchestration),compute-controller(per-node agent). -
Use: Lightweight, open-source toolkit for deploying IaaS clouds, often used in scientific/research communities (e.g., for cloud bursting to public resources).
-
7.4 Cloud-Based Data Processing - OLAP
-
OLAP (Online Analytical Processing): Technology for organizing large databases to support complex analytical queries quickly, used in business intelligence and data warehousing.
-
Functionality: Enables users to analyze multidimensional data from multiple perspectives (e.g., sales by product, region, time).
-
Core OLAP Operations:
-
Roll-up (Drill-up): Aggregating data to a higher level (e.g., city -> country).
-
Drill-down: Navigating to more detailed data (e.g., quarter -> month).
-
Slice: Selecting a single dimension (e.g., all data for "2023").
-
Dice: Selecting a sub-cube by specifying ranges on multiple dimensions (e.g., sales in Q1 2023 for Product A in Region X).
-
Pivot (Rotate): Reorienting the cube to view data from a different perspective (swapping rows and columns).
-
-
Relevance in Cloud: Cloud data warehouses (Amazon Redshift, Google BigQuery, Snowflake) are built on OLAP principles, offering scalable, managed platforms for large-scale analytics.