A. Introduction to Cloud Computing & Virtualization
Defining Cloud Computing
A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, services).
Five Essential Characteristics (NIST Definition):
-
On-demand self-service: Provision resources automatically without human interaction.
-
Broad network access: Available over the network via standard mechanisms (e.g., HTTP/HTTPS).
-
Resource pooling: Multi-tenant model with physical and virtual resources dynamically assigned.
-
Rapid elasticity: Resources scale rapidly outward and inward with demand.
-
Measured service: Resource usage monitored, controlled, and billed transparently.
Evolution & Deployment Models
| Model | Definition | Control & Ownership | Typical Use Case | Trade-offs |
|---|---|---|---|---|
| On-premises | Resources owned and managed internally. | Full control, high responsibility. | Legacy systems, strict data sovereignty. | High CAPEX, low elasticity. |
| Public Cloud | Resources owned by a third-party provider, offered to the public. | Low control, provider manages infrastructure. | Web applications, variable workloads. | Multi-tenancy, potential compliance concerns. |
| Private Cloud | Cloud infrastructure for exclusive use by a single organization. | High control, can be on/off-premises. | Sensitive data, regulated industries. | Higher cost than public, requires management. |
| Hybrid Cloud | Composition of two or more clouds (private/public) with orchestration. | Balanced control, data/application portability. | Bursting to public cloud, phased migration. | Complexity in networking, management, security. |
| Community Cloud | Shared by several organizations with shared concerns. | Shared control among community members. | Government agencies, consortiums. | Limited provider options, shared costs. |
[!TIP] Exam Focus: Be prepared to justify the choice of a deployment model for a given scenario (e.g., "A bank with strict regulatory requirements would likely choose Private or Hybrid cloud").
Core Technology Enabler: Virtualization
What is Virtualization?
The creation of a virtual (rather than actual) version of something, including virtual hardware platforms, storage devices, and network resources. It enables multiple isolated guest operating systems to run on a single physical host machine.
Key Components:
-
Hypervisor (Virtual Machine Monitor - VMM): Software layer that creates and runs VMs.
-
Type 1 (Bare-metal): Runs directly on host hardware. (e.g., VMware ESXi, Microsoft Hyper-V, Xen).
-
Type 2 (Hosted): Runs on a conventional OS as an application. (e.g., VirtualBox, VMware Workstation).
-
-
Virtual Machine (VM): An emulation of a physical computer, consisting of a virtual CPU (vCPU), virtual memory (vRAM), virtual storage (vDisk), and virtual network (vNIC).
Types of Virtualization:
-
Full Virtualization: Guest OS runs unmodified; hypervisor traps and emulates privileged instructions. (e.g., VMware, VirtualBox).
-
Para-virtualization: Guest OS is modified to make system calls directly to the hypervisor (more efficient). (e.g., Xen in PV mode).
-
Hardware-assisted Virtualization: CPU provides extensions (Intel VT-x, AMD-V) to assist hypervisor, enabling near-native performance for unmodified OS.
[!TIP] Common Pitfall: Confusing Type 1 (production, datacenter) with Type 2 (desktop, testing) hypervisors. Remember: Type 1 sits on bare metal.
B. Cloud Service Models (The SPI Framework)
| Aspect | IaaS (Infrastructure as a Service) | PaaS (Platform as a Service) | SaaS (Software as a Service) |
|---|---|---|---|
| Concept | Provides fundamental computing resources (VMs, storage, networks). | Provides a platform for developing, running, and managing applications. | Provides complete, ready-to-use software applications. |
| Analogy | "Renting a raw server/rack in a datacenter." | "Renting a pre-configured development environment (OS, runtime, DB)." | "Using a finished application (like a utility)." |
| User Control | OS, middleware, runtime, application, data. | Application, data. | Configuration/data only. |
| Provider Management | Physical hardware, virtualization, networking core. | OS, runtime, middleware, development tools, scaling. | Everything: application, data, OS, middleware, hardware. |
| Flexibility | Highest - Full control over stack. | Medium - Control over app code/config. | Lowest - Limited to provider's features. |
| Target User | IT Admins, Architects, DevOps. | Application Developers. | End-users (businesses/consumers). |
| Key Components | VMs, VPC/VNet, Block Storage (EBS), Object Storage (S3). | Application Runtime, Managed DB (RDS), Middleware, CI/CD tools. | Multi-tenant app, Web/API access, Automatic updates. |
| Provider Examples | AWS: EC2, EBS, VPC<br>Azure: Virtual Machines, Disks, VNet<br>GCP: Compute Engine, Persistent Disks, VPC | AWS: Elastic Beanstalk, RDS<br>Azure: App Service, SQL Database<br>GCP: App Engine, Cloud SQL | AWS: Workmail (limited), Chime<br>Azure: Microsoft 365, Dynamics 365<br>GCP: Google Workspace, Salesforce (partner) |
[!TIP] Exam Formula: The "Responsibility Pyramid" is key. Remember the mnemonic: "IaaS: I manage Everything above the Infrastructure. SaaS: I manage Nothing."
Control decreases from IaaS → PaaS → SaaS. Provider management responsibility increases from IaaS → PaaS → SaaS.
C. Introduction to Major Cloud Providers & Their Core Services
1. Amazon Web Services (AWS)
-
Global Infrastructure: Regions (geographic areas) → Availability Zones (AZs) (isolated locations within a region) → Edge Locations (for CloudFront CDN).
-
Core IaaS Services:
-
EC2 (Elastic Compute Cloud): Scalable VMs. Key concepts: Instances (VM sizes), AMIs (templates), Key Pairs (SSH auth).
-
S3 (Simple Storage Service): Object storage. Buckets (containers) hold Objects (files). Used for static websites, backups.
-
VPC (Virtual Private Cloud): Isolated virtual network. Define Subnets (public/private), route tables, internet gateway.
-
IAM (Identity and Access Management): Manage users, roles, and policies (JSON documents defining permissions).
-
2. Microsoft Azure
-
Global Infrastructure: Regions → Availability Zones (in select regions).
-
Core IaaS Services:
-
Virtual Machines: Similar to EC2. Use Images (marketplace/custom).
-
Blob Storage: Object storage (like S3). Containers hold Blobs.
-
Virtual Network (VNet): Equivalent to VPC. Subnets, Network Security Groups (NSGs) (firewall rules).
-
Azure Active Directory (AAD): Identity and access management service (cloud-based).
-
3. Google Cloud Platform (GCP)
-
Global Infrastructure: Regions → Zones (equivalent to AZs).
-
Core IaaS Services:
-
Compute Engine: VM service. Images, Machine Types.
-
Cloud Storage: Object storage. Buckets hold Objects.
-
VPC: Global, scalable network. Subnets per region.
-
Cloud IAM: Unified identity management. Members, roles, policies.
-
Provider Service Mapping (High-Level):
| Function | AWS | Azure | GCP |
|---|---|---|---|
| Virtual Compute | EC2 | Virtual Machines | Compute Engine |
| Object Storage | S3 | Blob Storage | Cloud Storage |
| Virtual Network | VPC | Virtual Network (VNet) | VPC |
| Identity Mgmt | IAM | Azure AD | Cloud IAM |
| Block Storage | EBS | Managed Disks | Persistent Disks |
| Firewall Rules | Security Groups | NSGs | Firewall Rules |
[!TIP] Exam Trap: Don't get bogged down in every service name. Focus on the conceptual equivalents (e.g., "Where do I define firewall rules?" → SG/NSG/Firewall). The naming differs, the concepts are similar.
D. Foundational Lab Setup & First Hands-On
1. Account & Access Setup
-
Sign up for Free Tier (AWS), Azure Pass/Free Account (Azure), or Free Trial (GCP). Always set up Billing Alerts immediately to avoid surprise charges.
-
Understand the free tier limits (e.g., 750 hours of t2.micro/t3.micro per month for 12 months on AWS).
2. Management Console & CLI
-
Web Console: AWS Management Console, Azure Portal, GCP Console. Point-and-click GUI.
-
Command Line Interface (CLI): Essential for automation and scripting.
-
aws <service> <command>(e.g.,aws ec2 describe-instances) -
az <group> <command>(e.g.,az vm list) -
gcloud <service> <command>(e.g.,gcloud compute instances list)
-
-
Basic CLI Flow: Authenticate (
aws configure/az login/gcloud auth login), then use commands to list, create, delete resources.
3. First Practical Exercise: Launching a Virtual Machine Generic Step-by-Step (Provider-Agnostic):
-
Choose Region: Select a region with free tier availability.
-
Select Image: Choose an OS (e.g., Amazon Linux 2, Ubuntu Server, Windows Server).
-
Choose Instance Type/Size: Select a free-tier eligible size (e.g.,
t2.micro,B1s). -
Configure Networking:
-
Create/select a Virtual Network/Subnet.
-
Enable Public IP assignment (crucial for external access).
-
Configure Security Group/Firewall/NSG: Add an inbound rule to allow SSH (port 22) for Linux or RDP (port 3389) for Windows from your IP (
0.0.0.0/0is insecure; use your specific IP).
-
-
Configure Authentication:
-
Linux: Create/select an existing SSH Key Pair. Download the
.pemprivate key. -
Windows: Let provider generate a random password, retrieve it using your key pair.
-
-
Launch & Connect:
-
Linux:
ssh -i /path/to/key.pem ec2-user@<public-ip> -
Windows: Use RDP client with public IP and retrieved password.
-
-
Verification & Cleanup:
-
Verify OS is running (
ping,uptime). -
(Optional) Install a web server:
sudo yum install httpd(Amazon Linux) orsudo apt install apache2(Ubuntu), start service, placeindex.htmlin/var/www/html/. -
CRITICAL: Terminate/Delete the VM after the lab to stop incurring compute charges. Delete associated storage (EBS/disk) if not set to auto-delete.
-
[!TIP] Critical Lab Habit: ALWAYS TERMINATE RESOURCES. The #1 cause of unexpected cloud bills is forgotten VMs. Use provider Cost Explorer and Billing Alerts.
E. Cloud Economics & Basic Cost Estimation
Key Cost Drivers:
-
Compute: Charged per second (AWS, GCP) or minute (Azure) of VM runtime. Depends on instance type, OS, region.
-
Storage:
-
Block Storage (EBS/Disks): Per GB-month of provisioned storage + I/O operations.
-
Object Storage (S3/Blob): Per GB-month of data stored + requests (GET/PUT) + data retrieval.
-
-
Data Transfer: Egress (data leaving cloud provider's network) is almost always charged. Ingress (incoming) is typically free.
Pricing Models:
-
On-Demand: Pay-as-you-go, no commitment. Highest hourly rate, maximum flexibility.
-
Reserved Instances / Savings Plans (AWS) / Reserved VM Instances (Azure): Commit to 1 or 3 years for significant discount (up to 70%). Requires upfront/scheduled payment.
-
Spot Instances / Preemptible VMs (GCP): Use unused capacity at deep discount (up to 90%). Can be terminated with short notice (2 min). Ideal for fault-tolerant, batch jobs.
Using Pricing Calculators:
-
Go to provider calculator (AWS Pricing Calculator, Azure Pricing Calculator, GCP Cloud Pricing Calculator).
-
Build a simple architecture: Add 1 x
t2.micro(Linux) running 24/7 for a month + 1 x S3 Standard bucket with 10 GB stored. -
Review breakdown: Note compute, storage, and any data transfer costs.
-
Estimate: The total monthly cost will be very low (often < $10) for this minimal setup within free tier.
Generic Cost Formula (Conceptual):
$$ \text{Total Monthly Cost} = \left( \text{Compute Hours} \times \text{Hourly Rate} \right) + \left( \text{Storage GB} \times \text{Rate per GB-month} \right) + \left( \text{Egress GB} \times \text{Rate per GB} \right) $$
\boxed{\text{Actual cost depends on region, service, and pricing model selected.}}
[!TIP] Exam Application: You may be asked to estimate the cost of a given diagram. Always state your assumptions (region, instance type, storage class, uptime hours). Free tier limits are your best friend for low-cost estimates.
F. Mini-Project / Capstone for Unit 1
Objective: Deploy a basic, functional web application using core IaaS components.
Scenario & Step-by-Step Implementation:
-
Launch a Linux VM: Follow the steps in Section D.3. Use a free-tier eligible instance (e.g.,
t2.micro). Ensure a public IP is assigned. -
Configure Security: In the VM's security group/NSG, add an inbound rule to allow HTTP (port 80) from
0.0.0.0/0(for testing; restrict in production). -
Connect & Setup Web Server:
# SSH into VM ssh -i mykey.pem ec2-user@<public-ip> # Update packages & install Apache (Amazon Linux/Ubuntu) sudo yum update -y # Amazon Linux sudo yum install httpd -y sudo systemctl start httpd sudo systemctl enable httpd # OR for Ubuntu: # sudo apt update && sudo apt install apache2 -y # sudo systemctl start apache2 # sudo systemctl enable apache2 # Create a simple webpage echo "<h1>Hello from My Cloud VM!</h1>" | sudo tee /var/www/html/index.html -
Verify Public Access: Open a browser and navigate to
http://<public-ip>. You should see your "Hello from My Cloud VM!" message. -
Document & Cleanup:
-
Screenshot 1: VM running in the cloud console.
-
Screenshot 2: Web browser displaying your hosted page.
-
Screenshot 3: Security group rule showing port 80 open.
-
Cost Estimate: Use the pricing calculator to estimate the monthly cost of this specific setup (1 x
t2.micro24/7 + 1 GB S3 bucket if used for storage). Note: If within free tier, cost may be $0.00. -
Terminate the VM to stop all charges.
-
[!TIP] Project Defense: Be ready to explain each step's purpose:
- Why port 80? → Standard HTTP port for web traffic.
- Why public IP? → To make the web server accessible from the internet.
- Why
systemctl enable? → Ensures web server starts on reboot.
- Why terminate? → Cost control is a fundamental cloud responsibility.