UNIT 4: CLOUD IMPLEMENTATION, ORCHESTRATION & OPERATIONS (LAB-FOCUSED)
4.1 Advanced Virtualization & Containerization Labs
4.1.1 Deep Dive: Hypervisor Types (Type-1 vs. Type-2) - Practical Setup & Comparison
| Feature | Type-1 (Bare-Metal) | Type-2 (Hosted) |
|---|---|---|
| Examples | VMware ESXi, Microsoft Hyper-V, Xen, KVM | VirtualBox, VMware Workstation, Parallels |
| Architecture | Runs directly on physical hardware | Runs on top of a host OS (e.g., Windows, Linux) |
| Performance | High (near-native), minimal overhead | Lower, due to host OS layer |
| Use Case | Production data centers, cloud providers | Development, testing, personal use |
| Management | Often requires dedicated management console | Managed via OS applications |
[!TIP] Exam Focus: Know which hypervisor is used in major cloud platforms (AWS Nitro/Hypervisor, Azure Hyper-V, GCP KVM). Type-1 is mandatory for production cloud infrastructure.
4.1.2 Docker Core Commands & Image Management Lab
Core Container Lifecycle Commands:
docker run -d --name <container> <image> # Create & start
docker exec -it <container> /bin/bash # Execute command in running container
docker commit <container> <new_image_name> # Create image from container changes
docker stop/start/restart <container> # Control state
docker rm -f <container> # Remove (force if running)
docker ps -a # List all containers
docker images # List local images
Building Custom Images with Dockerfile:
FROM ubuntu:20.04 # Base image
RUN apt-get update && apt-get install -y nginx # Install packages
COPY index.html /var/www/html/ # Copy files
EXPOSE 80 # Document port
CMD ["nginx", "-g", "daemon off;"] # Default command
Build & Tag: docker build -t my-nginx:latest .
Volume & Network Management:
-
Volumes:
docker volume create <name>; mount with-v <volume>:/pathfor persistent data. -
Networks:
docker network create <net>; connect containers with--network <net>for inter-container communication.
[!TIP] Common Pitfall: Forgetting to
EXPOSEports in Dockerfile doesn't publish them; must use-pflag indocker run. Volume data is lost if not using named volumes or bind mounts.
4.1.3 Docker Compose for Multi-Container Application Orchestration
docker-compose.yml Structure (Web + DB Example):
version: '3.8'
services:
web:
image: my-nginx:latest
ports:
- "8080:80"
volumes:
- app-data:/var/www/html
depends_on:
- db
db:
image: postgres:13
environment:
POSTGRES_PASSWORD: secret
volumes:
- db-data:/var/lib/postgresql/data
volumes:
app-data:
db-data:
Key Operations:
-
docker-compose up -d— Start all services in detached mode. -
docker-compose scale web=3— Scale a service (legacy; usedeployin Swarm mode). -
docker-compose down -v— Stop and remove containers & volumes.
[!TIP] Exam Ready:
depends_ononly controls start order, not readiness. Use health checks in production. For scaling in production, use Kubernetes or Docker Swarm.
4.2 Container Orchestration with Kubernetes (K8s) - Practical Labs
4.2.1 K8s Architecture & Core Components Lab
Core Components:
| Component | Role |
|---|---|
| Pod | Smallest deployable unit (1+ containers). |
| Deployment | Declarative management of Pods/ReplicaSets. |
| Service | Network endpoint for accessing Pods (stable IP/DNS). |
| ConfigMap | Non-sensitive configuration data as key-value pairs. |
| Secret | Sensitive data (passwords, tokens) stored as base64. |
| kube-apiserver | Frontend for Kubernetes control plane. |
| etcd | Highly available key-value store for cluster state. |
Local Cluster Setup: Use Minikube (minikube start) or Kind (kind create cluster).
[!TIP] Visual Aid: Search
for control plane/worker node relationships.DiagramSEARCH: kubernetes architecture diagram
4.2.2 Declarative Application Deployment & Management
Sample Deployment YAML (deployment.yaml):
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deploy
spec:
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:1.21
ports:
- containerPort: 80
Workflow:
kubectl apply -f deployment.yaml # Create/update
kubectl get pods # Verify
kubectl rollout status deployment/nginx-deploy
kubectl set image deployment/nginx-deploy nginx=nginx:1.22 # Rolling update
kubectl rollout undo deployment/nginx-deploy # Rollback
kubectl scale deployment/nginx-deploy --replicas=5 # Scale
[!TIP] Critical: YAML indentation is syntax-sensitive. Use
kubectl explain <resource>to learn field structure. Rolling updates are automatic; rollbacks require--to-revisionor undo.
4.2.3 Service Exposure & Ingress Configuration Lab
Service Types:
| Type | Use Case | Access |
|---|---|---|
| ClusterIP | Internal service-to-service | Cluster-internal IP |
| NodePort | External access (testing) | <NodeIP>:<NodePort> (30000-32767) |
| LoadBalancer | Cloud external access | Cloud provider LB IP |
Service YAML Example:
apiVersion: v1
kind: Service
metadata:
name: nginx-service
spec:
type: LoadBalancer
selector:
app: nginx
ports:
- protocol: TCP
port: 80
targetPort: 80
Basic Ingress Setup (requires Ingress Controller like Nginx):
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: example-ingress
spec:
rules:
- host: app.example.com
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: api-service
port:
number: 8080
- path: /
pathType: Prefix
backend:
service:
name: web-service
port:
number: 80
[!TIP] Common Error: Ingress won't work without an Ingress Controller installed. Use
minikube addons enable ingressfor Minikube.
4.3 Infrastructure as Code (IaC) - Hands-On
4.3.1 Terraform Fundamentals & State Management Lab
Terraform Workflow:
-
terraform init— Initialize working directory (download providers). -
terraform plan— Show execution plan. -
terraform apply— Execute plan to create resources. -
terraform destroy— Destroy managed infrastructure.
HCL Structure Example (main.tf):
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 4.0"
}
}
}
provider "aws" {
region = "us-east-1"
}
resource "aws_instance" "web" {
ami = "ami-0c55b159cbfafe1f0"
instance_type = "t2.micro"
tags = {
Name = "WebServer"
}
}
output "public_ip" {
value = aws_instance.web.public_ip
}
State Management:
-
State file (
terraform.tfstate) tracks resource mappings. -
Never edit manually; use
terraform statecommands. -
For teams, use remote state backend (S3, Azure Storage) with locking (DynamoDB).
[!TIP] Critical: State file contains sensitive data. Secure it. Use
terraform state listandterraform state show <resource>to inspect.
4.3.2 Provisioning Cloud Resources with Terraform
Lab Example: AWS VPC + EC2 + Security Group
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_security_group" "allow_http" {
vpc_id = aws_vpc.main.id
ingress {
from_port = 80
to_port = 80
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
}
resource "aws_instance" "web" {
ami = "ami-0c55b159cbfafe1f0"
instance_type = "t2.micro"
vpc_security_group_ids = [aws_security_group.allow_http.id]
subnet_id = aws_subnet.public.id
}
Using Modules: Create reusable modules (e.g., module "vpc" { source = "./modules/vpc" }).
[!TIP] Best Practice: Use variables (
variable "region" {}) and outputs for modularity. Tag all resources for cost tracking.
4.4 Configuration Management & Automation
4.4.1 Ansible Basics: Playbooks, Inventory, and Ad-Hoc Commands Lab
Ad-Hoc Command: ansible all -i inventory.ini -m ping (test connectivity).
Inventory File (inventory.ini):
[webservers]
web1 ansible_host=192.168.1.10
web2 ansible_host=192.168.1.11
[db]
db1 ansible_host=192.168.1.20
Idempotent Playbook (site.yml):
- hosts: webservers
become: yes
tasks:
- name: Install Nginx
apt:
name: nginx
state: present
- name: Start and enable Nginx
service:
name: nginx
state: started
enabled: yes
- name: Copy index.html
copy:
src: files/index.html
dest: /var/www/html/index.html
notify: Restart Nginx
handlers:
- name: Restart Nginx
service:
name: nginx
state: restarted
Variables & Templates: Use vars.yml or group_vars/. Templates with Jinja2: {{ variable }}.
[!TIP] Key Concept: Idempotency — running a playbook multiple times yields same result. Use
state: presentnotcommand: apt install.
4.4.2 Integrating Ansible with Provisioned Infrastructure
Lab: Terraform Output → Ansible Inventory
-
Terraform output (
outputs.tf):output "web_public_ips" { value = aws_instance.web[*].public_ip } -
After
terraform apply, capture IPs:terraform output -raw web_public_ips > ips.txt. -
Dynamic Inventory Script (Python/JSON) or generate static inventory:
# Generate inventory.ini from ips.txt echo "[webservers]" > inventory.ini cat ips.txt | awk '{print $$\displaystyle 1 " ansible_host=" $$2}' >> inventory.ini -
Run Ansible:
ansible-playbook -i inventory.ini site.yml.
[!TIP] Automation: Use
local-execprovisioner in Terraform to run Ansible post-apply, or use CI/CD pipeline to orchestrate.
4.5 Cloud Security & Identity Lab Exercises
4.5.1 Identity and Access Management (IAM) Deep Dive
Principle of Least Privilege (PoLP): Grant only minimum permissions needed.
-
AWS IAM Policy Example (S3 read-only):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::mybucket/*" } ] } -
Azure RBAC: Assign built-in roles (e.g.,
Contributor) at narrowest scope (resource group, not subscription). -
GCP IAM: Use predefined roles (e.g.,
roles/storage.objectViewer) or custom roles.
[!TIP] Exam Trap: Avoid wildcards (
*) inAction/Resourceunless absolutely necessary. Use conditions ("Condition") for extra restriction (e.g., IP whitelisting).
4.5.2 Secrets Management in the Cloud
| Method | Pros | Cons |
|---|---|---|
| K8s Secrets | Native, easy | Base64 encoded (not encrypted), etcd storage |
| AWS Secrets Manager | Auto-rotation, encryption, fine-grained IAM | Cost per secret |
| Azure Key Vault | HSM-backed, versioning | Integration complexity |
| HashiCorp Vault | Multi-cloud, dynamic secrets | Self-managed overhead |
Integration Example (K8s + AWS Secrets Manager):
-
Store secret in AWS Secrets Manager.
-
Use External Secrets Operator or Secrets Store CSI Driver to sync to K8s Secret.
-
Mount as environment variable or volume in Pod spec.
[!TIP] Never commit secrets to Git. Use
.gitignorefor state files and inventory with secrets. Rotate keys regularly.
4.5.3 Network Security Groups & Firewall Rules Configuration Lab
Micro-segmentation Example (AWS Security Group for 3-Tier App):
-
Web SG: Allow 80/443 from
0.0.0.0/0, 8080 from App SG only. -
App SG: Allow 8080 from Web SG, 5432 from DB SG only.
-
DB SG: Allow 5432 from App SG only, no internet access.
Azure NSG Rule:
az network nsg rule create --nsg-name myNSG --name Allow-App-To-DB \
--priority 100 --source-address-prefixes <App-SG-ID> \
--destination-port-ranges 5432 --access Allow --protocol Tcp
[!TIP] Security Hygiene: Default deny all inbound. Use descriptive names. Log traffic with VPC Flow Logs / NSG flow logs.
4.6 Monitoring, Logging & Cost Management Labs
4.6.1 Cloud-Native Monitoring & Alerting
AWS CloudWatch for EC2/K8s:
-
Metrics:
CPUUtilization,MemoryUtilization(custom),NetworkIn. -
Create Alarm:
aws cloudwatch put-metric-alarm --alarm-name HighCPU --metric-name CPUUtilization --namespace AWS/EC2 --statistic Average --period 300 --threshold 80 --comparison-operator GreaterThanThreshold --dimensions Name=InstanceId,Value=i-12345 --evaluation-periods 2 --alarm-actions arn:aws:sns:... -
Dashboard: Add widgets for graphs, numbers.
Azure Monitor / GCP Monitoring: Similar concepts — metrics, alerts, dashboards.
[!TIP] K8s Monitoring: Use Prometheus + Grafana (self-managed) or cloud-managed (Amazon Managed Service for Prometheus). Exporters:
node-exporter,kube-state-metrics.
4.6.2 Centralized Logging with EFK/ELK Stack or Cloud Logging Services
EFK Stack (Elasticsearch, Fluentd, Kibana) on K8s:
-
Deploy Elasticsearch (statefulset).
-
Deploy Fluentd as DaemonSet to collect container logs.
-
Deploy Kibana for visualization.
-
Configure Fluentd to parse JSON logs, add Kubernetes metadata.
Cloud Logging (AWS CloudWatch Logs):
aws logs create-log-group --log-group-name /aws/containerinsights/mycluster/application
aws logs put-log-events --log-group-name ... --log-stream-name ...
Query Example (CloudWatch Logs Insights):
fields @timestamp, @message
filter @logStream like 'nginx'
sort @timestamp desc
limit 20
[!TIP] Structured Logging: Ensure applications output JSON logs for easier parsing. Use
fluentdfilters to enrich with pod name, namespace.
4.6.3 Cloud Cost Tracking & Optimization Lab
Cost Management Steps:
-
Enable Cost Allocation Tags: Tag all resources (
Environment=Prod,Owner=TeamA). -
Use Cost Explorer/Budgets:
-
AWS:
aws ce get-cost-and-usage --time-period Start=$$\displaystyle (date -d '1 month ago' +%Y-%m-%d),End= $$(date +%Y-%m-%d) --granularity MONTHLY --metrics "BlendedCost" -
Set budget alerts at 80% of monthly budget.
-
-
Identify Underutilized Resources:
-
Low Utilization EC2: CloudWatch
CPUUtilization < 10%for 7 days. -
Unattached EBS Volumes:
aws ec2 describe-volumes --filters Name=status,Values=available. -
Idle Load Balancers: No healthy hosts or low request count.
-
-
Right-Sizing: Use AWS Compute Optimizer recommendations.
[!TIP] Cost Formula: Total Monthly Cost = \sum (Resource_Hourly_Rate \times Hours_Used) + Data_Transfer_Costs. Always check data transfer costs between zones/regions.
4.7 CI/CD Pipeline Integration for Cloud Applications (Lab)
4.7.1 End-to-End Pipeline with a CI/CD Tool
GitHub Actions Pipeline Example (.github/workflows/deploy.yml):
name: Deploy to K8s
on:
push:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Build Docker image
run: |
docker build -t myapp:${{ github.sha }} .
docker tag myapp:${{ github.sha }} myrepo/myapp:latest
- name: Push to Docker Hub
run: |
echo $$\displaystyle {{ secrets.DOCKER_PASSWORD }} | docker login -u $${{ secrets.DOCKER_USER }} --password-stdin
docker push myrepo/myapp:latest
deploy:
needs: build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Deploy to K8s
run: |
kubectl set image deployment/myapp myapp=myrepo/myapp:${{ github.sha }}
env:
KUBECONFIG: ${{ secrets.KUBECONFIG }}
Pipeline Stages: Code → Test → Build Image → Push Registry → Update K8s (via kubectl set image or Terraform).
[!TIP] Security: Store secrets (Docker Hub creds, kubeconfig) in CI/CD vault (GitHub Secrets, Jenkins Credentials). Never in code.
4.7.2 Pipeline Security: Integrating SAST/DAST and Secret Scanning
-
SAST (Static Application Security Testing): Scan code for vulnerabilities (e.g., Trivy for Dockerfiles, Bandit for Python).
-
DAST (Dynamic Application Security Testing): Scan running app (e.g., OWASP ZAP).
-
Secret Scanning: Use GitGuardian, TruffleHog, or built-in GitHub secret scanning.
Integration Example (GitHub Actions):
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: myrepo/myapp:latest
format: 'sarif'
output: 'trivy-results.sarif'
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: 'trivy-results.sarif'
[!TIP] Shift Left: Run security scans early (build stage). Fail pipeline on high-severity vulnerabilities.
4.8 Lab Integration & Mini-Project
4.8.1 Designing and Deploying a Secure, Scalable Multi-Tier Application
Architecture:
-
IaC (Terraform): Provision VPC, subnets (public/private), EC2/K8s nodes, RDS, Load Balancer.
-
Orchestration (K8s): Deploy frontend (Deployment + Service), backend (Deployment + Service), database (StatefulSet or cloud-managed RDS).
-
Configuration (Ansible): Bootstrap nodes (install Docker/K8s), configure app settings via ConfigMaps/Secrets.
-
CI/CD: Automate build/test/deploy on Git push.
Example Flow:
# Terraform creates infra & outputs K8s kubeconfig
terraform apply
# Ansible configures nodes (if bare metal)
ansible-playbook -i inventory.ini setup.yml
# CI/CD pipeline builds image & updates K8s deployment
# (Triggered by Git push)
4.8.2 Implementing Full Observability Stack
-
Metrics: Prometheus + Grafana (scrape K8s
/metricsendpoint) or CloudWatch. -
Logs: Fluentd → Elasticsearch → Kibana (or CloudWatch Logs).
-
Traces: Jaeger or AWS X-Ray for distributed tracing (instrument app code).
-
Dashboards: Single pane of glass showing request rate, error rate, latency (RED metrics), resource utilization.
4.8.3 Cost Report & Security Audit
Cost Report:
-
Use cloud provider cost tools with tags.
-
Generate CSV/PDF:
aws ce get-cost-and-usage --query 'ResultsByTime[].{Date:TimePeriod.Start, Cost:Total.BlendedCost}'. -
Identify top 5 costly resources.
Security Audit:
-
IAM: Review policies with IAM Access Analyzer / Azure AD Identity Protection.
-
Network: Check security group rules (no 0.0.0.0/0 on non-web ports).
-
K8s: Scan with kube-bench (CIS benchmarks), kubesec.
-
Compliance: Use AWS Config / Azure Policy to evaluate against standards.
[!TIP] Mini-Project Deliverables: Architecture diagram, IaC code repo, CI/CD pipeline config, monitoring dashboards, cost report, security audit checklist. Document everything — examiners love clear documentation.