Marc Andreesen said recently that 2012 will be remembered as the year of SaaS. What he meant is that SaaS has been around for a while, but it came of age this year, with examples of successes such as the Workday IPO. No one questions the significance of SaaS any more. But the year 2013 will see a shift to PaaS (Platform as a Service) with “most” new activities. There is already a blurring of the lines between IaaS and PaaS, as seen from Amazon’s AWS stack. But programmatic interface in PaaS will dominate as we move forward, catering to the developer community. The incumbents such as IBM, Oracle, SAP, Microsoft, and Adobe (representing “on-premise” software) will have to combat with pure-play cloud players.
I saw a list of cloud pioneers and new cloud tools that should be worth sharing. Among the names (arguably) of cloud pioneers here are the often quoted – Warren Vogel (Amazon CTO), Chris Pinkham (architect of EC2, now head of start-up Nimbula), Randy Bias (CloudScaling, formerly GoGrid), Jonathan Bryce (Rackspace/Openstack), Lew Tucker (CISCO), Rich Wolski (Eucalyptus), Chris Kemp (NASA CTO), Urs Holzle (Google), and Frank Frankovsky (Facebook). You can google their names to see the pioneering work they have done in moving cloud computing forward.
Todas las entradas hechas por Latest News from Cloud Computing Journal
CipherCloud Gets $30 Million from Andreessen
CipherCloud, the cloud data protection outfit, has gotten a sweet $30 million
round from existing backer Andreessen Horowitz.
It plans to use the money to accelerate its global go-to-market strategy
with expanded sales and marketing and to develop its cloud information
protection some more.
ClearStory: Sensemaking Over Big Data
By RyanKamauff
Led by Kleiner Perkins Caufield & Byers, with Andreessen Horowitz and Google Ventures Palo Alto, Calif. (December 5, 2012) – ClearStory Data, a company delivering a new big data solution that makes it simple for business users to find, combine and interactively analyze data from corporate sources and disparate third-party sources, today announced the closing […]
The Age of Cloud Will Be Hybrid: IDC Connections
IDC Analyst Simon Piff answers questions on behalf of IT Executives regarding the benefits and challenges of using one or a combination of clouds with an enterprise IT architecture, to include private, an on-premise, privately owned architecture; public, an off-premise, shared utility; and hybrid, any combination of the previous two. Regardless of what is selected, cloud has firmly established itself within the enterprise IT architecture and all organizations need to have a strategy to take advantage of what it has to offer.
Cloud Strategy First
The article discusses cloud strategy as the first and foremost step towards cloud adoption by larger enterprises. It talks about its merits and how vendors need to provide this critical piece in order to be successful in selling their cloud services.
Just returned from the AWS re:Invent conference in Las Vegas. It was a grand event with three days of serious business nicely interspersed with fun. With fifteen tracks to choose from, it had sessions for every IT role from developer to CIO, every cloud-based technology, companies of all sizes from startups to global enterprises, and partners to customers.
Utility Computing Gets Closer in the Cloud
Jack Clark at ZDnet recently published a great series of articles on the current state of cloud computing, which included an article on utility computing called “Cloud computing’s utility future gets closer“. It’s one of the best reviews of where we are in the progression toward utility computing I’ve seen recently – probably since John Cowan’s blog series on a similar topic or the GigaOm white paper by Paul Miller called Metered IT: the path to utility computing.
First, Clark states the cloud is changing nearly every aspect of the technology markets and more importantly how technology is accessed and used by organizations and individuals. Completely concur. The question of “what is cloud” is getting clearer every day. Cloud computing is clearly not just a new term for an old model, but a very real shift in the way IT resources are delivered and consumed.
Cloud Computing: EMC & VMware Spin Up Pivotal Initiative
EMC and VMware confirmed Tuesday that they’re reshuffling their assets and forming a so-called cloud and Big Data “virtual organization” called the Pivotal Initiative under EMC’s chief strategy officer, VMware’s former CEO Paul Martiz.
VMware is contributing Cloud Foundry, SpringSource, Gemstone and Cetas. EMC is putting in Greenplum and Pivotal Labs. The move involves 1,400 employees, 600 from VMware and 800 from EMC.
The companies said they “expect to formally unite these resources by Q2 2013, with a specific operational structure to be determined.” So evidently for now it’s being run out of EMC.
Red Hat CloudForms: Open Clouds Under Your Control
Red Hat CloudForms is an open hybrid cloud-management product ideal for enterprises looking to move their Red Hat Enterprise Linux workloads to the cloud. It delivers the flexibility and agility that businesses want with the control and governance that IT needs. This lets your organization build a hybrid cloud that encompasses your heterogeneous infrastructures – thereby avoiding vendor lock-in – while managing the applications running in that cloud. Download this whitepaper to learn more.
Healthcare as a Service – Implementing a Cloud Solution
Cloud security and cloud compliance are one of the hottest topics in cloud computing. During the course of 2012 we’ve seen many companies, specifically software vendors providing healthcare solutions, migrating or implementing their software in the cloud. While cloud computing brings many advantages to such ISVs’ (pay per use, scalability, and automation to name a few), specific regulations, such as HIPAA in the healthcare space, forces such players to pay attention to specific cloud issues around regulatory compliance.
The HIPAA regulation specifically requires Protected Health Information (PHI) data to be encrypted while in motion and while at rest. Any decent security engineer will tell you that implementing cloud encryption can be easily achieved using the same tools used on-premise. Right? Wrong (or to be more exact, partially wrong): Creating an encryption scheme is indeed an easy task to achieve, but that’s the easy part. Doing so without trusting a third party (your cloud provider or the encryption provider) is the tricky part. While implementing encryption as part of an overall software enrollment strategy, one should consider the following: Is the key management server installed on premise or in cloud? On premise is the secure option yet limits many of the cloud benefits, while a key management cloud deployment is attractive from a total-system stand point, but until recently required you to trust a third party with your encryption keys.
The Limits of Cloud: Gratuitous ARP and Failover
#Cloud
is great at many things. At other things, not so much. Understanding the limitations of cloud will better enable a successful migration strategy.
One of the truisms of technology is that takes a few years of adoption before folks really start figuring out what it excels at – and conversely what it doesn’t. That’s generally because early adoption is focused on lab-style experimentation that rarely extends beyond basic needs.
It’s when adoption reaches critical mass and folks start trying to use the technology to implement more advanced architectures that the «gotchas» start to be discovered.
Cloud is no exception.
A few of the things we’ve learned over the past years of adoption is that cloud is always on, it’s simple to manage, and it makes applications and infrastructure services easy to scale.
Some of the things we’re learning now is that cloud isn’t so great at supporting application mobility, monitoring of deployed services and at providing advanced networking capabilities.
The reason that last part is so important is that a variety of enterprise-class capabilities we’ve come to rely upon are ultimately enabled by some of the advanced networking techniques cloud simply does not support.
Take gratuitous ARP, for example. Most cloud providers do not allow or support this feature which ultimately means an inability to take advantage of higher-level functions traditionally taken for granted in the enterprise – like failover.
GRATUITOUS ARP and ITS IMPLICATIONS
For those unfamiliar with gratuitous ARP let’s get you familiar with it quickly. A gratuitous ARP is an unsolicited ARP request made by a network element (host, switch, device, etc… ) to resolve its own IP address. The source and destination IP address are identical to the source IP address assigned to the network element. The destination MAC is a broadcast address. Gratuitous ARP is used for a variety of reasons. For example, if there is an ARP reply to the request, it means there exists an IP conflict. When a system first boots up, it will often send a gratuitous ARP to indicate it is «up» and available. And finally, it is used as the basis for load balancing failover. To ensure availability of load balancing services, two load balancers will share an IP address (often referred to as a floating IP). Upstream devices recognize the «primary» device by means of a simple ARP entry associating the floating IP with the active device. If the active device fails, the secondary immediately notices (due to heartbeat monitoring between the two) and will send out a gratuitous ARP indicating it is now associated with the IP address and won’t the rest of the network please send subsequent traffic to it rather than the failed primary. VRRP and HSRP may also use gratuitous ARP to implement router failover.
Most cloud environments do not allow broadcast traffic of this nature. After all, it’s practically guaranteed that you are sharing a network segment with other tenants, and thus broadcasting traffic could certainly disrupt other tenant’s traffic. Additionally, as security minded folks will be eager to remind us, it is fairly well-established that the default for accepting gratuitous ARPs on the network should be «don’t do it».
The astute observer will realize the reason for this; there is no security, no ability to verify, no authentication, nothing. A network element configured to accept gratuitous ARPs does so at the risk of being tricked into trusting, explicitly, every gratuitous ARP – even those that may be attempting to fool the network into believing it is a device it is not supposed to be.
That, in essence, is ARP poisoning, and it’s one of the security risks associated with the use of gratuitous ARP. Granted, someone needs to be physically on the network to pull this off, but in a cloud environment that’s not nearly as difficult as it might be on a locked down corporate network. Gratuitous ARP can further be used to execute denial of service, man in the middle and MAC flooding attacks. None of which have particularly pleasant outcomes, especially in a cloud environment where such attacks would be against shared infrastructure, potentially impacting many tenants.
Thus cloud providers are understandably leery about allowing network elements to willy-nilly announce their own IP addresses.
That said, most enterprise-class network elements have implemented protections against these attacks precisely because of the reliance on gratuitous ARP for various infrastructure services. Most of these protections use a technique that will tentatively accept a gratuitous ARP, but not enter it in its ARP cache unless it has a valid IP-to-MAC mapping, as defined by the device configuration. Validation can take the form of matching against DHCP-assigned addresses or existence in a trusted database.
Obviously these techniques would put an undue burden on a cloud provider’s network given that any IP address on a network segment might be assigned to a very large set of MAC addresses.
Simply put, gratuitous ARP is not cloud-friendly, and thus it is you will be hard pressed to find a cloud provider that supports it.
What does that mean?
That means, ultimately, that failover mechanisms in the cloud cannot be based on traditional techniques unless a means to replicate gratuitous ARP functionality without its negative implications can be designed.
Which means, unfortunately, that traditional failover architectures – even using enterprise-class load balancers in cloud environments – cannot really be implemented today. What that means for IT preparing to migrate business critical applications and services to cloud environments is a careful review of their requirements and of the cloud environment’s capabilities to determine whether availability and uptime goals can – or cannot – be met using a combination of cloud and traditional load balancing services.