Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

May 13, 2014

OpenStack simplified: OpenStack Training by Sean Roberts and Colin McNamara)

Want to start out with OpenStack? Check out the FREE training guides on the OpenStack foundation site. The guides offer various levels of training ranging from beginner to architect, each guide building on the previous material.

Training available for consumption via:
  • Self paced book
  • Instructor led training
  • Community Instructor led training
One of the most common complaints I hear from potential users, operators and customers is that OpenStack is complicated. Sean and Colin echoed this when they said that there are thousands of features released every 6 months (the development cycle of OpenStack). This training platform will go a long way to helping to demystify OpenStack based cloud computing environments and how to implement and operate them.

Still queasy at the thought of launching an internal project yourself? Find yourself an integrator. At least you'll be able to participate and truly partner with your integrator of choice.

May 12, 2014

Keystone Security and Architecture Review: Keith Newstadt

Pertinent notes from the Keystone Security and Architecture Review at the OpenStack Summit in Atlanta, 2014.

Keystone is the gatekeeper for OpenStack and allows authentication to all OpenStack services. 


Keystone:



  • Is the single point of authentication for all OpenStack services
  • Offers SSO to OpenStack services
  • Is the common API layer on top of various authentication protocols
  • Reduces exposure of credentials

Basically:
  • User authenticates by sending credentials --> Keystone
  • Keystone sends a token once authenticated --> User
  • Keystone shares token --> OpenStack service
  • Service validates identity of user via token
Users identity credentials are sent to the LDAP server that then confirms the user ID and associated roles. Services can also authenticate with Keystone and act on a user's behalf. This presents different problems that can be mitigated by securing cached credentials, limiting the scope of this delegation, expiring tokens and direct management of Keystone and OpenStack.

Of course, as with any software, Keystone has an attack surface that opens it up to spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privileges. Newstadt suggests "Supply chain management":

Download --> build --> deploy --> patch
The key is the last step to ensure that the software deployed is free of vulnerabilities.

There has also been considerable interest in using industry standards including SAML, OpenID and OAUTH because they provide SSO, improved integration, control over user credentials and a unified user experience.


Newstadt's parting thoughts:
Protect credentials everywhere. Think about how they can be attacked.Securing Keystone is an ongoing process.Share findings and ideas. This is how we'll improve Keystone and security in OpenStack.

OpenStack Session: Security for Private Clouds (Bryan Payne)

Private clouds need security too, not just public clouds. Attack vectors are no longer limited to edge devices. "Found" USB keys loaded with malware can open up the cloud environment to attack from within an organization not to mention poorly designed security controls and policies. The bottom line is that no one wants a bot net running in their data center!

The way around this is to apply security principles to the environment. Logically separate specific use environments; make use of VPNs

Also, understanding the environment is key. Basically:
Orchestration + Known hardware = Secure infrastructure
[Applying security best practices at the outset and consistently throughout the life cycle of the environment with known hardware can help service providers (IT or actual CSPs) to protect the environment.]

Payne identified some of the biggest threats to clouds:
API endpoints
Web dashboard
Information leakage*
VM breakout*
Hardware sharing
Default images
Secondary attacks

*Easily the biggest threats according to Payne.

Information leakage can be mitigated by using TLS to protect communications between API endpoints, the web dashboard, Log feeds, AD/LDAP and external storage. VM breakouts can be basically prevented by using mandatory access controls, removing unnecessary privileges from the physical node and by hardening the build, the compiler and physical nodes.

Other attacks of concern include control plane compromise (mitigated by layered security via bi-directional firewalling, limiting data propagation, unique passwords everywhere) and upstream vulnerabilities (mitigated by security audits, aggressive security update policies).

Ultimately, cloud needs to be secure at least as everything else in the enterprise and deserves our attention. That said, I don't think we should despair because of complexity; rather, we've been through this before as web browsing, e-commerce and virtualization came into their own over the past 20 years.

Sep 23, 2013

Is Rogers taking aim at Bell and Telus?

Seems that Rogers is taking a page from Bell and Telus' playbook... While Bell and Telus were busy trying to out position each other in the data centre market, Rogers picked up 3 data centre service providers: BlackIron earlier this year, and now Pivot and Granite.

What's interesting here is that Rogers instantly gains a significant foot hold in the enterprise data centre and hosting market but also gains cloud computing capabilities via the Granite acquisition. One wonders if Rogers is moving into the enterprise managed services market and making a play for the lucrative long term hosting and services contracts that Bell and Telus have enjoyed for so long.

Recall that both Bell and Telus launched their cloud infrastructure products last year, which were really underwhelming as product offerings, and, as far as anyone can tell, haven't really gained much traction in the market. Probably because their respective IaaS offerings were marketed to increase demand for that oh-so-precious-commodity-with steadily-eroding-profit-margins: bandwidth. How's that working out now?

The questions now, are:

  • Will Rogers use the same tactic and try to use the DC and IaaS offerings to drive bandwidth sales?
  • Will Rogers use it to promote and grow a user community that will serve the ever-growing-with-steady-margins mobile market?
  • Will Rogers use this foothold to drive managed services sales?
Time will tell. But the Telecom market is heating up!

Oct 15, 2012

Live Blog: Cloud Launch -- Canada's National Cloud Conference

The Canadian Cloud Council's 2nd national conference justy kicked off with Sir Terry Matthews sharing his experiences creating businesses (91 including the hotel in which we are meeting today) and innovation. The quality and calibre of speakers at this event promises to make it very interesting.

In Matthews opener, he suggested that cloud computing can impact every level of the value chain: from electricity generation (everything uses power) all the way through to the hardware [and end user]. He went on to say that "The opportunities...for new companies out there are good," and, "New companies create new jobs." Despite the ongoing economic concerns, this stands as a compelling endorsement for job creation, innovation, and investment in Canada.

Strong start to Cloud Launch. The conversation these next two days is going to be extraordinary.

May 16, 2011

Shouldn't companies WANT to protect their assets?

Last week, CNET reported on the White House's proposed cyber security law "[that is] designed to force companies to do more to fend off cyberattacks".

The law seems to address shortcomings in critical infrastructure security moreso than private industry though there does appear to be language that requires the disclosure of security breaches by private companies. this approach, presumably, would provide consumers with information regarding a business' security policy and could affect the choices consumers make. This non-regulatory position adopted by the White House is interesting because as it echoes the Canadian Radio and Television Commission's (CRTC) position of letting market forces shape the industry.

Is a non-regulatory approach appropriate? Would the US Government randomly audit companies to determine their level of security? Would that be sufficient to force companies to do more to ensure security? Probably not, given the number of companies in t he US and the rate at which new vulnerabilities are discovered. Requiring companies to disclose breaches could work if market forces are adequately informed.

It will be interesting to see how this legislation is applied to the cloud and which of the parties, vendor or consumer, will be held accountable for maintaining appropriate levels of security given that most contracts currently put that burden squarely on the shoulders of consumers.

The fact that legislation is even required to force companies to maintain adequate cyber security systems begs the question: wouldn't companies WANT to protect their assets anyway?!

Dec 30, 2010

More on Cloud and the Environment

Obviously I've been on hiatus for a little while, mainly due to work obligations (I was Sessional Lecturer at McGill University and taught Managing e-Business to BComm and MBA students this fall in addition to my regular responsibilities). So, without further ado, I'll get on with my post.

This past fall, Jirka Danek, CTO of Public Works and Government Services Canada (PWGSC) addressed an audience regarding cloud computing, the environment, and how Canada can be a leader in this space. I've had several discussions around these points and I'm happy to see that they've been heard and are being promoted.

Essentially, Danek discussed several factors that could contribute to Canada's leadership in the cloud computing space, including:
  • Cheap, green energy--Quebec has an extensive hydro-electric power generation infrastructure
  • Favorable climate--by virtue of the cooler environmental temperatures, cooling costs would be lower
  • Government is moving towards cloud adoption as a means of reducing its costs
  • The US, one of the largest global markets, is geographically adjacent to Canada
One benefit that he neglected to mention is the trickle down effect that such an investment would have on Canada's economy; the jobs created and taxes collected would help give Canada an economic boost.

This merits the industry's attention. The cloud market will grow* to $40.5 billion by 2014 (IDC) and $121.1 billion (MarketsandMarkets) and, since the technology is evolving rapidly and doesn't seem to be a huge competitive differentiator at this time, the larger future economic profits will go to those who have leveraged the cost reducing advantages.

* There doesn't seem to be any consensus on the market size and growth among industry analysts. Evaluation is done using various estimating methods and include or exclude various segments.

Aug 12, 2010

ROI Can be Higher in a Private Cloud

A random white paper I read used the words, "...increase infrastructure ROI..." when discussing virtualization of servers. These words are not typically used in the context of cloud based services because everyone is so preoccupied with the benefits of using the public cloud.

In public cloud parlance, ROI us usually used in a comparison of the costs to buy infrastructure vs. the cost of using resources on demand in the cloud. In private cloud vocab, ROI means just that: return on investment. So, how does an organization "increase" the ROI for capital assets? By virtualizing and adopting cloud best practices for automated provisioning and deprovisioning-in other words, creating a private cloud. If usage of the asset is increased, then the return on the initial investment can be increased as well.

Jun 14, 2010

City of San Diego Reported to Outsource IT Services

GovTech reported that the City of San Diego is ready to outsource some IT services including help desk functions, laptop, desktop, and database server management.

Within the article, the City reportedly consolidated five email systems into one. Oddly, there is no mention of migrating any services into the cloud as various city and state governments have already. It would seem that migrating to a SaaS model, such as Google Apps, would generate a cost savings by simply reducing removing  license fees/maintenance contracts and person-hours required to maintain on-premises servers and productivity apps on upwards of 10,000 desktops and laptops.

That said, the article doesn't mention whether the City's licenses are up for renewal nor the asset lifecycle. So, it is entirely possible that such a migration is being considered. We may yet see an announcement to that effect in the near future.

May 31, 2010

Cloud Security Alliance - Canada Chapter

I've decided that I'm going to start working on building the Cloud Security Alliance (CSA) - Canada Chapter. There seems to be interest so I thought I would write up a quick entry to see if anyone was interested in joining the Canadian chapter.

The CSA is a fledgling organization dedicated to "promote the use of best practices for providing security within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing." As of this posting, there are 2 official chapters and 5 chapters in development. In addition, there are several working groups:
Group 1. Architecture and Framework
Group 2. Governance, Risk Management, Compliance, Audit, Physical, BCM, DR
Group 3. Legal and eDiscovery
Group 4. Portability & Interoperability and Application Security
Group 5. Identity and Access Mgt, Encryption & Key Mgt
Group 6. Data Center Operations and Incident Response
Group 7. Information Lifecycle Management & Storage
Group 8. Virtualization and Technology Compartmentalization
Editorial Group
Educational Working Group
Solution Provider Advisory Council

It's obvious to me that the questions of governance and security (issues important to me) are not going to go away by themselves. Nor should it be left solely to industry to develop competing views/models/tools - it's simply inefficient. It behooves us, the denizens of the industry, to help in those efforts.

Please let me know if you are interested in joining the CSA - Canada Chapter by sending your coordinates (name, company, title, email, phone) to pano(dot)xinos(at)gmail(dot)com.

[Edit: added working groups. --PX--]

May 27, 2010

Jurisdiction, or, I have to comply with whose laws?

Judith Hurwitz, of Hurwitz & Associates, has a slide in one of her presentations that refers to protecting data in the cloud and reads, "Government and Industry regulation must be adhered to regardless of the location of your applications and your information."

The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...

The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.

What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...

What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?

The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.

May 17, 2010

What, exactly, is ROI?

The acronym, ROI, means 'return on investment'. In other words, if I make $1.10 for every $1.00 spent on a project, my return on the $1.00 invested is 10%. Used in the context of cloud computing, this is incorrect.

When we talk about the economic benefit of cloud computing, we assess the difference between the total cost of ownership (TCO) of owning and operating the necessary infrastructure to make our applications available to customers and the TCO of of leasing that same infrastructure on demand. All else being equal, more than likely, the cost of owning and operating will be higher than leasing on demand. This is a cost saving proposition, not a ROI. In this case, we should be looking at the breakeven point--the point in time at which we have paid off the expense and get into the black.

What is usually missing from the evaluation of these cost savings is the sunk cost of application development: either way, those $ are going to be spent and are considered to be an investment. Aha! Now we're talking about investment. If TCO is (assumed) to be lower when leveraging a cloud environment, then it follows that the ROI will be higher.

Consider the following basic scenario:

Note that the OPEX is higher in the lease/on demand scenario. This is because most of the CAPEX that would have been incurred in an ownership scenario become OPEX in a lease/on demand scenario. So, when comparing the ownership and lease/on demand scenarios, the economic benefit, or return on the initial development investment, would be greater in a cloud based scenario. If we had considered an pre-existing application and its displacement to the cloud, then we would have been discussing a cost savings, and not a ROI.

May 7, 2010

A private cloud, by any other name, is a private cloud

In March, Tom Fisher, of SuccessFactors, was a guest speaker at Cloud Connect in Santa Clara. During his chat with M.R. Rangaswami, of Sand hill Group, he stated unequivocally that private cloud computing was simply a data center and that SaaS was cloud computing.

The problem with that statement is that it isn't completely wrong. Many organizations have a data center footprint and house servers on which they install software that is used throughout the organization; this is an application provided as a service, or, if we stretch a bit, SaaS (it's a stretch in my mind because there is no notion of multi-tenancy). Logically, then, if SaaS is cloud computing, and it is software that is installed on a server that is housed in the organization's data center, the organization is making use of a private cloud. To use Tom's analogy, "If it walks like a duck, it quacks like a duck, it's a duck." But I digress...

Back to the issue at hand. By itself, server virtualization is not cloud computing. However, if the organization were to automate the rapid provisioning and de-provisioning of the virtual resources using whatever home-grown, open source, or COTS middleware, then the organization is leveraging cloud computing on its own infrastructure--a private cloud. Server virtualization allows the organization to more efficiently utilize its servers' capacity whereas cloud computing increases the organization's agility, ability to rapidly test and deploy services to meet varying demand needs, and reduce its appetite for capital. Whether the infrastructure is around the world or in the organization's own data center is irrelevant.

Quack, quack!

May 5, 2010

Inaugural post

Well, here it is. My platform. To sum up, I’ve been following cloud computing for a long time now and have decided to start posting my thoughts on this revolutionary technology. Yes, I used the word ‘revolutionary’. I could have also called it a ‘paradigm shift’ or ‘game changing technology’ because this is exactly what it is and will be.

In this blog I will concentrate on the business issues surrounding cloud computing leaving the technical and standards issues to other, more qualified, individuals; afterall, it’s been a long time since I’ve done anything technical… I hope to make this blog informative and critical and will try to post at least once a week. If you feel that I’ve strayed from these goals, please feel free to drop me a line.