HTML Injection Attacks: Impact and Mitigation Strategies
Â
IBM Smart Cloud Provisioning Overview
1. Š 2013 IBM Corporation
IBM SmartCloud Provisioning overview
Rossella De Gaetano : rossella.degaetano@it.ibm.com
May 2013
2. Š 2013 IBM Corporation2
Companies need an affordable entry point for cloud
Customer goals:
â˘Provide agile service delivery that caters to
changing business needs.
â˘We know virtualization helps reduce capital
expense but how do I control my operational
cost?
â˘Need to increase the performance, utilization,
reliability and scalability of IT resources while
reducing IT complexity
â˘Ability to expand capabilities
VISIBILITY CONTROL AUTOMATION
See services in real time &
better predict business
outcomes
Better manage assets,
service & compliance.
Achieve greater efficiency
and service quality
Organizations need a low-cost, low-risk entry point to cloud computing technology
with compelling features that achieves their business goals.
3. Š 2013 IBM Corporation3
Core capabilities of SmartCloud Provisioning (and its components)
ď Distributed architecture for solution resilience.
ď Rapid scalable deployment designed to deliver near-instant deployment of 100s of virtual machines
in seconds instead of mins or hours.
ď Continuous operations during upgrades and maintenance resulting in no outages or downtime.
ď Reliable, non-stop cloud capable of automatically tolerating and recovering from software and
hardware failures.
ď Save IT labor resources at scale by enabling self-service request and highly automated operations
ď Hypervisor & hardware agnostic enabling choice and avoiding vendor lock-in.
ď Open source, commodity skills, small footprint.
High Scale Low Touch ICCT â Image Construction Virtual Image Library IWD
SmartCloud Provisioning
4. Š 2013 IBM Corporation4
Core capabilities of SmartCloud Provisioning (and its components)
ď Advanced Image lifecycle management & image composition tooling.
ď Tooling to simplify migration of workloads between hypervisors.
ď Hypervisor agnostic supporting image composition on different platforms.
ď Image publishing and image repository.
ď Run-time image activation allowing advanced customization from standardized templates.
ď SmartCloud Enterprise enabled, supporting integration with IBMâs public cloud.
High Scale Low Touch ICCT â Image Construction Virtual Image Library IWD
SmartCloud Provisioning
5. Š 2013 IBM Corporation5
Core capabilities of SmartCloud Provisioning (and its components)
ď Discovery of images across the virtual infrastructure.
ď Automatic indexing / cataloging of images.
ď Image comparison tooling to identify changes, and manage change.
ď Image version control to help standardise images.
ď Supports a wide range of image and OS types.
ď Portability checks and remediation to help create cross hypervisor images
High Scale Low Touch ICCT â Image Construction Virtual Image Library IWD
SmartCloud Provisioning
6. Š 2013 IBM Corporation6
Core capabilities of SmartCloud Provisioning (and its components)
ď PaaS pattern deployment.
ď GUI based pattern creation.
ď Deployment of IaaS & PaaS to advanced hypervisor managers (eg. VM control)
ď Pre-canned images available (chargeable)
High Scale Low Touch ICCT â Image Construction Virtual Image Library IWD
SmartCloud Provisioning
7. Š 2013 IBM Corporation7
Extending the Cloud capabilities beyond SmartCloud Provisioning
SmartCloud Monitoring Tivoli Storage Manager fVE Tivoli Usage & Accounting MgrTivoli Endpoint Manager
Health Analytics
Host & VM Monitoring
Event Response & Mgt
Capacity Planning
What-if Scenarios?
Patch Management
Compliance Reporting
Policy Enforcement
Centralised Backup
Policy Driven
Data Restore
Image Snapshots
Usage Reporting
Cognos Reporting
Accounting & Rating
Invoice Creation
Security and
Compliance
Availability and
Performance
Usage and
Accounting
Security and
Compliance
High Scale Low Touch ICCT â Image Construction Virtual Image Library IWD
SmartCloud Provisioning
8. Š 2013 IBM Corporation
IBM SmartCloud Provisioning
architecture and functionalities
May 2013
9. Š 2013 IBM Corporation9
SmartCloud Provisioning architecture
VMVM
Hypervisors & IAAS Management SHIMSHypervisors & IAAS Management SHIMS
vCenter
SHIM
REST APIsREST APIs
Self Service and Admin UISelf Service and Admin UI
HSLT
KVM, Xen, ESXi
IAAS API ShimIAAS API Shim
vCenter
Placement/DeploymentPlacement/Deployment
Virtual
Systems
Virtual
Systems
SCP
Virtual
Image
Library
ICON
VMControl
Virtualization Management
Based Provisioning
VMControl
SHIM
zLinux
zLinux
SHIM
10. Š 2013 IBM Corporation11
Patterns
ďŹ Deploy more than one VM in one shot
ďŹ The VMs can be deployed with no
interconnection (e.g. Deploy a pattern of
intermediate or basic VMs)
ďŹ The VMs can be deployed assuming after
boot they will be connected (e.g. WAS cluster)
ďŹ Add-ons and packages scripts can be used
to customize images
Note:
pre-canned image for pattern deployment can be downloaded from IBM
(charged!)
They can be used not only for IBM software
11. Š 2013 IBM Corporation12
Patterns
VM1
VM 2
VM 3
VM 2VM 2VM 2
VM 3
VM1VM1Virtual systems
Pattern
12. Š 2013 IBM Corporation
Image Management
June 2012
13. Š 2013 IBM Corporation14
In the beginning, there was the perfect imageâŚ1
Then users starting making changes and âsnapshotsââŚ
âŚand what they put in the images is unknownâŚ
2
Then they get copied to multiple locationsâŚ
âŚand some change againâŚ
3
Then you need to apply a critical security patchâŚhow? ⌠where?4
Whatâs the problem with Virtualization and Standardization?
14. Š 2013 IBM Corporation15
Capturing images is easy
ď§ There are many tool that simplify the process
ď§ All you need is enough space the store them
However managing images is hard
Standardization How to contain the proliferation of image variants?
Search How does one find a useful image?
Version control Who did what to which image, and when?
Drift Detection Identify images that diverge from initial configurations
Vulnerability Images must be updated with security patches
Image building Reduce manual labor to compose images
15. Š 2013 IBM Corporation16
IBM SmartCloud Provisioning Puts You Back in Control
ď§ Control over Image Versions, Content and Locations
âImage library allows check in, check out, and tracking of versions in the environment
â˘Changes can finally be tracked
âPowerful image analytics finds the content you need and can show the specific changes
from one image to another
â˘Encourages reuse and gives needed visibility to analyzing whole systems at a glance
âImages are tracked across multiple Clouds and/or multiple sites
â˘Critical for disaster recovery arrangements and decentralized use
ď§ Control over Image Construction
âBuild images using Company-certified OS, middleware, and application packages
â˘Avoids images being taken out of production due to non-compliance
16. Š 2013 IBM Corporation17
Two optionally installable components:
â˘Image Construction and Composition Tool
â˘Import images from heterogeneous providers
â˘Extend images
Avoid images being taken out of production due to non-compliance
â˘Image library
â˘Import & export images across an etherogeneous set of
repositories
â˘Assign version to images
â˘Search for images
â˘Compare images
Get full control on image lifecycle
17. Š 2013 IBM Corporation
High Scale Low Touch
May 2013
18. Š 2013 IBM Corporation19
Storage
node
Storage
node
Compute
node
First Box
Compute
node
⢠Out-of-the-box and running in less than 4 hours
⢠Get started with only 4 servers
⢠Out-of-the-box and running in less than 4 hours
⢠Get started with only 4 servers
⢠Quickly stand up a cloud
⢠Start small and scale based on need
⢠No additional pre-reqs such as databases, app
servers, messaging middleware
⢠Freedom of choice for hypervisors
â˘Avoid expensive vendor lock in
â˘VMWare ESX, KVM, Xen, Hyper-V
⢠Highly cost effective solution
⢠Requires no additional hypervisor management
tools
⢠Requires no HA hardware or software
⢠Rich set of interfaces into the cloud
⢠Web Interface, scripting and web services
⢠All function can be driven by a user or by scripts
for complete automation
HSLT
Quickly get started with HSLT
19. Š 2013 IBM Corporation20
Requested VMs will be up
and running under a minute
using standard HW
⢠Itâs Fast
⢠Can start 100 VMs in under 3 mins
⢠Can start a single VM and load OS in under 10 seconds
⢠Can go from bare metal to ready for work in under 5 minutes
⢠It Scales up to and beyond 50,000 VMs in an hour (50 nodes)
⢠Add capacity by simply plugging in a blade or server
⢠Writes only the data you change
⢠Peer-peer architecture to avoid traditional bottlenecks
⢠It's Fault-Tolerant
⢠âLive Updateâ capability to patch or upgrade the Cloud
⢠No single point of failure
⢠Automatic failure recovery
HSLT
Provides Unparalleled Scalability, Speed and Fault Tolerance
Hardware
Hypervisor
Bo
t
Hardware
Hypervisor
Mgt VM
VM Bo
t
Hardware
Hypervisor
Bo
t
Hardware
Hypervisor
VM Bo
t
Hardware
Hypervisor
VM Bo
t
Hardware
Hypervisor
VM Bo
t
Hardware
Hypervisor
Bo
t
Hardware
Hypervisor
Hardware
Hypervisor
VM Bo
t
Bo
t
20. Š 2013 IBM Corporation21
⢠HSLT coordinates three indipendent ingredients:
⢠Virtual servers
⢠Network addresses
⢠Storage volumes
When a request is made, a given virtual server is
attached to one or more network addresses and one
or more storage volumes
⢠This has several advantages:
⢠Quickly recover from failures â cheaper to replace than to fix:
- Swap out old VM and replace with fresh new VM on
different hardware
ďŹDramatically simplifies patch, image and change management:
- New versions can be easily swapped in, and old versions can be easily put back if
problems arise
- Servers can be restarted and then reattached to their previous storage volumes
and addresses to quickly restore their state
HSLT key concepts..
21. Š 2013 IBM Corporation22
No single points of failure, no bottlenecks in data
serving/processing, no intervention to repair broken parts!
Failures that will impact your users, slowdowns that your
users will notice, and extra work for the admin team!
ďŹ Multiple, load balanced instances of all services
ďŹ Parallel processing against storage
ďŹ Self-adapting peer-to-peer communication & coordination
ďŹ Recovery oriented computing
ďŹ Network deployed software & image updating
ďŹ Distributed request processing, data storage and messaging
ďŹ Designed to run on lower cost hardware and storage devices
ďŹ All services monitor and restart each other, and dynamically elect the leader
ďŹ Base software is loaded via network boot (PXE)
ďŹ Services are images, so update themselves by restarting with new image
version
ďŹ Single instance of critical services
ďŹ Serialized processing
ďŹ No automatic restart and rerouting of requests
ďŹ Patches and upgrades go everywhere
ďŹ Requires very high cost hardware
ďŹ The bigger the cloud the worse the damage
ďŹ Request for images bound to a single location
ďŹ Serialized, slow access and susceptible to peak overloads
ďŹ Patches/upgrades require taking down the Cloud to apply and they need to be
carefully applied
ďŹ When a service breaks, that part of the system is out
ďŹ Admins have to troubleshoot and fix
HSLT vs traditional hierarchical architecture
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
End Users
Server machines Storage devices
(iSCSI)
VMVMVMVMVM
End Users
VMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
VMVMVMVMVM
22. Š 2013 IBM Corporation23
1. Leader fails
⢠triggers reelection and another takes over
2. Agent fails
⢠watchdog restarts
3. Storage node fails
⢠Multi-path continues uninterrupted
⢠Agent connects to another replica
⢠Leader tries to restart
4. Compute node failure
⢠Partial faults cause agent to stop accepting requests
to evacuate (live migration available on KVM)
⢠Once empty will restart (PXE fresh image)
⢠Full failure detected by leader which stops sending
requests
⢠Leader cycleâs server power (PXE fresh image)
5. Service VM fails
⢠All services are clustered to tolerate individual faults
⢠Leader VM detects and replaces failed VM
6. Network fault
1.Redundant interfaces automatically take over
1. Leader fails
⢠triggers reelection and another takes over
2. Agent fails
⢠watchdog restarts
3. Storage node fails
⢠Multi-path continues uninterrupted
⢠Agent connects to another replica
⢠Leader tries to restart
4. Compute node failure
⢠Partial faults cause agent to stop accepting requests
to evacuate (live migration available on KVM)
⢠Once empty will restart (PXE fresh image)
⢠Full failure detected by leader which stops sending
requests
⢠Leader cycleâs server power (PXE fresh image)
5. Service VM fails
⢠All services are clustered to tolerate individual faults
⢠Leader VM detects and replaces failed VM
6. Network fault
1.Redundant interfaces automatically take over
Failure mode and automatic recovery in HSLT
23. Š 2013 IBM Corporation24
Additional resources
ď§ IBM SmartCloud Provisioning information center:
https://www.ibm.com/developerworks/mydeveloperworks/wikis/home?lang=en#/wiki/IBM
%20SmartCloud%20Provisioning/page/Home
ď§ IBM SmartCloud Provisioning WIKI:
https://www.ibm.com/developerworks/mydeveloperworks/wikis/home?lang=en#/wiki/IBM
%20SmartCloud%20Provisioning/page/Home
â˘Additional resources
â˘Customer interaction
â˘Demos
â˘Upcoming features
ď§ SmartCloud Provisioning and Orchestration community:
https://www.ibm.com/developerworks/mydeveloperworks/groups/service/html/communityvie
w?communityUuid=e5a54efe-3c9f-491b-af2a-e5400516b5aa
ď§ IBM SmartCloud Provisioning forum:
http://www.ibm.com/developerworks/forums/forum.jspa?forumID=2670
25. Š 2013 IBM Corporation26
vCenter or HSLT cloud groups?
vCenter HSLT
ďŹ deploy/delete persistent
images
ďŹ Capture images
ďŹ Modify hw resources of
deployed images
ďŹ Apply fixes
ďŹ deploy/delete patterns
ďŹ VMs takeover
ďŹ IPv6 support
ďŹ Can leverage Vmotion
ďŹ deploy/delete persistent images
ďŹ deploy/delete non persistent
images
ďŹ Capture images
ďŹ Modify hw resources of persistent
deployed images
ďŹ Apply fixes
ďŹ Attach elastic IP
ďŹ Attach disks
ďŹ Deploy/delete patterns
ďŹ Live migration available (KVM only)
ďŹ Low touch
ďŹ High scalability
ďŹ Supports KVM, ESXi, Xen, Hyper-V
26. Š 2013 IBM Corporation27
Static IPs vs elastic IPs
Static IPs Elastic IPs
ďŹ The IP group is configured
to use static IPs
ďŹ The IP address is assigned
at instance deployment time
ďŹ Can be an IPv4 or an IPv6
address (HSLT cloud group
supports IPv4 only)
ďŹ The vNIC of the instances
is configured for that IP
ďŹ The IP group is configured to use
DHCP
ďŹ The IP address is assigned after
the instance has been deployed
ďŹ Must be an IPv4 address
ďŹ The vNIC is not touched at all: NAT
is used
Hinweis der Redaktion
We recently tested a 50 node IBM SmartCloud Provisioning installation and we were able to load more than 10,000 VMs in an hour. We also added 14 brand new blades and had them available to provision VMs (from bare metal) in less than 6 minutes.
Typical Virtualization vendors mistakenly put the configurations inside the VM, making it either difficult or impossible to automate with scriptsc