SlideShare ist ein Scribd-Unternehmen logo
1 von 47
Downloaden Sie, um offline zu lesen
Cloud & Security
and opensource
Bae KwonHan <darjeeling@gmail.com>
Q : What is Cloud?
• Data Sync Service on the cloud
• Commercial Cloud Service
• Cloud Service Implementation with open
  source or closed source

• Any Cloud Service use instead of legacy
  infrastructure

• http://en.wikipedia.org/wiki/
  Cloud_computing
• Infrastructure as a Service
• Platform as a Service
• Service as a Service
• Backend as a Service
• Blah as a Service
COST
SURPLUS
Automation
IaaS
•   Packaging VM with network
•   Multitenancy
•   Volume Service
•   Object Store Service
•   AAA
•   Network Security Manager ( ACL )
•   API / CLI / GUI
Security on IaaS

• network Isolation!!
• VM access
• VM host
• ACL
• IaaS Manager
IaaS safe?
• VM data?
• VM memory access?
• volume data?
• DDOS?
• think about a service
• multi service distribution
AWS security support

• VPC ( Virtual Private Cloud )
• S3 Encryption
• AWS Identity and Access Management
• AWS Security Group
Commercial
    IaaS Implementation
•   Amazon AWS EC2
•   MS Azure Virtual Machines
•   Google CE
•   HP Cloud
•   Joyent
•   Rackspace Cloud
•   cafe24?
•   KT uCloud Biz
•   SKT tCloud Biz
•   Hostway?
•   VMWARE Product
OpenSource
  IaaS Implementation
• Openstack
• Cloudstack
• Eucalyptus
• others
http://ken.pepple.info/
   openstack/2012/09/25/
openstack-folsom-architecture/
PaaS
• Packaging Process with database on IaaS
• runtime, middleware, os
• Multitenancy
• AAA
• ACL on Process
• API / CLI / GUI
Security on PaaS

• API
• Process Isolation
• Database Isolation
• PaaS Manager
Commercial
    Platform as a Service
•   Heroku
•   Google App Engine
•   Engine Yard
•   Openshift
•   Windows Azure
•   vmware CloudFoundry
    •   appfog
    •   appcera
Opensource
 Platform as a Service

• VMWARE CloudFoundry
• Redhat OpenShift
Security on PaaS

• DDOS
• Manager Problem
• Application Problem
SaaS


• Packaging Service on Infrastructure
Security on SaaS

• API
• SaaS Manager
• connection hook
SaaS Implementation

• Google Apps
• iCloud
• SalesForce
• others?
Plus
           Baremetal as a Service
            or Metal as a Service
•   automate installing os
•   use out of band management
    •   IPMI
    •   dell Drac
    •   KVM over IP
    •   HP ILO
    •   IBM Remote Supervisor Adapter
MAAS Implementation

• opensource
 • ubuntu juju
• every hardware vender sells MAAS
Chain of aaS

• MaaS
• IaaS
• PaaS
• SaaS
Cloud Service User
• Cost
• you should know what/how you are doing
• you should know what/how they are doing
• focus on application programming
• focus on management console
• focus on AAA
OpenSource
why open source?
everything is
open source
open source
•   openstack
•   openvswich
•   cloudfoundry
•   openshift
•   opensource VM implementation
    •   KVM ( Kernel-based Virtual Machine )
    •   XEN
    •   LXC
    •   OpenVZ
    •   QEMU
    •   VirtualBOX
OpenStack
•   Infrastructure as a Service
•   started by rackspace cloud and NASA since 2010
    •   Compute ( nova )
    •   Object Storage ( Swift )
    •   Image Service ( Glance )
    •   Identity Service ( Keystone )
    •   Dashboard ( Horizon )
    •   Networking ( Quantum )
    •   Block Storage ( Cinder )
    •   Metering ( Ceilometer - Beta )
    •   Basic Cloud Ochestration ( Heat - Beta - PaaS )
openvswitch

• http://openvswitch.org/
• security : vlan isolation, traffic filtering
• QoS : traffic queuing, traffic shaping
• monitoring : NetFlow, sFlow, SPAN, RSPAN
• automated control
DevOps?
what we should know?

• What is cloud
• Every component of cloud service
• Every boundary of cloud component
• how application works
Q &A

Weitere ähnliche Inhalte

Was ist angesagt?

CloudSigma at Zadara Summit 2014
CloudSigma at Zadara Summit 2014CloudSigma at Zadara Summit 2014
CloudSigma at Zadara Summit 2014
CloudSigma
 

Was ist angesagt? (20)

OpenStack Management at Hyperscale
OpenStack Management at HyperscaleOpenStack Management at Hyperscale
OpenStack Management at Hyperscale
 
dodai_grizzly.pdf
dodai_grizzly.pdfdodai_grizzly.pdf
dodai_grizzly.pdf
 
CloudStack Collaboration Conference Opening Remarks
CloudStack Collaboration Conference Opening RemarksCloudStack Collaboration Conference Opening Remarks
CloudStack Collaboration Conference Opening Remarks
 
Briefing: Containers
Briefing: ContainersBriefing: Containers
Briefing: Containers
 
Leveraging OpenStack to Run Mesos/Marathon at Charter Communications
Leveraging OpenStack to Run Mesos/Marathon at Charter CommunicationsLeveraging OpenStack to Run Mesos/Marathon at Charter Communications
Leveraging OpenStack to Run Mesos/Marathon at Charter Communications
 
CloudStack EU User Group - Making stuff better through CloudStack
CloudStack EU User Group - Making stuff better through CloudStackCloudStack EU User Group - Making stuff better through CloudStack
CloudStack EU User Group - Making stuff better through CloudStack
 
How DreamHost builds a Public Cloud with OpenStack
How DreamHost builds a Public Cloud with OpenStackHow DreamHost builds a Public Cloud with OpenStack
How DreamHost builds a Public Cloud with OpenStack
 
Securing open stack for compliance
Securing open stack for complianceSecuring open stack for compliance
Securing open stack for compliance
 
CloudSigma at Zadara Summit 2014
CloudSigma at Zadara Summit 2014CloudSigma at Zadara Summit 2014
CloudSigma at Zadara Summit 2014
 
Fuse integration-services
Fuse integration-servicesFuse integration-services
Fuse integration-services
 
Brisbane DevOps Meetup - Reinvent 2015
Brisbane DevOps Meetup - Reinvent 2015Brisbane DevOps Meetup - Reinvent 2015
Brisbane DevOps Meetup - Reinvent 2015
 
Serving Files In Azure
Serving Files In AzureServing Files In Azure
Serving Files In Azure
 
It's a Serverless World
It's a Serverless WorldIt's a Serverless World
It's a Serverless World
 
Using the KVMhypervisor in CloudStack
Using the KVMhypervisor in CloudStackUsing the KVMhypervisor in CloudStack
Using the KVMhypervisor in CloudStack
 
OpenStack at Bloomberg
OpenStack at BloombergOpenStack at Bloomberg
OpenStack at Bloomberg
 
Telia latvija cloudstack
Telia latvija cloudstackTelia latvija cloudstack
Telia latvija cloudstack
 
Bitnami Bootcamp. OpenStack
Bitnami Bootcamp. OpenStackBitnami Bootcamp. OpenStack
Bitnami Bootcamp. OpenStack
 
CloudStack and testing
CloudStack and testingCloudStack and testing
CloudStack and testing
 
Java PaaS Apache Stratos
Java PaaS   Apache StratosJava PaaS   Apache Stratos
Java PaaS Apache Stratos
 
Percona xtradb cluster
Percona xtradb clusterPercona xtradb cluster
Percona xtradb cluster
 

Andere mochten auch

Andere mochten auch (10)

The Importance of open source in cloud computing
The Importance of open source in cloud computingThe Importance of open source in cloud computing
The Importance of open source in cloud computing
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?Cloud- A Technical or Organisational Challenge? Or Both?
Cloud- A Technical or Organisational Challenge? Or Both?
 
Cloud ppt
Cloud pptCloud ppt
Cloud ppt
 
CPAC Connectome Analysis in the Cloud
CPAC Connectome Analysis in the CloudCPAC Connectome Analysis in the Cloud
CPAC Connectome Analysis in the Cloud
 
Cloud Computing by AGDMOUN Khalid
Cloud Computing by AGDMOUN KhalidCloud Computing by AGDMOUN Khalid
Cloud Computing by AGDMOUN Khalid
 
Technical Analysis: Ichimoku Cloud by NSFX
Technical Analysis: Ichimoku Cloud by NSFXTechnical Analysis: Ichimoku Cloud by NSFX
Technical Analysis: Ichimoku Cloud by NSFX
 
Cloud computing Basics
Cloud computing BasicsCloud computing Basics
Cloud computing Basics
 
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing ppt
 
Introduction of Cloud computing
Introduction of Cloud computingIntroduction of Cloud computing
Introduction of Cloud computing
 

Ähnlich wie Cloud, Security and opensource 2012-12-28 at SSU

Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
IndicThreads
 
Intro to Docker October 2013
Intro to Docker October 2013Intro to Docker October 2013
Intro to Docker October 2013
Docker, Inc.
 
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
Lucas Jellema
 

Ähnlich wie Cloud, Security and opensource 2012-12-28 at SSU (20)

The Future of SDN in CloudStack by Chiradeep Vittal
The Future of SDN in CloudStack by Chiradeep VittalThe Future of SDN in CloudStack by Chiradeep Vittal
The Future of SDN in CloudStack by Chiradeep Vittal
 
Directions for CloudStack Networking
Directions for CloudStack  NetworkingDirections for CloudStack  Networking
Directions for CloudStack Networking
 
HOW CLOUD PLATFORMS ARE EVOLVING TO SUPPORT WEB-SCALE DIGITAL AND IT BUSINESS
HOW CLOUD PLATFORMS ARE EVOLVING TO SUPPORT WEB-SCALE DIGITAL AND IT BUSINESSHOW CLOUD PLATFORMS ARE EVOLVING TO SUPPORT WEB-SCALE DIGITAL AND IT BUSINESS
HOW CLOUD PLATFORMS ARE EVOLVING TO SUPPORT WEB-SCALE DIGITAL AND IT BUSINESS
 
Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
Current State of Affairs – Cloud Computing - Indicthreads Cloud Computing Con...
 
Cloud Native Camel Riding
Cloud Native Camel RidingCloud Native Camel Riding
Cloud Native Camel Riding
 
John Willis Cc Use Cases
John Willis Cc Use CasesJohn Willis Cc Use Cases
John Willis Cc Use Cases
 
Basics of Java Cloud
Basics of Java CloudBasics of Java Cloud
Basics of Java Cloud
 
Integration in the Age of DevOps
Integration in the Age of DevOpsIntegration in the Age of DevOps
Integration in the Age of DevOps
 
Intro to Docker October 2013
Intro to Docker October 2013Intro to Docker October 2013
Intro to Docker October 2013
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
 
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
Dutch Oracle Architects Platform - Reviewing Oracle OpenWorld 2017 and New Tr...
 
Chicago Microservices Integration Talk
Chicago Microservices Integration TalkChicago Microservices Integration Talk
Chicago Microservices Integration Talk
 
Application Lifecycle Management on AWS
Application Lifecycle Management on AWSApplication Lifecycle Management on AWS
Application Lifecycle Management on AWS
 
Nutanix basic
Nutanix basicNutanix basic
Nutanix basic
 
NDev Talk - Serverless Design Patterns
NDev Talk - Serverless Design PatternsNDev Talk - Serverless Design Patterns
NDev Talk - Serverless Design Patterns
 
Introduction: Build infrastucture-as-a-service Clouds with Apache CloudStack
Introduction: Build infrastucture-as-a-service Clouds with Apache CloudStackIntroduction: Build infrastucture-as-a-service Clouds with Apache CloudStack
Introduction: Build infrastucture-as-a-service Clouds with Apache CloudStack
 
OpenStack and Windows
OpenStack and WindowsOpenStack and Windows
OpenStack and Windows
 
Introduction to Cloud Computing 2021
Introduction to Cloud Computing 2021Introduction to Cloud Computing 2021
Introduction to Cloud Computing 2021
 
JDD 2016 - Jacek Bukowski - "Flying To Clouds" - Can It Be Easy?
JDD 2016 - Jacek Bukowski - "Flying To Clouds" - Can It Be Easy?JDD 2016 - Jacek Bukowski - "Flying To Clouds" - Can It Be Easy?
JDD 2016 - Jacek Bukowski - "Flying To Clouds" - Can It Be Easy?
 
Flying to clouds - can it be easy? Cloud Native Applications
Flying to clouds - can it be easy? Cloud Native ApplicationsFlying to clouds - can it be easy? Cloud Native Applications
Flying to clouds - can it be easy? Cloud Native Applications
 

Cloud, Security and opensource 2012-12-28 at SSU

  • 1. Cloud & Security and opensource Bae KwonHan <darjeeling@gmail.com>
  • 2.
  • 3. Q : What is Cloud?
  • 4. • Data Sync Service on the cloud • Commercial Cloud Service • Cloud Service Implementation with open source or closed source • Any Cloud Service use instead of legacy infrastructure • http://en.wikipedia.org/wiki/ Cloud_computing
  • 5. • Infrastructure as a Service • Platform as a Service • Service as a Service • Backend as a Service • Blah as a Service
  • 9.
  • 10.
  • 11. IaaS • Packaging VM with network • Multitenancy • Volume Service • Object Store Service • AAA • Network Security Manager ( ACL ) • API / CLI / GUI
  • 12. Security on IaaS • network Isolation!! • VM access • VM host • ACL • IaaS Manager
  • 13. IaaS safe? • VM data? • VM memory access? • volume data? • DDOS? • think about a service • multi service distribution
  • 14. AWS security support • VPC ( Virtual Private Cloud ) • S3 Encryption • AWS Identity and Access Management • AWS Security Group
  • 15. Commercial IaaS Implementation • Amazon AWS EC2 • MS Azure Virtual Machines • Google CE • HP Cloud • Joyent • Rackspace Cloud • cafe24? • KT uCloud Biz • SKT tCloud Biz • Hostway? • VMWARE Product
  • 16. OpenSource IaaS Implementation • Openstack • Cloudstack • Eucalyptus • others
  • 17.
  • 18. http://ken.pepple.info/ openstack/2012/09/25/ openstack-folsom-architecture/
  • 19. PaaS • Packaging Process with database on IaaS • runtime, middleware, os • Multitenancy • AAA • ACL on Process • API / CLI / GUI
  • 20.
  • 21. Security on PaaS • API • Process Isolation • Database Isolation • PaaS Manager
  • 22. Commercial Platform as a Service • Heroku • Google App Engine • Engine Yard • Openshift • Windows Azure • vmware CloudFoundry • appfog • appcera
  • 23. Opensource Platform as a Service • VMWARE CloudFoundry • Redhat OpenShift
  • 24. Security on PaaS • DDOS • Manager Problem • Application Problem
  • 25. SaaS • Packaging Service on Infrastructure
  • 26. Security on SaaS • API • SaaS Manager • connection hook
  • 27. SaaS Implementation • Google Apps • iCloud • SalesForce • others?
  • 28. Plus Baremetal as a Service or Metal as a Service • automate installing os • use out of band management • IPMI • dell Drac • KVM over IP • HP ILO • IBM Remote Supervisor Adapter
  • 29. MAAS Implementation • opensource • ubuntu juju • every hardware vender sells MAAS
  • 30. Chain of aaS • MaaS • IaaS • PaaS • SaaS
  • 32. • Cost • you should know what/how you are doing • you should know what/how they are doing • focus on application programming • focus on management console • focus on AAA
  • 36.
  • 37. open source • openstack • openvswich • cloudfoundry • openshift • opensource VM implementation • KVM ( Kernel-based Virtual Machine ) • XEN • LXC • OpenVZ • QEMU • VirtualBOX
  • 38. OpenStack • Infrastructure as a Service • started by rackspace cloud and NASA since 2010 • Compute ( nova ) • Object Storage ( Swift ) • Image Service ( Glance ) • Identity Service ( Keystone ) • Dashboard ( Horizon ) • Networking ( Quantum ) • Block Storage ( Cinder ) • Metering ( Ceilometer - Beta ) • Basic Cloud Ochestration ( Heat - Beta - PaaS )
  • 39. openvswitch • http://openvswitch.org/ • security : vlan isolation, traffic filtering • QoS : traffic queuing, traffic shaping • monitoring : NetFlow, sFlow, SPAN, RSPAN • automated control
  • 41.
  • 42.
  • 43.
  • 44.
  • 45.
  • 46. what we should know? • What is cloud • Every component of cloud service • Every boundary of cloud component • how application works
  • 47. Q &A