Popular Posts

Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Saturday, 2 September 2017

Why cloud computing for small businesses is a powerful solution








Source – telegraph.co.uk
What kind of business has the billing capability of a telecommunications giant, the e-commerce platform of a global online retailer and the security capability of a government agency?
Potentially any kind of business, as it happens. Today businesses of all sizes are accessing technological capabilities that were once the preserve of large companies simply by tapping into the cloud – an internet-based form of computing where processing resources and data are shared with computers and other devices on demand.
The cloud can be used for a host of business purposes, from storing and sharing documents and data through to accounting, collaboration, file backup and inspecting web and email traffic for viruses and spyware.
What’s more, it offers substantial cost savings by bundling together application development, infrastructure, maintenance and support services and allowing organisations to only pay for the services that they use.
Unsurprisingly, then, the global cloud services market is estimated to be worth $246.8 billion (£190bn) in 2017, according to analyst Gartner, with cloud adoption strategies likely to influence more than 50 per cent of IT outsourcing deals by 2020.
It is not just computing power that makes the cloud so influential. The technology also enables businesses to be more agile in how they create new products and services, respond to their customers and fend off competitive threats.
“In the last few years, the cloud has transformed businesses in a way that we could never have imagined,” says Andrew Lowe, operations, EALA infrastructure, cloud strategy and origination lead at consulting firm Accenture. “It allows organisations to tap new capabilities and rebuild their services and processes at a rapid pace.”
For start-ups, the process of adopting cloud as a service for business tools is relatively straightforward since they aren’t weighed down by cumbersome legacy systems. It is more challenging for established businesses to migrate since they have legacy applications and infrastructure that are not in the cloud. Fortunately, however, they are also likely to have experienced staff with strong technological skillsets – so moving to the cloud will give these staff the opportunity to use their skillsets in new and different ways.
As an example, capacity management skills will become redundant since capacity in a cloud world is theoretically infinite. So businesses can reassign their experts in this area to the management of finite budgets instead, giving them responsibility for forecasting demand and driving efficiency savings. Most companies are not geared up to adopt new technology at a rapid pace, but the agility of the cloud helps to improve the overall flexibility of the IT environment. In particular, it moves the IT team from being a traditional support function to taking a more proactive and strategic role within the company.
The most successful migrations to the cloud usually occur when a company embraces cloud as an enabler to its business goals as opposed to seeing it as a solution to its IT infrastructure problems. “Moving to the cloud can be a complex and challenging process,” says Mr Lowe.
“Before undertaking such a move, you need to understand the end-to-end business benefits and outcomes. What is the strategy you are looking to achieve and what agility  will it deliver back to you and your customers? Also, how will you undertake that migration? It is fundamental to understand the applications, processes and services that are being migrated. Simply moving to the cloud is not the end game. Understanding and realising the benefits of moving to the cloud requires on-going management and optimisation of the services.”
Making effective use of the cloud is a three-stage process, according to Accenture.
The first stage consists of defining at the outset exactly how the cloud will support the organisation, including which applications and processes will be moved onto it and which cloud infrastructure will best meet the business’s needs while minimising complexities and risks.
Next is the formal stage where applications are migrated onto the right cloud environment in a disciplined way. “Identifying applications that can be moved to the cloud requires organisations to have a fundamental understanding of the application itself, what it’s supporting and the business services that it’s delivering to clients and customers,” explains Mr Lowe.
The final stage is to embrace the agile approach to project management and the cultural change that it brings. The agile approach, which aims to achieve small goals quickly, is better suited to fast-moving technology projects than the step-by-step waterfall approach traditionally used on construction projects.
By enabling smaller companies to take on the multinationals, the cloud is shaking up the business world. “The cloud is both a catalyst and a connector,” says Mr Lowe. “It allows organisations to source, scale and deliver on demand better than ever before. This agility means they are better equipped to respond to market pressures, to out-innovate the competition and to keep ahead of the pack.”

about google app engine



Image result for google app engine


Google App Engine: Google App Engine is the Platform as a Service offering from the search giant. The development platform is free up to a certain level of used resources; fees are then charged for additional storage, bandwidth or CPU cycles. Targeted at Web developers and Web hosting applications, the only programming languages currently supported by App Engine are Python and Java.

About force.com


Image result for sales force.com



Force.com: Force.com is the Platform as a Service offering from Salesforce.com. With Apex Code, Salesforce.com's on-demand programming language, Force.com developers can create hosted applications and integrate client-side applications with Apex-based hosted components.

About Cloud Backup

Cloud backup: Cloud backup is the concept of sending copies of your datato an off-site server for backup storage. Enterprises have proven reluctant to adopt cloud backup for pertinent data, as security concerns and fears about storing critical information in the cloud persist. Several prominent cloud backup services are Amazon S3, Asigra and EMC's Mozy.

Cloud cartography: Cloud cartography is a strategy designed to pinpoint the physical locations of Web servers hosted on a third-party cloud computing service. The goal would be to map the service provider's infrastructure in order to identify where a particular virtual machine resides. This scheme was discovered during a study carried out on Amazon Web Services by researchers from MIT and the University of California, San Diego.

Cloud Security Alliance: The Cloud Security Alliance (CSA) is an organization created to promote security best practices for cloud computing providers. Headed by executive director Jim Reavis and technical director Chris Hoffab, the CSA claims such prominent members as AT&T, CA, Cisco, Google, Rackspace and Microsoft.

about Amazon web services

Image result for amazon aws
1.Amazon Elastic Compute Cloud (EC2): Amazon's EC2 is a cloud computing service that allows users to deploy and run their applications on rented virtual computers. Users can boot what are called Amazon Machine Images and create an instance, also known as a virtual machine, and pay for the amount of computing power they need by the hour. Amazon EC2 uses Xen virtualization, and the service allows users to adapt to changing performance and capacity needs with an auto-scaling function.

Amazon Simple Storage Service: Amazon's S3 is a cloud storage service that provides scalable, unlimited online archiving and backup for Amazon Web Services users. As of early March, Amazon S3 had stored more than 100 billion objects.
Application programming interface (API): An API is set of programming instructions that cloud computing providers release to developers in order to allow for the creation and deployment of applications on their cloud services. APIs are software-to-software interfaces that accelerate the application development process.

Saturday, 26 August 2017

AWS S3 Bucket Commands



Image result for aws s3
yum install s3cmd --enablerepo=epel -y

s3cmd --configure

Commands:
----------------
  Make bucket
      s3cmd mb s3://BUCKET

  Remove bucket
      s3cmd rb s3://BUCKET

  List objects or buckets
      s3cmd ls [s3://BUCKET[/PREFIX]]

  List all object in all buckets
      s3cmd la

  Put file into bucket
      s3cmd put FILE [FILE...] s3://BUCKET[/PREFIX]

  Get file from bucket
      s3cmd get s3://BUCKET/OBJECT LOCAL_FILE

  Delete file from bucket
      s3cmd del s3://BUCKET/OBJECT
  Delete file from bucket (alias for del)
      s3cmd rm s3://BUCKET/OBJECT

  Restore file from Glacier storage
      s3cmd restore s3://BUCKET/OBJECT

  Synchronize a directory tree to S3 (checks files freshness using size and
md5 checksum, unless overridden by options, see below)
      s3cmd sync LOCAL_DIR s3://BUCKET[/PREFIX] or s3://BUCKET[/PREFIX] LOCAL_DIR

  Disk usage by buckets
      s3cmd du [s3://BUCKET[/PREFIX]]

  Get various information about Buckets or Files
      s3cmd info s3://BUCKET[/OBJECT]

  Copy object
      s3cmd cp s3://BUCKET1/OBJECT1 s3://BUCKET2[/OBJECT2]

  Modify object metadata
      s3cmd modify s3://BUCKET1/OBJECT

  Move object
      s3cmd mv s3://BUCKET1/OBJECT1 s3://BUCKET2[/OBJECT2]

  Modify Access control list for Bucket or Files
      s3cmd setacl s3://BUCKET[/OBJECT]

  Modify Bucket Policy
      s3cmd setpolicy FILE s3://BUCKET

  Delete Bucket Policy
      s3cmd delpolicy s3://BUCKET

  Modify Bucket CORS
      s3cmd setcors FILE s3://BUCKET

  Delete Bucket CORS
      s3cmd delcors s3://BUCKET

  Modify Bucket Requester Pays policy
      s3cmd payer s3://BUCKET

  Show multipart uploads
      s3cmd multipart s3://BUCKET [Id]

  Abort a multipart upload
      s3cmd abortmp s3://BUCKET/OBJECT Id

  List parts of a multipart upload
      s3cmd listmp s3://BUCKET/OBJECT Id

  Enable/disable bucket access logging
      s3cmd accesslog s3://BUCKET

  Sign arbitrary string using the secret key
      s3cmd sign STRING-TO-SIGN

  Sign an S3 URL to provide limited public access with expiry
      s3cmd signurl s3://BUCKET/OBJECT <expiry_epoch|+expiry_offset>

  Fix invalid file names in a bucket
      s3cmd fixbucket s3://BUCKET[/PREFIX]

  Create Website from bucket
      s3cmd ws-create s3://BUCKET

  Delete Website
      s3cmd ws-delete s3://BUCKET

  Info about Website
      s3cmd ws-info s3://BUCKET

  Set or delete expiration rule for the bucket
      s3cmd expire s3://BUCKET

  Upload a lifecycle policy for the bucket
      s3cmd setlifecycle FILE s3://BUCKET

Friday, 25 August 2017

How to run OpenStack on AWS

Image result for aws open stack
OpenStack is a cloud operating system that controls vast computing resources through a data centre, while AWS (Amazon Web services) offers reliable, scalable and inexpensive cloud computing services. The installation of OpenStack on AWS is an instance of Cloud-on-a-Cloud.  
This article will guide you on installing OpenStack on top of AWS EC2. Installing OpenStack on a nested hypervisor environment is not a big deal when a QEMU emulator is used for launching virtual machines inside the virtual machine (VM). However, unlike the usual nested hypervisor set-up, installing OpenStack on AWS EC2 instances has a few restrictions on the networking side, for the OpenStack set-up to work properly. This article outlines the limitations and the solutions to run OpenStack on top of the AWS EC2 VM.
Limitations
The AWS environment will allow the packets to flow in their network only when the MAC address is known or registered in the AWS network environment. Also, the MAC address and the IP address are tightly mapped. So, the AWS environment will not allow packet flow if the MAC address registered for the given IP address is different.You may wonder whether the above restrictions will impact the OpenStack set-up on AWS EC2.Yes, they certainly will! While configuring Neutron networking, we create a virtual bridge (say, br-ex) for the provider network, where all the VM’s traffic will reach the Internet via the external bridge, followed by the actual physical NIC (say, eth1). In that case, we usually configure the external interface (NIC) with a special type of configuration, as given below.The provider interface uses a special configuration without an IP address assigned to it. Configure the second interface as the provider interface. Replace INTERFACE_NAME with the actual interface name, for example, eth1 or ens224.Next, edit the /etc/network/interfaces file to contain the following:
1
# The provider network interfaceauto INTERFACE_NAMEiface INTERFACE_NAME inet manualup ip link set dev $IFACE updown ip link set dev $IFACE down
Due to this special type of interface configuration, the restriction in AWS will hit OpenStack networking. In the mainstream OpenStack set-up, the above-mentioned provider interface is configured with a special NIC configuration that will have no IP for that interface, and will allow all packets via that specially configured NIC. Moreover, the VM packets reaching the Internet via this specially configured NIC will have the OpenStack tenant router’s gateway IP address as the source in each packet.
As I mentioned earlier, in the limitations above, AWS will only allow the packet flow when the MAC address is known/registered in its environment. Also, the IP address must match the MAC address.
In our case, the packet from the above-mentioned OpenStack tenant router will have the IP address of the router’s gateway in every single packet, and the packet source’s MAC address will be the MAC address of the router’s interface.
Note:  These details are available if you use ip netns show followed by ip netns exec qr-<router_ID> ifconfig commands in the OpenStack controller’s terminal. Since the MAC address is unknown or not registered in the AWS environment, the packets will be dropped when they reach the AWS switch. To allow the VM packets to reach the Internet via the AWS switch, we need to use some tricks/hacks in our OpenStack set-up.
Making use of what we have
One possible way is to register the router’s MAC address and its IP address with the AWS environment. However, this is not feasible. As of now, AWS does not have the feature of registering any random MAC address and IP address inside the VPC. Moreover, allowing this type of functionality will be a severe security threat to the environment.The other method is to make use of what we have. Since we have used a special type of interface configuration for the provider NIC, you will note that the IP address assigned to the provider NIC (say, eth1) is left unused. We could use this available/unused IP address for the OpenStack router’s gateway. The command given below will do the trick:
1
neutron router-gateway-set router provider --fixed-ip ip_address=<Registered_IP_address*>
IP address and MAC address mismatches
After configuring the router gateway with the AWS registered IP address, each packet from the router’s gateway will have the AWS registered IP address as the source IP address, but with the unregistered MAC address generated by the OVS. As I mentioned  earlier, while discussing the limitations of AWS, the IP address must match the MAC address registered; else, all the packets with the mismatched MAC and IP address will be dropped by the AWS switch. To make the registered MAC address match with the IP address, we need to change the MAC address of the router’s interface.
The following steps will do the magic.
Step 1) Install the macchanger tool.
Step 2) Note down the actual/original MAC address of the provider NIC (eth1).
Step 3) Change the MAC address of the provider NIC (eth1).
Step 4) Change the MAC address of the router’s gateway interface to the original MAC address of eth1.
Step 5) Now, try to ping 8.8.8.8 from the router namespace.
If you get a successful ping response, then we are done with the Cloud-on-the-Cloud set-up.
Key points to remember
Here are some important things that one needs to keep track of.
Changing the MAC address: In my case, I had used the Ubuntu 14.04 LTS server, with which there was no issue in changing the MAC address using the macchanger tool. However, when I tried the Ubuntu 16.04 LTS, I got an error saying, “No permission to modify the MAC address.” I suspect the error was due to the cloud-init tool not allowing the MAC address’ configuration. So, before setting up OpenStack, try changing the MAC address of the NIC.
Floating IP disabled: Associating a floating IP to any of OpenStack’s VMs will send the packet via the router’s gateway with the source IP address as the floating IP’s IP address. This will make the packets hit the AWS switch with a non-registered IP and MAC address, which results in the packets being dropped. So, I could not use the floating IP functionality in this set-up. However, I could access the VM publicly using the following NAT process.
Using NAT to access OpenStack’s VM: As mentioned earlier, I could access the OpenStack VM publicly using the registered IP address that was assigned to the router’s gateway. Use the following NAT command to access the OpenStack VM using the AWS EC2 instance’s elastic IP:
1
$ ip netns exec qrouter-f85bxxxx-61b2-xxxx-xxxx-xxxxba0xxxx iptables -t nat -A PREROUTING -p tcp -d 172.16.20.101 --dport 522 -j DNAT --to-destination 192.168.20.5:22
Note: In the above command, I had NAT forwarding for all packets for 172.16.20.101 with Port 522. Using the above NAT command, all the packets reaching 172.16.20.101 with Port number 522 are forwarded to 192.168.20.5:22.
Here, 172.16.20.101 is the registered IP address of the AWS EC2 instance which was assigned to the router’s gateway. 192.168.20.5 is the local IP of the OpenStack VM. Notably, 172.16.20.101 already has NAT with the AWS elastic IP, which means all the traffic that comes to the elastic IP (public IP) will be forwarded to this VPC local IP (172.16.20.101).
1
In short, [Elastic IP]:522 π 172.16.20.101:522  π 192.168.20.5:22
This means that you can SSH the OpenStack VM globally by using the elastic IP address and the respective port number.
Elastic IP address: For this type of customised OpenStack installation, we require at least two NICs for an AWS EC2 instance. One is for accessing the VM terminal for installing and accessing the dashboard. In short, it acts as a management network, a VM tunnel network or an API network. The last one is for an external network with a unique type of interface configuration and is mapped with the provider network bridge (say br-ex with eth1).AWS will not allow any packets to travel out of the VPC unless the elastic IP is attached to that IP address. To overcome this problem, we must attach the elastic IP for this NIC. This is so that the packets of the OpenStack’s VM reach the OpenStack router’s gateway and from the gateway, the packets get embedded with the registered MAC address. Then, the matching IP address will reach the AWS switch (VPC environment) via br-ex and eth1 (a special type of interface configuration), and then hit the AWS actual VPC gateway. From there, the packets will reach the Internet.
Other cloud platforms
In my analysis, I noticed that most of the cloud providers like Dreamhost and Auro-cloud have the same limitations for OpenStack networking.  So we could use the tricks/hacks mentioned above in any of those cloud providers to run an OpenStack cloud on top of them.
Note: Since we are using the QEMU emulator without KVM for the nested hypervisor environment, the VM’s performance will be slow.
If you want to try OpenStack on AWS, you can register for CloudEnabler’s Cloud Lab-as-a-Service offering provides a consistent and on-demand lab environment for OpenStack in AWS.