Overview
Join Bart Castle as he takes a look at the world of cloud computing.
Recommended Experience
- At least six months work experience in an IT environment with some exposure to cloud technologies
Related Certification
- CompTIA Cloud Essentials+
Related Job Functions
- Sales and Marketing professionals
- Business analysts
- Technical support staff
- Business process owners
Bart Castle has been a CBT Nuggets trainer since 2018, and has more than a decade of cloud computing experience. He has received all the core Amazon Web Services certifications, and he’s one of the few instructors worldwide to earn AWS Authorized Instructor Champion status.
Explaining Cloud Principles
Bart kicks off this look at the accepted definition-of, service models, and deployment models of cloud computing.
Knowledge Check
Cloud computing is a technology. True or false?
Cloud Characteristics
Bart takes a look at the five NIST-defined characteristics of a cloud computing service.
Knowledge Check
Which of the following are the correct cloud characteristics as defined by NIST? (Choose five)
Shared Responsibility
Bart checks out the NIST Cloud Reference Architecture and discusses the roles and shared-responsibilities of the cloud computing ecosystem.
Knowledge Check
Match the following cloud ecosystem roles and actors with the best description.
This interactive assessment is available in the full learning experience.
Infrastructure-as-a-Service
Bart takes a looked at the shared responsibilities of cloud providers and consumers in the Infrastructure-as-a-Service service model.
Knowledge Check
Which of the following are the correct IaaS provider responsibilities? (Choose three)
Platform-as-a-Service
Bart discusses the shared responsibilities of the Platform-as-a-Service cloud service model.
Knowledge Check
Which of the following are the primary characteristics of the cloud Platform-as-a-Service model? (Choose three)
Software-as-a-Service
Bart takes a look at the Software-as-a-Service model and it's shared responsibilities.
Knowledge Check
Which of the following are the best examples of the cloud Software-as-a-Service model? (Choose three)
Deployment Models
Bart discusses the NIST cloud deployment models: Public, Private, Hybrid, and Community cloud.
Knowledge Check
The NIST cloud deployment models are based on where the services are running, not the level of exclusivity. True or false?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Explaining Cloud Principles
0:03Hey, friend.
0:03Bart Castle here.
0:04Welcome to explaining cloud principles.
0:06Now, if you've been in the information technology world
0:08for any amount of time or if you've
0:10been a consumer in our modern world,
0:12you've probably heard people talk about using the cloud
0:15or going to the cloud, or putting things in the cloud.
0:18And indeed, for a lot of us that means that internet directly
0:21equals cloud.
0:22And that's a pretty good starting point.
0:24But it does leave a lot of the other specifics out
0:26of that explanation.
0:27And so, in the videos ahead, we're
0:28going to be making sure that we lock down
0:30what a cloud computing service is by looking
0:32at the key characteristics.
0:33We'll also be checking out the service models that you'll
0:36be running into and the deployment models that
0:38deal with how organizations actually
0:40put cloud services into action.
0:42On top of that, we'll also be talking
0:43about the important shared responsibility
0:45model between a consumer, like, yourself or your organization,
0:49and a provider, like, Google or Amazon or Microsoft or Apple
0:52or one of the many other types of cloud service providers
0:55that are out there.
0:56And so, as we begin this journey,
0:57I do want to start right off by saying,
0:59hey, keep in mind, friends, cloud computing
1:01is not a technology in itself.
1:04And I can't stress this enough.
1:05Just in the same way that a restaurant is not a food,
1:08a cloud service is not the technology itself.
1:11Instead, you want to think of it as a service model for making
1:15technology available.
1:17Just like a restaurant augments the food procurement process
1:20by cooking it and delivering it and serving it to you,
1:23a cloud service provider delivers technology services
1:26for us as consumers to use and leverage.
1:29This is exactly where things get really exciting
1:31for the world's businesses and for the world's consumers.
1:33Using technology through a cloud service
1:36might allow us to help solve problems, improve the business
1:39experience, improve the user's experience,
1:41or even improve the other stakeholders who
1:43might have a vested interest in those efforts.
1:45And so stick with me, friends, as we
1:47dig into explaining cloud principles.
Cloud Characteristics
0:02Hey, friend.
0:02Welcome back to Explaining Cloud Principles.
0:04Probably the best place for us to start
0:06is to establish what the traits and characteristics that
0:09make a technology service really fit the cloud computing
0:11definition.
0:12Because keep in mind, friends, there
0:13are a lot of different layers of technology services
0:15that are out there.
0:16And some of them fit parts of the cloud computing definition,
0:19and a lot of them don't necessarily
0:21live on the internet either.
0:22So you can see there's a lot of variability
0:24in some of our understandings around cloud computing.
0:26Best that we iron those out right away.
0:28Fortunately for us, there is a US-based organization
0:30called the National Institute of Standards and Technology,
0:33NIST, who has published an internationally
0:36accepted definition of what cloud computing is.
0:39And it forms the backbone of a lot
0:41of our broad understanding of what we consider a cloud
0:43computing service.
0:44So let's start out by grabbing a copy of that.
0:47Over here on Google, take a look for NIST cloud definition.
0:52And then make sure you grab the one that says "detail final".
0:54That'll get you over to the actual published document.
0:57It's the 800-145.
0:59And if you pull that up on screen here, and then let's
1:02make that fit nicely, cruise on down a little bit further,
1:06and they jump in, first, by establishing
1:08what those characteristics are.
1:09And indeed, there they are--
1:11the essential characteristics.
1:12So let's find just a few minutes taking
1:14a look through each one of these and how
1:16that helps shape our understanding of what
1:18cloud computing is.
1:19So the first one on here is on-demand self-service.
1:22And this is where they're talking about consumers being
1:25able to provision capabilities on their own
1:29without having to necessarily interact directly
1:32with the service provider.
1:33This might be done through a store, like, the Google Store,
1:37the Play Store, the Apple Store, where you're buying an app.
1:39Or it could be something where you're logging into a web page
1:42to purchase and sign up for those services.
1:44The key principle is that it does not
1:46require a direct engagement with a human
1:48or, really, a provider directly on the far side of it.
1:51It's something that you could do in your jammies,
1:53sitting at home with a credit card
1:55and bring those services up, keeping in mind that the cost
1:58aspect is not necessarily a requirement here.
2:00It's more about the mechanism of administration.
2:02And this is directly in contrast to traditional models
2:05where Bart and his team of people at the organization
2:08would have to choose what services we need, talk
2:10to some sort of a vendor directly, draw up
2:13a contract and an agreement.
2:15It could spend days, weeks, to months
2:17provisioning those services.
2:18As a contrast, now we're talking about a really simple, often
2:21point and click process, where we're
2:23able to procure those services.
2:25Also, keeping in mind that even though it's self-service,
2:27there may still be contracts that are a part of it.
2:30They're just also self-service, where
2:31you have to accept the terms of agreement
2:33or read through some contract as a part of it.
2:36That is all part of the self-service model.
2:38And again, the goal here is to ensure that consumers don't
2:41have to be tied down from a timeline perspective, waiting
2:44to engage with the service provider directly.
2:46And keep in mind here, friends, when I say service provider,
2:49I could be talking about a big public provider, like,
2:51Apple or Google or Amazon or Microsoft.
2:53But it could also be the provider
2:55that you work with in your own organization.
2:57If your company has a self-service portal
3:00for building virtual machines in your company, totally private,
3:03regular public users can't use it,
3:05that still fits the self-service model.
3:07Continuing on after that, we look at broad network access
3:10as the second characteristic.
3:12And this is really important, friends.
3:13We're not saying internet.
3:15Notice it does not say internet accessible.
3:17It says network accessible-- so over the network
3:20in access through a standard mechanism.
3:23So the client isn't really important.
3:25It could be through a smartphone,
3:27it could be through a full-blown desktop computer,
3:29it could be through a laptop, or even some weird kiosk thing
3:32that's in between.
3:33The point is to keep in mind that you're taking access
3:36over some sort of network media.
3:38This could happen in your own company's internal networks,
3:41where just you and your employees and your peers
3:43are able to interact with it, or it could certainly
3:45happen over the internet, one of the world's largest networks.
3:48And of course, keeping the mind, too, here,
3:50that lots of organizations also possess
3:52global spanning networks of their own.
3:55So we don't want to get locked down
3:56into one specific type of network,
3:58just recognizing that the cloud computing services themselves
4:00are accessed over the internet or over a private network
4:04or some combination of the two in between.
4:07One final thing to consider here when
4:08we talk about network access is also
4:11recognizing that it doesn't mean that it's always only online.
4:14You could download a piece of software from a service
4:17and then run it locally on your computer
4:19or if you're just doing a licensing
4:21scenario over the network.
4:23Those all fit this model.
4:24So just keep in mind that it starts and is largely
4:28dependent at some point of its life cycle
4:30on that network access.
4:32Moving on down past that, we get into resource pooling.
4:35And resource pooling is an interesting concept.
4:37This one goes directly back to the principles
4:40of virtualization.
4:41And I know we haven't really talked about virtualization
4:43much here.
4:44But the basic idea here is that resources
4:46are being pooled together, and they often
4:48serve multiple consumers at the same time.
4:51They also introduce the term "multi-tenant".
4:54And indeed, this is a safe concept.
4:56If you imagine an apartment complex, where
4:59there is one building with lots of small different apartments
5:03inside of it and then lots of different folks living
5:05in those apartments, that's the basic principle
5:08they're talking about with resource pooling.
5:10Part of the value proposition with pooling
5:12is that when a provider buys tools or hardware
5:15or infrastructure to run those systems,
5:17they're able to buy at large scale
5:20and then sell portions of it out to their customers.
5:22This is part of the profitability model for them.
5:24If they had to buy everything as one-offs
5:26for every single customer, it would deteriorate that value
5:29proposition pretty quickly.
5:30So resource pooling says that it is a shared set of resources.
5:34And again, it is not limited to just public service providers
5:37where they're selling their services to private consumers
5:40like you and I.
5:41It could be, again, in an organization
5:43that has a large virtualized data center where they're
5:46making different pieces of that infrastructure
5:48available to their users or their departments
5:50within the organization-- again, across the network,
5:54ideally, going to be driven and administered
5:56using some sort of a self-service model.
5:58And keeping in mind, friends, that we're
6:00trying to say that this is an inclusive model.
6:02It needs to have these five characteristics.
6:04But they may also have more options beyond that
6:06and still fit that cloud computing model.
6:09Continuing on down, after that, we get into rapid elasticity.
6:12And this one is really special and unique.
6:15And it goes directly back to the resource pool in question
6:18earlier on.
6:19The idea behind elasticity is to simply say
6:21that when we're trying to figure out
6:23what we need to deliver a system or a service,
6:26just imagine the last time you wanted to go shopping for a car
6:29or went shopping for a home.
6:30You had to take a look at your own specific needs
6:33and what those services and our availability
6:36out there, how they actually solve that problem for you.
6:39The problem is sometimes your family
6:41gets bigger or your auto requirements change over time.
6:44And this can leave us in a situation
6:46where what we chose at one time is no longer the best choice.
6:50For systems in the technology world, a lot of this
6:53has to do straight up with capacity planning.
6:55Do I need five servers?
6:57Do I need 10, 20, 30, 100 servers?
7:00And consider, too, that for a lot of organizations,
7:03their work, the actual load that they put on their systems,
7:06it might be driven by different time of year performance
7:09statistics.
7:10So imagine shopping at a holiday season or tax season
7:14or end of business quarter.
7:15Those are events that happened that require
7:17a lot more capacity.
7:19But they don't last all year long.
7:21And so rapid elasticity focuses on the interest
7:24in that we be able to grow the service
7:27and then shrink the service back down when
7:29we need to based on whatever demand is happening out there.
7:32So two important principles here--
7:34how much demand drives how much capacity?
7:37If your demand is variable, your capacity
7:39needs to be variable as well.
7:41And of course, if you're working with a public service provider,
7:43they own huge amounts of infrastructure, and lots of us
7:46are all using it together so the ability to grow and shrink
7:49each customer, it's an easy no-brainer for them.
7:52But if you are in an organization that
7:54owns all of the infrastructure, well,
7:56that means your IT and your service teams,
7:58they have to be concerned about owning enough capacity
8:00to meet whatever demand the organization is putting on it.
8:03And this is usually where the value proposition
8:05gets a little murky for in-house, on-premises data
8:08centers and the provisioning and management
8:10of those services over time.
8:11So five services so far, we're down to the fifth one.
8:15So far, we talked about broad network access,
8:17we talked about self-serviceability,
8:20we talked about pooling of resources, and then
8:22rapid elasticity.
8:24So the very last one on here, measured service,
8:27is really one of the most important value proposition
8:29pieces of it.
8:30It says that we should be able to optimize resources and use
8:35some sort of a metering capability
8:37to understand how that service is being used
8:39and furthermore, pay as a consumer for only
8:42what we've used.
8:43So this is very similar to the way that a lot of us
8:45get power from a power service provider.
8:48We're not paying a subscription flat fee every month.
8:51Instead, we're paying based on how much we actually use.
8:54So in the wintertime, my house needs a lot more heating
8:57energy.
8:57And I spend a lot more of my electricity to produce that.
9:00In the summertime, it could be air conditioning
9:02that's kicking on.
9:03And in the in-between months, we don't
9:05pay as much because our demand is not as high.
9:07Now, there's two key principles to keep in mind when
9:10we talk about measured service.
9:11First of all, as a consumer, you're
9:13paying for only what you've used.
9:15And this is usually a good model as long
9:17as you maintain it and keep that right visibility.
9:19The other side of it is that if you're
9:21going to be a service provider, you
9:23have to have sophisticated mechanisms to identify
9:26what has been used.
9:28And of course, if you're not Microsoft Azure or Amazon Web
9:31Services out there with a huge sophisticated toolkit,
9:34it means that your internal IT department
9:36have to come up with a way of identifying what
9:38each department has used on those shared resources,
9:42especially if it's flexible and dynamic and self-service.
9:45How are they going to keep tabs on it?
9:47So this implies additional sophistication in the services
9:50around delivering and managing whatever has
9:53been built in the back room.
9:54And so just looking back across the five key characteristics,
9:57self-serviceability focuses on the ease of access.
10:00It ensures that there's a simple on-road
10:02and map for selecting services, using them, and managing them.
10:07This could be through a web page or through a simple sort
10:09of app.
10:10The other part was broad network access.
10:12We said that it could be internet-based
10:13or it could be some internal private network
10:16or some hybrid version of that in between.
10:18The point is that we're going across the network
10:20to access or work with the services
10:22or to instantiate them.
10:24You might download something and use it.
10:26As long as it starts its life on the network
10:28or has some dependence on the network,
10:29that satisfies this characteristic.
10:31The third one, resource pooling, was important
10:34because of the sharing and the scalability that comes with it.
10:37If a vendor can buy a large amount of infrastructure
10:40and then share it amongst all of its tenants,
10:42this is going to improve the value
10:43proposition for the vendor and also for the consumer.
10:47Economy of scale is a big factor in the cloud computing world.
10:50The third one-- or the fourth one-- down there,
10:52rapid elasticity, deals with that principle
10:54of being able to grow and shrink the services based
10:57on the demand.
10:58Now, this is a really important characteristic
11:00when we consider how unpredictable a lot
11:02of workloads are out there.
11:03And then the very last one, measured service,
11:05goes along with all of these pieces.
11:07Because if you're a service provider
11:08and you're going to let people build things on their own
11:10and then run them for certain amounts of time,
11:12you're going to need the right sort of monitoring
11:14and metric information to identify
11:16what someone has used, how long they've used it,
11:19so that you can charge them for it.
11:21And from a consumer's perspective,
11:22it means that we're only having to pay for what
11:24we've specifically used.
11:26So as you begin looking at services in the technology
11:29role, ask yourself if it fits these five key characteristics.
11:33Without one of these characteristics,
11:35odds are it's not really specifically designed
11:37as a cloud computing service.
11:38And it's certainly a technical service,
11:40but it doesn't fit the cloud computing paradigm.
11:42And so now that we have an understanding
11:44of these characteristics, it prepares us
11:46for a look at some of the service models
11:48that we're going to find in the cloud computing world,
11:50like, infrastructure, platform, and software as a service,
11:53keeping in mind that in the end, it's
11:54all about the relationship between the consumer
11:56and the provider-- what we're having the provider do for us
11:59and what sort of controls are left for me as a consumer.
12:02So stick with me, friends.
12:03And I'll see you there.
Shared Responsibility
0:02Hey, friend.
0:02Welcome back to Explaining Cloud Principles.
0:04Now that we have a good understanding
0:06of the characteristics and traits that
0:07make a service actually fit the cloud computing definition,
0:10we can begin talking about some of the responsibilities that
0:13get exchanged as we look at the provider-consumer relationship.
0:17Keeping in mind that in this scenario right now,
0:19I am the provider--
0:20I have created this training content for you--
0:22and you are consuming it.
0:24You're the consumer in this relationship.
0:26Similarly, if I go and I use Gmail, Google is the provider
0:30and I am the consumer.
0:31Alternatively, if you're in your own organization
0:34and your IT department makes platforms
0:37available for your developers to use,
0:38they become the provider and the developers become the consumer.
0:42So as we look at this consumer and provider relationship,
0:46we recognize that understanding where those responsibilities
0:49lie between those two parties is the first part of the story.
0:52But also keep in mind that there are responsibilities
0:54outside of just the consumers and the providers that we
0:57should be aware of, as well.
0:59And so, fortunately for us, NIST defined a Cloud Reference
1:02Architecture, which is very useful in keeping
1:04this conversation moving.
1:05So let's actually go take a look at that real quick.
1:07Over here on the web, if you take a look for NIST cloud
1:10reference, you should be able to find
1:13the "Reference Architecture" itself.
1:15It is another document that they produced a few years back.
1:18And if you pop that open in your browsers or in your reader
1:22there, cruise on down into the table of contents
1:25and find the first section here about cloud computing reference
1:28architecture.
1:29Cool.
1:29And so, indeed, this is the diagram
1:31that I wanted us to take a look at.
1:32What they're describing here are the roles
1:35that exist within the cloud computing role.
1:37And you heard me talk about one already,
1:38and that was the cloud provider.
1:40They are the one that's creating and delivering the service.
1:42And take a look at all the different facets
1:44that they're responsible for.
1:45Indeed, there's a reason why they are the biggest
1:48chunk on this picture.
1:49They take on a lot of that burden.
1:51And for us as consumers, all of those things
1:53the provider is focusing on, they
1:55are things that we don't necessarily have to focus on.
1:57You can also see them calling out the three different service
2:00layers--
2:00Infrastructure, IaaS; Platform, PaaS; and Software
2:05As A Service, SaaS.
2:07So the provider is responsible for all the service management
2:10and delivery aspects of running whatever cloud service it is.
2:13And we're being generic here, friends.
2:15It could be a large infrastructure service,
2:17like Amazon Web Services, or it could
2:19be a software as a service product,
2:20like something you might buy in the Google Play Store.
2:23The point is, though, that that provider responsibility
2:25starts and ends with the delivery of those services.
2:28The other role you heard me describing was cloud consumer.
2:31Consumers are there as the person
2:33that creates the demand for whatever service out there has
2:36been created by the providers.
2:38The other two roles that are on here,
2:39the broker and the auditor, are important to keep
2:42in mind conceptually.
2:44A broker is someone who facilitates access
2:46to the service.
2:47You see them talking about intermediation, aggregation,
2:50and arbitrage.
2:51Let me see if I can scroll down a little bit there.
2:53The point is that they could either help you use a service,
2:56like a value-add reseller might do.
2:58Someone like a car salesman might
3:01help you buy the right car.
3:02They didn't build the car themselves.
3:04They're just an intermediary layer
3:05that helps you procure something appropriately from a provider.
3:09So brokering is something that your organization might
3:11do directly as a service to other cloud consumers,
3:14or you might have divisions within your IT department
3:17that play that brokering role.
3:19It's just important to recognize that for a lot of us,
3:21we may work through a broker to obtain cloud services,
3:24or we may seek the help of a broker
3:27to help augment the delivery of our cloud services.
3:29So an important principle to add to this little melange.
3:32The other role they have over here is cloud auditor.
3:35And it's great-- it's by design, friends.
3:37The auditor is not the provider, not the consumer or the broker.
3:41Instead, it is a separate entity,
3:43which is all about maintaining and measuring the quality of,
3:46the compliance, the security-- indeed,
3:49whatever it is-- the congruence to some sort of standard.
3:52So the auditor lives outside of this process and says,
3:55how is this interaction happening?
3:57To what degree is it being executed?
3:59And to what level does it meet a specific expected standard?
4:03So the auditors are on here to help play this quality
4:05assurance and quality control role,
4:07and they are specifically designed to not
4:09be the provider or consumer.
4:10This is that intermediation-- that disintermediation,
4:14I should say--
4:15separating them from the directly-invested parties.
4:17It also ensures that they can be on the side of the standard,
4:21and not one of the actually consuming or delivering
4:23parties.
4:24And that brings us down to the very last role
4:26on there, the cloud carrier.
4:27And this is possibly the most important.
4:29I like the way that they've depicted it here.
4:32Notice that it goes across all of the other roles.
4:35The point behind this is to recognize
4:37that, if you're the consumer, you
4:38are dependent on some sort of a network
4:40to use the cloud service.
4:42Similarly, if you're a provider, you
4:44are dependent on a carrier of a network of some sort
4:48to facilitate access to your consumers.
4:50And of course, the brokers and the auditors
4:52that use these services, to augment their delivery
4:55or measure their quality and their compliance standards--
4:58they all depend on that carrier and that network, as well.
5:01And so this helps us really understand
5:03that there is a tightly integrated role between all
5:05of these different players.
5:07The provider depends on the carrier
5:08to work with the consumer.
5:10The consumer needs the broker and the auditor
5:12to measure the quality of the service used by the provider.
5:15And the best that we can handle all those expectations,
5:18the better we can ensure the delivery of the value
5:20proposition itself.
5:22And so to get a little more specific here,
5:24we understand that there's these different actors and roles.
5:27The last piece is to recognize that there
5:28are different layers of that responsibility that's
5:31being exchanged across different service models.
5:33And so let's jump over to a slightly different look here.
5:37So this gives us a chance to take a look at the shared
5:39responsibility stack.
5:41Indeed, we're talking about different layers
5:43in which this consumer and provider
5:45breakdown might be happening.
5:47Recognizing that in traditional IT,
5:50when you owned all of the infrastructure
5:52and delivered it yourself, you owned every single piece
5:54of this and you had control over, and full responsibility
5:58for, the delivery of every one of those components,
6:00from the physical network up through the storage
6:03and the virtualization layers, including the operating system
6:06and all of the application components, the data
6:09and the authentication layers that allow people
6:11to actually use those services.
6:13So this is an important principle
6:14to keep in mind, because as we take a closer look at some
6:17of the other service models, like software, platform,
6:20and infrastructure as a service, we're
6:22going to see a different breakdown
6:23across these responsibility stacks.
6:25So it's a great primer to get us into the right layers
6:28of conversation to talk about, really,
6:30where specifically things fall in each one of those service
6:33models.
6:33And so just to kind of recap what
6:35we've discussed so far, as you begin
6:37looking at the world of cloud computing,
6:39we recognize that there is an ecosystem of roles and actors.
6:42And NIST defined a "Reference Architecture,"
6:44which helps us understand and describe
6:46the different roles that are out there.
6:48The two most basic ones are the provider and the consumer--
6:51whoever creates the service and then
6:53whoever's purchasing and using the service,
6:55just like me as the provider and you as the consumer
6:57in this video scenario.
6:59On top of that, we said that there's other auxiliary roles,
7:01like a broker or an auditor, who either
7:03helps in the delivery of, the selection, or the maintaining
7:06of those services, or the measuring of quality
7:09and security attestations or compliance standards
7:11through the auditor.
7:13We also discussed the importance of a carrier
7:15and how all of those other roles are
7:16dependent on what the carrier does and their availability
7:19and proficiency at delivering access
7:21to the provider and consumer world of cloud computing.
7:25In the end, we also took a look at the basic shared
7:27responsibility stack, where we went through
7:29all the different infrastructure layers, from the hardware,
7:32up into the software and virtualization layers, and then
7:35into the data, and the people and authentication layers,
7:37as well.
7:37These are going to be important models
7:39to look at in the next couple of videos,
7:41as we take a look at the breakdown between software
7:43platform and infrastructure as a service models,
7:45and how it affects each one of those shared responsibility
7:48layers.
7:48So stick with me, friends, and I'll see you there.
Infrastructure-as-a-Service
0:02Hey, friend.
0:02Welcome back to explaining cloud principles.
0:04So far, we've established the characteristics and traits
0:07that make a service fit the cloud computing definition.
0:10And we've also talked about some of the actors and roles that
0:12exist in the cloud ecosystem, like the provider, consumer,
0:15auditor, broker, and the carrier.
0:18This led us into a conversation around shared responsibility.
0:20And that's exactly where we're going to pick things up,
0:23by looking at the three different service models--
0:25infrastructure, platform, and software as a service--
0:28and how that responsibility shakes down
0:30across each one of those.
0:31In this first video, let's focus on maximizing
0:33control for the consumer by using infrastructure
0:36as a service.
0:37And so jumping right on in, we recognize
0:39that with infrastructure as a service, when
0:41we say that we're gaining more control,
0:43it's because the provider is leaving
0:45more aspects of this administration to us
0:47as consumers.
0:48So in infrastructure as a service,
0:50they're mostly focusing on delivering it up
0:52to the virtualization layer.
0:54So this means they're running the data centers.
0:56This means that they're out there dealing
0:57with the physical infrastructure--
0:58the power, the actual systems, and the racks that are out
1:02there, all the fans [WHIRRING] blowing in the data centers
1:05out there.
1:05Those are all directly the provider's responsibility
1:08in most of these scenarios.
1:10Keeping in mind again, friends, that when I say provider,
1:12it could be big public providers or it
1:14could be somebody in your organization, a technology
1:17team that delivers these services for you.
1:19On the flip side, then, consumers
1:21are left with the ability to administer all
1:23of these other layers on top.
1:26And this is where that maximizing of control comes in.
1:29So this implies that, while the provider is creating
1:31the virtual infrastructure for us--
1:33this would include things like the hypervisor, as well--
1:36it means that us, as consumers, can then
1:39configure the virtual infrastructure that
1:41lives on top of it.
1:43This is going to mean creating virtual machines,
1:46creating the virtual network, controlling the IP
1:49addressing, the routing of traffic,
1:51creating gateways and ingress and egress points.
1:54And it also means that we're going
1:56to be able to control how we protect those infrastructure
1:59components, as well.
2:00So I might be creating a firewall rule
2:02and then telling the provider to implement that rule for me.
2:06In the end, this is a great example
2:07of how that shared responsibility works.
2:09As a consumer, I choose what traffic I want to allow,
2:12but the provider is ultimately responsible for following
2:15my instructions.
2:16This goes back to that self-service principle
2:18that we were talking about previously, as well.
2:21In order for this to work at scale for millions of customers
2:24all over the world, providers need a self-service way
2:26of allowing this relationship to exist.
2:29Furthermore, it also means that for a lot of organizations that
2:32have concerns around maximizing control,
2:35it means that they definitely still have control
2:37over some of the biggest important parts,
2:38like the application, the data, and the authentication
2:41and authorization layers, as well.
2:43Indeed, for a lot of them, they may
2:45pick up the existing tools they have in their data centers
2:47and just plot them directly down using a lift-and-ship model.
2:52And this allows them to basically keep
2:53a lot of the same systems, while simply swapping out
2:56some of the provider-added value that goes with using
2:59an infrastructure as a service.
3:01So to illustrate this just a little smidgen,
3:03let's take a look over here at Amazon Web Services, where I've
3:06got this pulled up already.
3:08And I am taking a look at AWS's virtual private cloud
3:11interface.
3:12This is basically their virtual networking service.
3:15You would use this service to build the networks
3:17that you want to use.
3:18And that would include defining your virtual private cloud,
3:21like these are the high level container.
3:24The subnets-- and those are going
3:25to be like the small IP subnets where you could actually
3:28run virtual machines.
3:29And then it also supports things like creating
3:31the routing tables and the routes
3:33to control where traffic move between your different
3:35endpoints.
3:36On top of that, you see internet gateways
3:39for selectively allowing networks
3:40to access the internet.
3:42Or if you look further on down here,
3:43they have things like NAT services.
3:46They also offer, even further on down, virtual private network
3:50services.
3:50So all of these are configurable virtual layers
3:53on top of the infrastructure that AWS is offering.
3:56You're going to find comparable flavors of this
3:58in Microsoft Azure and in Google Cloud, as well.
4:01And so in the end, friends, when we talk about infrastructure
4:04as a service, it's all about maximizing the layers
4:06of control that the consumer is able to effectively administer.
4:10Now, this means that the shared responsibility model
4:13has consumers depending on service providers
4:16to manage the underlying infrastructure,
4:18while we get to configure to a high degree on top of it.
4:22This is going to include things like the virtual machines,
4:24configuring the virtual networks,
4:26configuring the routing, managing the firewalling
4:29of traffic, and of course, managing all of the operating
4:31system, application, and data layers that live on top of it.
4:35One of the most important principles to ask yourself,
4:37if you're going to begin studying for something
4:39like the Cloud Essentials cert, is
4:41to imagine what maintenance activities this is
4:43going to require of you.
4:45It means that, as a consumer, I'm
4:47not going to be patching and managing the hypervisors.
4:49I'm not going to be dealing with firmware on the servers.
4:52I'm not going to be handling power
4:53redundancy for the generators.
4:55Those are not concerns for me.
4:57As a consumer of infrastructure as a service,
5:00I will care about writing firewall rules.
5:02I will care about patching the operating systems,
5:05choosing what virtual machines I want to run,
5:07turning them on, turning them off, managing
5:09their survivability, and of course,
5:11all of the other application data and authentication
5:14layers that live on top of it.
5:15One of the last things to keep in mind
5:17here is that when we talk about shared responsibility,
5:19there's often multiple different layers of administration.
5:22I will need permission, as a consumer,
5:25to build resources in a cloud service provider's environment.
5:28This is different than needing permissions
5:30to log into a Windows domain that
5:32might be running in your cloud service provider's world.
5:35So keep those two worlds separate-- the service
5:38provider-level permissions for creating cloud resources
5:41and then all of the application-level permissions
5:44that also go into using those services.
5:46In later service models, coming up next,
5:49we'll be talking about how that layer begins
5:51to get pushed more and more off to the provider,
5:54leaving less controls for us as consumers,
5:56but remembering that this is often desirably so.
5:58So stick with me, friends.
5:59In the next lesson, we'll take a look at platform as a service.
6:02I hope this has been informative for you,
6:04and I'd like to thank you for viewing.
Platform-as-a-Service
0:02Hi, friend.
0:02Welcome back to explaining cloud principles.
0:04In the last lesson, we talked about the infrastructure
0:06as a service model of cloud computing
0:08and how it focuses on maximizing control for the consumer.
0:12Indeed, keeping in mind that the provider is focusing
0:14on delivering the virtual infrastructure,
0:16and then it's up to us as consumers
0:18to decide what sort of virtual machines, and networks,
0:20and systems, and services we want
0:22to run in those environments.
0:23Moving into platform as a service, possibly the most
0:26important and complex layer of all the service models,
0:29we are pushing burden off onto the cloud service provider.
0:32And we're saying, largely, we don't care about the underlying
0:36infrastructure as much.
0:37We care more about the functionality
0:39of the applications, and the data, and the security,
0:41and management of those layers, instead.
0:43And so as we get into platform as a service,
0:45I usually try to get people thinking
0:47about three key aspects of platform as a service.
0:50And the first one there would be build from pieces.
0:54So in almost every example of a platform,
0:58they are going to be giving you some sort
1:00of rudimentary components that you
1:02can use to build larger functionality from.
1:05Now, this might be a really simple way of just assembling
1:08components on a page, like drag and drop wizards or workflows.
1:11Or it could be something extremely granular,
1:14like using a system developer's kit, where
1:16there is code to allow you to shortcut some
1:18of the administration process.
1:20The point is, just like a box of LEGOs,
1:22they're giving us pieces that we can build from.
1:25The other key distinction I try to get people to think about
1:27are using APIs.
1:29Now, we're going to use APIs all around the cloud computing
1:32world.
1:32But for a lot of platform as a service offerings,
1:34it could be the only thing we talk to is an API itself.
1:39This implies that you could be using an API to create
1:41and build functionality, or you could
1:43be using it to access data.
1:44The point is that you don't get to manage the infrastructure
1:47in the background.
1:48The provider is giving you an API to talk to and interact
1:51with that you might be able to use as a part of building
1:53those pieces.
1:54One of the final concepts on here,
1:56then, is the notion of using containers.
1:59And there is a lot more to say about containers.
2:01But the basic principle behind a container
2:03is that it's a lightweight-style virtual machine that
2:06focuses more on providing libraries and platform
2:09functionality for a specific type of application
2:12or a specific language of code.
2:14And so as we look at the shared responsibility model
2:17and as you look at examples of platform as a service,
2:20look for these patterns of being able to build from pieces,
2:22using APIs, and then leveraging containers
2:25to shortcut the application development process.
2:28Indeed, for a lot of organizations,
2:30platform as a service is largely targeted at the consumers
2:34or at the developers themselves.
2:36And so as we take a closer look at the shared responsibility
2:38model, with platform as a service, the name of the game
2:41is all about focusing on those application layers.
2:45So this means that we're extending all the way up
2:47through the operating system and all
2:48the way up into the runtime and middleware
2:51in allowing the provider to handle
2:53most of that infrastructure.
2:55Now, keep in mind here, friends, that when
2:57we have them managing the runtime and the middleware,
2:59often, the client or the consumer
3:01still has the ability to choose those environments.
3:04For example, if you're using an Azure function,
3:07they have Python functions.
3:08They have functions for .NET.
3:10They have functions for Go and for Ruby.
3:13So you're still getting to pick what flavor of platform.
3:15But largely, the developer can just focus then on,
3:18what does the application do?
3:20And then further deal with the data and the administration
3:23of the people, authentication, and authorization layers.
3:26And you can see that we just took a huge bite out
3:28of the shared responsibility stack [GROWLING]
3:32and we passed a lot of that off onto the provider.
3:34This is what I meant by it being possibly
3:36one of the most important layers or service
3:38models within the paradigm.
3:40Infrastructure focuses on control.
3:42Platform focuses on increasing value
3:46by allowing us to customize and modify with the least
3:49amount of effort.
3:50Going back to those principles I used earlier on,
3:52building from pieces, using APIs,
3:54and leveraging containers.
3:56So as you look at the platform-as-a-service model,
3:58we recognize that we're increasingly dependent
4:01on the provider to deliver a high level of quality.
4:03And as I described with infrastructure as a service,
4:06on the exam, you're going to want
4:07to be thinking, what sort of maintenance
4:09does this leave for me?
4:10What sort of day-to-day actions am I going to be dealing with?
4:13So with platform as a service, I am not
4:15going to be designing the virtual networks, necessarily.
4:18I'm not going to be running a virtual machine, per se,
4:21or patching the operating system.
4:23Most of that is going to fall directly on the cloud service
4:26provider to deliver that part of the functionality.
4:28What I am going to be concerned about
4:30is choosing the right runtimes, choosing the right flavor
4:34of the platform, and building from the pieces
4:36that the service provider has offered me.
4:38I am going to continue to be concerned about the data
4:41security, and I am going to continue
4:42to be concerned about the authentication
4:45and authorization layers.
4:47And so platform as a service gives us
4:49a wide array of opportunities.
4:51For a good example behind this, one of my favorite platforms
4:53over the years is WordPress.
4:55Now, you can run WordPress blogs on your own systems.
4:59You can go out there and build a Linux server out there,
5:01install Apache and MySQL on it, and get that up and running.
5:04Or WordPress.com also offers a hosted website flavor.
5:09So this allows us to just jump straight
5:10into using the application without having
5:12to manage any of the other infrastructure components.
5:15Indeed, if we take a look out here on the web--
5:17let's jump over to WordPress.com.
5:19Yeah, you can see that WordPress.com offers
5:22a couple of different options.
5:23You can see they offer blogs, websites.
5:25They have domain hosting opportunities here, as well.
5:28And they do also offer managed self-hosted options, as well.
5:32So in this way, WordPress is making it easier
5:34for you to get down to the part you really care about,
5:36which was running the blog or delivering
5:38the website that you're trying to use and less
5:41on buying servers, choosing the operating system,
5:44installing all of the components.
5:46So this is where that principle of building from pieces
5:49comes from.
5:49They are giving you the pieces you
5:51need so that you can jump directly in and begin
5:53using them.
5:54Furthermore, as you get further into this paradigm
5:56and start using your WordPress site,
5:58they have other modular plugins that are available there,
6:01as well.
6:02This allows me to go in and choose things
6:03like adding a shopping cart or adding some other pluggable
6:07authentication for working with Google
6:09or working with other types of authentication providers
6:11out there.
6:12To get to be maybe a more pure platform
6:15model, if we take a look over on Amazon Web Services
6:18and take a look for Lambda, Lambda
6:21is a code execution environment that
6:25allows me to go in and create what they call a function.
6:28And I can write these from scratch.
6:29They support a variety of runtimes
6:31that are available in here.
6:32And what I'm going to do then is simply plop down some code
6:35and have Amazon run it for me in the background.
6:38So in this way, I'm shortcutting the process
6:40of using the platform and building the platform,
6:42and just going into the process of actually delivering
6:45the applications and the functionality itself.
6:47And so just to summarize, friends, platform as a service
6:50moves the responsibility model even further up.
6:53We're pushing more burden off onto the provider,
6:56which usually means a good, strong value return.
6:58And as consumers, we're largely focusing
7:00on what we can do with the platform components.
7:02Keeping in mind that they're largely
7:04focusing on giving us things that we can build from,
7:06pieces to use, or APIs that we can interact with,
7:11or offering a container execution environment
7:14where we can take already containerised application code
7:17and have them rune it for us.
7:19All of these share that one key theme, in which we are trying
7:22to reduce the effort required for developers
7:24to get their applications up and running.
7:26So as we begin looking forward into the next model, software
7:29as a service, keep in mind that for a lot of cloud computing
7:33services, they're built on these other layers.
7:35There are many platforms out there
7:37that run on infrastructure as a service.
7:40Similarly, as you get into the software as a service layers,
7:42you're going to find them also leveraging
7:44platform and infrastructure as a service, as well.
7:48So remember, these layers build up
7:49as you get into the more complex services
7:52into the software as a service world.
7:54So stick with me.
7:55In the next lesson, we're going to take a look
7:56at the penultimate tier, the one that allows the consumer
7:59to get the most value with the least amount of effort,
8:01and that's software as a service.
8:03Hope this has been informative for you,
8:04and I'd like to thank you for viewing.
Software-as-a-Service
0:02Hey, friend.
0:02Welcome back to Explaining Cloud Principles.
0:04So far we've talked about two of the three service models
0:07that NIST defines in the cloud computing world.
0:09That was infrastructure and platform as a service.
0:12In this video, let's take a look at the third, final, and
0:14penultimate tier of cloud service delivery, software
0:17as a service.
0:18And keep in mind, friends, as we move
0:19through these different service models-- from infrastructure,
0:22to platform, and now to software--
0:24the key theme is pushing responsibility off
0:26onto the provider.
0:27And so, with software as a service,
0:29we see the maximum amount of offloading occurring.
0:31Here, take all of that.
0:33And so, as we take a look at the stack,
0:35in software as a service, the provider
0:37is now responsible for an increasingly larger number
0:40of layers.
0:40So we're moving all the way up past the runtime and middleware
0:43of the platform, moving up into the application,
0:45and then even into some of the data storage and management
0:48elements here.
0:49And that means, for us, as consumers,
0:51we are responsible for really just configuring
0:53the application and storing our data in it.
0:56Keeping in mind that it doesn't mean
0:57that we have the ability to control
0:59the selection of applications.
1:01We may be able to choose features that are available,
1:03and all that kind of fits in the configuration realm.
1:06So here we are as consumers, and the providers then
1:09are handling the most layers across all of the other service
1:13models.
1:13Keep in mind, too, that data is kind of interesting,
1:15because data is something that both us are responsible for.
1:19I might be storing it there, but I
1:21get to choose things like permissions models around it--
1:23who can access and work with the data.
1:25And then I'm trusting the cloud provider
1:27to keep that information secure to the expectations
1:30that we've set.
1:31Another kind of aspect of this is
1:32to keep in mind that there's a few different variations
1:34on the software as a service theme.
1:37The first one will be simply not having to install software
1:40locally on your computer.
1:41So if you can do it directly through a web browser,
1:43that might be one option that you're doing.
1:45OK?
1:46And a lot of great browser based applications are out there.
1:49On the flip side, many browser based
1:52applications, like Google Gmail or Google Apps for Business,
1:55also often have a mobile app that
1:57could be available as well.
1:59So you could go into the Play Store and get the Gmail app
2:01and install it, and that would be the same flavor of software
2:05as a service.
2:06The client is then changing a little bit.
2:08Keep in mind, too, that, when we get
2:09into talking about browsers versus apps,
2:12there's also this other aspect where
2:13we're thinking about thick PCs-- regular desktops and laptops
2:16as well.
2:17And so the ability to support all these different platforms
2:20in a very flexible fashion is a great hallmark
2:22in the software as a service model.
2:24The final one that I want you to think about,
2:26too, is the notion that we might just
2:28be buying licenses directly through a cloud service.
2:32So maybe it's not so much about using it in a web browser,
2:34but rather being able to use a subscription
2:36or purchase a license where you can download the software,
2:39and then use it locally on your computer.
2:42In the end, friends, because software as a service
2:44pushes so much responsibility off onto the provider,
2:46it leaves a very strong value proposition
2:48for those us who are consuming those services.
2:51The other big thing to recognize is
2:53that, with software as a service,
2:54a lot of these providers are going above and beyond what
2:57we might be able to do deliver directly doing
3:00this in our own environments.
3:01Good example would be like Microsoft Exchange,
3:03is an enterprise email service that we've been running
3:06in our data centers for years.
3:07I used to be an exchange administrator.
3:09And now most of the clients I work
3:11with, they leave all of that exchange administration
3:13to Microsoft Office 365, a fully cloud based
3:17version of that server service, and Microsoft is running it
3:20for them in the background.
3:21And so the beautiful part is they get
3:23to have these enterprise tools.
3:24They get to reduce the amount of effort.
3:26And we can count on good old Microsoft, or Google,
3:29or our service providers to leverage
3:31their expertise in running and operating these systems.
3:34Because even on my best day as a good exchange administrator,
3:37I am still not the support infrastructure at Microsoft.
3:40And if I have to escalate a ticket, guess who I'm calling?
3:43I'm calling that provider.
3:45And so, often leaving it to their specialized hands,
3:47and being able to leverage things
3:49like a global infrastructure, where the exchange mail
3:52is now available in China, in Australia, in Europe,
3:56in South Africa, in Brazil, in North America, all
3:59over the world through infrastructure
4:01that Microsoft is delivering for us.
4:03And so let's spend a few minutes chatting
4:05about some other examples here.
4:07Some of you might be familiar with the Google Apps
4:09for businesses.
4:10And that would include something like Gmail.
4:12Gmail is a service that has grown a lot over the years.
4:15It used to be just for basic email.
4:17But now it has hooks into the other calendar
4:20suites, reminders.
4:21You've got Google Hangouts that's
4:22a part of that environment for messaging as well.
4:25And the browser based version is one option.
4:27And, like I mentioned, I can go and get that same application
4:30on my smartphone.
4:31Oops, there it is right there.
4:33So I have all of that mixed mode functionality.
4:36And here at CBT Nuggets, the rest of our company
4:38is using the enterprise version of Google.
4:40And so this is a great example of where
4:42we see tiers of service in different subscription
4:45levels that are available.
4:46If you're just a regular consumer
4:48and you want to use Gmail, there is a class of service
4:50that's freely available for you to use.
4:52Just provide some identification information and go from there.
4:56Or if you're a company, like us here at CBT Nuggets,
4:58we're actually paying for an enterprise support plan
5:01and subscription service that allows
5:03all of our hundreds of employees to use the Gmail service
5:06and some of the other enterprise tools,
5:08not to mention their document editors,
5:10like Google Docs, the spreadsheets,
5:12there's PowerPoint variations on that.
5:14And of course, as we consider some of the other alternatives
5:17there, we see products like Microsoft 365,
5:20which, again, offers a variety of options for how to interface
5:24with their service.
5:25It could be browser based.
5:26I have the mobile version of Microsoft Word on my phone
5:28here as well.
5:29And then, on top of that, I also have Cloud Storage, like things
5:33like OneDrive that's available.
5:34So you're talking about not just one simple cloud service,
5:37but an entire suite of services.
5:39And indeed Office 365 is very sweet
5:42and Google Apps for businesses is also a very sweet suite,
5:45and we love the fact that we can pick and choose
5:48a la carte which parts we need for each organization.
5:50These are all great hallmarks of the cloud software as a service
5:54model.
5:55One thing, to kind of pause here,
5:56too, is to recognize that, in most of these scenarios,
5:59even though you're doing it self-service,
6:00there is still some sort of a contract that's
6:02happening in the background.
6:03When I sign up for Office 365, I'm
6:06agreeing to their terms of service.
6:08And in there is some sort of expectation
6:10that's exchanged around what Office 365 will do for me,
6:14and what is expected of me as a user of their service.
6:17And so that principle of a contract,
6:19being fully self-service available,
6:21just a little checkbox that I can choose,
6:22is, again, another principle of software as a service.
6:25And one final aspect is to recognize
6:27that, if I'm using this product for a while,
6:29and it doesn't meet my needs, I can change the subscription.
6:32I could return it completely and stop using it,
6:35or I can make some other transformation
6:37and maybe move those services into some other flavor
6:40that Microsoft has available.
6:42So the ability to move and port between these services
6:44may also be another feature that's
6:46important to you and your organization.
6:48One final one that I use a lot here at CBT Nuggets
6:51are the Adobe Creative products.
6:52Indeed, when I'm doing my little whiteboards that you just
6:54saw me drawing on a few minutes ago,
6:56that's in Adobe Illustrator, and I edit all my video
6:58in Adobe Premiere.
7:00All of the licenses and the software
7:02that we use for that are available through something
7:04called the Adobe Creative Cloud.
7:05And the cool thing is they actually
7:07have a little like client application, which
7:09is this little app right here.
7:10And so I install that on my desktop-- oops, come back here.
7:14Yeah, so I install it on my desktop computer,
7:16and it gives me a gateway into their services.
7:18And, from here, I can go in and take a look at all the software
7:21I already have installed.
7:22Or if there's something new that I want to try,
7:24I can jump over here and take a look-- like, see here's
7:27Premiere Rush that they have available.
7:29I can install and download that.
7:31They've got some other cool 3D audio and 3D video editing
7:34tools here as well.
7:36And it's all about that licensing model.
7:38And so, just to kind of recap, friends,
7:40what we've talked about today is probably the most important
7:43and simplest to obtain software as a service
7:46model of all the cloud platforms that we've talked about.
7:49With infrastructure, it was all about maximizing control,
7:52giving us the most layers of control.
7:54With platform as a service, it was about a sweet trade-off
7:56between allowing the vendor to manage some
7:59of the more important layers of the infrastructure,
8:01and then giving us, as software developers,
8:03control over all the other components on top of that.
8:06Keeping in mind that we were able to build from pieces,
8:08leverage APIs, and leverage containers
8:11to run our workloads in.
8:12In this last video, here, where we were talking about software
8:15as a service, we said that we're focusing on ease of use,
8:17being able to obtain cloud services,
8:19either directly through a web browser,
8:21through a mobile application, or being able to leverage
8:24subscription and licensing models,
8:26like the Adobe Creative Cloud, where
8:27we're downloading the software and running it locally,
8:30but the licensing is still variable, flexible,
8:33and can be turned on and off.
8:34Which, again, fits some of those themes
8:36when we were talking about the key cloud characteristics.
8:39Now that we've talked about the service models
8:42and the core characteristics, in our next and final video,
8:44let's chat a little bit more about some of the deployment
8:47variations.
8:47As you heard me say, you can run cloud services in your own data
8:50center, and you can run them in the cloud as well.
8:53Heck, you can even dance if you want to.
8:54And connecting the dots together is another option with hybrid.
8:57So stick with me in the next lesson
8:59as we take a look at cloud deployment models.
9:01I hope this has been informative for you.
9:02And I'd like to thank you for viewing.
Deployment Models
0:02Hey, friend.
0:02Welcome back to Explaining Cloud Principles.
0:04So far throughout this video series,
0:06we've been focusing on dispelling
0:07some of the myths and misunderstandings around what
0:09a Cloud computing service is or is not.
0:11It was very helpful for us to check out
0:13the published standards that NIST puts out there.
0:15This led us to looking at the cloud
0:17definition and their "Reference Architecture"--
0:19the characteristics, the service models, the actors,
0:22and the roles that exist out there.
0:24And in this last video, let's take
0:25a look at one final additional aspect,
0:27and that is the deployment models that we'll find.
0:29This would be private, hybrid, public, and community cloud.
0:34And the first thing to keep in mind
0:35is, as you look at the deployment models,
0:37take it out of your head.
0:38It's not a question about where the services are running.
0:40Instead, it's more about the audience
0:42and the level of exclusivity.
0:44Similarly, we can go back to NIST
0:46and make sure we have that "Reference Architecture."
0:48So jumping on over to the web again,
0:50if we take a look for NIST Cloud definition--
0:54there we go.
0:55And grab that same document.
0:57Yep, pop that open.
0:58There we go.
0:59And then cruise on down into I think it's like on page five.
1:03Yeah.
1:03There we go, great.
1:04Passt the Service Models and on down to Deployment Models.
1:08Here, you can see NIST taking a stab
1:09at defining private, community, public, and hybrid cloud.
1:13I want you to have this handy, specifically
1:15because the verbiage they use here
1:17is better than the common understandings
1:19that a lot of people come to.
1:20When we say private cloud, first of all,
1:22it does not mean it's running in your data center.
1:24Instead, they're saying that it is talking about use
1:26by a single organization.
1:29So exclusivity is the key trait that they're focusing on there.
1:32So just like in a public bank, if you
1:34were using a bank in your own town,
1:36that is a public institution.
1:38But when you put money into your account,
1:40it doesn't end up in my account.
1:41It doesn't end up in your neighbor's account.
1:43It has exclusive levels of access
1:45for your use of that service.
1:47So you do want to recognize that private cloud is
1:49about exclusivity.
1:51They're also saying that it could be owned,
1:53managed, or even operated by that organization,
1:56a third party, or a combination of them, both on
1:59or off-premises.
2:00So we're really saying that, again, it's not about
2:02where it lives, necessarily.
2:04It's about that level of exclusivity.
2:06And so as I take another look at this,
2:08I'm going to do a little bit of drawing here.
2:10With private, the focus is on exclusive.
2:13That's the key term that they're talking about here.
2:15The other big thing to recognize is that, typically when
2:18we say private, there's often an enhanced level of security
2:21to it because of the level of control
2:23that's given to the consumers themselves.
2:25Keeping in mind, too, friends, that
2:26were also still contrasting this across these different service
2:29models.
2:30So the deployment model deals with the audience
2:33and the exclusivity, whereas the service models dealt more
2:35with the shared responsibility with the provider.
2:39The next layer that we look at is the one that many of us
2:42have come to know as basically internet-accessible,
2:44and they're talking about the public offerings here.
2:47The general public is the general term
2:51that they're trying to use for this part of it.
2:53And the basic principle here is that with just a credit
2:55card and basic internet access, you can go and obtain
2:57this public services.
2:58And they're meant to be broadly accessible.
3:01This is an interesting contrast here, friends.
3:03Most of the time when we say public cloud,
3:05we're pointing out that you don't really
3:07need to meet some specific use case scenario to leverage
3:10their services.
3:11On top of that, you may recognize, too,
3:13that there are going to be levels
3:14of privacy and exclusivity that still
3:16exist within the public cloud.
3:17It's not a free-for-all buffet where
3:19everybody can use your data and access your tools.
3:21Instead, we're pointing out that it's
3:23generally available for most organizations to leverage.
3:26The final one that they have on here is hybrid.
3:29And this stitches multiple ones together.
3:31Hybrid is saying that it's a combination of private, public,
3:34and then possibly the community model, as well.
3:37Hybrid is also probably going to be the most common one
3:40that you will run into.
3:41And the value behind it is very strong,
3:43because it allows organizations to choose
3:46which flavor of service and deployment scenario
3:50is best suited for them.
3:51So you may see them using a public software
3:53as a service provider for their email and their communications
3:57mediums.
3:57And then you may find them using portions of an infrastructure
4:01layer that they're running in their own data centers
4:03or maybe in a colocation facility.
4:05The point is that as a consumer, we're
4:08able to a la carte choose which types of services
4:11and where we want to run them.
4:13This is exactly where that hybridization concept
4:15comes from.
4:16On the exams, you would want to keep some of those key terms
4:18available.
4:19If it's highly exclusive, that would be the private model.
4:22With the public model, it's about general accessibility.
4:25And with the hybrid model, it's about combining one or more
4:28of the other deployment models that we've talked about.
4:31And that brings us down to the very last one, community.
4:33Community is an interesting beast, because a lot of us
4:36don't operate in a community world.
4:38The key term that they use there is for a specific demographic.
4:44Big old were there.
4:45And when we say that, we're talking
4:47about a very specific niche audience
4:49that has a common set of shared interests.
4:52That's the other big term here--
4:53shared concerns.
4:57One great example of this would be
4:59a lot of the government flavors or the highly secure versions
5:02of some of the public cloud providers.
5:03For example, Amazon Web Services has something called Gov Cloud,
5:07and Azure has a government flavor, as well.
5:09And if your organization does not
5:11have the right levels of certifications or quality
5:14and control expectations-- indeed, often a lot of them
5:16are invite-only scenarios-- they won't
5:19be able to leverage those services.
5:21So as a community offering, you're
5:23focusing on addressing specific concerns, often
5:25around compliance with security.
5:27But it's not limited to that completely.
5:29You may also find that a community
5:31service may be specific to a research scenario.
5:36You may also find that they use a common set of data that
5:39might be shared between them.
5:40You look at a lot of the artificial intelligence
5:42and machine learning offerings that are available out there,
5:45community clouds focus on that specific set of shared
5:48interests and concerns.
5:50And so wrapping all of this back together,
5:52we see that the NIST definition is not
5:54as simple as just saying where the services are running.
5:57Private is all about exclusivity.
5:59Community is all about meeting specific organizations
6:02that have shared concerns.
6:04The public cloud is all about general public usage.
6:07And then hybrid cloud is a composition of two or more
6:10of the different distinct cloud models.
6:12And so in the end, as an organization choosing what
6:15cloud services to use, we want to start first
6:17by identifying how much control we need to maintain.
6:21Some of this might be totally up to our druthers to decide.
6:23Others might be dictated us by the industry that we work in,
6:27by the geography and some of the national expectations
6:30around security and quality, or simply the data
6:32that you're working with, and maybe
6:34the audience or the nature of the service that you provide.
6:37Infrastructure maximizes our control.
6:40Platform allows us to develop and customize
6:42to a high degree of control, while still getting
6:44a good value return with the provider handling
6:47a lot of the administration.
6:48Software is the easiest on-ramp, but it also limits the options
6:52around how we want to control those particular deployments.
6:55The other aspect was deciding what
6:57deployment models are going to be most appropriate for us.
6:59Can we use publicly hosted data in shared data centers?
7:03Do we need to use private resources
7:05or need a higher degree of exclusivity of control?
7:08On top of that, we also looked at the hybrid and community
7:11models and how they allow us to blend together
7:13different deployment options.
7:14And if it's a very specific niche need,
7:16or you meet a certain shared concern model, like security
7:20or compliance, you may find yourself
7:22using some of the special community
7:24secure cloud versions that are available out there.
7:26In the end, friends, by using the NIST cloud definition
7:29document and the "Cloud Reference Architecture,"
7:32we ensure that our technical teams and our operations
7:35and business support teams are speaking the same language
7:37about using Cloud services so that when someone says private,
7:41and they really mean running it in their own data centers,
7:43we're not going to be confused and walk into that trap.
7:46On top of that, it also leads us down a conversation
7:48about those key characteristics.
7:50If it doesn't possess all five of the characteristics,
7:52odds are, it may not fit the cloud computing definition.
7:55And in the end, friends, the whole goal
7:56here is to make sure that organizations understand
7:59what they are getting themselves into as they
8:01begin sharing responsibility.
8:02And I'll tell you right now, friends,
8:03the idea of sharing responsibility-- it's not new.
8:06It's not a exclusive cloud computing concept.
8:09I've been working with customers who run in data centers,
8:12like colocation, or managed service providers
8:15for years and years way before the cloud service
8:17term was ever coined.
8:19So the idea of sharing and outsourcing resources
8:22is not new to businesses.
8:23And indeed, for a lot of us, when we first
8:25start talking to businesses about cloud computing,
8:27coming at it from an aspect of outsourcing
8:29may be the best inroad for helping them understand
8:32what's actually happening.
8:33It is a trade-off in control and responsibility.
8:36And ultimately, how we break down
8:37that control and responsibility directly
8:39affects the value, the maintenance,
8:41and the ongoing relationship of what we get from our cloud
8:43service providers.
8:44And so stick with me, friends, and hopefully
8:46in future lessons, I'll see you out there
8:48as we continue digging further into the wide world of cloud
8:50computing.
8:51I hope this has been informative for you,
8:52and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year