Planning for Multi-cloud Webinar
Transcript
[Music] thanks for joining the planning or multi-cloud presentation I've done a quite a bit of research and conversations with the community thinking through what is multi-cloud what are some of the challenges faced this presentation is geared towards the Enterprise Architect that has to look at a holistic view of multi-cloud our defined multi-cloud in a couple of minutes but overall the audience for this presentation is the Enterprise Architect not necessarily the application developer but the Enterprise Architect that has to worry about compliance security performance networking across
a dozen or so apps that you're looking to deploy or leverage in the cloud we won't spend a whole lot of time on this next slide other than to put it up for those on replay if you've connected with this webinar chances are you know who I am and you know how to find me so there's the obligatory smart we're gonna try and cover an awful lot in the next 40 minutes or so we'll cram as much information in as possible what I wanted to do
was not only give some practical theoretic overviews over what you should do and planning for multi cloud but point you in the directions of least some vendors to have conversations this podcast for this webinar is not sponsored by any particular vendor I have put stars next to vendors names that I have done business where for whether it's advisory work or creating content but this is not a sponsored pot what so let's go over the agenda this is what you found in the end of I will
go over a picture of the typical multi-cloud environment I see in this presentation that it starts with networking but actually your multi-cloud journey starts with data unfortunately there's not a awful lot of solutions and products on a market to really help you with the holistic challenge of data in the enterprise we'll get into that a little bit when we talk about data protection and considerations around data and then we'll have ten of three lamps conversation at the end about workload and change management specifically we're going
to talk about kind of the promise of kubernetes and the reality of where we're at as a industry so I found this picture to be more controversial than it should have been ok there's a foregone conclusion that everyone considered software-as-a-service a cloud a proper cloud technology that you should consider when you're thinking about multi cloud and as recently as this morning I was in a back-and-forth with peers on LinkedIn that kind of take the the financial analyst view of software as a service so specifically I
put on this line office 365 when Microsoft reports their earnings typically a lot of the pushback you get from industry analysts is that office 365 shouldn't be included in the mix of revenue because you know it's office productivity software how somehow magically just because it's office productivity software is not side SAS which it is says the argument can go you know what if I'm consuming as ap HANA as for as a SAS offering and it's driving seventy percent of all of the world's revenue s ap
in general or transactions there's somehow that's not says the reality on the ground is that when we adopt solutions like work force I'm sorry like work day or spin salesforce.com office 365 Oracle Business Suite as these are critical parts of our business critical work flows of data goes through these services so I put them on equal par as a AWS asier or a Google compute when we're considering all the things we need to do or to protect data to ensure compliance to ensure end users have
access to the applications and services they need these solutions become a critical part of our infrastructure one of the use cases that I gave as I made the argument that SAS offerings in office 365 specifically is a part of the infrastructure of multi-cloud think through this and think through the scenario I'm I'm about to get them you're a developer working on a CRM marketing campaign in AWS you're hosting a bunch of objects that are basically sales material marketing material collateral that you're hosting as part of
this campaign you have a customer portal the customer can come into the portal use their credentials to download this material if you're using also salesforce.com then as a developer I can easily create a scenario or even a function in AWS lambda that when I get a trigger lambda that says he thousand has downloaded the latest marketing material on project XYZ I trigger a lambda function that will then go to salesforce.com to update the customer record for Keith Townsend who works at the CTL advisor that says
the CTO advisor is interested in project XYZ follow-up with the user that is multi-cloud at no point did and that workflow did the technology or logic touch the private infrastructure we can go with all kind of variations of that movement but this type of activity is happening in the enterprise whether as infrastructure professionals as IT professionals we realize it or not people think of these things I'm not a developer I'm not even that great of a business analyst and I came up with this simple workflow
that people when you remove the barriers of IT and you're exposed directly to these services start the build so the ideal that office 365 salesforce.com workday or any of the other SAS offerings aren't part of your multi cloud strategy is a fallacy you have to consider this this is where I went back to the first conversation that the first step in understanding your cloud journey is to get to the data understanding data flows workflows what data exists and what platforms and why are the potential use
cases for the data in these platforms so starting with a network founded it pretty difficult to draw a picture of how a typical network for multi cloud infrastructure will look if we go back to the previous cloud I think in our minds this is where we would you know kind of have a firewall at the perimeter of the data center and services will kind of all come into that single point and then users can access those services ll be of that that traditional perimeter path in
reality that's not what's happening this is again to pick on SAS services again users are going to D SAS services directly I think the industry try it for a little while to hide office 365 behind VPNs and some companies still do it but for the most part customers are coming in or end-users are coming into solutions like office 365 Salesforce workday etc etc through the public Internet if they're not doing that today they probably will do it in the future and then we have this scenario
the use case that I just gave where you know you create some type of lambda function that trans acts on a Google a Google compute platform leveraging machine learning or on a blog stored in SharePoint on office 365 that traffic does not go through the private data center or it shouldn't have to go through the private data center you could force that traffic through but you need to give some thought to that question how what is your networking policy and this is separate from security your
networking policy around multi-cloud when you want end-users to when you want to able end-users developers and such to access resources from AWS into Google compute or office 365 or in Microsoft Azure what path do you want them to take as you get into the security conversation it starts to go around well how how do I enable C security in a matter that protects information I posted a unpopular opinion on Twitter the day before yesterday which is that firewalls no longer protect the perimeter I got a
lot of pushback I expected to get a lot of pushback from that statement because people still think of the perimeter as the data center extended into the cloud what do I mean by that well we put traditional firewalls inside of AWS whether those traditional firewalls are individual instances with a firewall cold-cold installed on it so that we're filtering all of our traffic through a gateway in AWS out or if we're running micro code on each AWS ec2 instance that has distributed firewalls inside that is a
very data center specific construct of a perimeter that perimeter no longer exists go back to our example about AWS lambda running cold on office 365 there is no firewall that protects against that traffic flow matter of fact I don't I'm not 100% sure we going back and forth with this with AWS with then some accounts that I've had and with Twitter and LinkedIn about a potential design that will force traffic through a B PC or lambda cold that goes into the data center the traffic is
analyzed at a firewall then goes back out to office 365 it takes the same path back into your data center that is convoluted so this is something that you have to give a great deal of thought to from a security perspective and also from a performance perspective if we start the tunnel all traffic through a point in the data center are we really leveraging the public cloud for what it's worth so let's talk about a couple of different scenarios of how we design a multi cloud
Network you know we can go with that latter example that I use which is internet only you know what let's use the public cloud as it was meant to be used in user sitting in their home office we'll access resources on public cloud through the neck Internet obviously all services will go through that Comcast or AT&T local home connection this reduces the overall friction from consuming cloud services however you have less control and visibility the from a compliance perspective here and if you're in a highly
regulated industry and you have PCI data take office 365 for a while wasn't even certified for PCI compliance you open up find a bit of pain when it comes to keeping your infrastructure in compliance enter the first obvious I think solution which is VPN we see this a lot I can establish a VPN connection to all of my multi cloud service providers AWS Azure Google compute and then force force all traffic for office 365 no need to only be accepted from a VPN connection from my
data center into the SAS offering which forces in users to have to VPN into your datacenter and take that path obviously you ant you solve the security problem but you increase overhead I can't I can't stress this enough especially as you get larger and you have more and more sights more and more entry points into your environment if you are a global company and you have a data center or a point of preference in Europe US Asia and you want to use the cloud service provider
closest to the end-user forcing this VPN type access creates an abundance of complexity in your environment you have to decide how you gonna low balance that traffic so that end users are going to the resource closest to their environment are you to use DNS or are you going to use some type of Geographic based load balancer that goes up on point of entry into your network to determine where this traffic go how are you going to share routes with your a public cloud provider and to
ensure that traffic always goes over those VPN tunnels how are you gonna handle fell over the complexity goes on and on when you go through a VPN option then let's talk about the obvious disadvantage which I alluded to other than overhead is performance when you you have a finite amount of bandwidth leaving your data center especially Internet bandwidth one of the complaints about internet bandwidth is that it is unreliable from a performance perspective the having the distributed model of Internet only allowing users to go in
through their private connection the choke point now becomes the internet the internet port and at the home users location and the SAS service providers ability to accommodate that traffic and that's usually you know not a problem so the next level of options is to get some type of dedicated connection expressvpn American Express link or Direct Connect some type of dedicated connection to your SAS provider this obviously is going to offer more security than both VPN and Internet only it can offer less complexity or than B
pin but you have some of the same challenges from a performance perspective you create the same bottleneck conditions but generally cloud providers allow more bandwidth with these dedicated connections you can get 10 gigabit connections direct connects versus a VPN last time I checked from AWS to your data center was limited to 4 gigabit 4 Giga bits per second so you can increase bandwidth hence increasing performance and relieving a bottleneck within your requirement well you reduce the overall [Music] flexibility of your options one other point when
it comes to dedicated connections and we'll get to it when we talk about kind of the interesting vendors in its face SAS services are most of the time either co-located or closed to public cloud instances so you'll have a lot of public class SAS services that are based in Amazon's AWS one of the advantages of a dedicated connection to AWS is that you can then funnel all of the traffic destined towards they Club the cloud a SAS hosted on a cloud provider such as AWS you
can funnel that to your direct connect so you know it kind of kills two birds with one stone there's complexities in that that we'll get into in a future podcast me I'm sorry webinar but it is a compelling solution to be able to help all of your sass traffic and all of your infrastructure-as-a-service track traffic over a single dedicated connection so who are some of the interesting network vendors in this space I broke this down into three different areas st man circus and hotel errs st
when I think when we figured st man we typically think of reducing mpls cost and ensuring that you can get the same level of performance for the internet as you can over a dedicated circuit if not better performance the ability to intelligently pick routes well it's that ability to intelligently pig routes that makes St wind even more extreme for multi-cloud there are plenty of options there's no shortage of vendors that will help you put virtual appliances inside of your B PC or your virtual networks and
as your google compute AWS to intelligently route traffic over the best path it's no different than what we do in the data center so riverbed Vitello which is now owned by cisco fellow plough are all interesting examples of SPO and solute solutions that extend beyond just a private data center and private network circuits you know what this is you know old-school I need a connection from my data center into the public cloud Baby Bells our resellers such as CDW are doing really interesting things when it
comes to circuits one of the cool things is that they are becoming a one-stop shop a TMT for example bought a SD win company so now they can offer some of the same SD win capability that you that users are using to avoid MPLS to intelligently direct traffic in the hybrid and multi-cloud use cases you can go to CDW and as well to get these solutions hotel errs Equinox qts Rackspace all offer either direct connects to providers or they'll terminate within they'll terminate a circuit within
their infrastructure and give you a portion of a circuit so let's say a port to AWS is typically 10 gigabits a hotel or we'll say hey you know what we'll give you a 1 gigabit connection or a half a megabit connection or their Tim ho 10 gigabits to cloud providers so not just a single cloud provider but they will share routes to you to all of the cloud providers they have co-located and their facilities so that you kind of again kill one bird with one stone
you can get a Tim you don't have to go out and get separate connections to Azure AWS Google compute work day works fake workday Salesforce etc if you get a single connection into one of these hotels they they'll put you as close as possible latency wise to these services so you know you won't call have a conversation so let's talk about another big topic which is data protecting this is a kind of lumped security and data protection all into one slide because again each one of
these areas is a webinar in itself and I want to directionally give you a place to start to research and go the number one challenge in my opinion of multi clout when it comes to security around your data is the differentiation and or differences in taxonomies control planes and capabilities there is a ton of other considerations that we're not going to go through in this webinar but from a high level I wanted to help you understand why security and multi cloud there's so much difficult than
security even hybrid cloud where I have my private data center in a single cloud provider in a private data center in a single cloud provider what is a web server today behind a elastic IP address should be a web server tomorrow I can create that policy where it starts to get complex is that what's a web server today in AWS may not exist tomorrow so I have to move up in my abstraction layers and help to understand groups of services and setting up my firewall and
that hybrid model between those two edges of the network I have my private data center I have my single cloud provider then as I start to go deeper I realized that the concept the firewall concepts break complete lambda or tensorflow or dedicated past services eks things that start or you know very simply object storage these things start to break down concepts of endpoints within the enterprise what is the end point when it relates to lambda modern-day firewalls don't have that context to know that oh if
I get I can say I allow port 443 which is the land of code to run against a web server but I don't know what that land echo spawns or has done I properly set up zero trust now you expand that beyond what service constructs and EWS is not the same as service constructs in Azure or Google compute lambda objects in AWS does not equal lamp does not equal as your functions and Azure how do i how do I control traffic between those two quote unquote
endpoints this is what I mean by control planes in order to go in order to put policy around lambda I need to go on to an I am in AWS configure those controls those controls don't necessarily translate in a capability perspective in Azure I may be able to control some aspects of service functions in AWS that I cannot control and lambda I'm sorry an azure then extend that out to that original use case that I gave of using lambda code to execute into salesforce.com now we
start to see the complexity of taxonomy and capability the the two just don't translate this is something that I wish I could point you to a vendor and say they've solved this problem they have you you have to do the heart you have to roll up your sleeves do the hard work and help them think through how you're going to deploy security policies across two separate security concepts or domains so a couple of topics that's a little bit easier to get our minds around which are
backup and disaster recovery as pertains to data protection some of the things that you should consider when you think through the simple concept of backup is one I'm surprised I still have to say this but I have to say this you have to backup public cloud you have to back up fast services you have to backup infrastructures services as a general rule of thumb especially the case when it comes to infrastructure service AWS as your kuku compute Oracle cloud etc will not back up your windows
emphasis or your lambda told or anything you deploy in AWS it's on the end-user to back up these infrastructure as a service based components the infrastructure itself is guaranteed against failure but not the workloads running on top if that data is somehow corrupted you need to go back and restore it from some weather or your rep whether you're using built in a replication in AWS etc etc you need to have a plan for how you backup your data software as a service generally speaking is not
backed up that that's a general concept things like workday those services are going to be backed up office 365 a little bit less clear whether or not Microsoft will be able to say I'll give you a a backup of a Visio that you had two months ago that is a question from the audience is can I talk about past backup for a little bit and I think I can equate pass back up to the same as I think what I just said about lambda so I
can deploy lambda cold and when I deployed landed lambda cold that understand under underlying code is stored in a three but object their van is deployed on demand if I make cold revisions if I make revisions to that underlying code it's upon me to have some type of methodology for backing up so if I want to revert back to a version of my land Nicole six months ago chances are I won't be able to go back to AWS and just hit rewind the same thing with
past service so if I'm consuming a database as a pass this gets you know kind of in between infrastructure as a service and and this gets in between infrastructure as a service for software as a service you need to check with your past provider especially in the case of a database you may be consuming a database as a past and part of that consumption is that they have some type of retention policy they may not have a retention policy and they may just provide the underlying
database the underlying database platform as something that you consume and bill projects so we'll get into how do you back up these platforms in the KU vendor session but for the most part you have to worry about state in all of your software as a service infrastructure service and expecting past platforms how do I back up the configuration because the configuration and a lot of these instances is the important part I left at a at someone's pain earlier this week the packet pushers on their network
break podcast talked about a minister that had passed away and the new administer was kind of slamming the day ahead and saying you know what the guy just wasn't good he to figure these core switches and he died without giving the password we have no idea of the VLAN configuration etc etc it's just a black box we don't know what to do with this server well that's the that's the state the the service itself can be as resilient as you want it to be but if
you need to revert things you need to pay attention to how you back that up and restore disaster recovery this is again something that's on paper seem simple it can be disaster recovery can be as simple as a AWS I want to protect between a double-a service in AWS region going down or AWS region going down or as complicated as I want to fell over from AWS to ash or from my private data data center into one of the public clouds this is a big talk
you know you you need to decide if you're going to take an application by application approach to it so I'm going to build cloud native applications that understand that underlying infrastructure is based off of Asia in my private data center and I'll build disaster recovery into that oven disaster recovery awareness into the application or if I'm going to build the disaster recovery awareness into my infrastructure this is what we do in the infrastructure today if a data center or a part of the data center fails
we can bring up that part of the data center in another location so the application developers don't have to worry about the underlying infrastructure the underlying infrastructure is built for resiliency you have to understand if you're going to approach this a multi cloud via the application from me SAS versus is versus past layer you know it's a solutions there's really not a dr use case in office 365 goes down other than having your local offline copies available to you there's really not a whole lot you
can do to failover a SAS solution to a different platform I asked in past are different again you can go at the application level for each one then RTO RPO you need to think about this a lot in the private data center we have a lot of control I can run out to Best Buy and hack together high-end PC use my array based snapshots or or or backups and restore a simple service to that machine and that can be my RTO RPO plan and my plan
is based on that and the public cloud that may not it's not me not it's not that simple or at least it's not very cheap for it to become that simple you have to worry about cost but in my opinion much more so when it comes around data and backup that you do on the when you're talking about hybrid cloud or private cloud instances of data protection so I'm gonna move a little bit faster because we're we have about seven minutes you guys have any questions
go ahead and put them in a Q&A session we have a question on firewalls that I'll come back to the end with Oh data grab you versus service gravity versus what I call service gravity what I think other people are pushed against me and calls service inertia this is again a dedicated webinar on we've had this Dave McCrory and I've had this conversation with Dave McCrory has come up with this I think time tested I did that we move compute closer to data the speed of
light restricts how much data we can move to give and compute so it's much easier to pick up a rack of CPUs and move that rack of CPUs close to our petabytes of data than it is to move the petabytes of data to the compute this image I think plays a pretty good role is that services are starting to push back I think a little bit on that concept I think gravity again I think data gravity is still very very very much a consideration when designing
or multi-cloud but as you start to leverage services like AI machine learning service service list high performs compute when I say high high performance compute I mean thousands of CPUs and potentially GPU GPUs and in some case massive storage object storage as that stuff exists in one cloud and you want to leverage a service or data and another cloud you have serious problems I mean we can't in our own data center recreate what Google has done with tensorflow and GCP so when we're talking about creating
algorithms based off a tremendous amount of data how do we do that that is a challenge so we're gonna talk about you know Canada cool vendors in this space in general from a security perspective zi scaler vmware cisco juniper and when I say cloud native I mean the native cloud solutions which is what we basically have to do do today you need to look to some of these vendors to have these challenging conversations I would say and any one of these vendors go and give them
the youth piece that I gave gave you and say how do I protect against that if they don't have a vision of how their products protect against it I don't think they'll have a complete solution but if they don't have any vision that raise an eyebrow and think man you know what are these guys really getting multi-cloud for backup and recovery Dru medallion seen an apple hasty rubric and the list literally goes on and on I meant it I should have put a star next to
Drew but I have done the they are fighting against they are fighting against the data gravity challenge by offering replication for data so I can put my data near the cloud let's say in a Colo and then I can replicate the bits and pieces that I need into a cloud or I can use these services as wholesale methodologies I can use these I can use these technologies as wholesale methodologies to move workloads from the private data center and to the cloud for dr asher has a
really cool service that they bought a company you should talk to them if you're primarily an azure they have a really cool dr automation product if you're just talking about going from the data center into the public cloud zurtle offers solutions for various public cloud and net vPro is a service provider that i partnered with too that i partnered with an affiliate with the refer folks to to implement some of these solutions which brings me to one of the questions why is there a star next
to some of the names again repeatedly if there's a star next to the name i have some type of business relationship with those vendors whether i've created content and advise them on their marketing strategy or outright help a affiliation agreement with them alright last line and we have we're out of time out of the overall team Bob go ahead for those who can stay on will go ahead and have the conversation around orchestration and workload management which is important briefly Netflix is the poster child for
adopting a hybrid file methodology for legacy applications a lot of people when they think of Netflix they think of the streaming service which is leveraging AWS CD ends and you have this perception that they're all in a cloud Netflix just as recently as two years ago published a paper saying we're finally all in a cloud their journey was extremely interesting when it as it relates to the enterprise they had a ton of legacy applications based on Java they adopted Maytals fear which is a data center
scheduling platform and built a container orchestration platform called titus which is a can to Corinne so if you want to compare it to something that's available I don't know open market we have kubernetes they took their monolithic applications their traditional Java apps put them inside of containers and then use Mesa sphere to schedule workloads to be injected into their tightest platform and placed a foreign different cloud providers whether it's will and in this case is hybrid if it's their own prim private data center or its
AWS amazing story I highly recommend you google AWS is I mean sorry Netflix its journey to cloud and read about their tightest journey and their container journey how they approached it from a organizational culture perspective and capability perspective but in general we get the same idea we we need a solution or a set of solutions to take cold weather that's legacy code you know it's a straight-up s ap application workload or if it's a native platform and use kubernetes to schedule that platform or that workload
across clouds I I'm not a fan of trying to adopt this any time soon unless your job is to build applications and provide those applications to consumers I say let the industry to continue to work out these kinks trying to balance workloads across clouds is fraught with challenges and if you go back realign the sessions you know you kind of get the ideal of what some of these challenges are most of us don't have 90% 100% of our workloads inside of containers which kind of simplifies
the challenges to it to an extent most of us still have these legacy workloads that require a lot of care and feeding there are stateful workloads Google will be one of the first folks Chelsie Hightower features just all the time don't put staple work workflows inside inside of kubernetes it's not a easy thing to do so but from a high point I wanted to make sure I talked about workload placement from a automated perspective this is the Nirvana of multi cloud while most people talk about
this I haven't ran into many traditional enterprises that's actively doing this at least not doing this at scale and if they've tried it they've run into every problem you think you would imagine that you run into I can't emphasize enough don't do it if you don't agree with me come have the conversation on Twitter or email me Keith at the CTO advisor comm and we can have the conversation so thanks for holding on I'll go back and answer the one question that I haven't answered in
the Q&A if you guys have more questions please go ahead and open it for those of you who are looking for pain I'll open up the audio to ask questions so one of the questions is what most of the traffic now being encrypted the placement of firewalls is now critical okay it needs to be more on the instances or closer to the data consumption or transport transfer points couldn't disagree with you more firewalls are useless firewalls are useful when you're talking about I need to protect
my internet circuit from pork skins etc etc when you're talking about traditional use cases for protecting the shield from external resources firewalls make sense where firewalls can't help us as much is when you talk about east-west traffic and I categorize east-west traffic as multi-cloud to multi-cloud traffic or server-to-server traffic when I'm in AWS and I build a application inside of AWS AWS gives me all the tools I need to protect workloads from each other if there is a bunch of web servers and a container in
a V PC by default one web server shouldn't be able to talk to another web server just because they're in the same container AWS gives me that capability inside the data center VMware in a sense gives me that type of capability if I'm inside the enterprise and I have a workstation side by side those workstations by default shouldn't be able to connect because the application patterns don't represent that type of traffic so why are we allowing that traffic we've interacted the concepts of firewalls to help
with that but in the public cloud we need to put the policy as close to what you're calling the endpoint as possible because the data is encrypted I can't inspect the data at the firewall breaking the encryption in TLS at the firewall is a fraud activity as a developer al just re-encrypted again so that you can't break it if you don't have the keys you can't break what the payload that I'm Cindy you have to have a methodology to put the policy as close to where
the data is either being generated or transmitted so I have to be able to apply my policy at the lambda and lambda versus this so have I listen to nuke at concepts such as can be I didn't put forth point on as a cool vendor and kind of dis face I should have forced point has bought a bunch of tasks B solutions so these are third party cloud security products and they've also bought traditional firewalls so in theory with their identity management solution and theory they
have all the tools needed to say that hey Keith Townsend is creating a lambda function or has created a lambda function that acts against a Oracle database that way he doesn't have access to I should be able to create a centralized policy that says the identity of Keith Townsend across all of my booty clouds does not have the ability there's zero trust between Keith Townsend and an Oracle DB that he'll holds all of ourselves data so Keith town can't exploit that security weakness to pull out
all of the cells data out of the Oracle piece just because he could create lambda call so that's the that's the Nirvana of cloud security we're not there multi cloud security and a firewall today doesn't solve that problem which I champion is a real problem in the enterprise people disagree with so