Tom Petrocelli's take on technology. Tom was a IT industry executive, analyst, and practitioner as well as the author of the book "Data Protection and Information Lifecycle Management" and many technical and market definition papers. He is also a natural technology curmudgeon.
Wednesday, February 09, 2011
Public Clouds : An Unregulated Utility
Friday, August 06, 2010
Storm Clouds Approaching
Monday, May 17, 2010
Building Castles in the Clouds
Despite my best intentions, I keep having conversations about cloud computing. This probably means it's almost in the mainstream. As both of my faithful readers know, I've been a bit critical of cloud computing. Not so much the idea of cloud computing itself. It's more about everyone piling onto the concept even where it is inappropriate. I also find the discussion of private versus public clouds mostly irrelevant. That's a business decision related to how you want to cost out IT. It has nothing to do with technology.
Having had a bit of time to think about it, here's what I think it is and isn't about. In a nutshell:
It's about running enterprise applications, wholly or in part , somewhere out in the IT infrastructure. You don't care where so long as it's somewhere appropriate. From a software perspective, it means instantiating application objects but not caring where that happens so long as it meets the needs of the object.
It's about metered usage, either as a service or in-house. Paying for only what you use is very attractive.
It's about better application resource utilization. You save money when you don't overbuy. Another way to look at it is that you align resources to how critical something in the application space is.
It's about flexibility. Being able to run application objects anywhere in the infrastructure means less dependence on certain assets. Makes for better availability and more cost savings.
Public versus private cloud arguments are only valid or relevant when talking about how you pay for IT. If it is in your best interest to convert a CAPEX to a variable expense, by all means go for the public cloud. The same is true when thinking of personnel costs. You might not have the expertise to run a private cloud so you either hire or go outside. These are classic outsourcing decisions.
Often, a cloud uses a virtualized hardware environment (storage, servers, and networks). but it doesn't have to. The virtual application space is what matters. That's why we have middleware.
The last point is key. While virtualized servers and storage provide a great environment for running a cloud, it's not necessary. It's the middleware environment that matters. For example, a lot of what we think of as cloud computing is achievable using existing Java 2 Enterprise Edition (J2EE) technology. J2EE environments, such as JBOSS, perform all the tasks needed to build a cloud. It handles:
Persistence
Coherency
Distribution
Synchronization
Object Caching and Reuse
J2EE allows you to instantiate objects on any physical server running the J2EE application server. It doesn't matter if that server is virtual or not. While that might be a good idea, it's not necessary to make a cloud.
One look at Google's cloud SDK tells the story. You import a library of Java objects that interact with the Google cloud and voila! Your application objects are running in their cloud. You could conceivably run some objects in their cloud and others in-house. It's not that easy of course but pretty close. Google provides all the infrastructure that you need to instantiate and manage application objects elsewhere. How they do it is unimportant.
The ultimate cloud would be virtual everything of course. That way you get maximum alignment and utilization. Virtual servers using virtualized/federated storage, with middleware that provides a virtual application space would meet the needs of a cloud nicely.
But in the end, it's the software that counts. The application is what it is really all about.
Wednesday, January 27, 2010
Nice. Not Thrilling But Nice.
I'm a bit puzzled by the recent Cisco-NetApp-VMWare announcement. Besides wondering how VMWare was even allowed to sleep with EMC's enemy, its focus on multi-tenancy security has me a a bit confused. Not confused in the “what the heck are they talking about” way. More of the “So what do they have to do with it anyway” manner.
Multi-tenancy is the sharing of an application amongst different users who, if they had their way, would much rather not share the same air . I saw this in the IP management software and call center outsourcing businesses. In both cases, customers needed to be assured that their incredibly valuable and secret data could never be viewed by someone else. For the outsourced software services provider, such as Salesforce.com, this is a a pain in the neck. An understandable one but a pain none-the-less. To get the economies of scale outsourcers need to be profitable, it is best if you don't have to repeat yourself too much. Multiple instances of the same applications require more hardware, more software licenses, and more maintenance. In other words, more costs.
In most cases, if an application is designed correctly you can use a (logically) single application and database for everyone. That's the crux of the matter – if it's designed right. Bugs happen and there is the potential for data to be exposed to the wrong people. This is a rare occurrence but people worry about it anyway. Customers should worry about backup processes more since there is much more risk there. It's like worrying about getting hit by a meteor. It can happen but almost never does. Meanwhile, you don't worry about getting in your car and driving on the highway. Guess which one is more likely to get you killed.
This intense customer worry drives many outsourced service providers to either give almost no guarantees about security of data or physically segregate data on different servers running separate instances of the application. Virtualization helps a lot in that you can run reasonably secure instances of applications on the same hardware with little chance of bleed over. Everyone gets their own application space but not their own physical box which cuts down on hardware costs. It still doesn't solve the major problem - the need to reduce the number of instances of databases and applications. Repeating software is expensive and still a problem.
This brings me back to the “Huh?” look on my face. While it's nice to see Cisco, NetApp and VMWare working together to support a secure virtual environment, it doesn't solve the main problem of multi-tenancy. You can already virtualize the heck out of your environment to save on hardware costs. Great, but that's not what the people in multi-tenancy environments really need. They need to run one instance of their database and one instance of their application and be sure that any one customer can't see another's data. One application that can act like a dozen applications. They need virtualized applications.
These applications exist. I've designed and marketed a couple myself. The problem is that customers don't believe it. They feel that if data is in one place or accessed from the same application, then it is a hazardous environment. That's not true of course. Your bank is able to keep your records secure from other users even when accessed online. These applications can be built now. Virtualized hardware resources don't really impact that.
What the new triumvirate (or Axis of Evil depending on who you talk to) is developing is great stuff for hardware service providers wanting to sell virtual resources. It's good for IT departments looking to save on hardware costs through high utilization. It really doesn't solve the multi-tenancy problem any more than VMWare, NetApp, or Cisco products do alone. It's fundamentally an application software problem that needs to be solved by application software vendors. Multi-tenancy problems need to be solved by Oracle, IBM, and Microsoft.
Now that would be a mind blowing announcement.
Monday, October 12, 2009
Lost In The Clouds
Ah! Lost in the clouds again.
Sounds nice right, unless you're a T-Mobile customer. In that case, lost in the clouds means your data was lost during an upgrade. Too bad. Most of the attention in the blogsphere has been centered on how stupid this appears. A lot of folks are railing against how avoidable this was, how best practices for data protection are well known, how unfortunately common this sort of thing is, etc. I wrote a book on that stuff years ago and it was not new then. Well, some of it was new but the basic blocking and tackling wasn't.
The central issue is being avoided though. It's uncomfortable to address if your company is involved in any type of outsourcing, and what major computer company isn't these days. In all the moaning about how Hitachi Data Systems and Microsoft (T-Mobile partners in this fiasco) should have done better, in all the technical details, in all the posturing about best practices, the core problem with outsourcing is being ignored.
Trust.
I don't care if it is Cloud Computing, call centers, data centers, or overnight delivery. When you outsource you have to trust the outsourcer to do as good or better a job as you would. You can't be looking over their shoulder 24/7. They can't have you in their shorts either. For the relationship to work there needs to be a lot of trust.
I have been on both sides of the outsourcing game. When you hand over a mission critical functions to someone else you have to do your homework. You have a duty to make sure that the outsourcer has the capabilities, best practices, and determination to do your business the way you need it done. They have to look out for your interests. It's a relationship that needs attention.
This is the problem with outsourced Cloud Computing. You have to have the expertise to evaluate your outsourcing partners, the time to conduct appraisals and look at references, and people to monitor performance and deal with problems. I'm not saying that T-Mobile didn't do this. Bad things happen to good companies. But with the hype around outsourced clouds, a lot of trust is being handed over to folks whose abilities are barely known. It's like getting married after the first date. And in this case, what happens in Vegas ends up all over the Internet. Like Paris Hilton, but I digress...
What worries me is that a lot of folks will get sucked in by the Cloud Computing hype who are not ready to do it right. I especially worry about smaller outfits with fewer resources. To them, Amazon S3 is a god send (not to pick on Amazon). Or Mozy for that matter. Solves a problem cheap and quick. Just what everyone wants. Don't worry. They're big companies. We can trust them, right? Right...
Trust takes time and effort. Any type of outsourcing, Cloud Computing or otherwise, requires a lot of trust. Go slow, take your time, and get to know each other first. You have the rest of your lives together. No need to rush.
Thursday, August 27, 2009
Cloudy Skies This Week
Recent blog posts and comments I made on Twitter might give some people the impression that I'm against cloud computing. I bet I've given some people the impression that I hate cloud computing. Despise it! Want to see it die! Nothing could be further from the truth. I love the idea of cloud computing. It's the cloud computing marketing that I take issue with.
Overall, what's not to like about the cloud idea? The promise of cloud computing (notice I say promise, not reality) is the ability to only buy what you need with the option to buy more later if you want to. In that respect, it deals with one of the key problems in computing: coarse granularity in systems. If I need 10 percent of a server, I might have to buy a whole server. Someday I might need that whole server but not right at the moment. Then again, maybe never. We have wonderful terms for buying more than you need such as underutilization. The best term is “a waste of money”. So, buying only what I need when I need it is a great way to manage my budget. Same goes for software. I no longer have to buy a software package designed for fifty people for just three people to use. It's efficient and cost effective. It also makes it easier to quantify the cost of running an application.
Cloud computing is also evolution not revolution. We have been doing limited purpose cloud computing for years. It's called web hosting. And email hosting. Oh. And application hosting. Do I notice when my hosting provider adds new resources in order to add more customers. Not really. I pay ten bucks and get a chunk of resources adequate to running my simple web site and that's how I like it.
So what's not to like? Well a couple of things really. Security of a cloud is no better than security in a non-cloud data center. You still have the problems of internal espionage, external break-ins, and other Dick Tracy stuff.
There is also a migration problem. When the day comes that your application needs to move to a dedicated system (don't kid yourself – it will happen), you might have a heck of a time moving it. Unlike moving up to a bigger piece of iron, applications may have to be rebuilt to live in a different type of environment. In that way, I suppose, it is different. It's worse... and nobody wants that.
This is especially true of clouds built around service frameworks like Amazon's. At some point the application might get big enough that it makes sense to bring it in house. Worse yet, you could find yourself dissatisfied with the service provider (like that never happens!) and forced into an acrimonious divorce. This is an especially nasty problem because they have you by the data stores if you get my meaning.
These are not reasons to forgo the cloud. They are reasons to be careful. Figure these issues out ahead of time and make good choices up front. And ignore the hype. If someone slaps “cloud” on something that seems not so cloudy, be suspicious.
Remember, cloud computing is a strategy and maybe an architecture. It's not a product no matter how many times the corporate talking head says so.
Monday, August 24, 2009
Green Clouds and Other Sickening Stuff
Last week I rented a car from Hertz that was supposed to be a “Green Collection” car. Since it was a Ford Fusion, I assumed they meant the Ford Fusion Hybrid. Hybrids are green. This car, however, was not a hybrid. It was a plain old Ford Fusion. I read the fine print and discovered that Hertz defines green as “ fuel efficient, environmentally-friendly cars”. The cars are all EPA rated at 28 mpg but no one gets that with normal driving. Now, a mid-sized sedan that got 23 miles to the gallon on average doesn't seem all that green to me. My fairly large crossover does better (and is rated better ) than that.
Which brings me to my latest pet peeve - meaningless and overused marketing terms that appear to have real meaning. Like “lite”, both green and cloud computing are overused and under defined. Both have come to mean almost anything some slick Willy marketeer wants them to mean.
Green, in the case of Hertz cars, doesn't mean really environmentally friendly. It means not as unfriendly as some other cars. Sort of a “we stink less” kind of promise. That's not what most people understand green to mean. Ask anyone what green is and they will tell you that it somehow helps or enhances the environment, like clean energy.
And all you computer geeks out there should not get too uppity since we have the same problem with cloud computing (and green computing for that matter). Steve Duplessie of ESG has the best definition of cloud computing that I have seen to date. He described it as a strategy for utilization and purchasing. That sentiment is a good description but drives product managers apoplectic. When you sell servers, storage, or software (or increasingly all three) you can't get people to buy a strategy. You need customers to buy stuff. Real stuff. Stuff that can be shipped in a box. You can't ship strategy.
So the response is to slap the word cloud on everything from hardware to software to services. Like green, it's meant to make people feel virtuous about buying something. I buy some VMWare software and slap it on a “cloud capable” server and I doing the cloud thing! Aren't I smart. I buy some offsite storage like Amazon S3 or rent a piece of software from Google instead of buying it and I'm the cloud king! Woo hoo!
There are two outcomes for this type of overheated terminology. One, sooner or later folks wise up and start to get annoyed at the labels, even when they are useful labels. Second, they get confused and stop buying the stuff we need to sell to stay in business. We came perilously close to that with SAN and NAS ten years ago and “Web 2.0” almost became a dirty word. Everyone get hurt when we do this sort of thing.
Here's my rules of thumb regarding marketing terms:
When one term can mean many different things, it's a bad term.
If you need white papers to simply describe what you mean, it's a bad term.
If you start to see a term everywhere even where you shouldn't, it's a bad term. Or at least has jumped the shark.
If you ask five people what something means and get three different answers, it's a bad term.
If VC's are investing in something with that term, it's a bad term. Just kidding about the VC's. We love you guys. Give us money!
What I'm waiting on now is Pond Computing. You know, green and cloudy.
Monday, May 18, 2009
Get Off Of My Cloud
With Oracle's recent acquisitions of VirtualIron and Sun Microsystems, it would appear that they are positioning themselves as a player in the emerging area of cloud computing. Last year when I was buying IT resources, the concept of purchasing virtualized resources sounded really good. No more tying up money in data centers. No more hiring people to babysit hardware and software systems. Instead, investment and attention would all be focused on developing applications that created revenue for the company. Why not just buy hunks of processor, memory, disk and bandwidth from someone whose job it was to provide infrastructure? They make money and I don't have to tie up precious capital in hardware that goes obsolete. The nice thing about applications is that they are forever. Hardware, on the other hand, is like a car – it starts to depreciate the minute it leaves the showroom.
A funny thing happen on the way to the cloud though. I began to worry about privacy and long term viability. Some data is so valuable that you don't want anyone taking a peak at it. Intellectual property records, social security numbers, patient data, and the like can't be trusted to anyone but yourself. This is not the same as Saleforce.com type data. If my data was sitting on someone's SAN, how could I be sure no one messed with it? When I rented a server that was pretty easy. I could look at the server, check out the storage, and see what the logs told me myself. Fairly basic protections could go a long way towards making me feel secure.
The public cloud however provides none of that. You know practically nothing about the security of the systems. Amazon S3 is a great idea until you realize that you are handing your data over to Amazon with only their reassurances that everything will be alright. You can't see or touch their gear because it's in the cloud somewhere. Given the proclivity of large companies to misuse data and ignore privacy, it seems foolish to give it over to a faceless cloud.
Even if you assume the best, a public cloud requires a level of trust in the provider that is unknown in recent memory and perhaps unprecedented. Do you really trust Google with your data? Do you think they will always make decisions that are in your interest and not there's? Of course not.
And what happens when the cloud evaporates one day? We've seen large numbers of online applications disappear in the recession. What makes us think that you cloud provider, especially the smaller ones, won't join them. Remember the Storage Service Provider fiasco when SSP when boom in the Internet bust? What will you do if your cloud providers goes belly up? Replacing an ISP or even a rented server is fairly easy. You find another one. Can you find another cloud to sit on quickly? And can you adapt your applications to the new cloud in time?
Note that I said “public cloud”. Building your own cloud is fundamentally different. It's just another form of cost effective architecture. That's where I think Oracle will go with all this. Given Sun's ability to deliver a data center in a cargo container, coupled with VirtualIron's software and Oracle applications, they will be able to deploy an entire private cloud to your doorstep. I envision a tractor trailer pulling up and leaving a cargo container with a data center in my back yard. One can dream can't one.
Cloud technology has a lot of advantages. That's been talked about ad nausem. You get many of those advantages even if you own it. A private cloud allows you to have the benefits of a virtualized environment without the privacy and security problems. Public clouds are risky. They might be inevitable but don't get your heads into the clouds lightly.
