Tom Petrocelli's take on technology. Tom was a IT industry executive, analyst, and practitioner as well as the author of the book "Data Protection and Information Lifecycle Management" and many technical and market definition papers. He is also a natural technology curmudgeon.

Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Wednesday, February 09, 2011

Public Clouds : An Unregulated Utility

What is a utility? It’s a little like art or pornography – we know it when we see it.
Public cloud services such as backup services, photograph storage like Flickr, and email like Gmail are quickly becoming completely ingrained in the fabric of modern life. The Internet offers a host of free or low-cost services that we come to rely on for managing, storing, and sharing our data. In fact we have become as dependent on these services almost as much as phone, electricity, and energy services. To me that makes them data utilities but unregulated ones.  And that’s dangerous.
In the past one of the defining elements of a utility was a sanctioned monopoly. There was only one gas company, only one phone company, and only one water company. If you didn’t like their service or their prices then tough! Back in the day, when our US Presidents were manly men who acted manly and had manly mustaches (such as Teddy Roosevelt), it was decided that this was a bad thing. These monopolies had the people by the… throat and that would not do. However, these were not just manly politicians. They were reasonably intelligent ones (and a few may have been receiving perfectly legal contributions from the utilities) who understood the importance of monopolies to early business development. So they struck a bargain. You get to keep your monopoly Mr. Phone Company President and we will regulate you and tell you what you can charge, what your service (i.e. product) will be like, and everyone will be happy. The people won’t get a royal screwing (we being Americans and not liking royal anything one bit) and the monopoly/utility will get unreasonable amounts of money. Bully for us!
Then, in an era of still manly Presidents (Yes sir Mr. Reagan sir!) but less manly politicians in general, things changed. Competition was the byword and deregulation become the way to do business like an American. Let the market, not big government, decide. However, deregulation does not mean no regulation. You see Mr. Cable Company CEO, you still need to pull wire through OUR towns. So we can tell you what to do. You still have a market share that is monopolistic? That means we can still regulate you so that we have no royal anything going on here in America. And this is why the cable company can’t raise rates when it wants to. What could be more un-American than making 500 channels of television unaffordable! Wars have been fought for less.
So what does this have to do with Public Cloud services. Even if you are enjoying the spirited economic history lesson (bully for you!) it is a reasonable question. You see, as we become more and more dependent on cloud services for functions that are important to our lives, they have us by the throats again. Do you want to see your photos disappear suddenly? Could you really live without Facebook? Not if you’re a 17 year old girl. Take away Facebook and their phones and you have a mental health crisis on your hands. Worse, if you are a small business that is using an online backup service or email from Google, Yahoo, etc. you rely on it to make your living. Don’t want that living to dry up so that you have to live in a cardboard box? Pay up! Mr. Roosevelt would not be amused.
This is only getting worse as smaller companies embrace cloud services for IT. Salesforce, Amazon, Google, and a host of other companies provide services that are critical to business. Worse, moving from one service to another is not trivial. Go ahead, try and change your email account, the one that all of your customers already have in their address books. It would become a symphony of missed opportunities.
Let’s take Mozy as an example. When they recently announced changes to their service plans, they did so as if it was just any old product – they just did it. Sure they risk losing customers especially amongst the geeky crowd. Clearly that isn’t bothering them too much. Why? Because changing is a pain and quite difficult for people who don’t know much about technology. For geeks like me, switching to another service isn’t all that hard. [Note: It was real easy for me personally because I didn’t use Mozy. Tried it years ago and didn’t much like it.] For the average American who got Mozy bundled with their new laptop, has no home infrastructure, and is scared stupid of losing their latest podcast about hipster living in New York City, switching is beyond them.
So Mozy, like lots of other cloud services, has nearly unlimited pricing power. They have their customers by the throat. For them, pouring costs into gaining new customers makes perfect sense. Worrying about losing them doesn’t. These people can’t really leave even if they want to. This is the modern definition of a utility. This is not to pick on Mozy (okay maybe a little) because there are lots of similar cloud services that have the same model. Herd in the cattle, pen them up, and do what you want to them.
Here’s what I think will happen. Nothing.
We do not live in an era of government officials with marvelous mustaches. They lack the moxie to stand up to a banking industry capable of bringing the entire world economy to its knees. Why would we expect them to even care about unregulated data utilities? That is, until they are forced to choose between losing their pictures of themselves with celebrities or paying through the nose to people who don’t contribute to their campaigns.
As consumers, what can we do. Be careful. Know the technology that you rely on enough to switch to a competitor. Build you own infrastructure and make the cloud secondary. All good ideas that enhance good ole American competition. It still won’t help when Facebook decides to start charging. Then you will have to man up and do without. Bully for you!
If I was a cloud service, I would starting looking at lobbyists and handing out contributions. You never know when a a member of the House Committee on  Committee on Science, Space, and Technology will suddenly be faced with paying to share pictures of their grandkids. Then you will see just how manly our government can be.
Fun U.S. History fact: The last U.S. President to sport a fantastic mustache in office was President Taft. Mr. Obama, it’s time!

Friday, August 06, 2010

Storm Clouds Approaching

IT shops have gotten to the point where they have a good handle on managing servers, networks, and storage. Headway is being made toward managing their virtual equivalents. Now, we have to add cloud computing to the mix. Cloud management may be the next great pain in the neck for IT shops. At the moment, not enough folks are seriously deploying in the cloud for it to be a crisis. That will change as more IT professionals accept cloud computing as something they can use to manage that tricky balance between cost and performance.
There are two paths we can go down (but in the long run) there’s still time to screw things up1. First, if cloud systems management is too difficult and the tools too primitive for too long, deployment to the cloud will be much slower and might even reverse. If, however, the benefits of the cloud are enough that deployment continues apace, sysadmins and programmers alike will find themselves wishing for someone to put them out of their misery. The sheer lack of tools will drive them to drink.
Cloud management is unlike other systems administration. Usually big chunks of an application, such as a service, are deployed to servers. With clouds, little bits of application, including individual and transient objects can be anywhere. Worse yet, individual objects might be parceled out to different clouds depending on their resource or security needs. It is possible to have different objects instantiated on different cloud services, public and private, which in turn execute them on different physical resources. Distribution on this scale can be very tough to deal with on conventional systems. No one is really sure how that will play out in a cloud.
The other big difference between clouds and other infrastructure, at least public clouds, is that you don’t necessarily have much visibility into the infrastructure. Managing applications that are not only distributed in a cloud but hidden behind a vendor’s veil of secrecy is like driving in a blinding snow storm. I don’t recommend it. There’s too much trust in the unseen and unknown.
How do you manage this type of environment? One approach is to build monitoring into the individual application objects. Daesin, an open source cloud API written for Java, allows this. Problem is that you have to build monitoring into your application objects and may be language dependant.
Standards will make a difference. The DMTF just announced an initiative for cloud monitoring called the Open Cloud Standards. DMTF management standards have spurred vendors to develop management products in the past.  Open cloud interfaces such as Open Stack will also help since it will provide an open and standard platform for accessing clouds. These type of standards make it easier to develop software to manage cloud services. Right now, folks who develop cloud infrastructure software such as TwinStrata have to interact with nearly a dozen APIs from many different vendors. It’s basically a Tower of Babel which makes software development much more difficult. Development will become easier when there is a single or limited number of APIs to deal with. When development is easier more tools will become available.
So, if you truly be believe that clouds are the next big thing, the next SAN/NAS or the next J2EE or .Net, then you need to start worrying about how to manage them. Now. 

1. My apologies to Led Zeppelin. Stairway to Heaven does not deserve that kind of abuse.

Monday, May 17, 2010

Building Castles in the Clouds

Despite my best intentions, I keep having conversations about cloud computing. This probably means it's almost in the mainstream. As both of my faithful readers know, I've been a bit critical of cloud computing. Not so much the idea of cloud computing itself. It's more about everyone piling onto the concept even where it is inappropriate. I also find the discussion of private versus public clouds mostly irrelevant. That's a business decision related to how you want to cost out IT. It has nothing to do with technology.

Having had a bit of time to think about it, here's what I think it is and isn't about. In a nutshell:

  • It's about running enterprise applications, wholly or in part , somewhere out in the IT infrastructure. You don't care where so long as it's somewhere appropriate. From a software perspective, it means instantiating application objects but not caring where that happens so long as it meets the needs of the object.

  • It's about metered usage, either as a service or in-house. Paying for only what you use is very attractive.

  • It's about better application resource utilization. You save money when you don't overbuy. Another way to look at it is that you align resources to how critical something in the application space is.

  • It's about flexibility. Being able to run application objects anywhere in the infrastructure means less dependence on certain assets. Makes for better availability and more cost savings.

  • Public versus private cloud arguments are only valid or relevant when talking about how you pay for IT. If it is in your best interest to convert a CAPEX to a variable expense, by all means go for the public cloud. The same is true when thinking of personnel costs. You might not have the expertise to run a private cloud so you either hire or go outside. These are classic outsourcing decisions.

  • Often, a cloud uses a virtualized hardware environment (storage, servers, and networks). but it doesn't have to. The virtual application space is what matters. That's why we have middleware.

The last point is key. While virtualized servers and storage provide a great environment for running a cloud, it's not necessary. It's the middleware environment that matters. For example, a lot of what we think of as cloud computing is achievable using existing Java 2 Enterprise Edition (J2EE) technology. J2EE environments, such as JBOSS, perform all the tasks needed to build a cloud. It handles:

  • Persistence

  • Coherency

  • Distribution

  • Synchronization

  • Object Caching and Reuse

J2EE allows you to instantiate objects on any physical server running the J2EE application server. It doesn't matter if that server is virtual or not. While that might be a good idea, it's not necessary to make a cloud.

One look at Google's cloud SDK tells the story. You import a library of Java objects that interact with the Google cloud and voila! Your application objects are running in their cloud. You could conceivably run some objects in their cloud and others in-house. It's not that easy of course but pretty close. Google provides all the infrastructure that you need to instantiate and manage application objects elsewhere. How they do it is unimportant.

The ultimate cloud would be virtual everything of course. That way you get maximum alignment and utilization. Virtual servers using virtualized/federated storage, with middleware that provides a virtual application space would meet the needs of a cloud nicely.

But in the end, it's the software that counts. The application is what it is really all about.

Wednesday, January 27, 2010

Nice. Not Thrilling But Nice.

I'm a bit puzzled by the recent Cisco-NetApp-VMWare announcement. Besides wondering how VMWare was even allowed to sleep with EMC's enemy, its focus on multi-tenancy security has me a a bit confused. Not confused in the “what the heck are they talking about” way. More of the “So what do they have to do with it anyway” manner.

Multi-tenancy is the sharing of an application amongst different users who, if they had their way, would much rather not share the same air . I saw this in the IP management software and call center outsourcing businesses. In both cases, customers needed to be assured that their incredibly valuable and secret data could never be viewed by someone else. For the outsourced software services provider, such as Salesforce.com, this is a a pain in the neck. An understandable one but a pain none-the-less. To get the economies of scale outsourcers need to be profitable, it is best if you don't have to repeat yourself too much. Multiple instances of the same applications require more hardware, more software licenses, and more maintenance. In other words, more costs.

In most cases, if an application is designed correctly you can use a (logically) single application and database for everyone. That's the crux of the matter – if it's designed right. Bugs happen and there is the potential for data to be exposed to the wrong people. This is a rare occurrence but people worry about it anyway. Customers should worry about backup processes more since there is much more risk there. It's like worrying about getting hit by a meteor. It can happen but almost never does. Meanwhile, you don't worry about getting in your car and driving on the highway. Guess which one is more likely to get you killed.

This intense customer worry drives many outsourced service providers to either give almost no guarantees about security of data or physically segregate data on different servers running separate instances of the application. Virtualization helps a lot in that you can run reasonably secure instances of applications on the same hardware with little chance of bleed over. Everyone gets their own application space but not their own physical box which cuts down on hardware costs. It still doesn't solve the major problem - the need to reduce the number of instances of databases and applications. Repeating software is expensive and still a problem.

This brings me back to the “Huh?” look on my face. While it's nice to see Cisco, NetApp and VMWare working together to support a secure virtual environment, it doesn't solve the main problem of multi-tenancy. You can already virtualize the heck out of your environment to save on hardware costs. Great, but that's not what the people in multi-tenancy environments really need. They need to run one instance of their database and one instance of their application and be sure that any one customer can't see another's data. One application that can act like a dozen applications. They need virtualized applications.

These applications exist. I've designed and marketed a couple myself. The problem is that customers don't believe it. They feel that if data is in one place or accessed from the same application, then it is a hazardous environment. That's not true of course. Your bank is able to keep your records secure from other users even when accessed online. These applications can be built now. Virtualized hardware resources don't really impact that.

What the new triumvirate (or Axis of Evil depending on who you talk to) is developing is great stuff for hardware service providers wanting to sell virtual resources. It's good for IT departments looking to save on hardware costs through high utilization. It really doesn't solve the multi-tenancy problem any more than VMWare, NetApp, or Cisco products do alone. It's fundamentally an application software problem that needs to be solved by application software vendors. Multi-tenancy problems need to be solved by Oracle, IBM, and Microsoft.

Now that would be a mind blowing announcement.

Monday, October 12, 2009

Lost In The Clouds

Ah! Lost in the clouds again.

Sounds nice right, unless you're a T-Mobile customer. In that case, lost in the clouds means your data was lost during an upgrade. Too bad. Most of the attention in the blogsphere has been centered on how stupid this appears. A lot of folks are railing against how avoidable this was, how best practices for data protection are well known, how unfortunately common this sort of thing is, etc. I wrote a book on that stuff years ago and it was not new then. Well, some of it was new but the basic blocking and tackling wasn't.

The central issue is being avoided though. It's uncomfortable to address if your company is involved in any type of outsourcing, and what major computer company isn't these days. In all the moaning about how Hitachi Data Systems and Microsoft (T-Mobile partners in this fiasco) should have done better, in all the technical details, in all the posturing about best practices, the core problem with outsourcing is being ignored.

Trust.

I don't care if it is Cloud Computing, call centers, data centers, or overnight delivery. When you outsource you have to trust the outsourcer to do as good or better a job as you would. You can't be looking over their shoulder 24/7. They can't have you in their shorts either. For the relationship to work there needs to be a lot of trust.

I have been on both sides of the outsourcing game. When you hand over a mission critical functions to someone else you have to do your homework. You have a duty to make sure that the outsourcer has the capabilities, best practices, and determination to do your business the way you need it done. They have to look out for your interests. It's a relationship that needs attention.

This is the problem with outsourced Cloud Computing. You have to have the expertise to evaluate your outsourcing partners, the time to conduct appraisals and look at references, and people to monitor performance and deal with problems. I'm not saying that T-Mobile didn't do this. Bad things happen to good companies. But with the hype around outsourced clouds, a lot of trust is being handed over to folks whose abilities are barely known. It's like getting married after the first date. And in this case, what happens in Vegas ends up all over the Internet. Like Paris Hilton, but I digress...

What worries me is that a lot of folks will get sucked in by the Cloud Computing hype who are not ready to do it right. I especially worry about smaller outfits with fewer resources. To them, Amazon S3 is a god send (not to pick on Amazon). Or Mozy for that matter. Solves a problem cheap and quick. Just what everyone wants. Don't worry. They're big companies. We can trust them, right? Right...

Trust takes time and effort. Any type of outsourcing, Cloud Computing or otherwise, requires a lot of trust. Go slow, take your time, and get to know each other first. You have the rest of your lives together. No need to rush.

Thursday, August 27, 2009

Cloudy Skies This Week

Recent blog posts and comments I made on Twitter might give some people the impression that I'm against cloud computing. I bet I've given some people the impression that I hate cloud computing. Despise it! Want to see it die! Nothing could be further from the truth. I love the idea of cloud computing. It's the cloud computing marketing that I take issue with.

Overall, what's not to like about the cloud idea? The promise of cloud computing (notice I say promise, not reality) is the ability to only buy what you need with the option to buy more later if you want to. In that respect, it deals with one of the key problems in computing: coarse granularity in systems. If I need 10 percent of a server, I might have to buy a whole server. Someday I might need that whole server but not right at the moment. Then again, maybe never. We have wonderful terms for buying more than you need such as underutilization. The best term is “a waste of money”. So, buying only what I need when I need it is a great way to manage my budget. Same goes for software. I no longer have to buy a software package designed for fifty people for just three people to use. It's efficient and cost effective. It also makes it easier to quantify the cost of running an application.

Cloud computing is also evolution not revolution. We have been doing limited purpose cloud computing for years. It's called web hosting. And email hosting. Oh. And application hosting. Do I notice when my hosting provider adds new resources in order to add more customers. Not really. I pay ten bucks and get a chunk of resources adequate to running my simple web site and that's how I like it.

So what's not to like? Well a couple of things really. Security of a cloud is no better than security in a non-cloud data center. You still have the problems of internal espionage, external break-ins, and other Dick Tracy stuff.

There is also a migration problem. When the day comes that your application needs to move to a dedicated system (don't kid yourself – it will happen), you might have a heck of a time moving it. Unlike moving up to a bigger piece of iron, applications may have to be rebuilt to live in a different type of environment. In that way, I suppose, it is different. It's worse... and nobody wants that.

This is especially true of clouds built around service frameworks like Amazon's. At some point the application might get big enough that it makes sense to bring it in house. Worse yet, you could find yourself dissatisfied with the service provider (like that never happens!) and forced into an acrimonious divorce. This is an especially nasty problem because they have you by the data stores if you get my meaning.

These are not reasons to forgo the cloud. They are reasons to be careful. Figure these issues out ahead of time and make good choices up front. And ignore the hype. If someone slaps “cloud” on something that seems not so cloudy, be suspicious.

Remember, cloud computing is a strategy and maybe an architecture. It's not a product no matter how many times the corporate talking head says so.

Monday, August 24, 2009

Green Clouds and Other Sickening Stuff

Last week I rented a car from Hertz that was supposed to be a “Green Collection” car. Since it was a Ford Fusion, I assumed they meant the Ford Fusion Hybrid. Hybrids are green. This car, however, was not a hybrid. It was a plain old Ford Fusion. I read the fine print and discovered that Hertz defines green as “ fuel efficient, environmentally-friendly cars”. The cars are all EPA rated at 28 mpg but no one gets that with normal driving. Now, a mid-sized sedan that got 23 miles to the gallon on average doesn't seem all that green to me. My fairly large crossover does better (and is rated better ) than that.

Which brings me to my latest pet peeve - meaningless and overused marketing terms that appear to have real meaning. Like “lite”, both green and cloud computing are overused and under defined. Both have come to mean almost anything some slick Willy marketeer wants them to mean.

Green, in the case of Hertz cars, doesn't mean really environmentally friendly. It means not as unfriendly as some other cars. Sort of a “we stink less” kind of promise. That's not what most people understand green to mean. Ask anyone what green is and they will tell you that it somehow helps or enhances the environment, like clean energy.

And all you computer geeks out there should not get too uppity since we have the same problem with cloud computing (and green computing for that matter). Steve Duplessie of ESG has the best definition of cloud computing that I have seen to date. He described it as a strategy for utilization and purchasing. That sentiment is a good description but drives product managers apoplectic. When you sell servers, storage, or software (or increasingly all three) you can't get people to buy a strategy. You need customers to buy stuff. Real stuff. Stuff that can be shipped in a box. You can't ship strategy.

So the response is to slap the word cloud on everything from hardware to software to services. Like green, it's meant to make people feel virtuous about buying something. I buy some VMWare software and slap it on a “cloud capable” server and I doing the cloud thing! Aren't I smart. I buy some offsite storage like Amazon S3 or rent a piece of software from Google instead of buying it and I'm the cloud king! Woo hoo!

There are two outcomes for this type of overheated terminology. One, sooner or later folks wise up and start to get annoyed at the labels, even when they are useful labels. Second, they get confused and stop buying the stuff we need to sell to stay in business. We came perilously close to that with SAN and NAS ten years ago and “Web 2.0” almost became a dirty word. Everyone get hurt when we do this sort of thing.

Here's my rules of thumb regarding marketing terms:

  1. When one term can mean many different things, it's a bad term.

  2. If you need white papers to simply describe what you mean, it's a bad term.

  3. If you start to see a term everywhere even where you shouldn't, it's a bad term. Or at least has jumped the shark.

  4. If you ask five people what something means and get three different answers, it's a bad term.

  5. If VC's are investing in something with that term, it's a bad term. Just kidding about the VC's. We love you guys. Give us money!

What I'm waiting on now is Pond Computing. You know, green and cloudy.

Monday, May 18, 2009

Get Off Of My Cloud

With Oracle's recent acquisitions of VirtualIron and Sun Microsystems, it would appear that they are positioning themselves as a player in the emerging area of cloud computing. Last year when I was buying IT resources, the concept of purchasing virtualized resources sounded really good. No more tying up money in data centers. No more hiring people to babysit hardware and software systems. Instead, investment and attention would all be focused on developing applications that created revenue for the company. Why not just buy hunks of processor, memory, disk and bandwidth from someone whose job it was to provide infrastructure? They make money and I don't have to tie up precious capital in hardware that goes obsolete. The nice thing about applications is that they are forever. Hardware, on the other hand, is like a car – it starts to depreciate the minute it leaves the showroom.

A funny thing happen on the way to the cloud though. I began to worry about privacy and long term viability. Some data is so valuable that you don't want anyone taking a peak at it. Intellectual property records, social security numbers, patient data, and the like can't be trusted to anyone but yourself. This is not the same as Saleforce.com type data. If my data was sitting on someone's SAN, how could I be sure no one messed with it? When I rented a server that was pretty easy. I could look at the server, check out the storage, and see what the logs told me myself. Fairly basic protections could go a long way towards making me feel secure.

The public cloud however provides none of that. You know practically nothing about the security of the systems. Amazon S3 is a great idea until you realize that you are handing your data over to Amazon with only their reassurances that everything will be alright. You can't see or touch their gear because it's in the cloud somewhere. Given the proclivity of large companies to misuse data and ignore privacy, it seems foolish to give it over to a faceless cloud.

Even if you assume the best, a public cloud requires a level of trust in the provider that is unknown in recent memory and perhaps unprecedented. Do you really trust Google with your data? Do you think they will always make decisions that are in your interest and not there's? Of course not.

And what happens when the cloud evaporates one day? We've seen large numbers of online applications disappear in the recession. What makes us think that you cloud provider, especially the smaller ones, won't join them. Remember the Storage Service Provider fiasco when SSP when boom in the Internet bust? What will you do if your cloud providers goes belly up? Replacing an ISP or even a rented server is fairly easy. You find another one. Can you find another cloud to sit on quickly? And can you adapt your applications to the new cloud in time?

Note that I said “public cloud”. Building your own cloud is fundamentally different. It's just another form of cost effective architecture. That's where I think Oracle will go with all this. Given Sun's ability to deliver a data center in a cargo container, coupled with VirtualIron's software and Oracle applications, they will be able to deploy an entire private cloud to your doorstep. I envision a tractor trailer pulling up and leaving a cargo container with a data center in my back yard. One can dream can't one.

Cloud technology has a lot of advantages. That's been talked about ad nausem. You get many of those advantages even if you own it. A private cloud allows you to have the benefits of a virtualized environment without the privacy and security problems. Public clouds are risky. They might be inevitable but don't get your heads into the clouds lightly.