Chris Colotti, Principal Architect - VMware

Transcription

Chris Colotti, Principal Architect - VMwarePlatinumsponsors:

vCloud Air Deep Dive 2014 VMware Inc. All rights reserved.

VMware vCloudHybrid ServiceVMware vCloud Air3

2014 VMware Inc. All rights reserved.

What Makes it a HybridData Center?5

What Defines a Hybrid ? hy·brid noun– The offspring of two plants or animals ofdifferent species or varieties, such as a mule(a hybrid of a donkey and a horse).– A thing made by combining two differentelements; a mixture. Adjective– of mixed character; composed of mixed parts.

What Makes it a Hybrid Data Center? Blur the lines between – Users and applications– Applications and infrastructure– Hardware and resources– Operations and management– Support and operations Simplify access to resources Faster time to market More geographic options faster Create a global architecture Treat it like any other physical location

vCloud Air Data Center LocationsNew JerseySterlingSanta ClaraDullesvCGSLas VegasSloughPhoenixvCGSDallasAvailable TodayOpening SoonAll Data Centers: Tier 3 N 1 UPS, Generator Multiple days of on-hand fuel with multiple contracts for emergency resupply Redundant power feeds to all systems8

Use Cases for the HybridData Center9

5 Starting Points to Hybrid CloudDev/TestTake a low-risk firststep and free upvaluable on-premisesdata center capacityby hosting dev/testworkloads in hybridcloudExtend productiontesting for upgradesand host new apps,e.g., MicrosoftExchange in hybridcloudDeliver disasterrecovery and extendthe data center fordev/test, seasonalworkloads, andadditional geolocationsModernizeEnterpriseApplicationsCreate NextGenerationApplicationsBuild and hostbusiness-criticalapplications and virtualdesktops in hybridcloud, including newapplications intraditional 3-tierarchitectures (Java)Evolve from traditionalapplications to nextgeneration applications(Spring, Ruby on Rails)to deliver on anyplatform, anywhere

Think Outside the Box - Free Your Mind If you built a new Physical Data Center what steps are there?– Networking– Infrastructure– Applications Always remember the definition of Hybrid Focus on applications not infrastructure– Get out of the break fix business– Get into the application business Don’t focus on it being “Cloudy”– Just because it’s “In the cloud” means little Forget everything you know about ESXi (to a point)– Wait, What?! Most any use case applies if you treat as any other Data Center

Bridging the Gap Between IT and the BusinessGrowing chasm betweenBusiness and IT due tolack of agilityLine of BusinessRequires speed, agility andthe ability to innovateLack of trust for businesscritical workloads in thepublic cloudITFocused on maintainingreliable, secure infrastructure

vCloud Air The True Hybrid CloudYour Datacenter /Private CloudExisting &New AppsVMware vCloudHybrid ServiceSeamlessNetworkingCommonManagementVMware vSphere &vCloud SuiteOne Support CallSoftware-DefinedData Center13

Any Application, Any OS, Same PlatformSupports a broad range of large-scale andmission-critical applicationsSQLRuns the largest number of guest operatingsystems: Generations of Windows and Linux distributions Both 32-bit and 64-bit editions Enterprise offering or free distributionvCloud Air is based on VMware vSphere - themost broadly deployed and trusted virtualizationplatform in the world

Running the Most Operating Systems – Based on vSphereMicrosoft Azure64-bit only: Windows Server 2008 R2 Windows Server 2012 SQL Server 2012 CentOS 6 SLES11 Ubuntu 12, 13 OpenSUSE 12Amazon Web Services EC2 Windows Server 2003 (32/64)Windows Server 2008 (32/64)Windows Server 2012RHEL 5 (32/64)RHEL 6 (32/64)SLES11 (32/64)Debian Squeeze 6 (32/64)Debian Wheezy (32/64)FreeBSD 9CentOS 6 (32/64)Ubuntu 10 (32/64)Ubuntu 11 (32/64)Ubuntu 12 (32/64)Amazon Linux (32/64)Fedora Core 4Fedora Core 8SLES 10 (32/64)OpenSolaris 2008.11 (32/64)OpenSolaris 2009.06 (32/64)Oracle Linux 5 (64)VMware vCloud Air Total: 8Total: 35 Data collected Sept 12, 2013MS-DOS 6.22Windows 3.1Windows 95Windows 98Windows NTWindows XP (32/64)Windows Vista (32/64)Windows 7 (32/64)Windows 8 (32/64)Windows 2000WinServer 2003 (32/64)WinServer 2008 (32/64)WinServer 2012RHEL 2.1RHEL 3 (32/64)RHEL 4 (32/64)RHEL 5 (32/64)RHEL 6 (32/64)SLES 8SLES 9 (32/64)SLES 10 (32/64)SLES 11 (32/64)SLED 10 (32/64)SLED 11 (32/64)Debian 4 (32/64)Debian 5 (32/64)Debian 6 (32/64)CentOS 4 (32/64) CentOS 5 (32/64)CentOS 6 (32/64)Oracle Linux 4 (32/64)Oracle Linux 5 (32/64)Oracle Linux 6 (32/64)Asianux 3 (32/64)Asianux 4 (32/64)Ubuntu 8 (32/64)Ubuntu 9 (32/64)Ubuntu 10 (32/64)Ubuntu 11 (32/64)Ubuntu 12 (32/64)Ubuntu 13 (32/64)FreeBSD 6 (32/64)FreeBSD 7 (32/64)FreeBSD 8 (32/64)FreeBSD 9 (32/64)Solaris 10 (32/64)Solaris 11IBM OS/2 Warp 4NetWare 5NetWare 6eComStation 1eComStation 2SCO UnixWare 7SCO OpenServer 5Toshiba 4690 6Total: 9015

vCloud Air Core Offerings16

The vCloud Air Primary Services to Mix and MatchIaaSDaaSRaaS

Infrastructure as a Service (IaaS) New applications built onIPsec VPNstandard Operating Systemsview.vmtm.org66.45.200.34PCoIP and 2.0/24Public-NET)– From P2V to V2Ccloud and on premises(192.168.20.0/24Public-NET)– View Security Servers– SharePointDT02(192.168.1.0/24 Corp-NET)ViewCS.5applications Build infrastructure in the(192.168.3.0/24Desktop-NET)DT01 Migration of existingAD01.41ViewSS.5– ExchangeViewSS.5AD02.42WDC (On Premises)vCHS Las Vegas (IaaS)– Web Servers

Desktop as a Service on vCloud Air (DaaS)Windows desktops and apps as a cloud service. Backed by VMware.Simple cloud desktops at a predictable cost, without sacrificing security and controlRemote OfficeMobileWorkersVMware Horizon DaaSVirtual desktop infrastructure, built onvCloud AirCorporate OfficeCorporateWi-Fi

Recovery as a Service(RaaS)Replication to vCloud Air: Warm standby capacity on vCloud Air Self-service protection, failover and failback workflowsper VM 15 min – 24 hr. recovery point objective (RPO) Initial data seeding by shipping a disk– Can be done without Downtime! Remote management and monitoring, with Production-level support Flexible subscription optionsData Protection Option for IaaS Machines Self Service or full vDC backup 365 day retentionvSphereReplication

Understanding the vCloudAir Structure21

How vCloud Air is StructuredTenant PortalDedicated Cloud – Las VegasVPC – VirginiavCloud Director APIvCloud Director APIEdgeNetworkingEdgeNetworkingEdgeNetworking

The vCloud Air Tenant Portal Single Sign-on to all your clouds– View the type of cloud– View by Region Same login for any access– vCloud API– Disaster Recovery Manage additional users– First user is always the uber-admin Manage Data Protection Options– IaaS Backup and Restore Access MyVMware– Order additional resources– Open support tickets

Two Service OfferingsDedicated CloudVirtual Private CloudPhysically IsolatedYour Own Private Cloud InstanceLogically IsolatedGuaranteed Resource AllocationBase Resources: 120GB vRAM 30GHz vCPUComputeBase Resources: 20GB vRAM 5GHz vCPUStarts at: 6 TBStorageStarts at: 2 TB 50 Mbps allocated 1 Gbps burstable Network 3 Public IPs 10 Mbps allocated 50 Mbps burstable 2 Public IPs2424

VMware vCloud Air - Virtual Private Cloud OnDemandInterested in participating in thevCloud Air OnDemand BetaProgam?The Product Team from vCloud Air is nowaccepting candidates interested in participatingin the Fall 2014 beta program.vmware.com/go/ondemandBETA IS CURRENTLY CLOSED25

vCloud Air IaaS Offering ComparisonDedicated CloudVirtual Private Cloud Dedicated Hosts Shared Hosts– More ISV Licensing options Over Commit Built-In Ideal for both– Test and Development– Production workloads needing reservations User controlled per machine settings Sub-divide pool of resources– Create multiple vDC’s Multiple Edge Gateway capability– Get more than 9 Interfaces– Limited ISV Mobility– Cost Effective– Shared API endpoint Fully reserved resources– No over commitment of resources– Eliminates the “Noisy Neighbor” Ideal for initial POC and testing Single Edge Gateway per vDC Used for vCloud Air Disaster Recovery

Treat the Edge Gateway as an Advanced Core Switch Familiar networking designINTERNET 10 total Interfaces per Edge– 1 Edge per VPCEDGEGATEWAY– Multiple Edges in Dedicated Static routes between interfacesautomaticallyTest/Dev NetworkPrivate (Corp) Network 5-tuple firewall rules– Deny all by default Advanced features– DHCP– Load Balancing– Static routingIsolated Network(Logging)DMZ Network

Connectivity to vCloud AirCustomer Data CentervCloud AirPrivate WAN connectivityzIPSec TunnelINTERNETPublicConnectivity Options: Public or secure access to vCloud AirDedicated connection to cloudHigh speed cross connect28

Network Virtualization in vCloud AirvCloud Air NetworkingvCloud AirIntegrated Management ConsolevCloud AirNetworking & SecurityVDC 1VDC 2 Nine routable IP spacesIntuitive design replicates traditional networksCustomizable to support production applicationsEdge GatewaySecures the edge of the virtual data center anddelivers network services: VXLANvSphereFirewallNATLoad BalancerSite-to-Site IPSec VPNActive/Standby High AvailabilityStateful Session FailoverVXLANFoundation for elastic portable virtualdatacenters. Encapsulation allows Isolation between Organization Networks Bring-your-own private IPv4 layer 3 addressspace29

Private Network Connectivity to vCloud AirOverviewINTERNETNEW!EDGEGATEWAY Two port connection options: Standard internet HTTPS IPsec VPN Direct Connect Private Line Cross ConnectBenefits Different price-performance-securityoptions to support different needs Supports more use cases for flexibilityand choice Supports multiple port connections atonce30

vCloud Air DeploymentExamplesCONFIDENTIAL31

IaaS – Distributed 1.155VPNPrivate NetworkLocal Active DirectorySharePoint AppCorp NetworkSharePoint DBActive DirectoryVPN or DirectConnect TrafficSharePoint Web

Mobile Back End With Direct ConnectCustomer Data CentervCloud AirDirect ConnectInternet

3rd Party Networking – F5 ExampleInternet192.40.57.21EDGEGATEWAYDNAT Any:AnyFirewall Any:Any(192.168.200.0/24 Public-NET).100BIP02(10.10.10.0/24 BIP-Internal-NET)(192.168.100.0/24 Corp-NET)AD05AD06

Global Technical Marketing Architecture One Physical Site 3 Virtual Private Clouds– RaaS in Dallas, TXCloud to CloudVPNCloud to CloudVPNDedicated IaaSvDC LVIPsec VPNvmtm.org– IaaS Sterling, VA– IaaS Las Vegas, NVCloud to CloudVPNCloud to CloudVPN 2 Dedicated Clouds– IaaS in Las Vegas, NV– DaaS in Las Vegas, NV IPsec VPN in Use DYN.com hosting all externalDedicated DaaSvDC LVVPC RaaS TX vDCIPsec VPNvCHS-DRReplicationVPC IaaS SterlingVA vDCDaaS SecureTunnelDNS Zone records– vmtm.orgVPC IaaS LV vDC(DaaS Provider)IPsec VPN

vCloud Air Object StorageBetaCONFIDENTIAL36

Service Scope RESTful API basedaccess GUI based managementAccess 99.95% availability 11 9’ of durability Self Healing -Content-MD5and CRC to detect datacorruption Bucket VersioningDurability&Availability Token-based Username and passwordbased Public URLsAuthentication PB scale Object size limit - 20TB 1000 Buckets, UnlimitedObjects Soft quota enforcementScalability

Popular Use CasesBackupArchivingImagingMediaShared File StorageLog repositoryLong term costeffective storagewithoutperformance limitsPetabyte scalestatic data withcustom metadataData repositoryshared data acrossmultiple virtualmachines/Users38

The Five Steps toExtending Your Data CenterBuilding Your Hybrid Data Center39

Step 1 – Size Your Resources (vDC)CPU: 5GHZ (burst 10GHZ)RAM: 20GBStorage: 2TB100% Memory Reservations50% vCPU ReservationLets think about the mathVirtual Private CloudDefine Reservations and LimitsOver CPU:Commitment30 GHZRatioWhat’s yourcomfortlevel today?RAM:120GB5:1? 6TBStorage:10:1? Maybe 20:1?Dedicated CloudWe haven’t forgotten about On-Premises its coming

Step 2 – Design Your TEWAYExternal IP Howmany routed networks?ONPREMISES Create multiple networks for different services EDGEGATEWAYROUTING(192.168.20.0/24Public-NET) 9 Interfacesto utilizeDEVICEExternal IP VPN Configuration Network Settings considerations(192.168.20.0/24 Public-NET) Firewall Rules Firewall rules are always reciprocalNetwork ImpactPrivateonmycurrent environment(10.0.0.0/24) Move my templates to the cloudDC01(192.168.10.0/24 Corp-NET)(192.168.10.0/24 Corp-NET) Other considerationsDC02 BackupEMAIL NetworksvCCNodeDedicated or Virtual Private Cloud

Step 3 – Establish Network ConnectivityPrivate LineINTERNETVPNExternal IPONPREMISESROUTINGDEVICEExternal IPEDGEGATEWAY(192.168.20.0/24 Public-NET)Private Network(10.0.0.0/24)(192.168.10.0/24 Corp-NET)DC01DC02EMAILvCCNodeDedicated or Virtual Private Cloud

Step 4 – Deploy Supporting InfrastructureINTERNETEDGEGATEWAYVPNExternal IPExternal IPONPREMISESROUTING(192.168.20.0/24 Public-NET)DEVICEEDGEGATEWAY(192.168.20.0/24 Public-NET)DNSSMTP(192.168.10.0/24 Corp-NET)DNSSMTPPrivate P01 APP02DC03(192.168.10.0/24 Corp-NET)DC04APP01 APP02Dedicated or Virtual Private Cloud

Step 5 – Expand Your Footprint FurtherDedicated IaaSvDC LVIPsec VPNVPC RaaS TX vDCDaaS vDC

Questions45

Network Virtualization in vCloud Air 29 vCloud Air Networking & Security vCloud Air vSphere VDC 1 VDC 2 VXLAN Integrated Management Console Edge Gateway Secures the edge of the virtual data center and delivers network services: Firewall NAT Load Balancer Site-to-Site IPSec VPN Active/