recommended strategy for hybrid cloud infrastructure · azure dns external dns azure integration...

59
RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE Step-by-step adoption Marcos Garcia Ron Marshall Senior Cloud Solutions Architect Senior Solutions Architect June 2018

Upload: others

Post on 28-May-2020

24 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE

Step-by-step adoption

Marcos Garcia Ron MarshallSenior Cloud Solutions Architect Senior Solutions Architect

June 2018

Page 2: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

WHAT YOU’LL LEARN TODAY

1. Hybrid Cloud means Containers everywhere

2. Manage every cloud with Cloudforms

3. Standardize on Ansible for Cloud Automation

4. Interconnect Data Silos

5. OpenShift on OpenStack works great

Page 3: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

A Red Hat perspectiveWHAT IS MULTICLOUD?

Using multiple clouds from multiple private OR public providers, for multiple workloads/tasks, without interconnectivity between clouds.

A combination of one or more public AND private clouds, with some degree of workload portability, integration, orchestration, and unified management across clouds.

noun • \ muhl-tee \ klaud \ noun • \ hī-bred \ klaud \

Source:https://www.redhat.com/en/topics/cloud-computing/what-is-multicloudhttps://www.redhat.com/en/topics/cloud-computing/what-is-hybrid-cloud

MULTICLOUD HYBRID CLOUD

Page 4: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Exposition of resources

Provide necessary environments to operations in minutes, not weeks or months

CLOUDDefinitions

APPLICATION PLATFORM

Consumption of resources

Able to easily access new developer environments to quickly build new apps and

move on

INFRASTRUCTURE PLATFORM

Page 5: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

TOP DRIVERS OF PUBLIC CLOUD ADOPTIONAgility, security, and productivity

[n=6,084 respondents weighted by country]Source: IDC, Top Drivers of Cloud Adoption by Type of Cloud Deployment. Doc # US42829717, Jun 2017.

PERCENTAGE OF RESPONDENTS

IMPROVE AGILITYIMPROVE SECURITY

IMPROVE STAFF PRODUCTIVITY

Reduce budget

Simplify or standardize IT

Shift from CapEx to OpExMore control to business units

Faster access to toolsReassign IT personnel

Improve time to market

50%30% 40%20%

Page 6: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

WHY ENTERPRISES CHOOSE PRIVATE CLOUDSecurity, compliance, control, and flexibility are top benefits

of user organizations surveyed cited increased security as the top benefit of private cloud.

of these organizations cited global compliance, enhanced IT control, flexibility, and data management as further benefits.

75%

70%

Source 451 Research for Red Hat, OpenStack Platform Delivers for Private Cloud Users, Dec 2016. :

Page 7: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

BENEFITS OF PRIVATE CLOUDComplete control over data, cost, and location

Source: Corina Marcuti for Luminus, 7 benefits of choosing a private cloud solution, Jan 2017. http://luminus.tech/2017/01/13/7-benefits-of-choosing-a-private-cloud-solution/

Create and customize to meet business

needs

CONTROLReduce cost of

infrastructure and operations over time

COSTSecure your info on your servers in your

datacenter

PRIVACYAvoid concerns about

vendor stability or longevity

NO LOCK-INAPI’s available 24x7,

to multiple teams

SELF-SERVICE

Page 8: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

USES both on-premise and public cloud infrastructure

UNIFIES management across all environments

SHARES resources across infrastructure platforms

PROVIDES a container environment with orchestration

ADHERES to open, common industry standards and APIs

OPEN HYBRID CLOUD PLATFORMA modern platform that takes advantage of all environments

Page 9: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

A COMMON FOUNDATION FOR HYBRID CLOUD INFRASTRUCTURE

PUBLICPHYSICAL VIRTUAL PRIVATE

RED HAT ENTERPRISE LINUX

Page 10: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

A MULTICLOUD APPLICATION PLATFORM

STANDARD MANAGEMENT

STANDARD WORKLOADS

MULTIPLE INFRASTRUCTURE

Page 11: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

SAME USER EXPERIENCEOCP on Amazon Public Cloud or on OpenStack Private Cloud

Page 12: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

DIVERSE INFRA CAN BE CHALLENGINGSILOS BLOCK BUSINESS INNOVATION AND VALUE

SILOED TOOLSETS

SILOEDTEAMS

BUSINESS VALUE

SILOED WORKLOADS

THIS IS BAD FOR YOUR TEAM’S CULTURE AND SUCCESS!

Page 13: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

DIVERSE INFRA CAN BE CHALLENGINGRED HAT MULTICLOUD UNLOCKS BUSINESS INNOVATION AND VALUE

SHARED TOOLSETS

SHARED MANAGEMENT

BUSINESS VALUE

MULTICLOUDCONTAINER WORKLOADS

Red Hat multicloud is the evolution of digital transformation.

Page 14: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

WHY SHOULD MANAGEMENT BE HYBRID? TO ELIMINATE DISPARATE SYSTEMS & DUPLICATION OF EFFORT

● Different management systems

● Different automation and policies

VIRTUALIZATION PUBLICCLOUD

CONTAINERSPRIVATECLOUD

Page 15: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

HYBRID CLOUD MANAGEMENT EFFICIENCY COMMON SYSTEM ELIMINATES DUPLICATION OF EFFORT

● One management system

● Consistent automation & policies

VIRTUALIZATION PRIVATECLOUD

PUBLIC CLOUD

CONTAINERS

HYBRID MANAGEMENT

Page 16: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

HYBRID CLOUD MANAGEMENTSELF-SERVICE, SYSTEM DEPLOYMENT, CONFIGURATION, & REMEDIATION

Order a service in a self-service

portal

Deploy instanceson VMs, in an

OpenStack private cloud, or public cloud

Automated OS deployment,

configuration, and errata updates

Infrastructure orchestration, application deployment, & automated remediation of

critical issues

Proactively monitor & identify issues

Monitor progress and inform the user when actions are completed

Page 17: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

ONE STEP FURTHER: HYBRID NETWORKINGConnect multiple clouds with your own VPNs or 3rd party SDN / SDWAN

VIRTUALIZATION PRIVATECLOUD

PUBLIC CLOUD

CONTAINERS

HYBRID NETWORK

● OVN● Contrail● Tigera● NSX-T● Cisco CSR1000v● Viptela, etc

Page 18: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

ONE STEP FURTHER: HYBRID STORAGEConnecting silos allows application portability and lower costs

VIRTUALIZATION PRIVATECLOUD

PUBLIC CLOUD

CONTAINERS

HYBRID STORAGE

Using

● Gluster

● Ceph

Expose common interfaces

● S3/Swift object APIs

● NFS/Samba POSIX folders

With geo-replication across clouds

Page 19: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

#1: Visibility and Policies

Page 20: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

(MULTI)CLOUDFORMSMANAGE CONTAINER, VIRTUAL, PRIVATE, AND PUBLIC CLOUD INFRASTRUCTURES

Page 21: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

CLOUDFORMS MULTICLOUD INTEGRATIONSCLOUDFORMS 4.6 DOES MULTICLOUD

Smart-State Analysis on Azure-managed disks

User data for GCE instance provisioning

Smart-State Analysis on EC2

Template provisioning from Service Catalogue

Reporting: Metering and Chargeback improvements

User experience: Security, dashboards, and filters

Security groups, flavors, and Smart-State for boot from vol.

OSP and CloudForms tenant synchronisation (on-demand)

Assign Chargeback Rate by Storage Volume Type.

CloudForms containerised deployment.

Transform VMware VM into a RHV VM + all the plumbing.

Bare metal management: introspect and manage, physical! (Lenovo Xclarity)

PUBLIC CLOUDOPENSHIFTCONTAINER PLATFORM

RED HATOPENSTACK PLATFORM

CLOUDFORMSVMware | RHV | Bare Metal

Page 22: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Demo: Dashboard and Reports

Page 23: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Demo: Topology view & OCP Dependencies

Page 24: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

DEMO: Smart State Analysis

Page 25: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

DEMO: Control Policies

Page 26: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

#2: Cloud Services Catalog

Page 27: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

CLOUDFORMS SERVICE CATALOG

Page 28: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

TASK TIME MINS

Create virtual machine

Add storage and networking

Queue between teams

Install operating system

Wait after install

Configure operating system

Install application platforms

Configure application platforms

Queue between teams

Security configuration and scan

2

3

120

2

60

1

2

1

120

2

ACTI(E )ORK TIME 13 minutes

13 minsTOTAL TIME

ACCELERATE SERVICE DELIVERYREQUEST

DEVELOPER

EN(IRONMENT

Page 29: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Cloudforms Native Provisioning Existing Tools (via Ansible)

Ansible Cloud ModulesOrchestration Templates

FOUR WAYS TO PROVISION CLOUD SERVICESFrom Cloudforms

Page 30: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

EXAMPLEYour applications and systems are more than just collections of configurations. They’re a finely tuned and ordered list of tasks and processes that result in your working application. Ansible can do it all: • Provisioning

• App Deployment

• Configuration Management

• Multi-tier Orchestration

Page 31: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

DEMO: Deploy Cloud Service

x2 Ticket Monster

DB

EAP+++

DBInstance

JBossInstances

DBDeploy.

Playbook

J(M + JBoss Deploy. + ELB

Playbook

Ansible Playbook

+

ELB

Playbook: https://github.com/marcosgm/workflow-demo/blob/master/plays/ticket-monster-aws.yml

Page 32: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

#3: Cloud Interconnect

Page 33: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Multiple VPN Options:

● AWS Virtual Private Gateway● Azure VPN Gateway● GCE Cloud VPN

Multiple peering options:

● AWS Direct Connect● Azure ExpressRoute● GCE Dedicated Interconnect

They cannot even agree on the icons! Corporate DC

Public Internet

EACH CLOUD HAS ITS NETWORKHow to connect the silos?

Page 34: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

resources:- type: Microsoft.Network/virtualNetworks/subnets name: "site2.scarter/outside" apiVersion: '2017-06-01' properties: addressPrefix: "10.2.1.0/24"

Resources: outsidesite2scarter: Type: AWS::EC2::Subnet Properties: CidrBlock: 10.2.1.0/24 AvailabilityZone: us-east-1a VpcId: Ref: site2scarter

Tags: - Key: Name Value: outside.site2.scarter

SO MANY WORDS… but only a few things matter

AWS CloudFormation Azure Resource Manager Template

SILOED AUTOMATION

Page 35: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

AWS CloudFormation

Azure Resource Manager Template

resources:- type: Microsoft.Network/virtualNetworks/subnets name: "site2.scarter/outside" apiVersion: '2017-06-01' properties: addressPrefix: "10.2.1.0/24"

Resources: outsidesite2scarter: Type: AWS::EC2::Subnet Properties: CidrBlock: 10.2.1.0/24 AvailabilityZone: us-east-1a VpcId: Ref: site2scarter

Tags: - Key: Name Value: outside.site2.scarter

vpc_list:- name: site2.scarter cidr: 10.2.0.0/16 networks: - name: mgmt.site2.scarter cidr: 10.2.0.0/24 - name: outside.site2.scarter cidr: 10.2.1.0/24 - name: inside.site2.scarter cidr: 10.2.2.0/24

DATA MODELSBetter Living Through Abstraction

Page 36: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Abstraction Through Automation

BGP OSPF VLAN ACL QOS EVPN AAALB

NETWORK AUTOMATION WITH ANSIBLE

Page 37: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Time to ValueConfiguration & Change Automation

Faster Customer Service

On-boarding

Time to RemediationAutomated Fault Remediation

Faster Execution of Change Requests

Faster Execution of Maintenance

Faster Troubleshooting and Remediation

IMPROVED OUTCOMES WITH AUTOMATION

Page 38: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

CONSISTENT ONBOARDING ACROSS CLOUDS

Provision Cloud Instance

Provision Cloud Network Services

Connect Cloud Router to DC

Establish VPN Tunnels

Provision Cloud Instance

Provision Cloud Network Services

Connect Cloud Router to DC

Establish VPN Tunnels

Establish VPN Tunnels

Establish VPN Tunnels

Connect DC Router to Cloud Router

Connect DC Router to Cloud Router

Cloud Model

Playbook ON-PREM

Provision Local Network Services

Provision Local Network Services

Page 39: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

control10.0.2.10

DC

host110.2.2.10

10.2.2.0/24

Site2

10.0.2.0/24

10.0.0.0/16

10.2.0.0/16

Scenario: Provision new cloud capacity using template and add to corporate SD-WAN

1. Provision the new Cloud node2. Configure remote router

a. Set Hostname, DNS, Banners, etc.b. Harden routerc. Configure Interfacesd. Backup

3. Add remote router to VPNa. Checkpoint Stateb. Create IPSEC VPNc. Configure BGPd. Check connectivitye. Rollback on failure

MULTI-SITE/CLOUD EXAMPLE

Public Internet

host110.1.2.10

10.1.2.0/24

Site1

10.1.0.0/16

https://github.com/network-automation/an-cloud-builder

Page 40: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

HYBRID STORAGE: FROM SILOS

Page 41: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

HYBRID STORAGE: TO COMMON DATA SETS

Offers both

● Data Locality● Geo Replication

Page 42: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

SAME STORAGE EXPERIENCE

Page 43: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Container-native Storage

EBS gp2

EBS gp2

EBS st1

EBS io1

vs.EBS sc1

STORAGE CAPACITY CONSOLIDATION

Page 44: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

SIMPLIFY CONTAINER AVAILABILITY

AVAILABILITYZONE A

AVAILABILITYZONE B

AVAILABILITYZONE C

Node Node Node Node Node Node

GLOBAL STORAGE NAMESPACE

Page 45: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

#4: OpenShift everywhere

Page 46: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

External DNSRoute 53 (R53)

ProvisioningCloudFormations

AWS INTEGRATION POINTS

AWS Logging, Metrics, etcLimited support…

Registry StorageSimple Storage Service (S3)

VM Storage and persistent container storageElastic Block Storage (EBS), S3

Master LB and App LBElastic Load Balancer (ELB)

OpenShift Virtual Machines10x EC2 in the RA

AuthenticationNo native provider

Ext ServicesService BrokerCheckout the summit demo!

Page 47: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Azure DNSExternal DNS

AZURE INTEGRATION POINTS

Azure Logging, Metrics, etc

Azure Active DirectoryUser Authentication

Azure Storage AccountVM storage, registry and persistant Container Storage

Azure Load BalancerIngress Traffic

Azure Virtual Machines(10x in the Reference Architecture

Registry storageNo native provider (use VHDs)

Ext ServicesService Broker

Page 48: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

GCP INTEGRATION POINTS

External DNSGoogle DNS

ProvisioningDeployment Manager

GCP Logging, Metrics, etcLimited support…

Registry StorageGoogle Virtual Disks

VM Storage and persistent container storageGoogle volumes and virtual disks

Master LB and App LBCloud Load Balancer

OpenShift Virtual MachinesGoogle Virtual Machines

AuthenticationNo native provider

Ext ServicesService Broker

Page 49: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

OPENSTACK INTEGRATIONNative networking and storage plugins

ANSIBLE

Page 50: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

NETWORKING IN THE PRIVATE CLOUDIMPROVE PERFORMANCE ON OPENSTACK AVOIDING DOUBLE ENCAPSULATION

VXLAN 1 - Tenant X VXLAN 2 - Tenant OCP

VM Tenant X VM - OCP Node

VXLAN 8 - Pod 1 VXLAN 9 - Pod 2

Pod 1 Containers

Pod 2 Containers

VXLAN 1 - Tenant X

VM Tenant X VM - OCP Node

VXLAN 3 - Pod 1 VXLAN 4 - Pod 2

Pod 1 Containers

Pod 2 Containers

OpenStack Kuryr

Any other cloud

BEFORE NOW

Page 51: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

STORAGE IN THE PRIVATE CLOUDSAVE TIME BY HAVING OPENSTACK MANAGE YOUR CONTAINER’S STORAGE NEEDS

Page 52: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

OPENSHIFT SER(ICE CATALOG

OpenShiftAnsibleBroker

OpenShiftTemplateBroker

AWSServiceBroker

IaaSServiceBrokers

ANSIBLE

OPENSHIFT

AMAZON WEB SERVICES

CLOUDFORMS SERVICES

Ansible Playbook Bundles

OpenShiftTemplates

PublicCloudServices

IaaSServices

SERVICE BROKER

SER(ICE BROKERS

Expose and Provision Services

Page 53: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Ansible Playbook Bundle (APB) for AWSWhen an OpenShift user requests an AWS service, an APB container runs to complete the task

Page 54: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

Start with us

Page 56: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

CLOUD ADOPTION WITH RED HATMove from traditional to cloud in 3 steps

DISCOVERReview and capture:

Infrastructure requirements

Processes

Workload/apps

Environment details

Develop a cloud migration strategy that is right for your business.

DESIGNIdentify target architecture:

Level of effort

Timelines

Organizational adoption

Critical and suitable apps

Build your implementation roadmap.

DEPLOYDeploy your environment(s):

Develop

Test

Deploy

Automated migration

Implementing cloud management and training and mentoring for IT staff.

Page 58: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

KEY TAKEAWAYS

1. Hybrid Cloud means Containers everywhere

2. Manage every cloud with Cloudforms

3. Standardize on Ansible for Cloud Automation

4. Interconnect Data Silos

5. OpenShift on OpenStack works great

Page 59: RECOMMENDED STRATEGY FOR HYBRID CLOUD INFRASTRUCTURE · Azure DNS External DNS AZURE INTEGRATION POINTS Azure Logging, Metrics, etc Azure Active Directory User Authentication Azure

THANK YOUplus.google.com/+RedHat

linkedin.com/company/red-hat

youtube.com/user/RedHatVideos

facebook.com/redhatinc

twitter.com/RedHat