Panoramica su Cloud Computing targata Red Hat AIPSI Meeting 2010



Similar documents
RED HAT ENTERPRISE VIRTUALIZATION

RED HAT ENTERPRISE VIRTUALIZATION & CLOUD COMPUTING

RPM Brotherhood: KVM VIRTUALIZATION TECHNOLOGY

How To Get The Most Out Of Redhat.Com

Red Hat Powered VDI: Setting a New Standard for Desktop Virtualization

YOUR STRATEGIC VIRTUALIZATION ALTERNATIVE. Greg Lissy Director, Red Hat Virtualization Business. James Rankin Senior Solutions Architect

RED HAT ENTERPRISE VIRTUALIZATION FOR SERVERS: COMPETITIVE FEATURES

FOR SERVERS 2.2: FEATURE matrix

Red Hat enterprise virtualization 3.0 feature comparison

RED HAT ENTERPRISE VIRTUALIZATION 3.0

KVM KERNEL BASED VIRTUAL MACHINE

RED HAT ENTERPRISE VIRTUALIZATION SCALING UP LOW LATENCY, VIRTUALIZATION, AND LINUX FOR WALL STREET OPERATIONS

Virtualization Management the ovirt way

Server Virtualization and Consolidation

Disaster Recovery Infrastructure

Next Generation Now: Red Hat Enterprise Linux 6 Virtualization A Unique Cloud Approach. Jeff Ruby Channel Manager jruby@redhat.com

ovirt Introduction James Rankin Product Manager Red Hat Virtualization Management the ovirt way

Cutting Costs with Red Hat Enterprise Virtualization. Chuck Dubuque Product Marketing Manager, Red Hat June 24, 2010

With Red Hat Enterprise Virtualization, you can: Take advantage of existing people skills and investments

OPEN CLOUD INFRASTRUCTURE BUILT FOR THE ENTERPRISE

An Alternative to the VMware Tax...

RED HAT ENTERPRISE Linux & VIRTUALIZATION

KVM, OpenStack, and the Open Cloud

What s New with VMware Virtual Infrastructure

Red Hat Cloud and Virtualization How to Sell. Karl Stevens Senior Solution Architect

Introduction to ovirt

The path to the cloud training

Servervirualisierung mit Citrix XenServer

With Red Hat Enterprise Virtualization, you can: Take advantage of existing people skills and investments.

OVA KVM THE SOLUTION. Virtually Unmatched. Get to know KVM. Low cost, super secure and infinitely scalable. JOIN WHAT IS GET SECURITY LOW COST

KVM Virtualization Roadmap and Technology Update

Red Hat Enterprise Virtualization 3.0 Live Chat Transcript Sponsored by Red Hat

Parallels Server 4 Bare Metal

Real World Cloud Infrastructure with Red Hat Enterprise Virtualization and Red Hat Network Satellite

RED HAT ENTERPRISE VIRTUALIZATION

IOS110. Virtualization 5/27/2014 1

Satish Mohan. Head Engineering. AMD Developer Conference, Bangalore

Creating One Time Password (OTP) infrastructures using Open Source sofware

VMware Virtual Infrastucture From the Virtualized to the Automated Data Center

Cloud^H^H^H^H^H Virtualization Technology. Andrew Jones May 2011

KVM: A Hypervisor for All Seasons. Avi Kivity avi@qumranet.com

RED HAT INFRASTRUCTURE AS A SERVICE OVERVIEW AND ROADMAP. Andrew Cathrow Red Hat, Inc. Wednesday, June 12, 2013

An Oracle White Paper August Oracle VM 3: Server Pool Deployment Planning Considerations for Scalability and Availability

F I G U R E 1. (% of respondents) Combination of multiple hypervisors Standardize on one hypervisor

International Journal of Advancements in Research & Technology, Volume 1, Issue6, November ISSN

SUSE Linux Enterprise 10 SP2: Virtualization Technology Support

Virtualization Technologies and Blackboard: The Future of Blackboard Software on Multi-Core Technologies

The virtualization of SAP environments to accommodate standardization and easier management is gaining momentum in data centers.

Developing a dynamic, real-time IT infrastructure with Red Hat integrated virtualization

RED HAT ENTERPRISE VIRTUALIZATION

Intel Cloud Builder Guide: Cloud Design and Deployment on Intel Platforms

RED HAT ENTERPRISE VIRTUALIZATION

Agenda. 1. Welcoming and intro 2. Introduction to RHEL-OSP 3. Deep Dive RHEL-OSP 4. Live Demo 5. OSP-Director 6. What's new in liberty

Stanislav Ulrych CTO RED HAT ENTERPRISE LINUX OPENSTACK PLATFORM

Full and Para Virtualization

W H I T E P A P E R K V M f o r S e r v e r V i r t u a l i z a t i o n : A n O p e n S o u r c e S o l u t i o n C o m e s o f A g e

red hat enterprise virtualization: vmware migration

Virtualization and Performance NSRC

KVM, OpenStack, and the Open Cloud

Hypervisor Competitive Differences: Beyond the Data Sheet. Chris Wolf Senior Analyst, Burton Group

Red Hat Enterprise Virtualization 3 on

VIRTUALIZATION 101. Brainstorm Conference 2013 PRESENTER INTRODUCTIONS

<Insert Picture Here> Introducing Oracle VM: Oracle s Virtualization Product Strategy

Lecture 2 Cloud Computing & Virtualization. Cloud Application Development (SE808, School of Software, Sun Yat-Sen University) Yabo (Arber) Xu

RED HAT CLOUD SUITE FOR APPLICATIONS

2972 Linux Options and Best Practices for Scaleup Virtualization

Cloud Computing with Red Hat Solutions. Sivaram Shunmugam Red Hat Asia Pacific Pte Ltd.

System and Storage Virtualization For ios (AS/400) Environment

Product Overview. Marc Skinner Principal Solutions Architect Red Hat RED HAT ENTERPRISE LINUX OPENSTACK PLATFORM

Red Hat Cloud, HP Edition Reference Architecture. Marc Nozell, Solution Architect, HP Ian Pilcher, Principal Architect, Red Hat

Comparing Free Virtualization Products

Data Centers and Cloud Computing

Virtualization with Windows

KVM Virtualized I/O Performance

The Art of Virtualization with Free Software

ENTERPRISE HYPERVISOR COMPARISON

Veritas InfoScale 7.0 Virtualization Guide - Linux

Scaling Microsoft Exchange in a Red Hat Enterprise Virtualization Environment

Virtualization and the U2 Databases

Xen Virtualization: Xen (source) and XenServer

OPEN SOURCE VIRTUALIZATION TRENDS. SYAMSUL ANUAR ABD NASIR Warix Technologies / Fedora Community Malaysia

Citrix XenServer Product Frequently Asked Questions

Windows Server 2008 R2 Hyper V. Public FAQ

Cloud Platform Comparison: CloudStack, Eucalyptus, vcloud Director and OpenStack

Virtualization: Know your options on Ubuntu. Nick Barcet. Ubuntu Server Product Manager

Virtual Compute Appliance Frequently Asked Questions

Enabling Technologies for Distributed Computing

Open Source Virtualization with ovirt. DI (FH) René Koch Systems Engineer Siedl Networks GmbH Grazer Linuxtage,

kvm: Kernel-based Virtual Machine for Linux

Transcription:

Panoramica su Cloud Computing targata Red Hat AIPSI Meeting 2010 Giuseppe Gippa Paterno' Solution Architect EMEA Security Expert gpaterno@redhat.com

Who am I Currently Solution Architect and EMEA Security Expert in Red Hat Visiting Researcher at Trinity College Dublin Previously Security Solution Architect in Sun and also in IBM Red Hat Certified Security Specialist (RHCSS), RH Architect (RHCA) and Cisco Certified Network Professinal (CCNP) Part of the italian security community sikurezza.org Forensic analisys for local govs More on: http://www.gpaterno.com/ http://www.scss.tcd.ie/giuseppe.paterno/ http://www.linkedin.com/in/gpaterno

Agenda Cloud computing Red Hat Virtualization Strategy Cloud Security (Gippa's hardcore security :)

What is a cloud? "A computing capability that provides an abstraction between the computing resource and its underlying technical architecture (e.g., servers, storage, networks), enabling convenient, ondemand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction." (from Wikipedia) 4

Build your own cloud! To summarize: efficient usage of YOUR resources Let's build your own cloud with the following characteristics: lower the costs, agility, reliability, scalability, accountability and... security!!! 5

Red Hat Virtualization Portfolio

7

RED HAT ENTERPRISE VIRTUALIZATION (RHEV) RHEV MANAGER FOR SERVERS Enterprise grade server management system RHEV MANAGER FOR DESKTOPS (beta) Virtual Desktop Infrastructure with SPICE RHEV HYPERVISOR Small footprint, high performance dedicated hypervisor Available only with RHEV Manager RED HAT ENTERPRISE LINUX (with KVM) High Performance, security, integrated hypervisor 8

RED HAT ENTERPRISE VIRTUALIZATION ARCHITECTURE 9

KERNEL-BASED VIRTUAL MACHINE (KVM) Included in Linux kernel since 2006 Runs Linux, Windows and other operating system guests Advanced features Live migration Memory page sharing Thin provisioning PCI Pass-through KVM architecture provides high feature-velocity leverages the power of Linux 10

KVM HYPERVISOR ADVANCED FEATURES Kernel Same-Page Merging (KSM) Memory Page Sharing Securely shares identical memory pages between virtual machines 11

KVM HYPERVISOR ADVANCED FEATURES Kernel Same-Page Merging (KSM) Enterprise Java workload benchmark Intel Xeon Processor X5550 with 24GB ram Running multiple 3GB Windows 2003 VMs Scaling up to 200% over-commit 12

KVM HYPERVISOR ADVANCED FEATURES Thin Provisioning Allocate storage only when needed Oversubscribe storage Transparent to virtual machine Improve Storage Utilization Reduced Storage Costs Works with NFS, iscsi and Fiber Channel Storage reporting and alerting 13

RED HAT ENTERPRISE VIRTUALIZATION CHOICE OF HYPERVISOR PLATFORMS RED HAT ENTERPRISE VIRTUALIZATION MANAGER FOR SERVERS Live Migration, High Availability, System Scheduler, Power Saver, Storage/Snapshots, thin provisioning WINDOWS GUESTS RHEL 3, 4, 5 GUESTS WINDOWS GUESTS RHEL 3, 4, 5 GUESTS RED HAT ENTERPRISE LINUX 5.4 RED HAT ENTERPRISE VIRTUALIZATION HYPERVISOR Performance, Scalability, Security RHEL Expertise Use hardened RHEL image as hypervisor Tuneable, configurable No RHEL Expertise Easy to use, out of the box configuration Small footprint, network boot, stateless

RED HAT ENTERPRISE VIRTUALIZATION GUEST SUPPORT Support for Red Hat Enterprise Linux guests Red Hat Enterprise Linux 3 - (32 and 64 bit) Red Hat Enterprise Linux 4 - (32 and 64 bit) Red Hat Enterprise Linux 5 - (32 and 64 bit) Para-virtualized drivers for high performance network and disk I/O Uses standard VirtIO interface Included as part of Linux kernels > 2.6.25 Backported into RHEL 4.8+ and RHEL 5.3+ kernels Available as download for RHEL 3 15

RED HAT ENTERPRISE VIRTUALIZATION GUEST SUPPORT & INTEROPERABILITY Support for Microsoft Windows Server guests Windows Server 2003 & 2003R2 - (32 and 64bit) Windows Server 2008 & 2008R2 - (32 and 64 bit) Server Virtualization Validation Program (SVVP) Certification from Microsoft Both RHEL 5.4 and RHEV-H Certified on AMD and Ensures fully supported environment Para-virtualized drivers for high performance network and disk I/O WHQL Certified signed drivers Included on Windows Update for seamless user experience 16

RED HAT ENTERPRISE VIRTUALIZATION MANAGEMENT FEATURES Feature Description High Availability Restart guest VMs from failed hosts automatically on other hosts Live Migration System Scheduler Move running VM between hosts with zero downtime Continuously load balance VMs based on resource usage/policies Power Saver Maintenance Manager Concentrate virtual machines on fewer servers during off-peak hours No downtime for virtual machines during planned maintenance windows Image Management Template based provisioning, thin provisioning and snapshots Monitoring and Reporting For all objects in system VM guests, hosts, networking, storage etc.

Gippa's vision of Cloud Security

How a Cloud stack is (vendors/labels apart) 19

Issues on security in a Cloud Not any different from a Service Oriented Architecture, but more dynamic. What are the aspects on security in a cloud? Hypervisor isolation Operating System security Network segregation and encryption Data encryption and isolation Strong authentication and authorization J2EE container protection Web content protection (XSS, javascript/ajax, etc...) Secure Web Services Database hardening and content encryption... and a lot more! Too much for a presentation, let's talk about hypervisor protection and isolation. 20

How's Defense in Depth in a Cloud 21

KVM HYPERVISOR ADVANCED FEATURES Security: inherits security features of Linux Includes support for SELinux Provides protection and isolation for virtual machines and host Compromised virtual machine cannot access other VMs or host svirt Project Sub-project of NSA's SELinux community Provides hardened hypervisors Contain any hypervisor breaches Will be included in RHEL 6 22

MAC and SE Linux Mandatory Access Control (MAC) is a kind of access control defined by the Trusted Computer System Evaluation Criteria [...] restricting access to objects based on the sensitivity of the information contained in the objects and the formal authorization (i.e., clearance) of subjects to access information of such sensitivity". (from Wikipedia) The most used MAC system in Linux is Security Enhanced Linux (SE Linux) Developed initially by NSA (National Security Agency) Several contributors, such as Red Hat, Tresys, IBM,... Certified Common Criteria (EaL4+) and used by military When used in stricted mode is even more secure Based on policies that confine user programs and system services to the minimum amount of privilege they require to do their jobs 23

svirt Project MAC in process-based virtualization (KVM, OpenVZ, etc...) Isolate guests using MAC security policy Contain hypervisor breaches Supports MAC security schemes (SELinux, SMACK) Provides: Strong isolation between active VMs Improved control over access to VM resources Improved control over access to shared resources Fine-grained interaction with the host MAC containment of Vms Interface with label networking/cipso Heavy usage of the MCS framework: system_u:object_r:virt_image_t:c<uuid> 24

svirt, the big picture 25

Check out document Virtualizzazione e Sicurezza on http://www.gpaterno.com/pubblicazioni/ (available in italian) 26

Q&A Thank you! Giuseppe Gippa Paterno' Solution Architect gpaterno@redhat.com