4 ms·
Based on my two decade experience in the field ranging being part of the team that was building super computers to one that was moving amazon.com to aws, there
by datadeft 4y ago
Based on my two decade experience in the field ranging being part of the team that was building super computers to one that was moving amazon.com to aws, there are many dimensions that you need to consider for computational workloads.
The primary deciding factor is always security. You simply cannot use any small vendor because of the physical security (or the lack thereof). Unless of course you do not care about security. If a red team can just waltz into you DC and connect directly to your infra is it game over for some businesses. You can easily do this with most vendors.
The secondary deciding factor is networking. Most traditional co-los have very limited understanding of networking. A CCIE or two can make a real difference. Unfortunately those guys usually work some bigger companies.
The third deciding factor air conditioning and electricity considerations. Worst case you are facing an OVH situation. https://www.datacenterdynamics.com/en/opinions/ovhclouds-data-center-fire-one-year-on-what-do-we-know/ https://www.datacenterdynamics.com/en/opinions/ovhclouds-dat....
(It is really funny, because I have warned them that their AC/cooling solution is not sufficient, and they explained to me that I am wrong. I was not aware of the rest (wooden elements, electricity fuckups, etc.)
"""During the year, an article in VO News by Clever Technologies claimed there were flaws in the power design of the site, for instance that the neighboring SBG4 facility was not independent, drawing power from the same circuit as SBG2. It's clear that the site had multiple generations, and among its work after the fire, OVHcloud reported digging a new power connection between the facilities.""")
The fourth would be probably pricing. TCO is one consideration, after you made sure that the minimum requirements are met, but only after.
So based on the needs somebody can choose wisely, based on the ___business requirements___. For example, running an airline vs running a complex simulations have very different requirements.
- latch 4y agoAWS and GC (and I assume Azure, but I haven't looked) have definitely set the standard with respect to checking off all the boxes when it comes to helping customers with security audits and requirements. This is a place other provides have serious lagged. I've been involved in cases where using the cloud is essentially a pass and not using the cloud raises red flags. From a sales point of view, I agree with you that, for a lot of folks, this might be the main concern. If you're doing B2B or government work this might be, by far, the most important thing to you. However, this is at least partially pure sales and security theatre. It's about checkboxes and being able to say "we use AWS" and having everyone else just nod their head and say "they use AWS." I'm not a security expert (though I have held security-related/focused programming roles), but as strong as AWS is with respect to paper security, in practice, the foundation of cloud (i.e. sharing resources), seems like a dealbreaker to me (especially in a rowhammer/spectre world). Not to mention the access AWS/Amazon themselves have and the complexity of cloud-hosted system (and how easy it is to misconfigure them (1)).) About 8 years ago, when I worked at a large international bank, that was certainly how cloud was seen. I'm not sure if that's changed. Of course, they owned their own (small) DCs. (1) - https://news.ycombinator.com/item?id=26154038 https://news.ycombinator.com/item?id=26154038 The tool was removed from github (conspiracy theory!), but I still find the discussion there relevant.
- metalspot 4y ago> The primary deciding factor is always security so, anywhere where your workloads or data are physically co-located on the same hardware as someone else's should be automatically disqualified, right?
- datadeft 4y agoNo. It is only a risk if an attacker can use it somewhow. Would you show me a scenario how could an attacker gain knowledge of which physical server my lambda function is running AWS and break out from the container and get access to my container? This risk is acceptable for most workloads. Maybe not for the tree letter gov agencies, this is why they got gov cloud. You see, again, what is the use-case? What is the risk? What risk is acceptable?