3 ms·
Have you seen a cloud bill recently!? My buddy worked for a company that was spending a million on their monthly AWS bill. You can easily buy all your own inf
by Hobadee 1y ago
Have you seen a cloud bill recently!? My buddy worked for a company that was spending a million on their monthly AWS bill. You can easily buy all your own infra, plus hire an engineer or two for the price that some of these companies are dropping on "inexpensive" cloud services.
- paulryanrogers 1y agoNow add SOC and PCI compliance, DR with RTO, HA, etc. No doubt it could still be cheaper. But self managed infra does add up quickly.
- dijit 1y agoYou don’t get away from any of those by hosting in a cloud. Your colo provider should be doing their part for physical access for ISO27001/SOC2 and PCI-DSS. I quite literally know all about this because I was running payment card infrastructure in a colo, as part of one of the largest e-commerce software suites in the UK at the time.
- paulryanrogers 1y agoIndeed. But cloud can provide a faster and easier path to getting there, at least IME.
- dijit 1y agoNo? Cloud gives you direct access to compute at the click of a button (provided you have quota). The ISO/PCI cert requirements are not accelerated by their use, only the initial deployment speed of your solution. If at all anything the latest I've seen is that there are more checks in cloud for various areas where you can accidentally leak data through poor permissions or because someone could enable those permissions. For example in Google Cloud there was an additional requisite that I monitor any admin users oauth2 application accesses for their google accounts; this was not a requirement for on-prem.
- paulryanrogers 1y agoYes? At least in my experience as a service provider. With cloud I can easily plug in a compliance vendor like Drata, add connectors to my other vendors, and get a significant amount of evidence quickly. Bespoke on-prem solutions bring plenty of their own challenges that are just N/A or handled by cloud vendors, like physical security. Maybe as a payment processor things shake out differently. Though having read far more of PCI v4 than I'd like, I doubt it.
- jauntywundrkind 1y agoAnd any one of those could become an existential risk, could take down your entire company. Do you trust your people to never slip up? To make sure there's really the reliability & security guarantees that your company depend on? Are there competent technical hands available at all times to handle issues as they come up? This adds significantly to the org chart, requires constant caring to be added, to keep it steered and staffed. I'm a huge fan of self hosting, of buying your own hardware. Especially for very technical entities, that have lots of overlap & intimacy with computers. But your company needs to have reason to believe it can do the job not just well, but to a degree where you're sure you won't lose the entire business. Needs to believe they really are on top of this huge domain! I see very clearly why folks go cloud, and I wish the world was in a better position, had more to say, to show why buying pizza boxes is gonna not just save you money buy be an enduring acceptable safe choice. Much safer to not wade in here, shutting the hell up is free, and there's plenty that can go wrong, but I do think Kubernetes presents the first maybe acceptable opportunity for broadly acceptable DIY computing, delivering key three things: an essential integrativeness of concerns allowing it to be a comprehensive cross-cutting platform for your business's compute, delivers strongly on the security and dependability you absolutely must have in a well known way, and avoids the historical trap of each company ending up married to their own specific boondoggle infrastructure that's been hand cobbled together by whomever had such and such task at the time. There's a stable practice here, one that many companies and practitioners are honing; there's much difference between Kube clusters sure, but these intracacies and elaborations support the creation of something that is mostly alike, if you look from one company's clusters to the next.
- luckylion 1y agoWould you trust cloud providers to never slip up though? I don't think the split is "perfect but pricey" vs "less expensive but shaky". It feels similar to the autonomous driving question, where safety of autonomous driving is often compared to perfection instead of human drivers. Would UniSuper engineers have trashed their entire infrastructure the way Google Cloud did? Granted, that's not a common thing to happen, but they got _very_ lucky that day that they had a backup elsewhere and didn't fully commit to trusting Google.
- sixtyj 1y agoYou can read DHH tweets how move from cloud to own infra was -90% of monthly money.