HP Launches Private Cloud for Test Service

Key features

  • Automated test process resulting in cost saving in
    time to execute tests
  • Integrated service monitoring across testing and
    operations
  • Improved consistency between development and
    test environments
  • Improved utilization of test environment

Overview

The HP Private Cloud for Test Service is comprehensive solution for implementing on-site private cloud capability to support the complete testing lifecycle. Made up of software, consulting, and best practices, it addresses common problems like slow time to market, costly test environments, and the business risk of defects deployed in operations. And it is the foundation and guidance for building a dynamic, scalable test environment. Integrated and automated from development through to operations.

More details on HP Site

Amazon publishes a cloud best practices

Amazon cloud best practices

Cloud Computing's Tipping Point

Half of federal agencies will be in the cloud within 12 months, according to our new cloud computing survey.

By Michael Biddick

Private clouds promise maximum control and strong security, while commercial cloud services are fast and flexible. Which works best? Government agencies are adopting both, as well as hybrids. The private cloud vs. public cloud debate is rapidly giving way to new models where agencies tap on-demand IT resources from a variety of cloud platforms -- private, commercial, hybrid, software as a service -- based on what best suits their needs.

There are few technology trends the U.S. government is embracing with such fervor as the cloud. In his Federal Cloud Computing Strategy report, published in February, federal CIO Vivek Kundra set a target of shifting 25% of the government's $80 billion in annual IT spending to cloud computing.

How fast will federal agencies make the transition? InformationWeek Government and InformationWeek Analytics surveyed 137 federal IT pros in February to gauge their plans. Our 2011 Federal Government Cloud Computing Survey shows a big jump in the use of cloud services, with 29% of respondents saying their agencies are using cloud services, up 10 points from last year. Another 29% plan to begin using the cloud within 12 months, which means adoption should surpass the 50% mark in the year ahead.

As federal IT teams evaluate where cloud computing fits in their broad IT strategies, they must answer some fundamental questions: Where will cloud services deliver savings over existing systems? How should they provision and manage cloud services? And the big one on everyone's mind, what about data security?

The Obama administration's "cloud first" policy requires agencies to use cloud services where possible for new IT requirements. Cloud computing is more than a new technology services approach; it demands changes to deep-rooted procurement processes and organizational culture. It's also an alternative to capital investment in systems and software, as agencies look to eliminate 800 data centers over the next four years in accordance with the Federal Data Center Consolidation Initiative.

The Office of Management and Budget's influence is shown in our survey, with 21% of respondents saying that compliance with OMB guidance is a driver in their shift to cloud computing.

The economies of scale from shared, centralized infrastructure have the potential to lower usage costs across government. In a pure utility model, users pay only for what they consume, but that doesn't translate to federal IT yet. However, with the prospect of decreasing budgets, agencies must find ways to direct limited funds to their core missions, which may mean having less money available for IT investments. Cloud computing could very well be part of how they cope.

Federal IT pros are clearly looking for savings in the cloud. In our survey, lowering IT costs is the No. 1 business driver of cloud computing, mentioned by 62% of respondents.

Private Clouds For Hire

Agencies face many challenges in moving to the cloud. Top among them is assuring the security of systems and data, identified by 77% of respondents. To address that concern, vendors are offering private clouds with tighter controls over the geographic location of data storage and other aspects of security.

The downside is that all of this comes at a price. The more unique a cloud environment, the harder it is to leverage the scale of the cloud model and, with that, realize the cost savings made possible by a wide user base and cheap resources. It's important that agencies perform their own cost assessments because private clouds and public clouds aren't always the least expensive choices. In general, private clouds don't offer the same savings as public clouds.

The Department of Defense and some intelligence agencies have launched data center improvement initiatives under the private cloud moniker. These efforts seek to employ service catalogs and orchestration technology for configuring and provisioning IT resources. While such initiatives will make data centers more efficient and have other value, it has been hard to demonstrate return on investment that's anywhere near what's possible with commercial cloud services. Private clouds often require a significant up-front investment in equipment, and the complexities of managing IT capacity remain, so the potential for long-term operational savings is difficult to establish.

Making SaaS Work

In the commercial market, SaaS gives companies enterprise-class capabilities without the ownership capital costs of self-managed applications. But once hooked, businesses may get socked with usage fees that, over time, exceed the cost of conventional software deployments. The trade-off may be worth it, however, since they're conserving up-front capital and not building IT empires in support of on-premises software.

In federal government, many CIOs are dealing with established software systems that represent substantial investments. Furthermore, technical challenges around integration and storage and legal requirements related to where data resides are potential barriers to SaaS. Storing information in the cloud will require "a technical mechanism" to achieve compliance with the records management laws and policies of the National Archives and Records Administration and the General Services Administration, according to the Federal Cloud Computing Strategy report.

Uncle Sam's SaaS portal, Apps.gov, has experienced only limited uptake by agencies, but Apps.gov isn't the only option. Agencies can procure SaaS through requests for proposals or piggyback on existing contract vehicles. The problem becomes the length of the certification and accreditation process required to ensure that a SaaS app satisfies an agency's security policies. A drawn-out procurement and C&A effort can negate any savings SaaS might provide.

Private clouds are the preferred model in government, with 46% of respondents already using or highly likely to use private clouds. But agencies are also looking to plug into cloud services outside of their data centers, and 27% say it's highly likely they will do that through a government portal such as Apps.gov.

What about commercial cloud services from vendors such as Amazon, Google and Microsoft? Going forward, federal IT pros are twice as likely to subscribe to those services when the services have been specifically adapted for government customers, such as Google's Government Cloud. In our survey, 11% are highly likely to adopt commercial cloud services; that jumps to 22% for commercial clouds adapted for government.

How FedRAMP Helps

To reduce barriers to entry, the federal CIO Council has established the Federal Risk and Authorization Management Program, or FedRAMP, which is intended to bring a standard approach to assessing and authorizing cloud services and products. The goal, according to Kundra, is to "allow joint authorizations and continuous security monitoring services for government and commercial cloud computing systems intended for multiagency use."

In theory, FedRAMP will lead to a common security risk model that can be leveraged across agencies. In reality, however, the program will get agencies only part of the way through that process. In our survey, 44% of respondents are unfamiliar with the FedRAMP program, and 26% have conducted their own C&A instead of taking advantage of it. A lot more work is needed to get more vendors through the program and to promote it within agencies.

Another new program, Standards Acceleration to Jumpstart Adoption of Cloud Computing, led by the National Institute of Standards and Technology, also has had limited impact. In our survey, 53% of federal IT pros haven't heard of the initiative, and only 5% find it very helpful.

As part of the SAJACC program, NIST published 25 use cases to help federal IT pros assess cloud-based offerings. Examples include "cloud bursting" from data centers to cloud services to meet spikes in demand, and migrating a queuing-based application to the cloud. While SAJACC may spur ideas, there isn't a lot of actionable information in the case studies to guide selection and adoption of cloud computing.

Real-World Scenarios

Agencies are looking for ways to take advantage of cloud computing, while maintaining data security and protection, and new initiatives take many forms. Here are a few examples of how agencies are getting started.

>> The U.S. Patent and Trademark Office's financial and acquisition system, dubbed Momentum, has one production environment and four test environments, comprising 25 servers with 10 integrations. The production database, including the failover database, is 2 TB, while the test database is 4 TB. (All are Oracle.) The test database is production-sized and refreshed with scrubbed production data periodically. USPTO is assessing the feasibility of moving Momentum to a cloud environment.

>> The Air Force Research Laboratory's Information Directorate is exploring how cloud technology might be used for cybersecurity mission assurance. Its goal is to see if cloud computing can increase the availability and redundancy of continuous operations.

>> The Department of Education is planning to issue an RFP for the operation and maintenance of its Migrant Student Information Exchange, and it's interested in cloud computing as a potential way of providing those capabilities. MSIX, implemented in 2007, contains records for 97% of the migrant student population, with data from 41 states.

>> The Department of Transportation, Federal Aviation Administration, and Air Traffic Organization may explore cloud computing in a test program. This program would provide a virtual production environment that simulates ATO's production environment, which is spread across a number of facilities. The virtual environment would be used to provide email service and to develop and test software.

Private Cloud Considerations

The easier it is for users to request services from a private cloud, the more complex the back-end processes have to be. From the service request to provisioning and managing the service, a mature process environment is required if you’re going to automate those tasks and achieve the benefits of rapid, on-demand provisioning and, ultimately, cost savings.

Unfortunately, the best server provisioning, orchestration, and management tools won’t compensate for a lack of well-conceived processes. While the ITIL has been a rallying cry for IT process improvement, many IT organizations aren’t at the level of maturity required for private clouds.

The ability to manage capacity is important in private clouds, though many traditional software tools don’t adapt well to that job. Monitoring application performance, faults, and security in a private cloud often requires a different set of tools. So far, the options that have sprung up in the market are geared toward virtualized data centers. IT organizations must determine how to integrate new cloud-aware tools with their enterprise management platforms to get a complete picture of their computing environments.

Our data shows agencies are very interested in rapidly expanding into the cloud, driven by cost savings, an ability to accelerate delivery of IT services and infrastructure, and the prospect of tight IT budgets and fewer data centers. But the transition presents challenges around security, systems integration, governance, and more.

To maximize the benefits, federal IT teams must enter the cloud with well-conceived business and deployment plans and a readiness to adjust along the way.

Cloud changing face of data centers

By Liau Yun Qing

Summary

Cloud computing will be one of the major forces shaping next-generation data centers, which look set to become smaller and more agile to meet evolving enterprise needs, say market watchers.
Cloud computing is one of the forces shaping data centers over the next five years, note market observers who also share their vision of next-generation data centers.
In a statement released last month, Gartner highlighted cloud computing as one of the four factors that will change datacenter space requirements in the next five years. "Datacenter managers are beginning to consider the possibility of shifting nonessential workloads to a cloud provider, freeing up much-needed floor space, power and cooling, which can then be focused on more-critical production workloads, and extending the useful life of the data center," said the research firm.
With the shift to offloading nonessential services to a cloud provider, the corporate datacenter landscape will change, according to Gartner. In fact, the research firm predicted that by 2018, datacenter space requirements will shrink to only 40 percent of what is required today as data centers focus on core business services. While these core business services will demand more IT resources, Garter noted that the shrinking size of server, storage and networking equipment will also contribute to the reduction in datacenter space.
Aside from turning to cloud services as a strategic decision, cloud computing is also helping to deliver energy efficiency to data centers, said Alex Tay, datacenter services executive at IBM Asia-Pacific. This, he explained in an e-mail interview, is a result of an increase in server utilization rates brought about by virtualization and consolidation of servers.
Flexibility, immediacy hallmark of next-gen data centers
According to the Gartner report, besides cloud computing, datacenter managers also need to focus three aspects when designing their future leading edge facilities. They are smarter datacenter designs, green IT pressures as well as solving density issues.
David Cappuccio, managing vice president and chief of research for infrastructure at Gartner, noted in the statement that data centers with traditional methods of design will "no longer work without understanding the outside forces that will have an impact on datacenter costs, size and longevity".
ZDNet Asia spoke to two data center players to find out what the blueprint of their next-generation data centers looks like.
For Big Blue, the next-generation data center has three primary features, said Tay. It is capable of supporting high-density computing, has the ability to optimize capital and operating cost, and boasts a flexible design that allows integration of newer technologies.
In addition, traditional datacenter considerations such as security, location and operations remain, he noted.
Over at Hewlett-Packard, the vision of the next-generation data center is "Instant-On", said Wolfgang Wittmer, senior vice president and general manager of enterprise servers, storage and networking at HP Asia-Pacific and Japan. In his e-mail, he explained that an Instant-On enterprise is one which serves customers, employees, partners and citizens with whatever they want and need instantly at any point in time and through any channel.
While Wittmer acknowledged that cloud delivery is becoming an important paradigm, he noted that multisourcing is the optimal model for businesses.
"Enterprises need to be able to choose from the full spectrum of delivery options," he said, noting that the company's hybrid delivery approach helps clients select the best method of service delivery and then integrate it into their environment.

Hewlett-Packard acquires Melodeo, a provider of cloud-based music delivery systems for mobile devices.

Hewlett-Packard (HPQ) this afternoon confirmed a TechCrunch report that it has acquired Melodeo, a provider of cloud-based music delivery systems for mobile devices.

In a statement, the company said the deal is “another example of our efforts to bring new, innovative technologies to market. We are excited about the potential of this technology to bring the power of cloud-based delivery service to millions of customers.”

The company declined to announce the terms of the deal.

Techcrunch earlier put the size of the deal at between $30 million and $35 million

(http://blogs.barrons.com/techtraderdaily/2010/06/23/hp-confirms-melodeo-deal/?mod=yahoobarrons)

Defence Signals Directorate (DSD)'s Cloud Computing Security Considerations


Australia releases cloud computing guide

Defence Signals Directorate (DSD), an Australian intelligence agency, has released an 18-page document urging government agencies in the country to carefully consider risks associated with cloud computing before adopting the technology.

The Cloud Computing Security Considerations deals with traditional cloud fears like security, location of servers and Service Level Agreement (SLA) issues. Agencies are advised to “balance the benefits of cloud computing with the security risks associated with the agency handing over control to a vendor”.

DSD treated cloud vendors with a big dose of caution in case of vendors who may “insecurely transmit, store and process the agency’s data”.

“Vendor’s responses to important security considerations must be captured in the SLA,” advised the paper. “Otherwise the customer only has vendor promises and marketing claims that can be hard to verify and may be unenforceable.”

The paper urged agencies to consider where offshore location data is stored, backed up and processed in, which country hosts the failover or redundant data centre and whether or not the vendor will notify the agency of any change in this area. Agencies were also asked to pick vendors who stored and managed data within Australia itself.

Cloud Computing Reference Architecture – Review of the Big Three

Blueprint for a cloud development and deployment model
By Srinivasan Sundara Rajan
Cloud Reference Architecture
Reference Architecture (RA) provides a blueprint of a to-be-model with a well-defined scope, the requirements it satisfies, and architectural decisions it realizes. By delivering best practices in a standardized, methodical way, an RA ensures consistency and quality across development and delivery projects.
Major players in the cloud computing field are:
  • Hewlett Packard
  • IBM
  • Microsoft (Unlike HP, IBM Microsoft's Cloud Reference Architecture is specific to HYPER-V )
They have created their reference architecture for cloud computing. This should be a very happy news for enterprise adoption as we have blueprints from the industry leaders.  We strive to analyze their reference architecture on how they view the blueprint of a cloud model.

The intention at this time, not to give any opinion on which is better, it is more of a understanding of their point of view.
For the rest of the article, Cloud Computing Reference Architecture is mentioned as (CCRA).
All the materials discussed in this article are taken from the publically available content (Google Search) of the respective vendors.
Service Consumer in CCRA
IBM:
Cloud Service Consumer or Client is viewed as ‘In House IT' who can use an array of Cloud integration tools to get the desired business capability. This could be individuals within the enterprise too, however the ‘In house IT' could be a general collection of all of them.
HP: Cloud Service Consumer is represented in ‘Demand' layer of CCRA. However the demand layer covers more than the consumer, but also service catalog, portal access for provision of services. The service provider plays a important role in the Demand layer too, as provider is the one who makes services available as Configure to Order through an automated service system.
Microsoft: The tenant/user self-service layer provides an interface for Hyper-V cloud tenants or authorized users to request, manage, and access services, such as VMs, that are provided by the Hyper-V cloud architecture.
Service Provider in CCRA
IBM:
Providers are the ones, who deliver the  Cloud Services to the  clients.  They consist of basic models:
  • Infrastructure-as-a-Service
  • Platform-as-a-Service
  • Software-as-a-Service
  • Business-Process-as-a-Service
The providers are also inclusive of existing third-party services and partner eco systems.
HP: Service Providers play their role in both ‘Demand', ‘Deliver' layers of CCRA. In the delivery layer, Service Providers intelligently orchestrates the configuration and activation of services and schedules for the provisioning of the necessary resources by aggregating data from the service configuration model.
Microsoft: Taking a service provider's perspective toward delivering infrastructure transforms the IT approach. If infrastructure is provided as a service, IT can use a shared resource model that makes it possible to achieve economies of scale. This, combined with the other principles, helps the organization to realize greater agility at lower cost. As evident this Reference Architecture concentrates more on IaaS delivery.
Service Creator in CCRA
IBM:
Service creator are the ones who use service development tools to develop new cloud services. This includes both the development of runtime artifacts and management-related aspects (e.g., monitoring, metering, provisioning, etc.). "Runtime artifacts" refers to any capability needed for running what is delivered as-a-service by a cloud deployment. Examples are JEE enterprise applications, database schemas, analytics, golden master virtual machine images, etc.
HP: Service creator plays a role in ‘ Supply Layer' which functions as the dynamic resource governor that integrates a dynamic and mixed work load utility function across a heterogeneous environment with a model based orchestration system to optimize the supply of resources to fulfill the delivery of service requests. Again there are templates and tools that support the Service Creator in ‘Supply Layer'.
Microsoft: The orchestration layer must provide the ability to design, test, implement, and monitor these IT workflows. The orchestration layer is the critical interface between the IT organization and its infrastructure and transforms intent into workflow and automation.
Infrastructure in CCRA
IBM:
"Infrastructure" represents all infrastructure elements needed on the cloud service provider side, which are needed to provide cloud services. This includes facilities, server, storage, and network resources, how these resources are wired up, placed within a data center, etc. The infrastructure element is purely scoped to the hardware infrastructure.
HP: "Infrastructure" layer is abstracted behind the ‘Supply Layer' and consists of power & cooling, servers , storage, network, Software, information and other external cloud.
Microsoft: "Infrastructure" layer covers, Servers, Storage, Networking, Virtualization.
Management Platform in CCRA
IBM:
Cloud management platform consists of Operational Support Services (OSS) and Business Support Services (BSS).
CIO, CTO & Developer Resources
Business Support Services represents the set of business-related services exposed by the Cloud platform, which are needed by Cloud Service Creators to implement a cloud service. Some of them being:
  • Customer Account Management
  • Service Catalog Offering
  • Pricing/Billing/Metering
  • Accounts Receivable and Payable
Operational Support Services represents the set of operational management / technical-related services exposed by the cloud platform, which are needed by Cloud Service Creators to implement a cloud service. Some of them being
  • Provisioning
  • Incident and Problem Management
  • Image Life Cycle Management
  • Platform and Virtualization Management
HP: Aspects of Cloud Management,  cuts across all the layers of CCRA below are some of the management aspects taken care in each layer (this is not the exhaustive list):
Demand Layer
  • User Access Management
  • Service Offer Management
Delivery Layer
  • Billing and Rating
  • Request Processing & Activation
Supply Layer
  • Usage Metering
  • Dynamic Work Load Management
Microsoft: The management layer consists of the tools and systems that are utilized to deploy and operate the infrastructure. In most cases, this consists of a variety of toolsets for managing hardware, software, and applications. Ideally, all components of the management system would use the automation layer and not introduce their own protocols, scripting languages, or other technologies, because this increases complexity and may require additional staff expertise.
Qos (Quality of Service) in CCRA
IBM:
Security, Resiliency, Performance & Consumability are cross-cutting aspects on QoS spanning the hardware infrastructure and Cloud Services. These non-functional aspects must be viewed from an end-to-end perspective including the structure of CCRA by itself, the way the hardware infrastructure is set up (e.g., in terms of isolation, network zoning setup, data center setup for disaster recovery, etc.) and how the cloud services are implemented. The major aspects of QoS being
  • Threat and Vulnerability Management
  • Data Protection
  • Availability & Continuity Management
  • Ease of doing business
  • Simplified Operations
HP: Much like Cloud Management QoS in CCRA cuts across all the layers of CCRA.
Demand Layer
  • Quality Of Experience
  • SLA Compliance
Delivery Layer
  • Quality Of Service
Supply Layer
  • Resource Monitoring and Dynamic allocation
Microsoft: The service management layer provides the means for automating and adapting IT service management best practices.
Summary
Availability of a Reference Architecture by the three leading industry pioneers is a good sign for the enterprises to adopt Cloud Computing based delivery model. As we have seen there is a fair amount of similarities in between which should pave the way for inter-operability and avoid vendor lock in with the cloud applications. The following diagram summarizes the common building blocks in the reference architecture published by the big 3. We also find the Microsoft Reference Architecture covers more physical aspects of a cloud platform.

References
IBM Presentation : Building Your Cloud Using IBM Cloud Computing Reference Architecture
HP Cloud Reference Architecture - HP Software Universe 2010 - Presentation on Slide Share
Microsoft Hyper-V Cloud Reference Architecture White Paper

Source: http://cloudcomputing.sys-con.com/node/1752894