CloudCheckr : Amazon Complexity Challenges Many Users

Firebrand Announces 2017 Accelerated CloudMASTER® Dates

By G C Network | December 23, 2016

Firebrand, the leader in Accelerated Learning, has recently announced it’s 2017 delivery schedule for their accelerated CloudMASTER® training course. Delivered in partnership with Logical Operations and the NCTA, this unique…

TAP Accelerates Artificial Intelligence

By G C Network | December 21, 2016

Photo credit: Shutterstock Over the past few years, the use of artificial intelligence has expanded more rapidly than many of us could have imagined. While this may invoke fear and…

Cognitive on Cloud

By G C Network | December 20, 2016

Photo credit: Shutterstock According to the IBM Institute for Business Value the market will see a rapid adoption of initial cognitive systems. The most likely candidates have moved beyond descriptive…

Europe: NCTA CloudMASTER® Hotspot

By G C Network | November 29, 2016

The ongoing digital transformation continues to generate a steady demand for workers with increasingly sophisticated digital skills. This process is multi-dimensional and workers with these highly specialized skills are very…

Smart Manufacturing Is Cloud Computing

By G C Network | November 27, 2016

As cloud computing simultaneously transforms multiple industries many have wondered about how this trend will affect manufacturing. Often characterized as “staid”, this vertical is not often cited when leading edge…

George Youmans, Jr.: The CloudMASTER Fashionista!

By G C Network | November 23, 2016

So how could a NCTA Certified CloudMASTER accelerate his career in the fashion industry? To answer that question, you would need to catch up with George Youmans, Jr. He has…

Is Cloud Interoperability a Myth?

By G C Network | November 20, 2016

Photo credit: Shutterstock As the industry matures, cloud computing will increasingly rely on interoperability in order to grow and deliver more value to industry. Assuming this is a fact, what…

Should Data Centers Think?

By G C Network | November 10, 2016

As cloud computing becomes the information technology mainstream, data center technology is accelerating at a breakneck speed. Concepts like software define infrastructure, data center analytics and Nonvolatile Memory Express (NVMe)…

For Top Cyber Threats, Look in the Mirror

By G C Network | October 31, 2016

A recent report by Praetorian, a cybersecurity company headquartered in Austin, TX, focused on threats that resulted in data compromise or access to sensitive information. Based on a review of…

Your Choice: Cloud Technician or Digital Transformer

By G C Network | October 28, 2016

The CompTIA Cloud+certification validates the skills and expertise of IT practitioners in implementing and maintaining cloud technologies.  This is exactly what it takes to become a good cloud technician.  In…

     A recently released infographic from CloudCheckr (https://cloudcheckr.com/) sheds quite a bit of light on the importance of expert advice when an enterprise decides to deploy to the cloud.  When AWS made Trusted Advisor free for the month of March, they took that opportunity to conduct an internal survey of their customers’ usage. CloudCheckr compared the initial scans of 400 users against a list of 125+ best practice checks. The survey was limited to users with over 10 EC2 instances. In aggregate, the users represent a total of just over 16,000 EC2 instances.



     They categorized survey results into 3 main categories: Cost, Availability, and Security; and that over 99% of their users were operating with at least one serious best practice exception. Their primary conclusion was that although cost often grabs the headlines, users suffer from a large number of availability and security issues.

  

     When considering availability, there were numerous serious configuration issues. Users repeatedly failed to optimally configure Auto Scaling and ELB. The failure to create sufficient EBS snapshots was an almost universal issue. When looking at security, they saw a smaller number of issues. However, the ones that did arise were very serious. Specifically, in S3, they saw nearly 1 in 5 users allowed unfettered access to their buckets through “Upload /Delete” or “Edit Permissions” set to everyone. As we explained in an earlier whitepaper, anyone using a simple bucket finder tool could locate and access these buckets.

     In short, typical Amazon Web Services users are not following relatively well know best practices when they deploy to the cloud.  This is not an indictment of the cloud computing model, but rather a realization that most cloud users can benefit greatly from the advice and support of a professional cloud deployment team. 

      Specific conclusion as provided by CloudChekr, are :

  • 96% of all users experienced at least 1 cost related exception(with many experiencing multiple exceptions).  
  • Price optimization remains a large hurdle for AWS users 
  • Nearly 98% suffered from at least 1 availability related exception. 
  • 44% of our users had at least one serious security related exception present  

Additional observations:
COST
  •  Spot instances worry users – there is a general concern of: “what if the price spikes and my instance is terminated?” This fear exists despite the fact that spikes occur very rarely, warnings are available, and proper configuration can significantly mitigate this “surprise termination” risk.
  • It is difficult and time consuming to map the cost scenarios for purchasing reserved instances. The customers who did make this transition had cobbled together home grown spreadsheets as a way of supporting this business decision.
  • The intricacies of matching the configurations between on demand instances and reserved instances while taking into consideration autoscaling and other necessary configurations were daunting. Many felt it was not worth the effort.
  • Amazon’s own process for regularly lowering the costs is a deterrent to purchasing RIs. This is especially true for RIs with a 3 year commitment. In fact, within the customers who did purchase RI, none expressed a desire to commit to 3 year commitments. All supported their refusal by referencing the regular AWS price drops and the fact that they could not accurately predict their business requirements 3 years out.

 
 AVAILABILITY

  • Users were generally surprised with the exceptions. They believed that they “had done everything right” but then realized that they underestimated the complexity of AWS.
  • Users were often unsure of exactly why something needed to be remedied. The underlying architecture of AWS continues to unfold and users are not always familiar with the latest AWS twist.
  • AWS dynamism played a large role in the number of exceptions. Users commented that they often fixed exceptions and, after a week of usage, found new exceptions had arisen.
  • Users remained very happy with the overall level of service from AWS. Despite the exceptions which diminish overall functionality, the users still found that AWS offered tremendous functionality advantages.

SECURITY

  • The AWS management console offered little functionality for helping with S3 security. It does not present a useful means of monitoring and controlling S3 inventory and usage. In fact, we found that most of our users were surprised when the inventory was reported. They often had 300-500% more buckets, objects and storage than they expected.
  • S3 is often an afterthought for users. EC2 commands more user attention. Users often failed to create and implement formal policies.
  • S3 cost was contributing to factor to the problems. Given the low cost, team members throw up objects and buckets at will while secure in the knowledge that they can store huge amounts of data at a minimal cost. Similarly, the low costdisincentives users to perform inventories from each region and perform an audit of objects and policies/configurations.  Since users did not know what they had stored, they could not determine the level of security.

·      
Bookmark and Share  

Cloud Musings on Forbes

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2012)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network

1 Comments

  1. Anonymous on March 26, 2013 at 5:32 pm

    Hi Everyone,

    I'm Aaron Klein a co-founder of CloudCheckr. I hope you found the results of our survey interesting and informative. If you are curious to see how well your AWS account is configured, we'd like to invite you to set up a free account on CloudCheckr. You just need to enter read only credentials from your AWS account into CloudCheckr, and within a few minutes, you can see how well you scored against our best practice checks: https://app.cloudcheckr.com/LogOn/Registration