CloudCheckr : Amazon Complexity Challenges Many Users

NJVC to Spotlight Cloudcuity at Gartner Data Center Conference

By G C Network | November 15, 2012

Las Vegas., Nov. 15, 2012 — NJVC, an information technology solutions provider headquartered in Northern Virginia, announces it will spotlight its Cloudcuity™ framework for delivering secure and unified cloud management…

NJVC Cloud Expert Kevin L. Jackson Launches Second Book: GovCloud II: Implementation and Cloud Brokerage Services

By G C Network | November 9, 2012

VIENNA, Va., Nov. 8, 2012—NJVC, an information technology (IT) solutions provider headquartered in northern Virginia, is pleased to announce that Kevin L. Jackson, vice president and general manager, cloud services,…

Virtustream a Visionary in Gartner 2012 IaaS Magic Quadrant

By G C Network | October 27, 2012

Congratulations to NJVC Cloudcuity partner Virtustream for being positioned as a visionary in the Gartner 2012 IaaS Magic Quadrant! Magic Quadrants provide a graphical competitive positioning of four types of…

GovCloud II: Implementation and Cloud Brokerage Services Now Available

By G C Network | October 22, 2012

I’m happy and proud to announce the release of my second book, “GovCloud II: Implementation and Cloud Brokerage Services” by my publisher Government Training Inc.   The public and private…

NJVC® Introduces Cloudcuity™ AppDeployer to Create and Sell Software Applications

By G C Network | October 18, 2012

Developers Can Create, Deploy and Publish Apps in the Cloud for Free Vienna, Va., Oct. 18, 2012 — NJVC®, an information technology (IT) solutions provider headquartered in Northern Virginia, introduces…

NJVC® Announces the Cloudcuity™ Government Marketplace, Powered by Virtustream’s Secure Cloud xChange

By G C Network | October 4, 2012

Vienna, Va., Oct. 4, 2012—NJVC®, an information technology solutions provider headquartered in Northern Virginia, and Virtustream, Inc., a leading enterprise cloud software company, today announced a new alliance to provide…

Cloudcuity™: Thought Leadership Translated to Operational Excellence

By G C Network | September 26, 2012

As my long time readers have certainly noticed, the frequency of my posts have lengthened over the past few months. First, I would like to offer my apologies for being…

NJVC® Unveils Cloudcuity™ Umbrella Framework for NJVC Cloud Services

By G C Network | September 13, 2012

Vienna, Va., Sept. 13, 2012 — NJVC®, an information technology (IT) solutions provider headquartered in Northern Virginia, introduces Cloudcuity™, a new framework for the company’s cloud service offerings to help…

NJVC® Announces SaaS Accelerate: Specialized Infrastructure Hosting and Managed Services Program for Software-as-a-Service Providers

By G C Network | August 25, 2012

VIENNA, Va., Aug. 15, 2012 —NJVC® announces the release of NJVC SaaS Accelerate, a specialized infrastructure hosting and managed services offering designed to support the business needs of software-as-a-service (SaaS)…

Texas Cloud Computing Lessons Learned

By G C Network | August 12, 2012

Late last week  the Texas Department of Information Resources (DIR) released an important whitepaper that reviewed it’s multi-year Pilot Texas Cloud Offering (PTCO). This project was designed to allow a…

     A recently released infographic from CloudCheckr (https://cloudcheckr.com/) sheds quite a bit of light on the importance of expert advice when an enterprise decides to deploy to the cloud.  When AWS made Trusted Advisor free for the month of March, they took that opportunity to conduct an internal survey of their customers’ usage. CloudCheckr compared the initial scans of 400 users against a list of 125+ best practice checks. The survey was limited to users with over 10 EC2 instances. In aggregate, the users represent a total of just over 16,000 EC2 instances.



     They categorized survey results into 3 main categories: Cost, Availability, and Security; and that over 99% of their users were operating with at least one serious best practice exception. Their primary conclusion was that although cost often grabs the headlines, users suffer from a large number of availability and security issues.

  

     When considering availability, there were numerous serious configuration issues. Users repeatedly failed to optimally configure Auto Scaling and ELB. The failure to create sufficient EBS snapshots was an almost universal issue. When looking at security, they saw a smaller number of issues. However, the ones that did arise were very serious. Specifically, in S3, they saw nearly 1 in 5 users allowed unfettered access to their buckets through “Upload /Delete” or “Edit Permissions” set to everyone. As we explained in an earlier whitepaper, anyone using a simple bucket finder tool could locate and access these buckets.

     In short, typical Amazon Web Services users are not following relatively well know best practices when they deploy to the cloud.  This is not an indictment of the cloud computing model, but rather a realization that most cloud users can benefit greatly from the advice and support of a professional cloud deployment team. 

      Specific conclusion as provided by CloudChekr, are :

  • 96% of all users experienced at least 1 cost related exception(with many experiencing multiple exceptions).  
  • Price optimization remains a large hurdle for AWS users 
  • Nearly 98% suffered from at least 1 availability related exception. 
  • 44% of our users had at least one serious security related exception present  

Additional observations:
COST
  •  Spot instances worry users – there is a general concern of: “what if the price spikes and my instance is terminated?” This fear exists despite the fact that spikes occur very rarely, warnings are available, and proper configuration can significantly mitigate this “surprise termination” risk.
  • It is difficult and time consuming to map the cost scenarios for purchasing reserved instances. The customers who did make this transition had cobbled together home grown spreadsheets as a way of supporting this business decision.
  • The intricacies of matching the configurations between on demand instances and reserved instances while taking into consideration autoscaling and other necessary configurations were daunting. Many felt it was not worth the effort.
  • Amazon’s own process for regularly lowering the costs is a deterrent to purchasing RIs. This is especially true for RIs with a 3 year commitment. In fact, within the customers who did purchase RI, none expressed a desire to commit to 3 year commitments. All supported their refusal by referencing the regular AWS price drops and the fact that they could not accurately predict their business requirements 3 years out.

 
 AVAILABILITY

  • Users were generally surprised with the exceptions. They believed that they “had done everything right” but then realized that they underestimated the complexity of AWS.
  • Users were often unsure of exactly why something needed to be remedied. The underlying architecture of AWS continues to unfold and users are not always familiar with the latest AWS twist.
  • AWS dynamism played a large role in the number of exceptions. Users commented that they often fixed exceptions and, after a week of usage, found new exceptions had arisen.
  • Users remained very happy with the overall level of service from AWS. Despite the exceptions which diminish overall functionality, the users still found that AWS offered tremendous functionality advantages.

SECURITY

  • The AWS management console offered little functionality for helping with S3 security. It does not present a useful means of monitoring and controlling S3 inventory and usage. In fact, we found that most of our users were surprised when the inventory was reported. They often had 300-500% more buckets, objects and storage than they expected.
  • S3 is often an afterthought for users. EC2 commands more user attention. Users often failed to create and implement formal policies.
  • S3 cost was contributing to factor to the problems. Given the low cost, team members throw up objects and buckets at will while secure in the knowledge that they can store huge amounts of data at a minimal cost. Similarly, the low costdisincentives users to perform inventories from each region and perform an audit of objects and policies/configurations.  Since users did not know what they had stored, they could not determine the level of security.

·      
Bookmark and Share  

Cloud Musings on Forbes

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2012)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network

1 Comments

  1. Anonymous on March 26, 2013 at 5:32 pm

    Hi Everyone,

    I'm Aaron Klein a co-founder of CloudCheckr. I hope you found the results of our survey interesting and informative. If you are curious to see how well your AWS account is configured, we'd like to invite you to set up a free account on CloudCheckr. You just need to enter read only credentials from your AWS account into CloudCheckr, and within a few minutes, you can see how well you scored against our best practice checks: https://app.cloudcheckr.com/LogOn/Registration