Cornell Red Cloud: Campus-based Hybrid Cloud. Steven Lee Cornell University Center for Advanced Computing

Similar documents
Federated XDMoD Requirements

Award No /1/2016 NSF-Arlington, VA

Eucalyptus Overview The most widely deployed on-premise cloud computing platform

NGF0502 AWS Student Slides

Introduction to Cloud Computing

EdgeConnect for Amazon Web Services (AWS)

AWS Solutions Architect Associate (SAA-C01) Sample Exam Questions

Introduction to Amazon Web Services

AUTOMATING IBM SPECTRUM SCALE CLUSTER BUILDS IN AWS PROOF OF CONCEPT

AWS Solution Architecture Patterns

Installing VMware vsphere 5.1 Components

Introduction to HPC Resources and Linux

DenyAll WAF User guide for AWS

Best Practices for Migrating Servers to Microsoft Azure with PlateSpin Migrate

OpenNebula on VMware: Cloud Reference Architecture

Pexip Infinity and Amazon Web Services Deployment Guide

COP Cloud Computing. Presented by: Sanketh Beerabbi University of Central Florida

Training on Amazon AWS Cloud Computing. Course Content

Cloudera s Enterprise Data Hub on the Amazon Web Services Cloud: Quick Start Reference Deployment October 2014

Installation of Informatica Services on Amazon EC2

Create a Dual Stack Virtual Private Cloud (VPC) in AWS

Oracle WebLogic Server 12c on AWS. December 2018

Eucalyptus User Console Guide

ForeScout CounterACT. (AWS) Plugin. Configuration Guide. Version 1.3

CPM. Quick Start Guide V2.4.0

Pexip Infinity and Amazon Web Services Deployment Guide

White Paper. Platform9 ROI for Hybrid Clouds

Developing Enterprise Cloud Solutions with Azure

Deploy the Firepower Management Center Virtual On the AWS Cloud

Security Camp 2016 Cloud Security. August 18, 2016

Eucalyptus User Console Guide

Cloud Computing. UCD IT Services Experience

Amazon Elastic Compute Cloud (EC2)

High Performance Computing Resources at MSU

Amazon Web Services Cloud Computing in Action. Jeff Barr

Documentation. This PDF was generated for your convenience. For the latest documentation, always see

Scheduling Computational and Storage Resources on the NRP

271 Waverley Oaks Rd. Telephone: Suite 206 Waltham, MA USA

Automating Elasticity. March 2018

Installation Guide Revision B. McAfee Cloud Workload Security 5.0.0

Amazon AWS-Solutions-Architect-Professional Exam

LINUX, WINDOWS(MCSE),

Centrify Identity Services for AWS

CIT 668: System Architecture. Amazon Web Services

Configuring a Palo Alto Firewall in AWS

Quick start guide for Infscape UrBackup Appliance on Amazon Web Services

Cloudera s Enterprise Data Hub on the AWS Cloud

BERLIN. 2015, Amazon Web Services, Inc. or its affiliates. All rights reserved

EBOOK: VMware Cloud on AWS: Optimized for the Next-Generation Hybrid Cloud

Bringing OpenStack to the Enterprise. An enterprise-class solution ensures you get the required performance, reliability, and security

LBRN - HPC systems : CCT, LSU

AWS Integration Guide. Full documentation available at

F5 BIG-IQ Centralized Management and Amazon Web Services: Setup. Version 5.4

25 Best Practice Tips for architecting Amazon VPC

SuperMike-II Launch Workshop. System Overview and Allocations

Cisco CSR1000V Overview. Cisco CSR 1000V Use Cases in Amazon AWS

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

Introduction to cloud computing

Minfy-Magnaquest Migration Use Case

OnCommand Cloud Manager 3.2 Deploying and Managing ONTAP Cloud Systems

AWS Course Syllabus. Linux Fundamentals. Installation and Initialization:

AWS Administration. Suggested Pre-requisites Basic IT Knowledge

2013 AWS Worldwide Public Sector Summit Washington, D.C.

Enterprise Network Compute System (ENCS)

Technical Brief. Adding Zadara Storage to VMware Cloud on AWS

Enroll Now to Take online Course Contact: Demo video By Chandra sir

globus online Globus Nexus Steve Tuecke Computation Institute University of Chicago and Argonne National Laboratory

SURVEY PAPER ON CLOUD COMPUTING

How to go serverless with AWS Lambda

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX

XSEDE s Campus Bridging Project Jim Ferguson National Institute for Computational Sciences

Exam Questions AWS-Certified- Developer-Associate

AWS_SOA-C00 Exam. Volume: 758 Questions

Open Cloud Reference Architecture

ThoughtSpot on AWS Quick Start Guide

Database Level 100. Rohit Rahi November Copyright 2018, Oracle and/or its affiliates. All rights reserved.

Elastic Efficient Execution of Varied Containers. Sharma Podila Nov 7th 2016, QCon San Francisco

Introduction to Virtualization

CSC- Bioweek 2018 Using cpouta for cloud computing Kimmo Mattila, Shubham Kapoor, Ari-Matti Saren (Jukka Nousiainen)

SaaSaMe Transport Workload Snapshot Export for. Alibaba Cloud

Container Orchestration on Amazon Web Services. Arun

S U M M I T B e r l i n

FAST TRACK YOUR AMAZON AWS CLOUD TECHNICAL SKILLS. Enterprise Website Hosting with AWS

Organizational Update: December 2015

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3

How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT

Infoblox Installation Guide. vnios for Amazon Web Services

Amazon Elastic Compute Cloud

HySecure Quick Start Guide. HySecure 5.0

Jetstream: Adding Cloud-based Computing to the National Cyberinfrastructure

ArcGIS for Server: Administration and Security. Amr Wahba

At Course Completion Prepares you as per certification requirements for AWS Developer Associate.

Andrew Pullin, Senior Software Designer, School of Computer Science / x4338 / HP5165 Last Updated: October 05, 2015

McAfee Cloud Workload Security Suite Amazon Machine Image Installation Guide

Building a Modular and Scalable Virtual Network Architecture with Amazon VPC

HPC Capabilities at Research Intensive Universities

PARTLY CLOUDY DESIGN & DEVELOPMENT OF A HYBRID CLOUD SYSTEM

Georgia State University Cyberinfrastructure Plan

Installation and User Guide

ForeScout Amazon Web Services (AWS) Plugin

Transcription:

Cornell Red Cloud: Campus-based Hybrid Cloud Steven Lee Cornell University Center for Advanced Computing shl1@cornell.edu

Cornell Center for Advanced Computing (CAC) Profile

CAC mission, impact on research Research computing and consulting services Mission: accelerate discovery and broaden impact Wide range of services HPC cluster maintenance and storage to data management, programming, and visualization Impact on research Supporting Cornell faculty with over $100 million in research funding from NSF, NIH, USDA, DOE, NASA Management roles in national cyberinfrastructure program NSF Computer, Information Science & Engineering Advisory Committee

Red Cloud & Aristotle Cloud Federation Overview

Red Cloud overview Launched 2011 Motivation: for workloads not suitable for HPC batch queues Features AWS-compatible API Compute: EC2 Storage: object storage (S3); block storage (EBS) Networking: elastic IP/security groups Accounts and access management: IAM 10 Gigabit Network Interconnect No CPU/RAM over-subscription Subscription model Limits accidental research budget overruns

Red Cloud infrastructure Cloud stack: Eucalyptus 2 locations Cornell s main Ithaca campus Weill Cornell Medicine NYC Compute: 472 CPU cores Users can choose from instance types up to 28 cores/192gb RAM Storage Storage in Ithaca cloud is hosted in a Ceph cluster with ~1 PB capacity Storage in NYC cloud is hosted in a Dell SAN Networking 10 Gbit Ethernet interconnect between cloud components Each cloud has a 10 Gbit uplink to Cornell campus network

On-demand scalable infrastructure, deployed in minutes Red Cloud gives users a fully customizable computing resource Many instance sizes to choose from Get root access to instances Allocate block storage in increments of GB Define network access policies via security groups Managing cloud resources via web console, command line client, API Application examples Develop/test code and burst production workload to AWS if necessary Web portals Interactive workloads Software as a service: MATLAB MDCS Cluster Virtualize center s internal infrastructure: web portals, file servers, Nagios monitor, etc.

Aristotle Cloud Federation NSF CC*DNI DIBBs project (2015-2020) Cornell (PI); University at Buffalo, UC Santa Barbara (co-pis) Federated cloud model goals Optimize time to science Share resources fairly among institutions Cross-institution allocations Burst to remote federated cloud sites or public cloud during peak usage Open XDMoD cloud monitoring and metrics

Layered Security Cloud perimeter, stack & instances

Cloud perimeter security Red Cloud installations are located in central data centers in Ithaca and NYC on their own subnets Leverage central IT security for Network access control by campus firewall Restricts network access to Red Cloud infrastructure Cloud controllers, storage, nodes running cloud instances Allows unrestricted network access to cloud instances Monitoring Cloud instances are protected by user-defined policies for its security group per AWS architecture Red Cloud subnet is monitored like a network in the data center Photos, CAC systems staff illustrations, serves as liaisons between IT security graphics and users here. Security incident reporting and handling

Cloud stack security features Red Cloud accounts are integrated with CAC s Active Directory and fully automated account management system PIs and their proxies can add and remove users from their projects Eucalyptus Web Console supports InCommon via Globus Auth Enable SSO by all Aristotle Cloud Federation users Access to cloud resources and quotas can be defined on per-user basis by PIs via AWS-styled IAM policies

Cloud stack security features (cont.) Users can define network access policies for their instances Each instance is placed in a security group during startup Users defines network access policies for the security group Default policy denies all inbound access Users must explicitly grant access by protocol, IP address and range User education and easy-to-use management GUI are critical Why can t I ssh into my new instance?

Securing cloud instances Base Linux and Windows images are maintained by CAC staff Linux Initial root access granted by user-specified ssh keypairs Password logins are not allowed in base images Windows Can configure Windows images to auto-join domains at startup Users are encourage to patch their running instances periodically

Lessons learned User education and communications are critical Capacity planning Forgot to shut down instances? Need new cloud capacity? Time to burst to public cloud? Liaison between central IT security and user Who s generating this traffic and why? Advocating to enable research Analyzing Twitter data during Super Bowl overwhelms Internet link