Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #14801 > unrolled thread
| Started by | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| First post | 2015-05-19 21:53 +0100 |
| Last post | 2015-05-22 08:54 +0100 |
| Articles | 17 — 5 participants |
Back to article view | Back to comp.os.linux.misc
Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-19 21:53 +0100
Re: Cloud hosting - good groups or forums? noydb@no.way (Bruce Sinclair) - 2015-05-19 23:05 +0000
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 07:55 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 08:14 +0100
Re: Cloud hosting - good groups or forums? The Natural Philosopher <tnp@invalid.invalid> - 2015-05-20 09:26 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 10:26 +0100
Re: Cloud hosting - good groups or forums? Joe Beanfish <joebeanfish@nospam.duh> - 2015-05-20 13:44 +0000
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 15:31 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 13:06 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-20 08:46 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-21 11:11 +0100
Re: Cloud hosting - good groups or forums? Marc Haber <mh+usenetspam1118@zugschl.us> - 2015-05-21 12:27 +0200
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-21 14:52 +0100
Re: Cloud hosting - good groups or forums? The Natural Philosopher <tnp@invalid.invalid> - 2015-05-21 22:51 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-21 23:57 +0100
Re: Cloud hosting - good groups or forums? The Natural Philosopher <tnp@invalid.invalid> - 2015-05-22 00:07 +0100
Re: Cloud hosting - good groups or forums? Tim Watts <tw_usenet@dionic.net> - 2015-05-22 08:54 +0100
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-19 21:53 +0100 |
| Subject | Cloud hosting - good groups or forums? |
| Message-ID | <gfks2c-n8p.ln1@squidward.dionic.net> |
Anyone know any? We're running a mid sized VMWare cluster at work and it's EOL next year. The original plan was to simply replace it in situ - but for various reasons that option may be untenable. I'm trying to get my head around external hosting (of >160 Debian VMs to claim on-topic) - but so far my limited enquiries have concluded that cloud hosting will cost us about 5-7 times what it costs to buy and house our own hardware and VMWare licenses, including backup/DR. (Who said outsourcing saves money?) I have tried and failed to find a very general VM/cloud forum/group covering the UK and/or the EU to bat some ideas around and I suspect this is not the place to get specific. Does not have to be VMWare centric... If anyone has any leads I would be very grateful :) Cheers! Tim
[toc] | [next] | [standalone]
| From | noydb@no.way (Bruce Sinclair) |
|---|---|
| Date | 2015-05-19 23:05 +0000 |
| Message-ID | <mjgj1l$9q6$2@dont-email.me> |
| In reply to | #14801 |
In article <gfks2c-n8p.ln1@squidward.dionic.net>, Tim Watts <tw_usenet@dionic.net> wrote: >Anyone know any? > >We're running a mid sized VMWare cluster at work and it's EOL next year. >The original plan was to simply replace it in situ - but for various >reasons that option may be untenable. > >I'm trying to get my head around external hosting (of >160 Debian VMs to >claim on-topic) - but so far my limited enquiries have concluded that >cloud hosting will cost us about 5-7 times what it costs to buy and >house our own hardware and VMWare licenses, including backup/DR. > >(Who said outsourcing saves money?) Ooo! ... ooo ! I know this one ... pick me ! ... .. the outsourcers (of course :) ).
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 07:55 +0100 |
| Message-ID | <snnt2c-s6u.ln1@squidward.dionic.net> |
| In reply to | #14802 |
On 20/05/15 00:05, Bruce Sinclair wrote: >> >> (Who said outsourcing saves money?) > > > Ooo! ... ooo ! I know this one ... pick me ! ... > > > .. the outsourcers (of course :) ). > And a lot of people bang on about Amazon AWS/VPC/whatever-todays-product-is-called. But from what I can see and tried: 1) If the host dies, you need manual intervention to get you VM back; 2) No IPv6; 3) No VM console access (linuux VMs dump their output to a bufffer, but no direct input possible). 4) The most obtuse pricing model under the sun. 1+3 are killers and seem to preclude using amazon to run "some servers that need to stay up". I rely on 4 very occasionally to fix a machine (usually fsck threw a wobbler). 1 is just poor. 2 is not so urgent for us but does not inspire much confidence... 4 could be defended - you pay for what you use - but it makes estimation of costs very difficult, even when you have a year's worth of usage stats from VMWare. So I am not sure why people rave so much over Amazon...
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 08:14 +0100 |
| Message-ID | <4sot2c-p9v.ln1@squidward.dionic.net> |
| In reply to | #14805 |
On 20/05/15 07:55, Tim Watts wrote: > So I am not sure why people rave so much over Amazon... I would add, that for the odd server, Linode are very good. OTOH it gets expensive fast of you need loads. What we really need is the ability to buy a VMWare resource pool plus a load of IPv4 addresses with the freedom to do what we like within the pool. Most of the time our VMs (web servers) are very low consumption, but periodically one will need to do some serious work. This works well now as it basically can access all the resource it wants that is not being used by any other VM. But I have no idea if there's a name for "buy a resource pool". Is that a private cloud? Hybrid cloud? Too much marketing bollocks and silly jargon obscuring something that is basically actually very simple. I guess I'll have to phone some sales weasels.
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2015-05-20 09:26 +0100 |
| Message-ID | <mjhgga$6li$1@news.albasani.net> |
| In reply to | #14806 |
On 20/05/15 08:14, Tim Watts wrote: > On 20/05/15 07:55, Tim Watts wrote: >> So I am not sure why people rave so much over Amazon... > > > I would add, that for the odd server, Linode are very good. > > OTOH it gets expensive fast of you need loads. > > What we really need is the ability to buy a VMWare resource pool Does it have to be VMware? That's rather old hat these days plus a > load of IPv4 addresses with the freedom to do what we like within the > pool. Most of the time our VMs (web servers) are very low consumption, > but periodically one will need to do some serious work. This works well > now as it basically can access all the resource it wants that is not > being used by any other VM. What you are describing can in my opinion be satisfied in two ways. 1/. Buy your own big tin blade/RAID server and get it hosted somewhere physically, and then build WTF you like. Last time I looked it was about £10k a year for a rack in a dark office with fat pipe and some IP addresses. 2/. Rent as many VMS as you like from someone who already has exactly that. > > But I have no idea if there's a name for "buy a resource pool". Is that > a private cloud? Hybrid cloud? Too much marketing bollocks and silly > jargon obscuring something that is basically actually very simple. > Forget the bollocks, identify your technical needs and approach a SMALL VM porovider. Gridwatch is hosted on Gigatux, and marcs machines have a hundred off VMS on each, and they fully can grab CPU and bandwidth when needed (up to 100Mps I think) and each one has a private IP address. You could probably run vmware on top of that as well, as the basic hypervisor is Xen I think. But why bother? you can have as many linux machines as you are prepared to commission, and IIRC he can load windows server as well. http://www.gigatux.com/ > I guess I'll have to phone some sales weasels. Phone Marc. He is technical sales and everything. And because of that if you want to cut a deal for 100 machines of mixed windows/linux flavour, he can probably get out his spreadsheet and give you a price. My experience is that disk is cheap, CPU is cheap, but RAM is expensive so bear that in mind. What you have described is fully satisfied by one or more virtual machines hosted somewhere with good connectivity. The only two decisions are whether you own the physical kit, and what level of support you need. I recommend a smaller player, because my experience is that whilst prices are not rock bottom, neither is the service you get, and of increasing importance 'big' hosting enterprises are targeted by seriously unpleasant DDOS attacks far more frequently than smaller players. -- Everything you read in newspapers is absolutely true, except for the rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 10:26 +0100 |
| Message-ID | <sj0u2c-034.ln1@squidward.dionic.net> |
| In reply to | #14809 |
On 20/05/15 09:26, The Natural Philosopher wrote: > Does it have to be VMware? That's rather old hat these days > Doesn't have to be - but it must be *as good*. Not much IME beats it (except on price[1]). Extremely reliable, hot migration of host (OK everything can do that) and hot migration of VM storage (not so easy). Good performance monitoring. Console access to VMs. Resource limiting - I have had a very busy VM burn 2000+ IOPS (from a budget of about 5000 that the SAN can manage). Legit work - but I could quickly impose an IOPS cap on the VM to prevent it mashing the others. As far as I know, Xen (for example) can't do all of those. > > plus a >> load of IPv4 addresses with the freedom to do what we like within the >> pool. Most of the time our VMs (web servers) are very low consumption, >> but periodically one will need to do some serious work. This works well >> now as it basically can access all the resource it wants that is not >> being used by any other VM. > > What you are describing can in my opinion be satisfied in two ways. > > 1/. Buy your own big tin blade/RAID server and get it hosted somewhere > physically, and then build WTF you like. Last time I looked it was about > £10k a year for a rack in a dark office with fat pipe and some IP > addresses. That is what we are currently doing and I agree - clearly the most flexible solution. The hard part is that the datacentre we are in may not be an option next year and it comes with a 10gig pipe to JANET. It's actually the connection that gets infeasibly expensive very quickly. > > 2/. Rent as many VMS as you like from someone who already has exactly > that. > > >> >> But I have no idea if there's a name for "buy a resource pool". Is that >> a private cloud? Hybrid cloud? Too much marketing bollocks and silly >> jargon obscuring something that is basically actually very simple. >> > > Forget the bollocks, identify your technical needs and approach a SMALL > VM porovider. > > Gridwatch is hosted on Gigatux, and marcs machines have a hundred off > VMS on each, and they fully can grab CPU and bandwidth when needed (up > to 100Mps I think) and each one has a private IP address. > You could probably run vmware on top of that as well, as the basic > hypervisor is Xen I think. But why bother? you can have as many linux > machines as you are prepared to commission, and IIRC he can load windows > server as well. > > http://www.gigatux.com/ With caveats about Xen noted (unless that has improved) - thanks, I will have a look. > > >> I guess I'll have to phone some sales weasels. > > > > Phone Marc. He is technical sales and everything. > > And because of that if you want to cut a deal for 100 machines of mixed > windows/linux flavour, he can probably get out his spreadsheet and give > you a price. > > > My experience is that disk is cheap, CPU is cheap, but RAM is expensive > so bear that in mind. > > What you have described is fully satisfied by one or more virtual > machines hosted somewhere with good connectivity. The only two decisions > are whether you own the physical kit, and what level of support you need. > > > I recommend a smaller player, because my experience is that whilst > prices are not rock bottom, neither is the service you get, and of > increasing importance 'big' hosting enterprises are targeted by > seriously unpleasant DDOS attacks far more frequently than smaller players. Yes - that (DDOS) is a very good point.
[toc] | [prev] | [next] | [standalone]
| From | Joe Beanfish <joebeanfish@nospam.duh> |
|---|---|
| Date | 2015-05-20 13:44 +0000 |
| Message-ID | <mji33p$mn9$3@dont-email.me> |
| In reply to | #14806 |
On Wed, 20 May 2015 08:14:44 +0100, Tim Watts wrote: > On 20/05/15 07:55, Tim Watts wrote: >> So I am not sure why people rave so much over Amazon... > > > I would add, that for the odd server, Linode are very good. > > OTOH it gets expensive fast of you need loads. > > What we really need is the ability to buy a VMWare resource pool plus a > load of IPv4 addresses with the freedom to do what we like within the > pool. Most of the time our VMs (web servers) are very low consumption, > but periodically one will need to do some serious work. This works well > now as it basically can access all the resource it wants that is not > being used by any other VM. > > But I have no idea if there's a name for "buy a resource pool". Is that > a private cloud? Hybrid cloud? Too much marketing bollocks and silly > jargon obscuring something that is basically actually very simple. > > I guess I'll have to phone some sales weasels. I've just started exploring Expedient's VMWare pool usage model you mention. I don't have enough info about pricing etc yet, but I know they're good on redundancy etc. of the underlying hardware. https://www.expedient.com/ So far we just use them for our internet connection but are considering them for a possible move to vm cloud and/or colocation.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 15:31 +0100 |
| Message-ID | <neiu2c-lpe.ln1@squidward.dionic.net> |
| In reply to | #14815 |
On 20/05/15 14:44, Joe Beanfish wrote: > I've just started exploring Expedient's VMWare pool usage model > you mention. I don't have enough info about pricing etc yet, but I > know they're good on redundancy etc. of the underlying hardware. > https://www.expedient.com/ > > So far we just use them for our internet connection but are considering > them for a possible move to vm cloud and/or colocation. > Thanks Joe! I'm looking at them now... Tim
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 13:06 +0100 |
| Message-ID | <vu9u2c-ps9.ln1@squidward.dionic.net> |
| In reply to | #14802 |
On 20/05/15 00:05, Bruce Sinclair wrote: >> (Who said outsourcing saves money?) > > > Ooo! ... ooo ! I know this one ... pick me ! ... > > > .. the outsourcers (of course :) ). > Re: Amazon EC2: http://blog.awe.sm/2012/12/18/aws-the-good-the-bad-and-the-ugly/#~pde2twD6CvrBTH "Virtual hardware doesn’t last as long as real hardware. Our average observed lifetime for a virtual machine on EC2 over the last 3 years has been about 200 days. After that, the chances of it being “retired” rise hugely. And Amazon’s “retirement” process is unpredictable: sometime they’ll notify you ten days in advance that a box is going to be shut down; sometimes the retirement notification email arrives 2 hours after the box has already failed. Rapidly-failing hardware is not too big a deal — it’s easy to spin up fresh hardware, after all — but it’s important to be aware of it, and invest in deployment automation early, to limit the amount of time you need to burn replacing boxes all the time." That horrifies me. I can see the point of EC2 for spinning up loads of short lived VMs for a big compute job - or as media servers where it is assumed there are N identical servers and they are individually redundant. But for "proper servers" it looks a hopeless service - no to mention the lack of console access.
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-20 08:46 +0100 |
| Message-ID | <mnqt2c-8r.ln1@squidward.dionic.net> |
| In reply to | #14801 |
On 19/05/15 21:53, Tim Watts wrote: > Anyone know any? > > We're running a mid sized VMWare cluster at work and it's EOL next year. > The original plan was to simply replace it in situ - but for various > reasons that option may be untenable. > > I'm trying to get my head around external hosting (of >160 Debian VMs to > claim on-topic) - but so far my limited enquiries have concluded that > cloud hosting will cost us about 5-7 times what it costs to buy and > house our own hardware and VMWare licenses, including backup/DR. > > (Who said outsourcing saves money?) > > I have tried and failed to find a very general VM/cloud forum/group > covering the UK and/or the EU to bat some ideas around and I suspect > this is not the place to get specific. Does not have to be VMWare > centric... > > If anyone has any leads I would be very grateful :) > > Cheers! > > Tim "Cloud infrastructure" might be the magic word... Stumbled on this - good a start as any I guess: http://www.clouddir.co.uk/category/cloud-infrastructure/
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-21 11:11 +0100 |
| Message-ID | <1kn03c-ck4.ln1@squidward.dionic.net> |
| In reply to | #14801 |
On 19/05/15 21:53, Tim Watts wrote: > I have tried and failed to find a very general VM/cloud forum/group > covering the UK and/or the EU to bat some ideas around and I suspect > this is not the place to get specific. Does not have to be VMWare > centric... > I learnt something yesterday - If we went cloud, the terminology seems to be "virtual datacentre" or "virtual infrastructure". Had a very informed chat with one of the smaller London based providers and they use VMWare vCloud to allow multi-tenancy (another buzzword) on a large physical cluster. It seems that each "tenant" gets what they perceive to be a personal VMWare virtual cluster and they can treat it as they like and manage it more or less as a real VMWare cluster, minus the hardware aggravations. Firewalling is achieved at the hypervisor level using vShield Edge to give a customer managed border firewall. It's still sodding expensive, but at least it defines what I want (at least in functionality) from a cloud provider. Therefore I can at least get some quotes on an equal and informed footing for that particular solution. And it does not require a custom build as one of the bigger hosting companies offered (eg "You need firewalling? OK, we can add in a physical box, extra dosh, consultancy fees etc"...)
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2015-05-21 12:27 +0200 |
| Message-ID | <mjkbtl$cm5$1@news1.tnib.de> |
| In reply to | #14823 |
Tim Watts <tw_usenet@dionic.net> wrote: >If we went cloud, the terminology seems to be "virtual datacentre" or >"virtual infrastructure". > >Had a very informed chat with one of the smaller London based providers >and they use VMWare vCloud to allow multi-tenancy (another buzzword) on >a large physical cluster. > >It seems that each "tenant" gets what they perceive to be a personal >VMWare virtual cluster and they can treat it as they like and manage it >more or less as a real VMWare cluster, minus the hardware aggravations. > >Firewalling is achieved at the hypervisor level using vShield Edge to >give a customer managed border firewall. > >It's still sodding expensive, but at least it defines what I want (at >least in functionality) from a cloud provider. If you define all those properties as "must have", you'll rule out all of the cheaper virtualization techniques and you'll end up with the "soddingly expensive" VMware-based offers only. Greetings Marc -- -------------------------------------- !! No courtesy copies, please !! ----- Marc Haber | " Questions are the | Mailadresse im Header Mannheim, Germany | Beginning of Wisdom " | http://www.zugschlus.de/ Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-21 14:52 +0100 |
| Message-ID | <oh413c-lmd.ln1@squidward.dionic.net> |
| In reply to | #14824 |
On 21/05/15 11:27, Marc Haber wrote: > Tim Watts <tw_usenet@dionic.net> wrote: >> If we went cloud, the terminology seems to be "virtual datacentre" or >> "virtual infrastructure". >> >> Had a very informed chat with one of the smaller London based providers >> and they use VMWare vCloud to allow multi-tenancy (another buzzword) on >> a large physical cluster. >> >> It seems that each "tenant" gets what they perceive to be a personal >> VMWare virtual cluster and they can treat it as they like and manage it >> more or less as a real VMWare cluster, minus the hardware aggravations. >> >> Firewalling is achieved at the hypervisor level using vShield Edge to >> give a customer managed border firewall. >> >> It's still sodding expensive, but at least it defines what I want (at >> least in functionality) from a cloud provider. > > If you define all those properties as "must have", you'll rule out all > of the cheaper virtualization techniques and you'll end up with the > "soddingly expensive" VMware-based offers only. ^^^ That's an example discussion, it's not an absolute specification... But it is a good specification of features (if any other product or set of products can achieve similar). Obviously I don't care how the SAN works as long as it's fast enough - but vSAN does look cute as an aside... I have probably proved we should DIY as we do now... Essentially, we MUST have: VM Console access Reliable VMs (ie no random shutdowns because the host feels like it) Firewall A certain amount of resource (about 220vCPU, 390GB RAM, >7000IOPS) Straight forward management of the above. Hot migration for host and datastore (volume) Some backup/DR solution that works with the above. Nice to have - resource control/limiting on a VM basis. These are things I'm not prepare to compromise on - How's Xen with respect to those (specifically hot migration and console access to both Windows and Linux VMs)? It's been a long time and my experience with Xen has not been happy previously. (we'll allow the firewall to be external as VMWare's vShield is a bit special but it's not the only way to get a border firewall). Cheers Tim
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2015-05-21 22:51 +0100 |
| Message-ID | <mjlk1n$gcp$1@news.albasani.net> |
| In reply to | #14825 |
On 21/05/15 14:52, Tim Watts wrote: > On 21/05/15 11:27, Marc Haber wrote: >> Tim Watts <tw_usenet@dionic.net> wrote: >>> If we went cloud, the terminology seems to be "virtual datacentre" or >>> "virtual infrastructure". >>> >>> Had a very informed chat with one of the smaller London based providers >>> and they use VMWare vCloud to allow multi-tenancy (another buzzword) on >>> a large physical cluster. >>> >>> It seems that each "tenant" gets what they perceive to be a personal >>> VMWare virtual cluster and they can treat it as they like and manage it >>> more or less as a real VMWare cluster, minus the hardware aggravations. >>> >>> Firewalling is achieved at the hypervisor level using vShield Edge to >>> give a customer managed border firewall. >>> >>> It's still sodding expensive, but at least it defines what I want (at >>> least in functionality) from a cloud provider. >> >> If you define all those properties as "must have", you'll rule out all >> of the cheaper virtualization techniques and you'll end up with the >> "soddingly expensive" VMware-based offers only. > > ^^^ That's an example discussion, it's not an absolute specification... > But it is a good specification of features (if any other product or set > of products can achieve similar). > > Obviously I don't care how the SAN works as long as it's fast enough - > but vSAN does look cute as an aside... > > > I have probably proved we should DIY as we do now... > > > Essentially, we MUST have: > > VM Console access > Reliable VMs (ie no random shutdowns because the host feels like it) > Firewall > A certain amount of resource (about 220vCPU, 390GB RAM, >7000IOPS) > Straight forward management of the above. > Hot migration for host and datastore (volume) > Some backup/DR solution that works with the above. > > > Nice to have - resource control/limiting on a VM basis. > > > These are things I'm not prepare to compromise on - > How's Xen with respect to those (specifically hot migration and console > access to both Windows and Linux VMs)? It's been a long time and my > experience with Xen has not been happy previously. > The console access to my xen based server is pretty much 'an 80x25 console on a serial port' type access - i.e its enough to reboot the thing and look at basic issues, but as soon as there is enough machine up and running you want ssh or better. I am not sure how a 'console' works with a windows VM at all. so wont comment/ Obviously once its up any windows based remote access software will work as well as can be expected with the limited bandwidth of your Internet connection from the point of management. Although some providers provide backup, I do my own with rsync over ssh to a home server. RAID will be almost standard, so what that means in terms of hot migration if by that term you mean swapping to a second VM if the first one screws up, is not clear. Ultimately if you have VM on the same underlying platform its not gonna be an option if the whole hardware platform goes down. > > (we'll allow the firewall to be external as VMWare's vShield is a bit > special but it's not the only way to get a border firewall). > On linux I have a firewall on a per VM basis using Iptables. That's enough.Its never let me down yet. And it does enable tailored access on a per VM basis. Ultimately if you want to manage the thing from everywhere, you need a pretty simple firewall. allow all ouitgoi8ng, established and so on an disallow all incoming connections except services you need to be globally available and ssh only from ranges of IP addresses used to manage the thing. Yes. its not quite as simple as VMware with its browser based remote screen capability, but in practice you don't need that to manage most linux systems with a GUI, and as far as windows goes IIRC - and it is some time since i have played with windows - there are remote management tools that run within windows itself that are sufficient unto the day. Likewise windows has its own firewalling capabilities. > > > Cheers > > Tim -- Everything you read in newspapers is absolutely true, except for the rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-21 23:57 +0100 |
| Message-ID | <uf423c-o71.ln1@squidward.dionic.net> |
| In reply to | #14830 |
On 21/05/15 22:51, The Natural Philosopher wrote:
> The console access to my xen based server is pretty much 'an 80x25
> console on a serial port' type access - i.e its enough to reboot the
> thing and look at basic issues, but as soon as there is enough machine
> up and running you want ssh or better.
Indeed that would be fine.
> I am not sure how a 'console' works with a windows VM at all. so wont
> comment/ Obviously once its up any windows based remote access software
> will work as well as can be expected with the limited bandwidth of your
> Internet connection from the point of management.
I did some reading and I *think* it pulls a VNC job - good enough to
deal with boot problems until RDP is up and running.
>
> Although some providers provide backup, I do my own with rsync over ssh
> to a home server.
That would be not hugely practical with 20TB to backup up :)
On eof the driving factors with you have a lot of VMs is being able to
get from the backup to running VMs quickly in the event of a disaster
("disaster" might include needing to revert a VM that boned itself).
For that, full disk backups (plus the VM metadata) is the quickest way.
Our current solution uses Veeam Backup which can cooperate with VMWare's
Changed Block Tracking list (blocks that have been written since last
backup) so incremental backups are cheap.
> RAID will be almost standard, so what that means in terms of hot
> migration if by that term you mean swapping to a second VM if the first
> one screws up, is not clear. Ultimately if you have VM on the same
> underlying platform its not gonna be an option if the whole hardware
> platform goes down.
Host migration is moving the running VM to a new physical host - I know
Xen has been able to do that forever. Used for load balancing the host.
VMWare ESX(i) tends (unless disabled) tends to do this itself to balance
the host loads - typically a dozen or more hot migrations will happen in
any day depending on how VM loads change.
Disk (or volume) migration is used to balance IO to the luns on a SAN
(on my EqualLogic at least, the max IO queue depth is 32 and too many
VMs on a single LUN can cause poor latency). I am not sure how relevant
this is with other SANs or even vSAN. But essentially you can have the
VMs disks hot-moved from data store to data store.
>
>>
>> (we'll allow the firewall to be external as VMWare's vShield is a bit
>> special but it's not the only way to get a border firewall).
>>
>
> On linux I have a firewall on a per VM basis using Iptables.
> That's enough.Its never let me down yet.
It's an option. My firewall needs are very simple - mostly ports 80,443
open or not open to the Internet at large. Everything else presented to
our dept network.
> And it does enable tailored access on a per VM basis. Ultimately if you
> want to manage the thing from everywhere, you need a pretty simple
> firewall. allow all ouitgoi8ng, established and so on an disallow all
> incoming connections except services you need to be globally available
> and ssh only from ranges of IP addresses used to manage the thing.
>
> Yes. its not quite as simple as VMware with its browser based remote
> screen capability, but in practice you don't need that to manage most
> linux systems with a GUI, and as far as windows goes IIRC - and it is
> some time since i have played with windows - there are remote management
> tools that run within windows itself that are sufficient unto the day.
>
> Likewise windows has its own firewalling capabilities.
>
>
>>
>>
>> Cheers
>>
>> Tim
>
>
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2015-05-22 00:07 +0100 |
| Message-ID | <mjlofk$foc$1@news.albasani.net> |
| In reply to | #14831 |
On 21/05/15 23:57, Tim Watts wrote:
> On 21/05/15 22:51, The Natural Philosopher wrote:
>
>> The console access to my xen based server is pretty much 'an 80x25
>> console on a serial port' type access - i.e its enough to reboot the
>> thing and look at basic issues, but as soon as there is enough machine
>> up and running you want ssh or better.
>
> Indeed that would be fine.
>
>> I am not sure how a 'console' works with a windows VM at all. so wont
>> comment/ Obviously once its up any windows based remote access software
>> will work as well as can be expected with the limited bandwidth of your
>> Internet connection from the point of management.
>
> I did some reading and I *think* it pulls a VNC job - good enough to
> deal with boot problems until RDP is up and running.
>
>>
>> Although some providers provide backup, I do my own with rsync over ssh
>> to a home server.
>
> That would be not hugely practical with 20TB to backup up :)
>
Well that depends on how fast the data is changing and what bandwidth
you have.
I mean how is the data going to get ON the machine in the first place?
Presumably you will have it somewhere else so can just 'preload' the
backup with it when you load the server.
Then rsync just tracks the changes.
> On eof the driving factors with you have a lot of VMs is being able to
> get from the backup to running VMs quickly in the event of a disaster
> ("disaster" might include needing to revert a VM that boned itself).
>
Mmm. Sounds like what you would need is a different physical backup
server in the same location with uber high bandwidth between it and the
VMS that do the work
> For that, full disk backups (plus the VM metadata) is the quickest way.
> Our current solution uses Veeam Backup which can cooperate with VMWare's
> Changed Block Tracking list (blocks that have been written since last
> backup) so incremental backups are cheap.
>
>> RAID will be almost standard, so what that means in terms of hot
>> migration if by that term you mean swapping to a second VM if the first
>> one screws up, is not clear. Ultimately if you have VM on the same
>> underlying platform its not gonna be an option if the whole hardware
>> platform goes down.
>
> Host migration is moving the running VM to a new physical host - I know
> Xen has been able to do that forever. Used for load balancing the host.
> VMWare ESX(i) tends (unless disabled) tends to do this itself to balance
> the host loads - typically a dozen or more hot migrations will happen in
> any day depending on how VM loads change.
>
> Disk (or volume) migration is used to balance IO to the luns on a SAN
> (on my EqualLogic at least, the max IO queue depth is 32 and too many
> VMs on a single LUN can cause poor latency). I am not sure how relevant
> this is with other SANs or even vSAN. But essentially you can have the
> VMs disks hot-moved from data store to data store.
>
>>
>>>
>>> (we'll allow the firewall to be external as VMWare's vShield is a bit
>>> special but it's not the only way to get a border firewall).
>>>
>>
>> On linux I have a firewall on a per VM basis using Iptables.
>> That's enough.Its never let me down yet.
>
> It's an option. My firewall needs are very simple - mostly ports 80,443
> open or not open to the Internet at large. Everything else presented to
> our dept network.
>
Yes. That dupes roughly what I had when I had a fixed IP address at
home. All ports open to home, no ports except webs and mail open to the
rest of the world
Look its just a thought, but at the sort of level you are running, maybe
a pair of blade chassis, with a humongous RAID on each that are yours to
own in a given data centre is in fact a solution.
Rackspace and a shitload of internet bandwidth might be less than 20 k a
year for a pair of big blades.
And you could shove a couple of fibres between em to do the backups.
A lotta capital though - tens of thousands. But this has to be an earner
or you wouldn't be taking it this far as it is.
>> And it does enable tailored access on a per VM basis. Ultimately if you
>> want to manage the thing from everywhere, you need a pretty simple
>> firewall. allow all ouitgoi8ng, established and so on an disallow all
>> incoming connections except services you need to be globally available
>> and ssh only from ranges of IP addresses used to manage the thing.
>>
>> Yes. its not quite as simple as VMware with its browser based remote
>> screen capability, but in practice you don't need that to manage most
>> linux systems with a GUI, and as far as windows goes IIRC - and it is
>> some time since i have played with windows - there are remote management
>> tools that run within windows itself that are sufficient unto the day.
>>
>> Likewise windows has its own firewalling capabilities.
>>
>>
>>>
>>>
>>> Cheers
>>>
>>> Tim
>>
>>
>
--
Everything you read in newspapers is absolutely true, except for the
rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Date | 2015-05-22 08:54 +0100 |
| Message-ID | <du333c-vi4.ln1@squidward.dionic.net> |
| In reply to | #14832 |
On 22/05/15 00:07, The Natural Philosopher wrote:
>
> Well that depends on how fast the data is changing and what bandwidth
> you have.
It could be as much as 6TB in one day if one of the larger machines hits
a full backup cycle (which is every 4 weeks - we do not trust
incrementals without a periodic refresh).
The offsite backup system I have now (with the disks and linux head
nodes) live sin my building. It survives OK on a gigabit fibre building
link to the rest of the college.
We had that fibre chopped by workmen repairing the pavement the other
month and it was an observable fact that the backups could not cope
using the building's 100mbit/s backup link. They could not even manage a
full daily run inside a day.
> I mean how is the data going to get ON the machine in the first place?
> Presumably you will have it somewhere else so can just 'preload' the
> backup with it when you load the server.
Direct transfer from the existing system.
>
> Then rsync just tracks the changes.
rsync is not the correct solution here - well, it could be part of the
solution - rsnapshot makes for a nice way to offer per-file retrieval.
But with a large virtual system, you need an efficient disaster recovery
mechanism which means block level.
The other thing is it is unlikely with a forthcoming building move that
I will have anywhere to house the backup system, so it will have to go
in a datacentre too. On the plus side, if the hosting company provide it:
1) If the kit blows up, they get to do the restoration;
2) It does not count as chargeable bandwidth.
>
>> On eof the driving factors with you have a lot of VMs is being able to
>> get from the backup to running VMs quickly in the event of a disaster
>> ("disaster" might include needing to revert a VM that boned itself).
>>
>
> Mmm. Sounds like what you would need is a different physical backup
> server in the same location with uber high bandwidth between it and the
> VMS that do the work
Indeed - gigabit min, and that would take a week to do a full DR
restoration. 10 gig would be ideal, but OTT. We are academic, so a tiny
risk of disaster can be balanced against being offline for 1,2,3 weeks -
which would be out of the question if we were a commercial entity.
The important thing is that we still have the means to recover, rather
than how long it takes (within reason).
> Look its just a thought, but at the sort of level you are running, maybe
> a pair of blade chassis, with a humongous RAID on each that are yours to
> own in a given data centre is in fact a solution.
Our current system is (not commercially sensitive):
4 Dell R610s with 2 CPU sockets (12 cores total) and 192GB RAM.
1 EqualLogic PS6500e iSCSI SAN with 48 x 1TB SATA disks
1 EqualLogic PS4100x iSCSI SAN with 24 x 600GB 10k SAS disks
Pair of stacked gig switches to interlink.
It's quite a decent system - runs 180 VMs quite happily on 3 of 4 hosts
to allow maintenance and failure.
It's tiny compared to HPC setups used by the likes of the particle
physics guys (Those can number 100s of 1U nodes and petabytes of storage
interconnected with insane (multiple 10's gig) networking.
> Rackspace and a shitload of internet bandwidth might be less than 20 k a
> year for a pair of big blades.
> And you could shove a couple of fibres between em to do the backups.
>
> A lotta capital though - tens of thousands. But this has to be an earner
> or you wouldn't be taking it this far as it is.
A bit more than that :)
But that's OK - this setup earns its income - that's why it had to be
professional, well sourced and reliable to maintain long term reputation.
There's no question of doing this on the cheap. If I replicated the
current system, it would be the one above but with 50% capacity added to
everything. But I am extremely interested in VMWare's vSAN as I could
lose the SANs (expensive) in favour of more nodes carrying their own
storage. vSAN aggregates this cluster wide and provides fault resilience
(think Google Filesystem - similar idea).
The thing that caught me out is that outsourcing this as a virtual
datacentre is SO much more expensive (5x ish it seems). I would perhaps
expected double the cost. OK those guys do all the hardware and
networking, but OTOH they can share multiple customers on very large
clusters which allows diversity to be factored in.
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.misc
csiph-web