|

Data Protection for Hybrid Clouds

April 22, 2014, Data Storage Innovation Conference, Santa Clara, CA—David Chapa from E Vault talked about some of the challenges facing IT managers with multiple data sites and configurations. Protection and recovery can be administered as a single entity independent of the data locations.

One issue is how to define a cloud infrastructure. As virtualization takes over computers, networks, and storage, the idea that a data center and its associated services as distinct entities is becoming obsolete. The common aspects of all cloud infrastructure is agility and reduced management due to increased automation.

The trends in deployment models are to improve security, virtualization, and still have decent backup and recovery capabilities. Over 70 percent of users have some functions in a cloud, and more are using clouds than planned from last year. The earlier barriers to entry for security, access, and control from ’08-’11 are now mostly resolved and the whole industry is now relatively mature.

The deployment models for deployment include many options and aspects of the cloud. The proliferation of (X)aaS and the many types of cloud structure are accessed through public, private, and hybrid structures which can offer numerous feature sets for the various use cases. The mature, but still changing nature of the underlying technologies enable multiple service options to the end user.

The service options are now including backup and disaster recovery capabilities and archive functions. These extended services are becoming stable and can help address the squeeze of fixed budgets and growing data. With more functions available as an external service, the IT manager can leverage existing staff to address critical items rather than have their time consumed with administrivia.

Backup in the cloud can be self-service with a seed for the initial load, and then full or incremental scheduled snapshots. Even though public clouds are multi-tenant, they can be secure and separated from the other users. For more critical or time-sensitive data, a local and cloud hybrid offers local backup of fast moving data, and longer term data getting backed up in the cloud. The data for 7-14 days are released to the cloud on a rolling schedule. For highest security and fastest response, a private cloud also offers single tenant control of all functions and operations.

Deployment models are also split across the public, hybrid, and private boundaries. A good report from the EU helps to define some of the important parameters for the various cloud types. A public cloud uses no on-premise equipment and is a multi-tenant system that may have security issues. The best practice is to encrypt the data before transmission and store the encrypted backup in the cloud.

Hybrid configurations have some equipment in both on- and off-premises where the in-house equipment includes servers and storage while the cloud just looks like another node to the system. Private clouds are single tenant, so the security concerns are minimized at the cost of additional internal staff effort to maintain the equipment and data.

Some considerations for implementing a cloud system for backup and recovery operations include budget constraints, the amount of data to protect, the type of data, and the time available for recovery and restore operations. the frequency of restore and recovery operations can be a factor, as is the size and experience of the IT staff. If the data sets are less than 4 TB, a SaaS backup is a viable option as long as the recovery time is the main objective. Otherwise a hybrid solution provides a good balance of cost and recovery time since the data will always be in the cloud.

A cloud-based protection scheme would be of a replication-based, incremental forever nature. This type of approach can reduce costs and complexity and also reduce the number of tapes needed for that hot data. Security comes from encryption of all data at rest and in flight, to enable secure off-site security. The cloud-based system permits ubiquitous access to the backup data. A way to limit exposure is to have all key management local to the system, and not in the cloud.

The alternatives for backup and protection are evaluated with cost of ownership versus the existing solutions, and the time dependence of the recovery efforts. A data set in the cloud is going to be much slower than a local copy due to the delays in the long distance transport. Cost examples are available for various configurations, but it is necessary to define underlying assumptions for hardware cycles, data growth rate, and the costs of the hardware, software, and maintenance for both the hardware and software. The operating costs should also include the costs for power and cooling, even if these items are not budgeted.

A cloud-based approach offers greater agility in the system, and can offset CAPEX with OPEX while reducing total cost of operations. A cloud backup and a local production system can offer a resilient disaster recovery capability and increased control. The active backup from the primary to the cloud can replace significant internal resources.

Cloud service providers are not equal. You need to evaluate all the possible vendors and pick the best fit. The best choice has to be considered the same as a badged employee, so the level of certifications and performance metrics are important.
 

Similar Posts