Cloud ComputingUnit 212 min read
Cloud Service Models: SaaS, PaaS, IaaS – Definitions, Workings & Real-World Use
Unit 2 of Cloud Computing explores the three foundational cloud service models—SaaS, PaaS, and IaaS—covering their definitions, technical architectures, real-world applications (e.g., eSewa, Google Workspace), and how they differ in control, scalability, and cost. Includes comparison tables, layered diagrams, and exam-
TAKEAWAYS:
- SaaS (Software-as-a-Service) delivers ready-to-use applications over the internet (e.g., Google Docs, eSewa), abstracting infrastructure and platform layers from users.
- PaaS (Platform-as-a-Service) provides development tools and runtime environments (e.g., Heroku, Google App Engine) to build and deploy apps without managing OS or hardware.
- IaaS (Infrastructure-as-a-Service) offers virtualized computing resources (e.g., AWS EC2, DigitalOcean) where users control OS, storage, and deployed applications.
- Control vs. convenience: IaaS gives users the most control (low-level management), while SaaS offers the least (end-user access only).
- Cost models: SaaS uses subscription fees; PaaS/IaaS often employ pay-as-you-go pricing tied to resource usage.
- Real-world tie: eSewa uses SaaS for its payment platform, while banks like NMB use PaaS for internal loan-processing apps.
1. Definitions and Core Concepts
Cloud service models define how cloud providers deliver resources to users. The National Institute of Standards and Technology (NIST) classifies them into three primary layers, each abstracting underlying complexity:
Key Idea: Each layer builds on the one below it, hiding infrastructure details progressively.
1.1 SaaS (Software-as-a-Service)
Definition: SaaS delivers ready-to-use software applications over the internet, eliminating the need for local installation, maintenance, or updates. User Responsibility: None (end-users access via a web browser or app). Provider Responsibility: Everything (applications, data, runtime, middleware, OS, virtualization, servers, networking, storage).
Example:
- eSewa: Uses SaaS for its mobile payment platform. Users access the app without knowing the underlying servers or databases.
- Google Workspace: Provides email, docs, and calendars as SaaS.
Worked Example: eSewa Transaction Flow
- User opens the eSewa app (SaaS).
- App communicates with eSewa’s backend servers (hidden from the user).
- Payment processing, authentication, and transaction logging occur on eSewa’s infrastructure (PaaS/IaaS layers).
- User receives a confirmation—no visibility into the underlying cloud layers.
2. PaaS (Platform-as-a-Service)
Definition: PaaS provides a development and deployment platform for building, testing, and running applications without managing the underlying infrastructure. User Responsibility: Applications and data. Provider Responsibility: Runtime, middleware, OS, virtualization, servers, networking, storage.
Example:
- Heroku: Developers deploy apps (e.g., a Node.js web app) without configuring servers.
- Google App Engine: Supports Python/Java apps with auto-scaling.
Real-World Tie: NMB Bank’s Loan Processing NMB Bank uses PaaS (e.g., Microsoft Azure) to deploy its internal loan-approval system. Developers write code in Python/Java, while Azure handles:
- Scaling during peak hours (e.g., loan season).
- Database management (SQL/NoSQL).
- Security patches for the underlying OS.
Visual: PaaS Abstraction Layers
3. IaaS (Infrastructure-as-a-Service)
Definition: IaaS offers virtualized computing resources (e.g., servers, storage, networks) over the internet. Users manage the OS, middleware, and applications. User Responsibility: OS, middleware, apps, data, runtime. Provider Responsibility: Physical servers, virtualization, storage, networking.
Example:
- AWS EC2: Users launch virtual machines (VMs) with custom OS (e.g., Ubuntu).
- DigitalOcean Droplets: Pre-configured VMs for hosting websites.
Worked Example: Daraz Order Queue System Daraz uses IaaS (e.g., AWS) to handle order processing during sales like Daraz Great Republic Day Sale:
- Scaling: During peak traffic, AWS auto-scales VMs to handle 10x more orders.
- Database: Daraz uses managed IaaS databases (e.g., RDS) for order storage.
- Control: Daraz’s team configures the OS, installs custom software (e.g., Redis for caching), and deploys apps.
4. Comparison Table: SaaS vs. PaaS vs. IaaS
| Feature | SaaS | PaaS | IaaS |
|---|---|---|---|
| User Control | None (end-user access only) | Apps and data | OS, middleware, apps, data |
| Provider Control | Everything | Runtime to physical infrastructure | Physical infrastructure only |
| Examples | Google Docs, eSewa, Slack | Heroku, Google App Engine | AWS EC2, DigitalOcean, Azure VMs |
| Use Case | End-users (no IT skills needed) | Developers (build/deploy apps) | IT teams (full infrastructure mgmt) |
| Deployment Speed | Instant (click to use) | Minutes (app deployment) | Hours (VM setup) |
| Cost Model | Subscription (per user) | Pay-per-usage (e.g., $/hour) | Pay-per-usage (e.g., $/VM-hour) |
| Customization | None | Limited (app logic) | Full (OS, software, networking) |
5. How They Work Together: A Real-World Trace
Let’s trace how Pathao (ride-hailing app) uses all three models:
SaaS Layer:
- Riders/drivers use the Pathao app (SaaS) to request rides or sign up.
- No need to install or maintain anything.
PaaS Layer:
- Pathao’s backend (e.g., ride-matching algorithm) runs on Google Cloud PaaS.
- Developers deploy code without managing servers.
IaaS Layer:
- During Diwali (peak demand), Pathao scales by launching AWS EC2 VMs (IaaS) for:
- Real-time GPS tracking.
- Payment processing (integrated with Khalti).
- User authentication databases.
- During Diwali (peak demand), Pathao scales by launching AWS EC2 VMs (IaaS) for:
Visual: Pathao’s Cloud Stack
sequenceDiagram
participant Rider as Rider (SaaS User)
participant PathaoApp as Pathao App (SaaS)
participant Backend as Pathao Backend (PaaS)
participant VMs as AWS EC2 VMs (IaaS)
participant Database as DynamoDB (IaaS)
Rider->>PathaoApp: Requests Ride
PathaoApp->>Backend: Sends Request (PaaS)
Backend->>VMs: Processes Matching (IaaS)
VMs->>Database: Updates Ride Status
Database-->>VMs: Returns Driver Location
VMs-->>Backend: Confirms Ride
Backend-->>PathaoApp: Updates UI
PathaoApp-->>Rider: Shows Driver ETA6. Advantages and Disadvantages
SaaS
✅ Pros:
- No installation/maintenance (e.g., eSewa updates automatically).
- Accessible from any device with an internet connection.
- Lower upfront costs (subscription-based).
❌ Cons:
- Limited customization (e.g., Google Docs’ templates).
- Data security risks (provider controls all layers).
- Vendor lock-in (migrating from eSewa to another payment system is hard).
PaaS
✅ Pros:
- Faster development (e.g., Heroku’s one-click deployments).
- No infrastructure management (focus on coding).
- Built-in scalability (e.g., auto-scaling in Google App Engine).
❌ Cons:
- Vendor-specific tools (e.g., Heroku’s CLI).
- Limited OS/customization (e.g., can’t install custom kernels).
- Costs can rise with usage (e.g., Azure’s pay-per-request pricing).
IaaS
✅ Pros:
- Maximum flexibility (install any OS/software).
- Cost-effective for large-scale deployments (e.g., Daraz’s VMs).
- Granular control over security and performance.
❌ Cons:
- Steep learning curve (managing VMs, networking).
- Higher operational overhead (patching, backups).
- Hidden costs (e.g., data transfer fees in AWS).
7. In the Real World
eSewa (SaaS):
- Idea Used: Multi-tenancy SaaS architecture.
- How: eSewa’s platform serves thousands of users simultaneously, with a single instance of the software handling all transactions. Users never see the underlying servers or databases—just a seamless payment interface.
Ncell’s Customer Portal (PaaS):
- Idea Used: PaaS for internal tools.
- How: Ncell uses Microsoft Azure PaaS to deploy its internal customer complaint resolution system. Agents log complaints via a web portal, while Azure handles:
- Auto-scaling during peak call volumes.
- Integration with CRM databases.
- Security compliance (e.g., GDPR for customer data).
NEPSE’s Trading Platform (Hybrid: SaaS + IaaS):
- Idea Used: SaaS for traders + IaaS for backend.
- How: NEPSE’s online trading platform is SaaS for investors (they access it via a web app). However, the backend uses IaaS (AWS) to:
- Handle high-frequency trades during market openings.
- Store transaction logs in scalable databases.
- Ensure uptime during power outages (via AWS’s multi-region failover).
8. Exam Tip
How This Unit is Tested:
Definitions and Comparisons (30%):
- Expect compare SaaS vs. PaaS vs. IaaS questions. Use the table above but add real examples (e.g., "eSewa is SaaS because users don’t manage any infrastructure").
- Common Pitfall: Confusing PaaS and IaaS. Remember: PaaS = platform for developers; IaaS = infrastructure for IT admins.
Worked Examples (25%):
- Trace a real system: For example, describe how Khalti uses SaaS for merchants but IaaS for fraud detection (high-performance VMs).
- Draw diagrams: Always include a layered model (like the Pathao trace) or a sequence diagram for protocol flows (e.g., how a SaaS app communicates with PaaS/IaaS).
Advantages/Disadvantages (20%):
- Bullet points with examples: Instead of generic lists, tie pros/cons to real-world scenarios:
- "SaaS’s advantage of no maintenance is why eSewa users don’t need to update their app."
- "IaaS’s disadvantage of operational overhead is why Daraz uses managed databases (RDS) instead of raw VMs."
- Bullet points with examples: Instead of generic lists, tie pros/cons to real-world scenarios:
Short-Answer Questions (15%):
- Key phrases to memorize:
- "SaaS abstracts everything except the user interface."
- "PaaS provides a runtime environment without infrastructure management."
- "IaaS offers ‘bare metal’ virtualization for full control."
- Example Answer Snippet:
"Google Workspace is SaaS because it delivers email, docs, and calendars as a service, while Google Cloud Platform’s App Engine is PaaS because developers deploy apps without managing the underlying OS or servers."
- Key phrases to memorize:
Critical Thinking (10%):
- Scenario-based questions: You might be asked:
- "A bank wants to deploy a loan-processing system. Should it use SaaS, PaaS, or IaaS? Justify with pros/cons."
- Answer: "PaaS is ideal because the bank needs to develop custom loan-approval logic but doesn’t want to manage servers. IaaS would add operational overhead, while SaaS lacks customization for internal workflows."
- Scenario-based questions: You might be asked:
9. Common Mistakes to Avoid
- Mixing layers: Don’t say "Heroku is IaaS"—it’s PaaS because it abstracts the OS.
- Ignoring real-world ties: Always relate answers to Nepalese examples (e.g., eSewa, Ncell, NEPSE).
- Overcomplicating diagrams: For layered models, stick to 3–4 layers max (e.g., User → SaaS → PaaS → IaaS → Infrastructure).
- Assuming all clouds are public: Some IaaS/PaaS services are private cloud (e.g., a bank’s internal Azure stack).
10. Quick Revision Checklist
Before the exam, verify you can:
- Draw and label the three-layer cloud model (SaaS/PaaS/IaaS).
- List one Nepalese and one global example for each model.
- Explain why a company would choose PaaS over IaaS (or vice versa).
- Describe how multi-tenancy works in SaaS (e.g., eSewa serving 10M users from one codebase).
- Compare cost models (subscription vs. pay-as-you-go).
- Trace a real system (e.g., Pathao or Daraz) through all three layers.
Based on the TU BCA syllabus for Cloud Computing (CACS402), unit 2.
Discussion
Loading…