Cloud ComputingUnit 511 min read

Cloud Architecture: Models, Layers, Components & Real-World Systems

Unit 5 of Cloud Computing explores the foundational architecture of cloud systems, covering layered models (NIST, OSI), cloud components (front-end, back-end, network), deployment topologies, and real-world implementations like AWS/Azure’s multi-tier designs. Students learn how cloud systems are structured, how data fl

Core Concepts: What is Cloud Architecture?

Cloud architecture refers to the system design of cloud computing environments, including:

  • Layered models (how services stack: hardware → software → applications).
  • Components (front-end clients, back-end servers, networks, storage).
  • Topologies (how servers and data centers are physically/logically arranged).
  • Standards (NIST reference architecture, OSI model adaptations).

Cloud architecture ensures scalability, reliability, and interoperability—key for services like eSewa’s payment processing or Ncell’s 5G network management.


1. Layered Models: The NIST and OSI Adaptations

Cloud architectures are built in layers, similar to the OSI model but tailored for cloud services. The National Institute of Standards and Technology (NIST) defines five primary layers:

Application LayerPlatform LayerInfrastructure LayerNetwork LayerSecurity & Management LayerPhysical Layerhigher abstraction, closer to user
NIST Cloud Architecture Layers (simplified for Nepal’s context: e.g., eSewa’s app = Application, NTC’s servers = Physical)

Key Layers Explained

Layer Function Example in Nepal
Physical Layer Hardware: servers, storage, networking gear (routers, switches). NTC’s data centers: Racks of servers handling internet traffic.
Network Layer Connectivity: VPNs, load balancers, CDNs. Daraz’s global CDN: Caches product images closer to users to speed up delivery.
Infrastructure Layer Virtualized resources: VMs, containers, storage pools. AWS EC2: Virtual machines for hosting websites like Onlinekhabar.com.
Platform Layer Runtime environments: databases, middleware (e.g., Kubernetes, Heroku). Khalti’s backend: Uses PaaS to run payment validation logic.
Application Layer End-user services: APIs, web/mobile apps. eSewa app: Front-end for bill payments; back-end APIs connect to banks.

How Data Flows Through Layers

Example: When you pay a Nepal Electricity Authority (NEA) bill via eSewa:

  1. Your phone (front-end) sends a request to eSewa’s API layer.
  2. The API forwards it to Khalti’s payment gateway (platform layer).
  3. Khalti validates the transaction with NEA’s database (infrastructure layer).
  4. The response travels back through the network to your phone.

2. Cloud Architecture Components

Cloud systems consist of three main components:

APIsFront-End Clients (Mobile/Web)API GatewayBack-End ServersCloud Storage (S3/NEA DB)CDN (Cloudflare)Global Users
Data flow in a Nepalese cloud system (e.g., Daraz order processing)

A. Front-End (Client Side)

  • Devices: Mobile apps (e.g., Pathao rider app), web browsers, IoT devices.
  • Protocols: HTTP/HTTPS, WebSockets (for real-time updates like traffic alerts on HamroPatrika).
  • Example: Your WhatsApp Web is a front-end client accessing Google’s cloud servers.

B. Back-End (Server Side)

  • Servers: Physical/virtual machines (e.g., Google Cloud VMs).
  • Services:
    • Compute: AWS EC2, Azure Virtual Machines.
    • Storage: S3 (AWS), Blob Storage (Azure).
    • Networking: Load balancers, firewalls.
  • Example: Nepal Stock Exchange (NEPSE) uses back-end servers to process trades in real-time.

C. Network (Connectivity)

  • Types:
    • LAN/WAN: Connects data centers (e.g., NTC’s fiber-optic backbone).
    • CDNs: Distributes content (e.g., YouTube’s global servers).
    • API Gateways: Routes requests (e.g., eSewa’s payment API).
  • Protocols: TCP/IP, DNS, HTTPS.

3. Cloud Deployment Topologies

How servers and data are physically/logically arranged affects performance and cost.

Centralized Cloud (NTC)Distributed Cloud (eSewa)Peer-to-Peer (Khalti P2P Transfers)
Nepal-specific cloud deployment examples with real services

A. Centralized vs. Distributed Architectures

Topology Description Example
Centralized Single data center; all traffic routed through one hub. Old Ncell billing system (before cloud migration).
Distributed Multiple data centers (geo-redundancy). Google Cloud: Servers in Kathmandu, Singapore, and the US.
Hybrid Mix of on-premises and cloud (e.g., sensitive data on-site, public cloud for scaling). Banks like NMB: Use cloud for customer apps but keep core ledgers on-site.

B. Peer-to-Peer (P2P) in Cloud Storage

  • How it works: Data is split across nodes (e.g., IPFS, Storj).
  • Example: Blockchain-based storage (like Filecoin) uses P2P to store files decentralized.

4. Real-World Cloud Architectures

A. eSewa’s Payment Processing (Multi-Layered)

sequenceDiagram
    participant User as User (Mobile App)
    participant API as eSewa API Gateway
    participant Auth as Authentication Service
    participant Payment as Khalti/Payment Gateway
    participant DB as NEA Database
    participant CDN as Cloudflare CDN

    User->>API: POST /pay?amount=500&to=NEA
    API->>Auth: Verify User & OTP
    Auth-->>API: Authenticated
    API->>Payment: Request Payment
    Payment->>DB: Check NEA Balance
    DB-->>Payment: Balance Valid
    Payment-->>API: Success
    API->>CDN: Cache Transaction
    CDN-->>User: Payment Confirmation

B. Daraz’s Microservices Architecture

  • Problem: Monolithic apps are hard to scale.
  • Solution: Microservices (each service runs independently).
    • User Service: Handles logins.
    • Order Service: Processes carts.
    • Payment Service: Integrates with Khalti.
    • Inventory Service: Tracks stock.
  • Orchestration: Uses Kubernetes to manage containers.

5. Cloud Architecture Standards

Application (SaaS)UserPlatform (PaaS)DeveloperInfrastructure (IaaS)AdminPhysicalHardware
NIST vs. OSI: Cloud layers mapped to roles (e.g., PaaS for Nepali app developers)

A. NIST Cloud Computing Reference Architecture

NIST defines 7 interdependent layers:

  1. Security & Identity Management
  2. Application Services
  3. Data Services
  4. Runtime Environment
  5. Control Plane
  6. Management Plane
  7. Physical Infrastructure

B. OSI Model vs. Cloud Architecture

OSI Layer Cloud Equivalent Protocol/Technology
Application SaaS, APIs HTTP, REST, GraphQL
Presentation Data encoding (JSON, XML) gRPC, Avro
Session Load balancing, WebSockets NGINX, HAProxy
Transport TCP/UDP connections TLS, QUIC
Network Routing, VPNs BGP, IPsec
Data Link Switches, VLANs Ethernet, MPLS
Physical Servers, fiber, data centers 10G Ethernet, SDN

6. Advantages and Challenges

Advantages

  • Scalability: Add servers on demand (e.g., Black Friday sales on Daraz).
  • Cost Efficiency: Pay-as-you-go (e.g., startups using AWS Free Tier).
  • Disaster Recovery: Geo-redundancy (e.g., Google’s backup servers).
  • Global Reach: Low-latency CDNs (e.g., Netflix’s global streaming).

Challenges

  • Complexity: Managing multi-layered systems (e.g., Khalti’s fraud detection).
  • Security Risks: Data breaches (e.g., 2021 Nepal Police hack).
  • Vendor Lock-in: Difficulty migrating between AWS/Azure (e.g., Nepal Rastra Bank’s cloud strategy).

In the Real World

  1. eSewa’s API Layers

    • How it uses cloud architecture:
      • Front-end: Mobile/web app (React Native).
      • Back-end: Microservices (Node.js for APIs, Python for ML fraud detection).
      • Database: PostgreSQL (structured data) + Redis (caching).
      • Network: Cloudflare CDN for fast load times.
    • Why it matters: During Dashain, eSewa handles 10x normal traffic—cloud scaling prevents crashes.
  2. Daraz’s Microservices for Faster Orders

    • Problem: Monolithic apps slow down during sales events.
    • Solution: Split into services:
      • User Service: Manages logins (auth0).
      • Cart Service: Handles items (Redis cache).
      • Payment Service: Integrates Khalti (Kubernetes pods).
    • Result: 30% faster checkout during Republic Day sales.
  3. Ncell’s 5G Core Network (Distributed Cloud)

    • Architecture:
      • Edge Computing: Processes data locally (e.g., Kathmandu traffic cameras).
      • Central Cloud: AWS for analytics (e.g., predicting network congestion).
    • Why it works: Reduces latency for real-time gaming (e.g., Free Fire in Nepal).

Exam Tip

This unit is heavily tested on:

  1. Layered models: Draw and label the NIST or OSI-adapted cloud layers. Expect questions on where a specific service (e.g., load balancer) sits.
  2. Component diagrams: Sketch the front-end ↔ back-end ↔ network flow. Always include a real example (e.g., eSewa, Daraz).
  3. Topology comparisons: Be ready to contrast centralized vs. distributed architectures with Nepalese examples (e.g., NTC vs. Google Cloud).
  4. Standards: Know NIST’s 7 layers and how they map to OSI. Questions may ask: “Which cloud layer handles authentication?” (Answer: Security & Identity Management).
  5. Real-world applications: Always tie answers to Nepal. For example:
    • “How would you design Khalti’s cloud architecture?” → Microservices + Kubernetes + Redis caching.
    • “What topology does NEPSE use?” → Hybrid (on-prem for trades, cloud for APIs).

Common pitfalls:

  • Forgetting the physical layer (servers/data centers).
  • Mixing PaaS/IaaS/SaaS layers (e.g., calling Kubernetes “SaaS”).
  • Not explaining why a layer exists (e.g., “CDNs reduce latency”).

Pro tip: Memorize the eSewa/Daraz/Ncell examples—examiners love case studies!


Based on the TU BIM syllabus for Cloud Computing (IT277), unit 5.

Discussion

Loading…