Cloud ComputingUnit 511 min read
Cloud Architecture: Models, Layers, Components & Real-World Systems
Unit 5 of Cloud Computing explores the foundational architecture of cloud systems, covering layered models (NIST, OSI), cloud components (front-end, back-end, network), deployment topologies, and real-world implementations like AWS/Azure’s multi-tier designs. Students learn how cloud systems are structured, how data fl
Core Concepts: What is Cloud Architecture?
Cloud architecture refers to the system design of cloud computing environments, including:
- Layered models (how services stack: hardware → software → applications).
- Components (front-end clients, back-end servers, networks, storage).
- Topologies (how servers and data centers are physically/logically arranged).
- Standards (NIST reference architecture, OSI model adaptations).
Cloud architecture ensures scalability, reliability, and interoperability—key for services like eSewa’s payment processing or Ncell’s 5G network management.
1. Layered Models: The NIST and OSI Adaptations
Cloud architectures are built in layers, similar to the OSI model but tailored for cloud services. The National Institute of Standards and Technology (NIST) defines five primary layers:
Key Layers Explained
| Layer | Function | Example in Nepal |
|---|---|---|
| Physical Layer | Hardware: servers, storage, networking gear (routers, switches). | NTC’s data centers: Racks of servers handling internet traffic. |
| Network Layer | Connectivity: VPNs, load balancers, CDNs. | Daraz’s global CDN: Caches product images closer to users to speed up delivery. |
| Infrastructure Layer | Virtualized resources: VMs, containers, storage pools. | AWS EC2: Virtual machines for hosting websites like Onlinekhabar.com. |
| Platform Layer | Runtime environments: databases, middleware (e.g., Kubernetes, Heroku). | Khalti’s backend: Uses PaaS to run payment validation logic. |
| Application Layer | End-user services: APIs, web/mobile apps. | eSewa app: Front-end for bill payments; back-end APIs connect to banks. |
How Data Flows Through Layers
Example: When you pay a Nepal Electricity Authority (NEA) bill via eSewa:
- Your phone (front-end) sends a request to eSewa’s API layer.
- The API forwards it to Khalti’s payment gateway (platform layer).
- Khalti validates the transaction with NEA’s database (infrastructure layer).
- The response travels back through the network to your phone.
2. Cloud Architecture Components
Cloud systems consist of three main components:
A. Front-End (Client Side)
- Devices: Mobile apps (e.g., Pathao rider app), web browsers, IoT devices.
- Protocols: HTTP/HTTPS, WebSockets (for real-time updates like traffic alerts on HamroPatrika).
- Example: Your WhatsApp Web is a front-end client accessing Google’s cloud servers.
B. Back-End (Server Side)
- Servers: Physical/virtual machines (e.g., Google Cloud VMs).
- Services:
- Compute: AWS EC2, Azure Virtual Machines.
- Storage: S3 (AWS), Blob Storage (Azure).
- Networking: Load balancers, firewalls.
- Example: Nepal Stock Exchange (NEPSE) uses back-end servers to process trades in real-time.
C. Network (Connectivity)
- Types:
- LAN/WAN: Connects data centers (e.g., NTC’s fiber-optic backbone).
- CDNs: Distributes content (e.g., YouTube’s global servers).
- API Gateways: Routes requests (e.g., eSewa’s payment API).
- Protocols: TCP/IP, DNS, HTTPS.
3. Cloud Deployment Topologies
How servers and data are physically/logically arranged affects performance and cost.
A. Centralized vs. Distributed Architectures
| Topology | Description | Example |
|---|---|---|
| Centralized | Single data center; all traffic routed through one hub. | Old Ncell billing system (before cloud migration). |
| Distributed | Multiple data centers (geo-redundancy). | Google Cloud: Servers in Kathmandu, Singapore, and the US. |
| Hybrid | Mix of on-premises and cloud (e.g., sensitive data on-site, public cloud for scaling). | Banks like NMB: Use cloud for customer apps but keep core ledgers on-site. |
B. Peer-to-Peer (P2P) in Cloud Storage
- How it works: Data is split across nodes (e.g., IPFS, Storj).
- Example: Blockchain-based storage (like Filecoin) uses P2P to store files decentralized.
4. Real-World Cloud Architectures
A. eSewa’s Payment Processing (Multi-Layered)
sequenceDiagram
participant User as User (Mobile App)
participant API as eSewa API Gateway
participant Auth as Authentication Service
participant Payment as Khalti/Payment Gateway
participant DB as NEA Database
participant CDN as Cloudflare CDN
User->>API: POST /pay?amount=500&to=NEA
API->>Auth: Verify User & OTP
Auth-->>API: Authenticated
API->>Payment: Request Payment
Payment->>DB: Check NEA Balance
DB-->>Payment: Balance Valid
Payment-->>API: Success
API->>CDN: Cache Transaction
CDN-->>User: Payment ConfirmationB. Daraz’s Microservices Architecture
- Problem: Monolithic apps are hard to scale.
- Solution: Microservices (each service runs independently).
- User Service: Handles logins.
- Order Service: Processes carts.
- Payment Service: Integrates with Khalti.
- Inventory Service: Tracks stock.
- Orchestration: Uses Kubernetes to manage containers.
5. Cloud Architecture Standards
A. NIST Cloud Computing Reference Architecture
NIST defines 7 interdependent layers:
- Security & Identity Management
- Application Services
- Data Services
- Runtime Environment
- Control Plane
- Management Plane
- Physical Infrastructure
B. OSI Model vs. Cloud Architecture
| OSI Layer | Cloud Equivalent | Protocol/Technology |
|---|---|---|
| Application | SaaS, APIs | HTTP, REST, GraphQL |
| Presentation | Data encoding (JSON, XML) | gRPC, Avro |
| Session | Load balancing, WebSockets | NGINX, HAProxy |
| Transport | TCP/UDP connections | TLS, QUIC |
| Network | Routing, VPNs | BGP, IPsec |
| Data Link | Switches, VLANs | Ethernet, MPLS |
| Physical | Servers, fiber, data centers | 10G Ethernet, SDN |
6. Advantages and Challenges
Advantages
- Scalability: Add servers on demand (e.g., Black Friday sales on Daraz).
- Cost Efficiency: Pay-as-you-go (e.g., startups using AWS Free Tier).
- Disaster Recovery: Geo-redundancy (e.g., Google’s backup servers).
- Global Reach: Low-latency CDNs (e.g., Netflix’s global streaming).
Challenges
- Complexity: Managing multi-layered systems (e.g., Khalti’s fraud detection).
- Security Risks: Data breaches (e.g., 2021 Nepal Police hack).
- Vendor Lock-in: Difficulty migrating between AWS/Azure (e.g., Nepal Rastra Bank’s cloud strategy).
In the Real World
eSewa’s API Layers
- How it uses cloud architecture:
- Front-end: Mobile/web app (React Native).
- Back-end: Microservices (Node.js for APIs, Python for ML fraud detection).
- Database: PostgreSQL (structured data) + Redis (caching).
- Network: Cloudflare CDN for fast load times.
- Why it matters: During Dashain, eSewa handles 10x normal traffic—cloud scaling prevents crashes.
- How it uses cloud architecture:
Daraz’s Microservices for Faster Orders
- Problem: Monolithic apps slow down during sales events.
- Solution: Split into services:
- User Service: Manages logins (auth0).
- Cart Service: Handles items (Redis cache).
- Payment Service: Integrates Khalti (Kubernetes pods).
- Result: 30% faster checkout during Republic Day sales.
Ncell’s 5G Core Network (Distributed Cloud)
- Architecture:
- Edge Computing: Processes data locally (e.g., Kathmandu traffic cameras).
- Central Cloud: AWS for analytics (e.g., predicting network congestion).
- Why it works: Reduces latency for real-time gaming (e.g., Free Fire in Nepal).
- Architecture:
Exam Tip
This unit is heavily tested on:
- Layered models: Draw and label the NIST or OSI-adapted cloud layers. Expect questions on where a specific service (e.g., load balancer) sits.
- Component diagrams: Sketch the front-end ↔ back-end ↔ network flow. Always include a real example (e.g., eSewa, Daraz).
- Topology comparisons: Be ready to contrast centralized vs. distributed architectures with Nepalese examples (e.g., NTC vs. Google Cloud).
- Standards: Know NIST’s 7 layers and how they map to OSI. Questions may ask: “Which cloud layer handles authentication?” (Answer: Security & Identity Management).
- Real-world applications: Always tie answers to Nepal. For example:
- “How would you design Khalti’s cloud architecture?” → Microservices + Kubernetes + Redis caching.
- “What topology does NEPSE use?” → Hybrid (on-prem for trades, cloud for APIs).
Common pitfalls:
- Forgetting the physical layer (servers/data centers).
- Mixing PaaS/IaaS/SaaS layers (e.g., calling Kubernetes “SaaS”).
- Not explaining why a layer exists (e.g., “CDNs reduce latency”).
Pro tip: Memorize the eSewa/Daraz/Ncell examples—examiners love case studies!
Based on the TU BIM syllabus for Cloud Computing (IT277), unit 5.
Discussion
Loading…