Cloud ComputingUnit 314 min read
Cloud Deployment Models: Public, Private, Hybrid, Community
Unit 3 of Cloud Computing explores how cloud services are deployed in real-world scenarios, covering public, private, hybrid, and community models, their architectures, use cases, and trade-offs.
TAKEAWAYS:
- Cloud deployment models define where and how cloud services are hosted, accessed, and managed (public vs. private vs. hybrid).
- Public clouds (e.g., AWS, Google Cloud) offer shared, scalable resources but require strict security controls.
- Private clouds (e.g., corporate data centers) provide full control and isolation but demand high upfront costs.
- Hybrid clouds (e.g., Ncell’s backend + AWS for peak traffic) combine public and private for flexibility and compliance.
- Community clouds (e.g., NTC’s shared infrastructure for telecom providers) serve specific groups with shared needs.
- Cost, security, scalability, and compliance are the key factors when choosing a deployment model.
1. Introduction to Cloud Deployment Models
Cloud deployment models determine how cloud resources are allocated, secured, and accessed. Unlike service models (IaaS/PaaS/SaaS), which define what is delivered, deployment models define where and how the cloud operates.
Why Does It Matter?
- Security: Private clouds isolate sensitive data (e.g., bank transactions).
- Cost: Public clouds reduce capital expenditure (e.g., Daraz’s seasonal sales).
- Compliance: Government clouds (e.g., Nepal’s e-Governance) require strict data sovereignty.
- Scalability: Hybrid clouds handle unpredictable loads (e.g., Pathao during Diwali).
2. The Four Cloud Deployment Models
Use this table to compare them at a glance:
| Model | Definition | Ownership | Access Control | Best For | Examples (Nepal/Global) |
|---|---|---|---|---|---|
| Public | Shared multi-tenant infrastructure (third-party provider). | Provider (AWS, Google Cloud) | Shared security policies | Startups, SMEs, scalable apps | eSewa (AWS), YouTube (Google Cloud) |
| Private | Dedicated single-tenant infrastructure (on-premises or hosted). | Organization | Full control | Banks, hospitals, high-security data | Nabil Bank’s core banking system |
| Hybrid | Combines public + private with orchestration (e.g., VPN, API gateways). | Mixed | Selective integration | Hybrid workloads (e.g., Ncell + AWS) | Daraz’s inventory + private ERP |
| Community | Shared infrastructure for a specific community (e.g., industry, government). | Shared governance | Community-defined rules | Telecom providers, research groups | NTC’s shared cloud for ISPs |
3. Deep Dive: How Each Model Works
A. Public Cloud
Definition: A third-party provider (e.g., AWS, Azure) hosts resources in a shared, multi-tenant environment. Users pay for what they use (pay-as-you-go).
How It Works:
- Resource Pooling: Physical servers are virtualized into shared instances.
- Self-Service Portal: Users provision resources via dashboards (e.g., AWS Console).
- Automatic Scaling: Resources scale up/down based on demand (e.g., WhatsApp’s message queues).
Visual: Public Cloud Architecture
flowchart TD
A["Users (eSewa, Daraz)"] -->|"HTTPS"| B["Load Balancer"]
B --> C["Public Cloud Provider (AWS/Azure)"]
C --> D["Shared Virtual Machines"]
C --> E["Shared Storage (S3/Blob Storage)"]
C --> F["Shared Network (VPC/Subnets)"]
D -->|"Isolated"| G["User A: Web App"]
D -->|"Isolated"| H["User B: Database"]Real-World Example: eSewa’s Public Cloud
- Why? eSewa uses AWS to handle millions of transactions/day without investing in physical servers.
- How?
- Compute: EC2 instances for APIs.
- Storage: S3 for user data backups.
- Database: RDS (PostgreSQL) for transaction logs.
- Challenge: Ensures PCI-DSS compliance (payment security) in a shared environment.
B. Private Cloud
Definition: Dedicated cloud infrastructure for a single organization, hosted on-premises or by a third party. Offers full control over security and customization.
How It Works:
- Dedicated Hardware: No sharing with other tenants.
- Custom Security: Firewalls, encryption, and access controls tailored to the org.
- Internal Management: IT teams handle updates, patches, and scaling.
Visual: Private Cloud vs. Public Cloud
flowchart LR
subgraph Private Cloud ["Nabil Bank's Private Cloud"]
A["Dedicated Servers"] --> B["Internal Firewall"]
B --> C["Core Banking App"]
B --> D["Customer Data DB"]
end
subgraph Public Cloud ["AWS"]
E["Shared Servers"] --> F["Multi-Tenant VMs"]
F --> G["eSewa App"]
endReal-World Example: Nabil Bank’s Private Cloud
- Why? Handles sensitive financial data (loans, accounts) requiring Nepal Rastra Bank (NRB) compliance.
- How?
- On-Premises Servers: IBM Power Systems for transaction processing.
- Custom Encryption: AES-256 for data at rest.
- Disaster Recovery: Mirrored data centers in Kathmandu and Pokhara.
- Cost: High upfront investment (~$500K+) but zero shared-risk exposure.
C. Hybrid Cloud
Definition: A combination of public and private clouds, connected via secure channels (e.g., VPN, API gateways). Data/missions move between environments based on needs.
How It Works:
- Workload Segmentation:
- Private Cloud: Sensitive data (e.g., customer PII).
- Public Cloud: Scalable services (e.g., seasonal promotions).
- Orchestration: Tools like AWS Outposts or Azure Arc manage hybrid workflows.
- Data Sync: APIs or cloud bursting (e.g., Ncell routing overflow traffic to AWS).
Visual: Hybrid Cloud Workflow (Ncell Example)
sequenceDiagram
participant User as Customer
participant NcellCore as Ncell Private Cloud
participant AWS as AWS Public Cloud
participant Database as Private DB
User->>NcellCore: Calls 9800000000
NcellCore->>AWS: Checks if traffic spike (e.g., Diwali)
AWS-->>NcellCore: Yes, route to AWS
NcellCore->>AWS: Spin up EC2 for IVR
AWS->>User: Handles call
AWS->>Database: Writes logs to private DB via VPNReal-World Example: Ncell’s Hybrid Cloud
- Why? Avoids public cloud latency for core services but uses AWS for peak-hour call routing.
- How?
- Private Cloud: Core billing system (on-prem).
- Public Cloud: AWS Lambda for real-time fraud detection.
- Connection: Direct Connect (dedicated 10Gbps link).
- Result: 99.99% uptime during festivals (vs. 99.9% with pure public cloud).
D. Community Cloud
Definition: Shared infrastructure for a specific community (e.g., government agencies, healthcare providers, or telecom operators). Governed by a joint steering committee.
How It Works:
- Shared Costs: Members split infrastructure costs.
- Custom Policies: Security/compliance tailored to the community (e.g., HIPAA for hospitals).
- Limited Access: Only authorized members can use resources.
Visual: Community Cloud Topology
flowchart TD
subgraph Community Cloud ["NTC Telecom Cloud"]
A["ISP 1: Ncell"] --> B["Shared Core Network"]
A["ISP 2: NTC"] --> B
A["ISP 3: Smart"] --> B
B --> C["Shared SDN Controller"]
B --> D["Community Storage"]
endReal-World Example: NTC’s Community Cloud for ISPs
- Why? Telecom providers (Ncell, Smart, NTC) share backbone infrastructure to reduce costs.
- How?
- Shared Peering: Reduces inter-ISP latency.
- Joint Security: DDoS protection via community firewalls.
- Cost Savings: Each ISP pays ~30% less than building private infrastructure.
- Challenge: Neutrality rules ensure no ISP gets preferential treatment.
4. Key Factors in Choosing a Deployment Model
Use this decision tree to pick the right model:
flowchart TD
A["Need for Scalability?"] -->|"Yes"| B["Public or Hybrid"]
A -->|"No"| C["Private or Community"]
B --> D["Need for Security?"] -->|"High"| E["Hybrid (Public for scale, Private for data)"]
B --> D -->|"Low"| F["Public Cloud"]
C --> G["Budget?"] -->|"High"| H["Private Cloud"]
C --> G -->|"Low"| I["Community Cloud"]Decision Criteria Table
| Factor | Public | Private | Hybrid | Community |
|---|---|---|---|---|
| Cost | Low (pay-as-you-go) | High (CAPEX) | Medium (mixed costs) | Medium (shared costs) |
| Security | Medium (shared controls) | High (dedicated) | High (selective) | Medium (community rules) |
| Scalability | High | Low | High | Medium |
| Compliance | Limited (provider rules) | Full control | Selective | Community-defined |
| Use Case | Startups, web apps | Banks, healthcare | Enterprise apps | Telecom, government |
5. Worked Example: Daraz’s Hybrid Cloud Strategy
Scenario: Daraz Nepal faces spikes in traffic during sales (e.g., Dashain, Tihar) but needs secure inventory management.
Solution:
- Private Cloud: On-premises ERP (SAP) for inventory and orders.
- Public Cloud (AWS): Auto-scaling web servers and CDN for global users.
- Connection: AWS Direct Connect for low-latency data sync.
Step-by-Step Trace:
- Normal Traffic:
- All requests handled by private cloud servers.
- Peak Traffic (e.g., Dashain Sale):
- CloudWatch detects traffic surge.
- Auto Scaling spins up 100+ EC2 instances in AWS.
- Route 53 directs users to the nearest AWS region (e.g., Singapore).
- Post-Sale:
- AWS instances scale down to zero.
- Inventory updates sync back to private SAP database.
Visual: Daraz’s Hybrid Workflow
sequenceDiagram
participant User as Customer
participant DarazPrivate as Daraz Private Cloud
participant AWS as AWS Public Cloud
participant CDN as CloudFront CDN
User->>CDN: Requests product page
CDN->>AWS: Fetches static content
User->>DarazPrivate: Places order
DarazPrivate->>AWS: Triggers scaling if needed
AWS->>DarazPrivate: Syncs order to ERPOutcome:
- Cost Savings: ~40% lower than pure public cloud.
- Performance: <200ms latency even during sales.
- Security: Inventory data never leaves private cloud.
6. Advantages and Disadvantages
| Model | Advantages | Disadvantages |
|---|---|---|
| Public | - Low cost<br>- Infinite scalability<br>- No maintenance | - Security risks (shared tenant)<br>- Limited customization |
| Private | - Full control<br>- High security<br>- Compliance-ready | - High cost<br>- Limited scalability |
| Hybrid | - Best of both worlds<br>- Flexible<br>- Cost-efficient | - Complex to manage<br>- Integration challenges |
| Community | - Shared costs<br>- Tailored for niche needs | - Limited to specific groups<br>- Governance issues |
7. Real-World Applications in Nepal
| Company/App | Deployment Model | Why? |
|---|---|---|
| eSewa | Public (AWS) | Handles millions of transactions/day; no need for private infrastructure. |
| Nabil Bank | Private | NRB compliance requires dedicated, air-gapped systems. |
| Ncell | Hybrid | Core network private, but uses AWS for peak-hour call routing. |
| NTC | Community | ISPs share backbone to reduce costs and improve connectivity. |
| Khalti | Hybrid | Private cloud for payments, public cloud for marketing APIs. |
| Nepal Stock Exchange (NEPSE) | Private | Market data integrity requires zero shared infrastructure. |
8. Common Misconceptions
"All clouds are the same."
- Reality: Public clouds (AWS) ≠ private clouds (on-prem). Security, cost, and compliance vary wildly.
"Hybrid clouds are just ‘public + private.’"
- Reality: They require orchestration tools (e.g., Kubernetes, Terraform) to manage workloads seamlessly.
"Community clouds are only for governments."
- Reality: Any group with shared needs can use them (e.g., university research clusters).
9. Exam Tip: How This Unit Is Tested
This unit is heavily tested in TU/PU exams via:
Definitions & Comparisons (3–5 marks):
- "Differentiate between public and private clouds with examples."
- Key: Use the table above and real-world examples (e.g., eSewa vs. Nabil Bank).
Scenario-Based Questions (5–8 marks):
- "A hospital wants to store patient records securely but needs to scale its telemedicine app. Recommend a deployment model and justify."
- Key: Hybrid cloud (private for records, public for app scaling). Draw a sequence diagram like the Ncell example.
Diagram-Based Questions (4–6 marks):
- "Draw and label the architecture of a hybrid cloud."
- Key: Use the Daraz hybrid workflow or Ncell example as a template.
Short Answer (2–3 marks):
- "What is a community cloud? Give one Nepalese example."
- Answer: "A shared cloud for a specific group. Example: NTC’s community cloud for ISPs."
Pro Tip:
- Memorize the 4 models and one real-world example each.
- Practice drawing hybrid/public/private architectures.
- Relate to Nepal: Examiners love eSewa, Ncell, Nabil Bank, and NTC as examples.
10. Summary Checklist
Before the exam, ensure you can: ✅ Define all 4 deployment models and their key characteristics. ✅ Compare them using a table (cost, security, scalability). ✅ Explain how hybrid clouds work with a sequence diagram. ✅ Give 2 Nepalese examples for each model (e.g., eSewa = public). ✅ Describe one real-world scenario (e.g., Daraz’s hybrid strategy). ✅ Draw architecture diagrams for public/private/hybrid clouds.
Based on the TU BIM syllabus for Cloud Computing (IT277), unit 3.
Discussion
Loading…