Cloud ComputingUnit 317 min read

Cloud Deployment Models: Public, Private, Hybrid, Community

Unit 3 of Cloud Computing explores how cloud services are deployed—public clouds (shared infrastructure), private clouds (dedicated), hybrid clouds (combined), and community clouds (shared by organizations). It covers their architectures, use cases, advantages, and real-world applications in Nepal (e.g., NTC’s private

TAKEAWAYS:

  • Cloud deployment models determine who owns, manages, and accesses the cloud infrastructure (public vs. private vs. hybrid).
  • Public clouds (e.g., AWS, Google Cloud) offer scalability and cost-efficiency but lack control; private clouds (e.g., NTC’s internal cloud) provide security and customization at higher costs.
  • Hybrid clouds (e.g., banks using AWS for public services and private servers for sensitive data) balance flexibility and security.
  • Community clouds (e.g., shared healthcare cloud for hospitals) are niche but reduce costs for collaborative organizations.
  • Workload suitability drives model choice: bursty workloads (e.g., Pathao’s ride-hailing) fit public clouds; sensitive data (e.g., Ncell’s customer records) needs private clouds.
  • Migration challenges (data transfer, compatibility) must be planned when switching models.

1. Definitions and Core Concepts

Cloud deployment models define how cloud resources are allocated, accessed, and managed based on ownership, control, and sharing. The four primary models are:

Model Definition Ownership Access Control Use Case Examples
Public Cloud Shared infrastructure owned by third-party providers (e.g., AWS, Azure). Provider (e.g., Google) Multi-tenant (shared) Startups, eSewa, Daraz, YouTube
Private Cloud Dedicated infrastructure for a single organization (on-premises or hosted). Organization (e.g., NTC) Single-tenant (exclusive) Banks, government databases, Ncell CRM
Hybrid Cloud Combines public and private clouds with orchestration between them. Mixed (org + provider) Hybrid (selective sharing) Hospitals (public for patient portals, private for records), Pathao’s backend
Community Cloud Shared infrastructure for a specific community (e.g., universities, healthcare). Shared governance Multi-tenant (restricted) Pokhara University’s research cloud, Nepal Police’s shared database

Why does this matter? Deployment models directly impact cost, security, scalability, and compliance. For example:

  • A public cloud like AWS lets Daraz scale during sales (e.g., Dashain) without buying physical servers.
  • A private cloud ensures NTC’s network traffic data remains isolated from external threats.
  • A hybrid model allows NEPSE to use public clouds for investor portals while keeping trading data private.

2. How Each Model Works: Architectural Overview

Use the layered cloud architecture to visualize deployment models. All models share the same 5-layer stack (from bottom to top):

  1. Physical Infrastructure (servers, storage, networking hardware).
  2. Virtualization Layer (hypervisors like VMware, KVM).
  3. Resource Pooling Layer (CPU, RAM, storage allocated dynamically).
  4. Service Layer (IaaS/PaaS/SaaS interfaces).
  5. User Interface Layer (APIs, dashboards, CLI).

Public Cloud: Shared Everything

  • Physical Infrastructure: Owned by providers (e.g., Google’s data centers in the US/Europe).
  • Virtualization: Multi-tenant hypervisors (e.g., AWS Nitro) isolate customer VMs.
  • Access: Users pay per usage (e.g., $0.05/GB storage on S3).
  • Example Trace: When you upload a video to YouTube, it uses Google Cloud’s public infrastructure. The video is stored in multi-tenant storage, processed by shared GPUs, and delivered via CDNs (content delivery networks) worldwide.

Private Cloud: Dedicated Control

  • Physical Infrastructure: Owned by the organization (on-premises or hosted by a provider like IBM).
  • Virtualization: Single-tenant hypervisors (e.g., Nutanix) for exclusive use.
  • Access: Restricted to authorized users (e.g., NTC employees).
  • Example Trace: NTC’s private cloud hosts its billing system. When you pay your electricity bill via eSewa, the transaction data first lands in NTC’s private cloud, where it’s processed by dedicated servers before being logged in a secure database.
sequenceDiagram
    participant User as You (eSewa App)
    participant PublicCloud as Public Cloud (eSewa)
    participant PrivateCloud as NTC Private Cloud
    participant Database as Secure Database
    User->>PublicCloud: Pay bill via eSewa
    PublicCloud->>PrivateCloud: Forward transaction data (encrypted)
    PrivateCloud->>Database: Store in private DB
    Database-->>PrivateCloud: Confirm receipt
    PrivateCloud-->>PublicCloud: Send confirmation
    PublicCloud-->>User: Show "Payment successful"
    note right of PrivateCloud: **Private cloud ensures no third party accesses billing data.**

Hybrid Cloud: Best of Both Worlds

  • Physical Infrastructure: Mix of public and private.
  • Orchestration: Tools like AWS Outposts or Azure Arc connect the two.
  • Access: Sensitive data stays private; scalable services use public.
  • Example Trace: Ncell’s hybrid cloud uses:
    • Public cloud (AWS): Hosts its customer portal (e.g., checking balance via app).
    • Private cloud (on-premises): Stores call records and subscriber data.
    • Workflow: When you recharge via Khalti, the transaction is processed in AWS (public), but your call logs remain in Ncell’s private servers.

Community Cloud: Shared Purpose

  • Physical Infrastructure: Shared by organizations with common goals (e.g., healthcare providers).
  • Governance: Jointly managed (e.g., a consortium).
  • Example: Pokhara University’s research cloud is shared by multiple departments (e.g., engineering, medicine) to pool resources for AI projects without building separate labs.

3. Key Differences: Comparison Table

Feature Public Cloud Private Cloud Hybrid Cloud Community Cloud
Ownership Third-party (AWS, Azure) Single organization Mixed Shared consortium
Cost Pay-as-you-go (low upfront) High upfront (CAPEX) Variable (public + private) Shared costs
Scalability High (elastic) Limited (fixed resources) High (public layer) Moderate
Security Moderate (shared responsibility) High (dedicated) High (private for sensitive) High (restricted access)
Compliance Varies (e.g., GDPR on AWS) Full control (e.g., HIPAA) Custom (selective compliance) Shared governance
Use Case Startups, SaaS (e.g., Slack) Banks, government (e.g., NTC) Healthcare, finance (e.g., Ncell) Universities, NGOs
Example in Nepal Daraz (AWS), eSewa (Google Cloud) NTC, Nepal Rastra Bank Pathao (AWS + private DBs) Nepal Police’s shared database

4. Real-World Applications in Nepal

Example 1: NTC’s Private Cloud for Network Management

  • Model: Private cloud (on-premises).
  • Why? NTC’s core network infrastructure (e.g., fiber optics, switches) requires low latency and high security. A public cloud couldn’t guarantee the sub-millisecond response times needed for traffic routing.
  • How? NTC uses VMware-based private cloud to:
    • Monitor real-time traffic (e.g., during Dashain when usage spikes).
    • Isolate critical systems from cyber threats.
  • Visual: NTC’s fiber optic network control center (where private cloud servers manage routes).

Example 2: Daraz’s Public Cloud for E-Commerce

  • Model: Public cloud (AWS).
  • Why? Daraz needs to scale instantly during sales (e.g., Dashain, Tihar) without over-provisioning servers. AWS’s auto-scaling handles traffic surges (e.g., 10x users during festivals).
  • How? Daraz uses:
    • AWS EC2: Dynamically spins up servers for product pages.
    • S3: Stores images/videos (pay only for storage used).
    • CloudFront: CDN for fast global delivery.
  • Worked Example: During a Daraz sale, the system:
    1. Detects traffic spike (e.g., 50,000 concurrent users).
    2. AWS auto-scales EC2 instances from 100 → 1,000.
    3. CloudFront caches product pages in Nepal’s nearest region (e.g., Singapore).
    4. Users experience <2s load times even with heavy traffic.
sequenceDiagram
    participant User as Customer (Daraz App)
    participant CDN as AWS CloudFront (Nepal Region)
    participant EC2 as Auto-scaled EC2 Instances
    participant DB as DynamoDB (NoSQL)
    User->>CDN: Request product page
    CDN->>CDN: Check cache (hit/miss)
    alt Cache Miss
        CDN->>EC2: Fetch from origin
        EC2->>DB: Query product data
        DB-->>EC2: Return data
        EC2-->>CDN: Send HTML/CSS
    end
    CDN-->>User: Deliver page (<2s)
    note right of User: **Public cloud scales seamlessly.**

Example 3: Pathao’s Hybrid Cloud for Ride-Hailing

  • Model: Hybrid (AWS public + private DBs).
  • Why? Pathao needs:
    • Public cloud: For user-facing apps (scalable, global).
    • Private cloud: For driver/passenger data (GDPR-compliant).
  • How? Workflow:
    1. You open Pathao app → connects to AWS (public) for ride requests.
    2. AWS routes request to nearest driver (using AWS Lambda).
    3. Driver/payment data is encrypted and sent to Pathao’s private cloud (hosted in Nepal).
    4. Private cloud updates your ride history (never exposed to AWS).

Example 4: NEPSE’s Hybrid Cloud for Stock Trading

  • Model: Hybrid (private for trading data, public for investor portals).
  • Why? NEPSE must:
    • Keep trading volumes and order books private (high-security).
    • Allow public access to stock prices via its website.
  • How?
    • Private cloud: Hosts real-time trading data (e.g., NEPSE’s NEPSE Online Trading System).
    • Public cloud (Azure): Hosts investor dashboards (e.g., checking stock prices).
    • Orchestration: Azure Arc syncs data between the two securely.

5. Advantages and Disadvantages

Model Advantages Disadvantages
Public Cloud - Cost-effective (pay per use).<br>- Scalable (instant elasticity).<br>- No maintenance (provider handles updates). - Security risks (shared responsibility model).<br>- Compliance issues (data sovereignty laws).<br>- Vendor lock-in.
Private Cloud - Full control (custom security, compliance).<br>- Predictable performance (dedicated resources).<br>- Regulatory compliance (e.g., HIPAA, GDPR). - High cost (CAPEX for hardware).<br>- Limited scalability (manual upgrades).<br>- Maintenance burden (IT team required).
Hybrid Cloud - Flexibility (use public for scale, private for sensitive data).<br>- Optimized costs (right-size workloads).<br>- Best of both worlds. - Complexity (orchestration tools needed).<br>- Data transfer costs (syncing between clouds).<br>- Management overhead.
Community Cloud - Shared costs (lower than private).<br>- Collaborative innovation (e.g., research).<br>- Custom compliance (tailored to community needs). - Limited flexibility (governed by consortium).<br>- Slower decision-making (shared control).<br>- Niche use cases.

6. Choosing the Right Model: Decision Factors

Use this flowchart to decide which model fits your needs:

flowchart TD
    A["Start: What are your requirements?"] --> B{"Need scalability?"}
    B -->|"Yes"| C{"Can you afford public cloud costs?"}
    C -->|"Yes"| D["Public Cloud<br/>(e.g., AWS, Google Cloud)"]
    C -->|"No"| E["Hybrid Cloud<br/>(Public + Private)"]
    B -->|"No"| F{"Need strict compliance?"}
    F -->|"Yes"| G["Private Cloud<br/>(e.g., NTC, banks)"]
    F -->|"No"| H{"Shared community?"}
    H -->|"Yes"| I["Community Cloud<br/>(e.g., universities)"]
    H -->|"No"| J["Private Cloud<br/>(Custom setup)"]

Worked Example: Choosing for a Nepalese Bank Scenario: A bank wants to modernize its online banking system but must comply with Nepal Rastra Bank’s (NRB) regulations. Analysis:

  1. Sensitive Data: Customer transactions and KYC data → must be private.
  2. Public-Facing: Mobile app and website → can use public cloud.
  3. Cost: High initial investment for private cloud → hybrid is optimal. Solution: Use AWS public cloud for:
  • Mobile app hosting (scalable during Diwali).
  • Customer support chatbots. And private cloud (on-premises) for:
  • Transaction processing.
  • KYC document storage.

7. Migration Challenges and Strategies

Switching deployment models involves technical, financial, and operational hurdles. Common challenges:

Challenge Solution
Data Transfer Use AWS Snowball or Azure Data Box for large datasets.
Application Compatibility Test with containerization (Docker, Kubernetes) for portability.
Downtime Implement blue-green deployment (run old and new systems in parallel).
Security Risks Use encryption (AES-256) and zero-trust models during migration.
Cost Overruns Start with hybrid (migrate non-critical workloads first).

Example: Ncell’s migration from private to hybrid cloud:

  1. Assessment: Identified 30% of workloads (e.g., customer portal) could move to AWS.
  2. Pilot: Migrated SMS gateway to AWS first (low risk).
  3. Orchestration: Used AWS Outposts to connect private cloud to AWS.
  4. Result: Reduced costs by 40% while maintaining compliance.

8. Exam Tip: How This Unit is Tested

This unit is heavily tested in TU/PU exams with a mix of:

  1. Definitions and Comparisons (2–4 marks):

    • "Differentiate between public and private clouds with examples from Nepalese companies."
    • Key: Use the comparison table above and cite real examples (e.g., NTC vs. Daraz).
  2. Scenario-Based Questions (5–8 marks):

    • "A hospital in Kathmandu wants to store patient records securely but also use cloud-based appointment scheduling. Recommend a deployment model and justify your choice."
    • Approach:
      • Identify sensitive data (private cloud).
      • Identify scalable needs (public cloud for scheduling).
      • Conclude hybrid with AWS Outposts for connectivity.
  3. Diagram-Based Questions (3–5 marks):

    • "Draw and label a hybrid cloud architecture for a Nepalese bank, showing how public and private layers interact."
    • Tip: Use the hybrid cloud sequence diagram from earlier and add labels like:
      • "Public: Customer login portal (AWS)"
      • "Private: Transaction DB (on-premises)"
      • "Orchestration: Azure Arc"
  4. Short Answer on Advantages/Disadvantages (2 marks each):

    • "List two advantages of a community cloud for Pokhara University."
    • Answer:
      1. Shared costs reduce per-department expenses.
      2. Collaborative research (e.g., shared AI labs).
  5. Case Study Analysis (10–12 marks):

    • "Analyze why NEPSE might choose a hybrid cloud over a public cloud. Include a workflow diagram."
    • Structure:
      1. Introduction: Briefly define hybrid cloud.
      2. NEPSE’s Needs:
        • Public: Investor portals (scalable).
        • Private: Trading data (secure).
      3. Workflow Diagram: Use the hybrid cloud cloudDiagram from earlier.
      4. Conclusion: Hybrid balances compliance and scalability.

Pro Tip:

  • Memorize the 4 models and one Nepalese example each (e.g., NTC = private, Daraz = public).
  • Practice drawing the layered architecture and hybrid cloud workflows.
  • For scenario questions, always:
    1. Identify data sensitivity.
    2. Identify scalability needs.
    3. Match to the best model.

Based on the TU BITM syllabus for Cloud Computing (IT277), unit 3.

Discussion

Loading…