COE 558Lecture 02Reference
Reference sheet
E2C continuum and cloud computing compressed onto one page: the definitions, formulas and numbers to have in your head before a quiz or exam.
The E2C continuum and the fog
The continuum is a range of latencies: moving away from the client adds latency and adds capacity. The cloud stays centralized for economies of scale, so mini data centers (the fog) go out instead. Part 01: Latency continuum and the fog
| Layer | Span | Services | Priority | RTT floor | Example |
|---|---|---|---|---|---|
| Edge | LAN | Compute, storage | Autonomy | ~1 µs at 100 m | Obstacle detection |
| Fog | WAN | Compute, storage, networking | Coordination | ~0.5 ms at 50 km | Traffic signals, collision coordination |
| Cloud | Internet | Full data center | Global connectivity | ~40 ms at 4,000 km | Fleet-wide model training |
| Resource | Medium | Very large | Ratio |
|---|---|---|---|
| Network | $95 per Mbit/s per month | $13 | 7.1 |
| Storage | $2.20 per GB per month | $0.40 | 5.7 |
| Administration | ~140 servers per admin | >1,000 | 7.1 |
| Aspect | Fog | Edge |
|---|---|---|
| Structure | Hierarchical, multi-layer | A few peripheral devices |
| Services | Compute, networking, storage, control, acceleration | Specific applications in a fixed logic location |
| Location | Between end devices and the cloud | The end-device layer itself |
Roles of edge, fog and cloud
Edge serves the client, fog serves many edges, cloud serves everyone. Part 02: Edge, fog and cloud layers
| Layer | Role | Scope | Data horizon | Example |
|---|---|---|---|---|
| Edge | Immediate processing near the client | One client or site | Milliseconds (act and discard) | Wake-word detection |
| Fog | Intermediate layer for a region | Many edges in a district | Seconds to days | Traffic management |
| Cloud | Centralized, large-scale processing | Everyone, globally | Months to years | Training an AI model |
- Fog benefits: less edge-to-cloud traffic, geo-restricted data for compliance, shorter edge-to-edge paths.
- Edge roles: WAN boundary, offload target, fast small-data processing, gateway that hides the fog (like a reverse proxy).
- Cloud: big compute (HPC), big storage (big data), big networking (multi-cloud).
- IoT tree: devices sense, gateways process locally, fog coordinates regionally, cloud analyses globally.
- Fog filtering example: 200 × 4 Mbps = 800 Mbps raw becomes 3.2 Mbps of events, about 250× less.
Vehicle platoon
- Setup
- v = 30 m/s (108 km/h), gap about 10 m
- Cloud, 60 ms
- d = 30 × 0.06 = 1.8 m
- RSU (fog), 5 ms
- d = 30 × 0.005 = 0.15 m
- Car or V2V, 1 ms
- d = 30 × 0.001 = 0.03 m
- Mapping
- Cars are edge nodes, RSUs and the RSUC are fog, the cloud coordinates globally.
| Question | This course | NIST SP 500-325 |
|---|---|---|
| What edge names | Layer on the WAN boundary | End devices and their users |
| Where a gateway sits | Edge layer | Among the fog nodes |
| Use it for | Exam answers in this course | Papers citing NIST SP 500-325 |
Legacy IT and virtualization
A VM is an efficient, isolated duplicate of a real machine. Part 03: Legacy IT and virtualization basics
Legacy IT stack
- Bottom to top
- Data center, networking, storage, server, virtualization, operating system, databases, security, applications
- Legacy IT
- The customer manages all nine layers.
- McCarthy (1961)
- Computing sold like a utility: shared capacity, pay per use, network access.
Popek and Goldberg's three properties
- Equivalence
- Programs see an environment essentially identical to the real machine.
- Efficiency
- A statistically dominant subset of instructions runs directly on the real CPU. Rules out emulators and simulators.
- Resource control
- The VMM keeps complete control of real resources; a guest cannot reach what it was not given.
| Aspect | Virtualization | Emulation | Simulation |
|---|---|---|---|
| Core idea | Logical copies of physical resources | Mimics a hardware/software interface | Models a system's behaviour |
| Runs natively | Most guest instructions | Nothing, all translated | The model only |
| Same ISA | Yes | No | Not applicable |
| Speed | Close to native | Much slower | Whatever the model needs |
| Example | VMware, VirtualBox | BlueStacks, console emulator | Flight simulator |
| Full (unmodified guest) | Para (modified guest) | |
|---|---|---|
| Type 1, bare metal | VMware ESXi, Xen HVM | Xen PV |
| Type 2, hosted | VirtualBox, VMware Workstation | Paravirtual drivers in hosted products |
Hypervisors and containers
Cloud providers use Type 1: less overhead is more sellable capacity, and a thinner layer between tenants is stronger isolation. Part 04: Hypervisors and containers
| Property | Type 1 (bare metal) | Type 2 (hosted) |
|---|---|---|
| Runs on | The hardware, as the lowest layer | A process of a host OS |
| Overhead (slide) | ≈5% | ≈10% |
| Resource management | Direct | Indirect, through the host OS |
| Administration | Needs more skill | Easy, like a desktop app |
| Isolation | Stronger | Weaker: host OS compromise exposes guests |
| Examples | ESXi, Hyper-V, KVM (debated), AWS Nitro | VirtualBox, VMware Workstation, Parallels |
| Property | VM | Container |
|---|---|---|
| Kernel | One guest kernel per VM | Shared host kernel |
| Start-up | Seconds to minutes | Milliseconds to about a second |
| Isolation boundary | Hypervisor and virtual hardware | System call interface of a shared kernel |
| OS family | Any the virtual hardware supports | Same as the host kernel only |
| Image size | Gigabytes | Megabytes |
| Aspect | Namespaces | Cgroups |
|---|---|---|
| Question | What can a process see? | How much can it use? |
| Mechanism | Own view of a kernel resource | Quotas, weights, accounting, freezing |
| Types or functions | PID, network, mount, UTS, IPC, user, cgroup, time | Limiting, prioritization, accounting, control |
| Example files or flags | CLONE_NEWPID, CLONE_NEWNET | cpu.max, cpu.weight, memory.max, cgroup.freeze |
On-premise cost and TCO
Five dual-socket Xeon E5-2640 v2 servers, open-source software, a 3-year horizon. Part 05: On-premise TCO case study
| Aspect | CapEx | OpEx |
|---|---|---|
| When paid | Upfront and lumpy | Recurring and smooth |
| Accounting | Capitalised, then depreciated | Expensed in the period |
| Examples | Servers, SAN, switches, racks | Power, cooling, rent, salaries, maintenance |
| Cloud analogue | None, the provider owns the hardware | Pay as you go |
Case study numbers (slides 33 and 34)
- Servers
- 5 × 3,500 = 17,500 EUR
- SAN
- 35,000 EUR (≈50.9% of CapEx, 39.0% of TCO)
- Switches
- 4 × 3,677.50 = 14,710 EUR
- Facilities, cooling kit
- 897 + 717 EUR
- CapEx
- 68,824 EUR
- Power
- 5 × 308 W, 13,490 kWh at 0.22 EUR/kWh: 2,962 EUR/yr (slide)
- Cooling
- 5 × 385 W: 3,702 EUR/yr (slide)
- Rent
- 5 m² × 5 EUR × 12 = 300 EUR/yr
- OpEx
- 6,964 EUR/yr, 20,891 EUR over three years
- TCO, 3 years
- 89,715 EUR, about 498 EUR per server per month (76.7% CapEx)
Cloud cost and the break-even
A cloud bill is pure OpEx: unit price times metered quantity. Part 06: Cost case study and NIST models
| Period | Traditional IT | AWS |
|---|---|---|
| Start | 68,824 | 0 |
| Each year | 6,964 | 19,364 (5 VMs) |
| After 3 years | 89,715 | 58,093 |
| After 5 years | 103,644 | 96,820 |
| After 6 years | 110,608 | 116,184 |
NIST SP 800-145: 5-3-4
Five essential characteristics, three service models, four deployment models. Part 06: Cost case study and NIST models
| Characteristic | Meaning | Example |
|---|---|---|
| On-demand self-service | Provision unilaterally, no human at the provider | Launch a VM from the console at 2 a.m. |
| Broad network access | Standard mechanisms, heterogeneous clients | Same storage from phone, laptop or script |
| Resource pooling | Multi-tenant, location independent | You pick a region, never a rack |
| Rapid elasticity | Scale out and in with demand, appears unlimited | Auto scaling group at peak |
| Measured service | Metered, reported to provider and consumer | Line items of the slide 35 bill |
| Model | Users | Location |
|---|---|---|
| Public | The general public | On the provider's premises |
| Private | One organization | On or off premises |
| Community | Organizations with shared concerns | On or off premises |
| Hybrid | Composition of distinct clouds bound by portability technology | Spans its components |
- Cloud bursting is the canonical hybrid example.
- Keep some traditional IT for latency, data residency, regulation and vendor lock-in.
Service models: IaaS, PaaS, SaaS
Machine means IaaS, runtime means PaaS, finished app means SaaS. Part 07: Service models
| Layer | On-prem | IaaS | PaaS | SaaS |
|---|---|---|---|---|
| Applications | Customer | Customer | Customer | Provider |
| Security | Customer | Customer | Provider | Provider |
| Databases | Customer | Customer | Provider | Provider |
| Operating systems | Customer | Customer | Provider | Provider |
| Virtualization | Customer | Provider | Provider | Provider |
| Server, storage, networking, data center | Customer | Provider | Provider | Provider |
| Type | Addressing | Access | AWS | Typical use |
|---|---|---|---|---|
| Block | Fixed-size block on a volume | Mounted as a raw disk by one server | EBS | Boot disk, database files |
| File | Path in a directory tree | Shared over the network | EFS | Shared home directories |
| Object | Unique ID in a flat namespace | HTTP API (PUT, GET) | S3 | Media, backups, data lakes |
Public cloud hyperscalers
Hyperscale is economics: roughly 1/5 to 1/7 of medium-sized unit prices. Part 08: Public cloud hyperscalers
Market and history
- Market, Q2 2026
- $143.4B, +43% year on year
- Shares
- Amazon 28%, Microsoft 20%, Google 15%, top three 63%
- AWS
- S3 (March 2006), EC2 (August 2006), from Amazon's internal platform
- Google Cloud
- App Engine PaaS (April 2008), Compute Engine GA (December 2013)
- Azure
- Announced October 2008, GA February 2010, renamed Microsoft Azure in 2014
- Spectrum
- EC2 gives control (kernel up), App Engine gives convenience (constrained app shape), Azure 2009 sat between.
| Block | Need | AWS | Google Cloud | Azure |
|---|---|---|---|---|
| Compute | Virtual machines | EC2 | Compute Engine | Virtual Machines |
| Compute | Kubernetes | EKS (slide: ECS) | GKE | AKS |
| Storage | Object | S3 | Cloud Storage | Blob Storage |
| Storage | Block | EBS | Persistent Disk | Managed Disks |
| Database | NoSQL | DynamoDB | Bigtable | Cosmos DB |
| Database | Relational | RDS | Cloud SQL | SQL Database |
| Networking | Private network | VPC | VPC | Virtual Network |
| Networking | DNS | Route 53 | Cloud DNS | Azure DNS |
| Networking | CDN | CloudFront | Cloud CDN | Azure Front Door |
| Deployment and Management | Infrastructure as code | CloudFormation | Infrastructure Manager | Resource Manager |
| Deployment and Management | Identity and access | IAM | Cloud IAM | Entra ID with Azure RBAC |
| Application Services | Messaging | SQS, SNS | Pub/Sub | Queue Storage, Service Bus |
Private cloud platforms
A private IaaS platform turns owned servers into self-service, pooled, metered resources for one organization. Part 09: Private cloud platforms
| Service | Manages | AWS equivalent |
|---|---|---|
| Nova | Compute instances | EC2 |
| Swift | Objects over HTTP | S3 |
| Cinder | Block volumes | EBS |
| Neutron | Virtual networks | VPC |
| Keystone | Identity, tokens, catalog | IAM |
| Glance | Boot images | AMI catalog |
| Horizon | Web dashboard | Management Console |
| Placement | Host inventory and usage | No direct equivalent |
| Aspect | OpenStack | OpenNebula |
|---|---|---|
| Origin | Rackspace and NASA | Complutense University of Madrid |
| First release | 2010 | 2008 |
| Steward | OpenInfra, under the Linux Foundation | OpenNebula Systems |
| Architecture | Many REST services, AMQP, SQL | Single front-end (oned) plus drivers |
| Main API | REST, authenticated by Keystone | XML-RPC |
| Hypervisors today | Mostly KVM | KVM and LXC |
| License | Apache 2.0 | Apache 2.0 |
SLAs and availability
Each extra nine cuts the downtime budget tenfold. Part 10: SLAs and availability
| Availability | Per year | Per month | Per day |
|---|---|---|---|
| 99% | 3.65 d | 7.2 h | 14.4 min |
| 99.9% | 8.76 h | 43.2 min | 1.44 min |
| 99.95% | 4.38 h | 21.6 min | 43.2 s |
| 99.99% | 52.56 min | 4.32 min | 8.64 s |
| 99.999% | 5.26 min | 25.9 s | 0.86 s |
SLI, SLO, SLA
- SLI
- The measurement, for example the share of valid requests that succeeded.
- SLO
- An internal target for an SLI. Missing it triggers engineering work, not payments.
- SLA
- A contract naming SLOs and the consequence of missing them.
- EC2 example
- 99.99% monthly per region (99.5% single instance). Credits 10%, 30% below 99.0%, 100% below 95.0%. Credits are the sole remedy.
| Topology | Formula | Result |
|---|---|---|
| Series (hard dependencies) | A = ∏ Aᵢ ≤ min Aᵢ | 99.8001% |
| Parallel (redundant replicas) | A = 1 − ∏ (1 − Aᵢ) | 99.9999% |
Slide errata
Answer with the corrected fact, and mention the slide's version when a question depends on it.
What the slides get wrong
- Slide 10
- "Mini Data Cener" should read Mini Data Center. Part 02
- Slide 20
- Full and para (guest modified?) are a separate axis from Type 1 and Type 2 (where it runs). VM/370 is 1972, not 1970/71. Part 03
- Slide 22
- vSphere is the suite; the Type 1 hypervisor is ESXi. KVM's label is debated. Part 04
- Slide 24
- Type 2 has less isolation than Type 1. 5% and 10% are workload-dependent approximations. Part 04
- Slide 25
- Virtual hardware is shared only when the container host is a VM. The SCI is the kernel entry point; the kernel manages hardware. Part 04
- Slides 26, 27
- Linux has eight namespace types. One namespace is not a container: a container is several namespaces plus cgroups plus a root filesystem. Part 04
- Slide 32
- Routine maintenance is OpEx (IAS 16 paragraph 12), not CapEx. Part 05
- Slides 33, 34
- European number format (17.500 € is 17,500 EUR). KVM is a keyboard-video-mouse switch. Rent is per m² per month. Part 05
- Slide 35
- Monthly rows sum to 318, not 323; yearly rows to 3,816, not 3,878. Part 06
- Slide 36
- The AWS column is five VMs (19,364 ≈ 5 × 3,873), never stated. Part 06
- Slides 42, 44
- "Comany" should read Company. Linking private clouds to the community cloud is a hybrid composition. Part 06
- Slides 47, 48
- The customer always keeps data, identities, access management and endpoints, even in PaaS and SaaS. Part 07
- Slides 53, 54, 56
- Gmail (2004) predates App Engine. Container Engine is GKE, Deployment Manager gives way to Infrastructure Manager, "Cosmo DB" is Cosmos DB, IAM maps to Entra ID plus RBAC. Part 08
- Slides 60, 62
- Titled "Public" but OpenStack and OpenNebula are private platforms. OpenNebula dropped Firecracker, LXD and vCenter drivers. Part 09
- Slide 66
- The second box should read Service 2, at 99.9%. Part 10
- Slide 67
- The calculator screenshot is internally inconsistent; 0.11% of a 365-day year is about 9 h 38 min. Part 10