Posts

The Horseshoe Theory of Political Extremism

Image
  This is my second attempt at political satire. Have you heard of the Horseshoe Theory of Political Extremism? It's like the saying goes: "the farther right you go, the closer you get to the left, and vice versa." It's like a horseshoe - the ends may seem far apart, but they actually bend towards each other. It's almost like the political spectrum is a giant, bendy straw that can suck up any ideology, no matter how extreme! But don't worry, the straw, as in this short essay, is made of rubber, so it won't poke your eye out. They say politics makes for strange bedfellows, but if you venture to the fringes of the political spectrum, you’ll find the strangest bedfellows of all — the far left and far right, nestled together like two peas in an extremist pod. On the surface, these two camps couldn’t seem more different. The far left reads Das Kapital, dreams of a worldwide communist revolution, and gets misty-eyed singing The Internationale. The far right read...

How MSPs Can Deliver IT-as-a-Service with Better Governance

Image
 Sanjay Basu As a solutions architect, I often support partners who deliver managed IT services to their end customers. Similarly, I work with large enterprises who manage IT for multiple business units. One of the most frequent requests I get is for best practices on how to align Oracle Cloud Infrastructure solutions and Identity and Access Management (IAM) policies with business-specific governance use cases. For enterprise customers, this means having better control over usage costs across multiple business units. For managed service providers (MSPs), this involves having better cost governance over the IT environments that they manage for end customers in their Oracle Cloud Infrastructure tenancy. This post is structured like a case study, in which an example enterprise customer, ACME CORP's Central IT team, faces the following business challenge: How do they enable their departmental IT stakeholders, and the operators within those departments, to have the aut...

Dedicated Access to GlusterFS-Based Shared Storage on Oracle Cloud Infrastructure

Image
 Sanjay Basu Oracle Cloud Infrastructure (OCI) provides bare metal compute instances for both high-frequency CPU and GPU environments, that's why OCI is naturally great infrastructure for many high-performance computing (HPC) applications that need that processing power. However, many applications also require fast access to shared file systems in order to execute quickly and efficiently. Companies developing machine-learning-based applications want to provision their own shared file systems on Oracle Cloud Infrastructure because they are already using them elsewhere and are familiar with them, their performance characteristics, and other features. We recommend using GlusterFS for very fast shared file storage for HPC, machine-learning, or deep-learning workloads using GPU nodes. GlusterFS is a distributed, scale-out file system that lets you rapidly provision additional storage based on your storage consumption needs. It incorporates automatic failover as a primar...

Integrating Security with DevOps on Oracle Cloud (Part 2 of 2)

Image
 Sanjay Basu This post is part 2 in our blog series about how we integrate security with a generic DevOps-based application development process. In part 1 , we defined DevOps methodology and practices, focusing on how to integrate continuous security into the larger DevOps process to support continuous application development and operation. In this post, we cover some of the fundamental infrastructure components, such as cloud firewall services, identity management services, and continuous patching without downtime. Network and Application Security Services When you develop an application, or add or remove features, it’s essential to ensure that only required TCP ports are open. Opening ports that aren’t required can lead to exploits and compromises caused by vulnerabilities in the OS or supporting applications. The following figure shows the danger of keeping TCP ports open and accessible to nontrusted networks. Diagram courtesy of https://geekflare.com/port-...

Integrating Security with DevOps on Oracle Cloud (Part 1 of 2)

Image
 Sanjay Basu   Modern development organizations are increasingly using cloud computing attributes like elasticity, API-driven infrastructure as code (IaC), and native immutability for their DevOps and agile development practices. Through DevOps, organizations are seeing these outcomes: Speed up software development and systems deployment cycles Reduce the time and cost to transform an idea into a finished product Unify agile software development and operations, removing barriers to an integrated and iterative process Industrialize the tools and techniques of development and operations with automation at the core In the many engagements in which we've helped customers migrate and develop applications in Oracle Cloud, I have found that security is often a critical missing element in customer DevOps processes. In these cases, security is treated like a siloed and gated activity which, when missed or applied too late, leads to missed project deadlines and vulnerable ...

Part 4 of 4 - Oracle IaaS and Seven Pillars of Trusted Enterprise Cloud Platform

Image
  Note : My original blog series was published in ORACLE CLOUD INFRASTRUCTURE blog site. I have republished it here with permission. Official Disclaimer : The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of Oracle Corporation. The concluding post of this series, in which we mapped Oracle's seven pillars of a trusted computing platform to Oracle Cloud Infrastructure security capabilities, covers a few services that were introduced or enhanced since the publication of earlier posts ( Part 1 , Part 2 and Part 3 ), along with relevant services from the Oracle Cloud Security portfolio for enterprises. New and Enhanced Features First, let's explore the major new services and features that enhance the security of customer environments on Oracle Cloud Infrastructure. Encrypt your Data using Keys you Control In October 2018, we announced the release of Oracle Cloud Infrastructure Key...

Part 3 of 4 - Oracle IaaS and Seven Pillars of Trusted Enterprise Cloud Platform

Image
  Sanjay Basu Note : My original blog series was published in ORACLE CLOUD INFRASTRUCTURE blog site. I have republished it here with permission. Official Disclaimer : The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of Oracle Corporation. This post is the third one in the series in which we are mapping Oracle's seven pillars of a trusted computing platform to Oracle Cloud Infrastructure security capabilities. This post covers the rest of the pillars. The fourth and final installment in this series will highlight some security services and enhancements that have been added to the portfolio.   Links to Part 1 and Part 2 . 5: Secure Hybrid Cloud Oracle Cloud Infrastructure supports SAML 2.0 federation via Oracle Identity Cloud Service ( IDCS ), Microsoft Active Directory Federation Service (ADFS), and any SAML 2.0 compliant identity provider. Customers can also use Oracle C...

Part 2 of 4 - Oracle IaaS and Seven Pillars of Trusted Enterprise Cloud Platform

Image
 Sanjay Basu Note : My original blog series was published in ORACLE CLOUD INFRASTRUCTURE blog site. I have republished it here with permission. Official Disclaimer : The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of Oracle Corporation. This is the second part of our blog series where we do a deep dive into the Oracle Cloud Infrastructure security approach. As a recap, we design our security architecture and build security solutions based on seven core pillars . And under each of these pillars, we focus on delivering solutions and capabilities to help ensure our customers can improve the security posture of their overall cloud infrastructure. In the first post, we discussed how we enable customers to achieve isolation and encrypt their data . In this post, we dig into our 3rd and 4th pillars, and discuss how you can obtain the security controls and visibility needed for your cloud ...