AppFog – Polyglot Public/Private PaaS goes GA

AppFog (the company formerly known as PhpFog) has become the latest enthusiastic adopter of CloudFoundry to go to General Availability with a value-added implementation of the open source CloudFoundry.org stack. The key differentiator is the RAM-based pricing policy around the Public Cloud offering – roughly $25 per GByte per month (first 2Gbytes are Free).

Private PaaS Update – Stackato 2.0 and Cumulogic 1.0

ActiveState Stackato and CumuLogic are private PaaS. Over the last few weeks Stackato has moved to a 2.0 version and CumuLogic has moved out of Beta to a 1.0 release. CumuLogic 1.0 is a Java-only PaaS with support for Amazon, HP Cloud Services, and private clouds including Citrix CloudStack, Eucalyptus, OpenStack and VMware vSphere. Stackato has a similar range of public and privae IaaS on which it operates (vSphere, KVM, XenServer, OpenStack, EC2 AMI, HP CS) but it has a much broader set of language compatibilities including .NET.ther new features in Version 2.0 are a centralized web-based management console and some support for charge-back (i.e. billing) through API. Performace management is through integration with New Relic. There is additional security support in multi-tenancy by using Linux Containers (LXC).

Storage Hypervisors: Worth the Hype

Just what are storage hypervisors? There are several companies that claim to have storage hypervisors. Wikipedia states that a hypervisor is “conceptually one level higher than a supervisory program”. We also know that from our normal use of hypervisors that they manage the underlying resources that a guest uses. Do these definitions work for a storage hypervisor?

Defense in Depth: Know Your Attack Surfaces

The 6/28 Virtualization Security Podcast we spoke about attacks, defense in depth, and compliance with Davi Ottenhiemer and Matt Wallace. Davi and Matt just published a book on how to defend your virtual environment against attack. Unlike other books, this approaches the problem from the point of view of well know attacks. It even gives examples of some of the more interesting attacks against any of the virtual environments, not just VMware vSphere. The discussion eventually found its way to even newer attacks and their impact on the environment.

Defense in Depth: Storage Security in a Hybrid Cloud

Storage Security is not only about Encryption, which is just one aspect of Storage Security requirements for the virtual and cloud environments. It is also about increasing defense in depth and knowledge of what is touching your storage environment. As well as providing security around those touch points and to a great extent auditing and protecting the data residing within the storage devices regardless of where the devices live: within the virtual environment or within a cloud.