In the
first part, I talked about participation in the Private Cloud tender and gave arguments in choosing the hardware complex. In the second part, I will share with you how we decided on the software component of the cloud.
To begin, consider what services are included in the Private Cloud. The map below shows standard services:

- Portal Service is a single user portal that provides access to cloud services: service catalog, change request, request for a new service, incident management, reports, etc.
- Service Catalog set of services available to the user. The services provided are managed here (design, life cycle)
- End-user reporting provides the user with reports on the services or resources used, SLA compliance, billing and security
- Billing determines the billing model, provides relevant reports.
- Orchestration is the link between business logic and the automated process (workflow) necessary to implement the end-user service.
- Resources Management resource management, resource isolation between related projects (multi-tenancy)
- Service Metering regular resource reporting, chargeback & showback
- Template Lifecycle Management IaaS & PaaS template creation and support service (template), software and OS image management required for creating IaaS & PaaS templates
- Security Management Private Cloud Security Service
- Plateform Ressources includes all the necessary software to provide PaaS service (databases, web servers, etc.)
- Execution resources provides the necessary resources for the execution of PaaS (operating systems, virtual machines, antivirus, etc.)
- Virtualization Layer hardware complex abstraction (hypervisor & infrastructure management API)
- Hardware resources are computing and network resources, storage, etc.
- Security resources necessary for security of IaaS & PaaS services (firewall, intrusion detection & prevention, antivirus, log inspection, vulnerability management)
- Performance and Scalability is responsible for providing scalable resources, load balancing
- Availability and Continuity backup, high availability, disaster recovery plan
- Operational Support provides service in accordance with the ITIL approach.
- Business Support a set of processes responsible for the business relationship between the Private Cloud provider and the customer
')
After reading this list of services, it is clear that VMware or Microsoft do not cover all the required services and an additional solution is needed.
This solution turned out to be a proposal from HP: Operation Orchestration and Cloud Service Automation, which provide Portal Service, Request Management, Service Catalog, Orchestration, Resources Provisioning and Security Management Services.
This choice became even more reasonable when we decided to use two hypervisors simultaneously. The fact is that bronze and silver SLAs do not require all those cool VMware solutions that provide high availability and thus do not justify the high cost of its licenses. It was decided that Microsoft Hyper-V would suit bronze and silver, and VMware for gold and platinum. Let me remind you of the RPO / RTO required by the customer:
- bronze: best effort, not included in DRP
- silver: 24h / 48, included in DRP
- gold: 2h / 4h, enters DRP
- platinum: real time / 2h, enters DRP
The HP solution is an agnostic approach to cloud management: it equally supports Microsoft and VMWare. Thus, cloud management becomes transparent, regardless of the level of virtualization. In addition, not least, HP provides connectors for more than 4,000 software and hardware solutions, which allows them to be included in an automated process.
Microsoft licenses are much cheaper (in this and interest), perhaps this is a commercial move in order to find its niche in the market. In this case, this niche is virtual machines, with non-critical requirements of RTO / RPO.
We get the following cloud macro-architecture (I have given only the most significant elements):

Thus, the choice of FlexPod architecture, which is certified with VMware and Microsoft, is justified.
We did not consider a competitive offer from CA - Automation Suite for Data Centers, there was no time for that. And so this decision does not claim to be the absolute and only correct.
In the next part - about the issues of macro-design of iron.