SUSE Linux Enterprise Server (SLES) with 24/7 support – now available with Committed Use Discounts

Optimizing your costs is a major priority for Google Cloud. We do this with products that deliver a great combination of price and performance, recommendations that help you right size your deployment, and by offering the right pricing models. Committed Use Discounts is one such model that allows you to get high discounts against commitments to use for a defined period.Today, we are excited to announce the general availability of committed use discounts (“CUDs”) for SUSE Linux Enterprise Server (“SLES”) with 24/7 support. CUDs are a very effective way of saving on your cloud costs when you have some predictability in your workloads. Now you can take the same advantage for SLES licenses. SLES CUDs can save you as much as 79% on license costs compared to pay-as-you-go prices.SUSE was our first partner to offer software license committed use discounts. Our close collaboration with SUSE enabled the expansion of these CUD offerings. This is an important step in helping our partners and customers grow their business on Google Cloud. Here is what Frank Powell, President of Managecore, a Google Cloud Partner had to say about this offering: “We are excited to join Google and SUSE on this new CUD offering for SLES. This will enable our joint customers to accelerate their workload migrations to cloud, from proprietary to more open source solutions. At the same time, it allows them to leverage the maximum discounts, providing choice and flexibility to run their modern workloads on Google Cloud.” Manish Patil, SUSE Sr. Director for Global Cloud Alliances had to say this: “Expansion of our CUD offering for SLES in addition to SLES for SAP is another exceptional joint innovative offering for customers resulting in more savings, choice, and elasticity in terms of running more stable and predictable workloads securely on Google Cloud.” How do committed use discounts work for SLES?SLES CUDs are region-specific — similar to how SLES for SAP CUDs work today. Therefore, you will need to buy commitments in the same region as the instances consuming these licenses. When you purchase SLES commitments, they form a “pool” of licenses that automatically apply to your running VM instances within a selected project in a specified region. Commitments can also be shared across projects within the same billing account by turning on billing account sharing. Discounts apply to any active VMs, so the commitment is not tied to any particular VM.When commitments expire, your running VMs continue to run at on-demand rates. However, it is important to note that after you purchase a commitment, it is not editable or cancelable. You must pay the agreed upon monthly amount for the duration of the commitment. Refer to Purchasing commitments for licenses for more information. How can I purchase committed use discounts for SLES?SLES CUDs can be purchased on a one-year or three-year contract, and each are priced according to your virtual machine vCPU counts. After purchasing, you will be billed monthly for the commitments regardless of your usage.* Price as of this article’s publish dateHow much can I save by using committed use discounts for SLES?By purchasing SLES committed use discounts, you can save as much as 79% on SLES license costs compared to the current pay-as-you-go prices. Here is a helpful comparison of discounts possible on CUDs relative to pay-as-you-go prices:* Approximate effective hourly price as of blog publish date, calculated using VMs running 730 hours per month,12 months per year. ** Discounts compared to current pay-as-you-go pricing.What if I need to upgrade my SLES version after purchasing a commitment? SLES CUDs are version-agnostic and are not affected when you perform OS upgrades or downgrades. For example, if you purchased a commitment for SLES 12, you may upgrade to SLES 15 and continue to use the same commitment without any action from your end. Additionally, commitments are not affected by future pricing changes to the pay-as-you-go prices for Compute Engine resources.You can find more information on purchasing CUDs for SLES on our CUDs documentation. We are always looking to diversify our offerings to help customers optimize costs on Google Cloud. We hope this helps you find the most cost-optimal plan for your SUSE Linux Enterprise Server deployment needs.
Quelle: Google Cloud Platform

Dive deep into NAT gateway’s SNAT port behavior

In our last blog, we examined a scenario on how network address translation (NAT) gateway mitigates connection failures happening at the same destination endpoint with its randomized source network address translation (SNAT) port selection and reuse timers. In addition to handling these scenarios, NAT gateway’s unique SNAT port allocation is beneficial to dynamic, scaling workloads connecting to several different destination endpoints over the internet. In this blog, let’s deep dive into the key aspects of NAT gateway’s SNAT port behavior that makes it the preferred solution for different outbound scenarios in Azure.

Why SNAT ports are important to outbound connectivity

For anyone working in a virtual cloud space, it is likely that you will encounter internet connection failures at some point. One of the most common reasons for connection failures is SNAT port exhaustion, which happens when the source endpoint of a connection runs out of SNAT ports to make new connections over the internet.

Source endpoints use ports through a process called SNAT, which allows destination endpoints to identify where traffic was sent and where to send return traffic. NAT gateway SNATs the private IPs and ports of virtual machines (VMs) within a subnet to NAT gateway’s public IP address and ports before connecting outbound, and in turn provides a scalable and secure means to connect outbound.

Figure 1: Source network address translation by NAT gateway: connections going to the same destination endpoint over the internet are differentiated by the use of different source ports.

With each new connection to the same destination IP and port, a new source port is used. A new source port is necessary so that each connection can be distinguished from one another. SNAT port exhaustion is an all too easy issue to encounter with recurring connections going to the same destination endpoint since a different source port must be used for each new connection.

How NAT gateway allocates SNAT ports

NAT gateway solves the problem of SNAT port exhaustion by providing a dynamic pool of SNAT ports, consumable by all virtual machines in its associated subnets. This means that customers don’t need to worry about knowing the traffic patterns of their individual virtual machines since ports are not pool-based in fixed amounts to each virtual machine. By providing SNAT ports on-demand to virtual machines, the risk of SNAT exhaustion is significantly reduced, which in turn helps prevent connection failures.

Figure 2: SNAT ports are allocated on-demand by NAT gateway, which alleviates the risk of SNAT port exhaustion. 

Customers can ensure that they have enough SNAT ports for connecting outbound by scaling their NAT gateway with public IP addresses. Each NAT gateway public IP address provides 64,512 SNAT ports, and NAT gateway can scale to use up to 16 public IP addresses. This means that NAT gateway can provide over one million SNAT ports for connecting outbound.

How NAT gateway selects and reuses SNAT ports

Another key component of NAT gateway’s SNAT port behavior that helps prevent outbound connectivity failures is how it selects SNAT ports. Whether connecting to the same or different destination endpoints over the internet, NAT gateway selects a SNAT port at random from its available inventory.

Figure 3: NAT gateway randomly selects SNAT ports from its available inventory to make new outbound connections.

A SNAT port can be reused to connect to the same destination endpoint. However, before doing so, NAT gateway places a reuse cooldown timer on that port after the initial connection closes.

NAT gateway’s SNAT port reuse cooldown timer helps prevent ports from being selected too quickly for connecting to the same destination endpoint. This is advantageous when destination endpoints have their own source port reuse cooldown timers in place.

Figure 4: SNAT port 111 is released and placed in a cooldown period before it can connect to the same destination endpoint again. In the meantime, port 106 (dotted outline) is selected at random from the available inventory of ports to connect to the destination endpoint. The destination endpoint has a firewall with its own source port cooldown timer. There is no issue getting past the on-premise destination’s firewall since the connection from source port 106 is new.

What happens then when all SNAT ports are in use? When NAT gateway cannot find any available SNAT ports to make new outbound connections, it can reuse a SNAT port that is currently in use so long as that SNAT port connects to a different destination endpoint. This specific behavior is beneficial to any customer who is making outbound connections to multiple destination endpoints with NAT gateway.

Figure 5: When all SNAT ports are in use, NAT gateway can reuse a SNAT port to connect outbound so long as the port actively in use goes to a different destination endpoint. Ports in use by destination 1 are shown in blue. Port connecting to destination 2 is shown in yellow. Port 111 is yellow with a blue outline to show it is connected to destinations 1 and 2 simultaneously.

What have we learned about NAT gateway’s SNAT port behavior?

In this blog, we explored how NAT gateway allocates, selects, and reuses SNAT ports for connecting outbound. To summarize:

Function
NAT gateway SNAT port behavior
Benefit

SNAT port capacity
Up to 16 public IP addresses.
 
64,512 SNAT ports / NAT gateway public IP addresses.   
Easy to scale for large and variable workloads.

SNAT port allocation
Dynamic and On-demand.
Great for flexible, unknown, and large-scale workloads.

SNAT port selection
Randomized.
Reduces risk of connection failures to the same destination endpoint.

SNAT port reuse
Reuse to a different destination—connect outbound immediately.
 
Reuse to the same destination—set on a cooldown timer.
Reduces risk of connection failures to the same destination endpoint with source port reuse cooldown timers.

Deploy NAT gateway today

Whether your outbound scenario requires you to make many connections to the same or to several different destination endpoints, NAT gateway provides a highly scalable and reliable way to make these connections over the internet. See the NAT gateway SNAT behavior article to learn more.

NAT gateway is easy to use and can be deployed to your virtual network with just a few clicks of a button. Deploy NAT gateway today and follow along on how with: Create a NAT gateway using the Azure portal.
Quelle: Azure

Amazon S3 fügt einen neuen Richtlinienbedingungsschlüssel hinzu, um die serverseitige Verschlüsselung mit vom Kunden bereitgestellten Schlüsseln (SSE-C) erforderlich zu machen oder einzuschränken

Mit dem neuen Amazon-S3-Bedingungsschlüssel kannst du Richtlinien erstellen, mit denen du die Verwendung der serverseitigen Verschlüsselung mit vom Kunden bereitgestellten Schlüsseln (SSE-C) kontrollieren kannst. Mit Amazon-S3-Bedingungsschlüsseln kannst du Bedingungen für die Erteilung von Berechtigungen im optionalen Element „Condition“ eines Buckets oder einer IAM-Richtlinie angeben. Eine solche Bedingung ist die serverseitige Verschlüsselung (SSE) mit deiner bevorzugten Verschlüsselungsmethode.
Quelle: aws.amazon.com

AWS Trusted Advisor Priority ist jetzt allgemein für Kunden von AWS Enterprise Support verfügbar

AWS Trusted Advisor Priority ist jetzt allgemein für Kunden von AWS Enterprise Support verfügbar und hilft IT-Führungskräften, sich durch kuratierte Empfehlungen, die von ihren AWS-Kontoteams priorisiert werden, auf wichtige Cloud-Optimierungsmöglichkeiten zu konzentrieren. AWS Trusted Advisor bietet Empfehlungen, die Ihnen dabei helfen, die bewährten Methoden von AWS in Bezug auf Kostenoptimierung, Leistung, Sicherheit, Zuverlässigkeit und Servicekontingente zu befolgen.
Quelle: aws.amazon.com

AWS Graviton2-basierte Amazon-EC2-C6g-, C6gd- und M6gd-Instances sind jetzt in weiteren Regionen verfügbar

Amazon EC2 C6g- und C6gd-Instances sind ab heute in der AWS-Region Asien-Pazifik (Osaka) verfügbar Außerdem sind M6gd-Instances jetzt in der Region Europa (Stockholm) verfügbar. C6g- und C6gd-Instances sind ideal für anspruchsvolle Workloads wie High Performance Computing (HPC), Batch-Verarbeitung, Ad-Serving, Videocodierung, Gaming, wissenschaftliche Modellierung, verteilte Analytik und CPU-basierte Machine-Learning-Inferenz. M6gd-Instances sind ideal für allgemeine Anwendungen, z. B. Anwendungsserver, Microservices, mittelgroße Datenspeicher und Caching-Flotten. C6gd- und M6gd-Instances bieten bis zu 50 % mehr NVMe-Speicher GB/vCPU im Vergleich zu x86-basierten Instances und sind ideal für Anwendungen, die schnellen, lokalen Speicher mit niedriger Latenz benötigen.
Quelle: aws.amazon.com

Amazon SageMaker Canvas erweitert Fähigkeiten, um Daten für Machine Learning besser vorzubereiten und zu analysieren

Wir freuen uns, erweiterte Fähigkeiten für die Datenvorbereitung und -analyse in Amazon SageMaker Canvas ankündigen zu können, darunter das Ersetzen fehlender Werte, das Ersetzen von Ausreißern und die Flexibilität, verschiedene Stichprobenumfänge für Ihre Datensätze wählen zu können. Amazon SageMaker Canvas ist eine visuelle Point-and-Click-Oberfläche, mit der Geschäftsanalysten selbst genaue ML-Vorhersagen erstellen können – ohne Erfahrung mit Machine Learning (ML) zu haben oder eine einzige Zeile Code schreiben zu müssen. Mit SageMaker Canvas ist es einfach, auf Daten aus verschiedenen Quellen zuzugreifen und diese zu kombinieren, Daten automatisch zu bereinigen und ML-Modelle zu entwickeln, um mit wenigen Klicks präzise Vorhersagen zu treffen.
Quelle: aws.amazon.com