Top Google Cloud infrastructure blogs of 2021

You sometimes hear people say that cloud infrastructure is commoditized, not differentiated. At Google Cloud, we like to think it’s differentiated, just like the content our blog visitors like to read about. Year after year, blogs about compute, storage, and networking — as well as physical infrastructure like data centers and cables — are consistently among the most-read content of the year. Here are the top Google Cloud infrastructure stories of 2021, by readership. Read on to relive your favorites, or to catch up on any stories you may have missed.1. The Dunant subsea cable, connecting the US and mainland Europe, is ready for serviceNews about our subsea cables is a perennial reader favorite, and the Dunant ready-for-service announcement was no exception. Originally announced in 2018, the Dunant cable will transmit 250 Terabits of data per second between the U.S. and France. Details here.2. New Tau VMs deliver leading price-performance for scale-out workloadsWe welcomed a new addition to our Compute Engine family this year! Based on 3rd Gen AMD EPYC processors, the T2D (the first instance type in the Tau VM family), offers 56% higher absolute performance and 42% higher price-performance compared to general-purpose VMs from any of the leading public cloud vendors — all without having to reengineer your workloads for another microprocessor architecture. Read the blog here. 3. Colossus under the hood: a peek into Google’s scalable storage systemIt’s no secret that a lot of the technologies that underlie Google Cloud were originally designed to power Google as a whole, and the Colossus file system is just one example. In this post, Google storage leads take you on a behind-the-scenes look into the Colossus architecture and how it delivers its impressive scalability. More here. 4. Expanding our global footprint with new cloud regionsYear in, year out, the number of geographies where you can find a Google Cloud region continues to grow. A year ago, we announced new regions in Chile, Germany and Saudi Arabia. More recently, we announced we would open a second region in Germany, and new U.S. regions in Columbus, Ohio, and Dallas, Texas.5. Hola, South America! Announcing the Firmina subsea cableAlong with a new GCP region in Chile, we also announced that we’re building a subsea cable to South America that goes from the East coast of the United States all the way to Argentina. Firmina joins the Curie subsea cable, which takes a Pacific route from the U.S. to South America. Read about Firmina here.  6. Announcing Backup for GKE: the easiest way to protect GKE workloadsAnyone that runs mission-critical workloads in the cloud needs an easy way to back them up. Backup for GKE, a first-party backup solution that makes it easy to protect stateful data from applications running in GKE, was one of our most popular storage launches of 2021. Read all about it here. 7. Introducing Network Connectivity Center: A revolution in simplifying on-prem and cloud networkingMeanwhile, over in Google Cloud networking land, readers grooved on news of our new Network Connectivity Center, a network management solution that works across on-prem and cloud-based networks. Get the details. 8. What’s in a name? Understanding the Google Cloud network “edge”People throw around the word ‘edge’ all the time, but what exactly does it mean — especially in the context of Google Cloud? In this popular blog post, learn about the difference between Google Cloud regions and zones, edge POPs, Cloud CDN, Cloud Interconnect POPs, edge nodes, and region extensions. Read all about it. 9. How Cloud Storage delivers 11 nines of durability—and how you can helpBesides new product launches, the content that resonates most reliably with readers tends to be explainers. In this top storage piece, learn what we even mean by 11 nines, and the techniques Cloud Storage uses to achieve it. Check it out. 10. Google named a Leader in 2021 Gartner Magic Quadrant for Cloud Infrastructure and Platform Services againWith all this great technology, it’s fitting that Google Cloud was named a leader in the 2021 Gartner Magic Quadrant for Cloud Infrastructure and Platform Services. Again. Check out the blog and register to read the full report here. Hopefully this list gives you a taste of what the fuss over Google Cloud infrastructure is all about. Thanks for reading, and stay tuned for 2022!Related Article10 ways Google Cloud IaaS stands outAcross compute, networking and storage, Google Cloud has a multitude of features that make it the best choice.Read Article
Quelle: Google Cloud Platform

Policy Troubleshooter for BeyondCorp Enterprise is now GA!

Having the ability to access corporate resources and information remotely and securely has been crucial for countless organizations during the course of the COVID-19 pandemic. Yet, many employees may agree that this process is not always seamless, especially if they were blocked from getting to an app or a resource they should be able to access. Adding to this frustration is the challenge of getting in touch with IT support to figure out what was happening and why, which can be even more difficult in a remote environment.Our aim with BeyondCorp Enterprise, Google Cloud’s zero trust access solution, is to provide a frictionless experience for users and admins, and today, we are happy to announce that Policy Troubleshooter for BeyondCorp Enterprise is now generally available, providing support for administrators to triage blocked access events and easily unblock users. BeyondCorp Enterprise provides users with simple and secure access to applications across clouds and across devices. Administrators are able to configure and apply granular rules to manage access to sensitive corporate resources. While these policies define how trust is established and maintained as part of the zero trust model, sometimes the layering of rules can make it difficult for end-users to understand why access to an application or resource may fail.Administrators can enable this feature to generate a troubleshooting URL per Identity-Aware Proxy (IAP) resource in real-time for denied events. End-users who find themselves blocked will see a “Troubleshooter URL”  which can be copied and sent to the administrator via email, who can quickly use the information to diagnose the error and identify why access requests fail.Troubleshooting information presented to BeyondCorp Enterprise users when access is deniedPolicy Troubleshooter gives admins essential visibility of access events across their environment. Once arriving on the BeyondCorp Enterprise Troubleshooter analysis page, the administrator can see different views. The Summary View shows an aggregate view of all the relevant policy and membership findings.Administrators presented with a Summary View of the troubleshooting findingsIn addition, the Identity and Access Management (IAM) policy view shows a list of effective IAM bindings evaluation results, granted or not, together with a high-level view on where the failures occurred. Admins can also see a table displaying the user’s and device context.Administrators can also toggle to the IAM Policy View to see Binding DetailsAdministrators can investigate further in the Binding details to identify where the failures occurredWith this information, admins can give end-users more detailed information about why access failed, including things like group membership status, time or location constraints, or device rules such as attempting access from a disallowed device. Policy Troubleshooter also enables admins to update policies to allow access if warranted.Detailed troubleshooting of access levels and conditionsAdmins can also use Policy Troubleshooter to test hypothetical events and scenarios, gaining insight and visibility into the potential impact of new security policies. By proactively troubleshooting hypothetical requests, they can verify that users have the right permissions to access resources and prevent future access interruptions and interactions with IT support staff.Administrators can navigate to the Policy Troubleshooter for BeyondCorp Enterprise landing page to proactively troubleshoot hypothetical requestsPolicy Troubleshooter for BeyondCorp Enterprise is a valuable tool for organizations that need to apply multiple rules to multiple resources for different groups of users. Regardless of whether the workforce is remote, providing the ability for admins to triage access failure events and unblock users in a timely way is absolutely critical for an organization’s productivity. If you are interested in learning more, please reference our documentation to get started. This new feature will also be showcased during Google Cloud Security Talks on December 15. To see a demo, register for this free event and join us live or on-demand to learn about all of the work Google is doing to support customers’ implementations of zero trust!Related ArticleJoin us for Google Cloud Security Talks: Zero Trust editionJoin us for Google Cloud Security Talks with sessions focused on zero trust. Learn how you can protect your users and critical information.Read Article
Quelle: Google Cloud Platform

Use your favorite DevOps and security solutions with GKE Autopilot out of the box

Organizations that are modernizing with the cloud are increasingly looking for ways to simplify and automate container orchestration with high levels of security, reliability and scalability. GKE Autopilot, which became generally available earlier this year, is a revolutionary mode of operations for managed Kubernetes that makes this possible, reducing the need for hands-on cluster management while delivering a strong security posture and improved resource utilization. (Not familiar with GKE Autopilot yet? Check out the Autopilot breakout session at Google Cloud Next ‘21, which gives a rundown of everything this new Kubernetes platform can do.)One of the great advantages of GKE Autopilot is that despite being a fully managed Kubernetes platform that provides you with a hands-off approach to nodes, it still supports the ability to run node agents using DaemonSets. This allows you to do actions like collect node-level metrics without needing to run a sidecar in every Pod. While some administrative-level functionality like privileged pods is restricted in Autopilot for regular user pods, we have worked with our partners to bring some of the most popular solutions to Autopilot, granting additional privileges when needed. This lets you run these popular products on Autopilot without modification, and still take full advantage of our fully managed platform.Building on partnerships with leading ISVs in observability, security, CI/CD, and configuration management, this represents a differentiated approach to running partner tooling. Compared with other clouds and competitive platforms, GKE Autopilot does not require intensive reconfiguration (such as the use of sidecar containers) for many partner solutions. As such, today we are pleased to share the following partner solutions that are compatible with GKE Autopilot, and operate in a uniform manner across GKE:Aqua supports securing and ensuring compliance for the full lifecycle of workloads on GKE Autopilot, and specifically the Kubernetes pods, which run multiple containers with shared sets of storage and networking resources. More here.CircleCI allows teams to release code rapidly by automating the build test and delivery process. CircleCI’s ‘orbs’ bundle configuration elements such as jobs, commands and executors into reusable packages and support deployment to GKE Autopilot. More here.Codefresh’s Gitops controller is an agent installed in a cluster that monitors the cluster and any defined Git repositories for changes. It allows you to deploy any kind of application to your GKE Autopilot cluster using Gitops. More here.Chronosphere’s collector and GKE Autopilot work together to make engineers more productive by giving them faster and more actionable alerts that they can triage rapidly, allowing them to spend less time on monitoring instrumentation, meanwhile knowing that their clusters are running in a secure, highly available, and optimized manner. More here.Datadog provides comprehensive visibility into all your containerized apps running on GKE Autopilot by collecting metrics, logs and traces, which help to surface performance issues and provide context to troubleshoot them. More here.Dynatrace uses its software intelligence platform to track the availability, health and utilization of applications running on GKE Autopilot and to prioritize anomalies or automatically determine their root causes. More here.GitLab can be installed on GKE Autopilot easily out of the box using the official Helm Charts and can be configured to match a customer use case, including access to other Google Cloud resources such as storage and databases. More here.Hashicorp Terraform can be used to provision a GKE Autopilot cluster distributed across multiple zones for high availability with a unified workflow and full lifecycle management. Hahsicorp Vault runs on GKE Autopilot and provides secure storage and management of secrets. Read more about Terraform and Vault.Palo Alto Networks’ Prisma Cloud Daemonset Defenders enforce the policies you want for your environment, while Prisma Cloud Radar displays a comprehensive visualization of your GKE Autopilot nodes and clusters so you can identify risks and investigate incidents. More here.Snyk’s developer security platform helps developers build software securely across the cloud-native application stack, including code, open source, containers, Kubernetes and infrastructure as code, and works seamlessly with GKE Autopilot. More here.Splunk Observability Cloud provides developers and operators with deep visibility into the composition, state, and ongoing issues within a cluster, while GKE Autopilot automatically manages the cluster’s resources to maximum efficiency. More here.Sysdig’s Secure Devops Platform allows you to follow container security best practices on your GKE Autopilot clusters, including monitoring and securing your workloads using the Sysdig Agent. More here.If you are using any of the above partner solutions in your existing enterprise workflows, you should be able to use them seamlessly with GKE Autopilot. Over time, we will continue to expand the scope of our partnerships and supported solutions, and we hope you use GKE Autopilot to kickstart your modernization journey with containers in the cloud. Get started today with the free tier.Related ArticleIntroducing GKE Autopilot: a revolution in managed KubernetesGKE Autopilot gives you a fully managed, hardened Kubernetes cluster out of the box, for true hands-free operations.Read Article
Quelle: Google Cloud Platform

Amazon Redshift führt RA3.xlplus-Cluster mit nur einem Knoten ein

Amazon Redshift hat die Möglichkeit eingeführt, einen RA3.xlplus-Cluster mit nur einem Knoten zu betreiben. Amazon Redshift RA3-Cluster unterstützen viele wichtige Funktionen wie von Amazon Redshift verwalteten Speicher (Redshift Managed Storage, RMS), Datenfreigabe und AQUA. Mit RA3.xlplus-Clustern mit einem Knoten können Sie die Vorteile der fortschrittlichsten Redshift-Funktionen zu geringeren Kosten nutzen. Sie können DS2.xlarge- oder DC2.large-Cluster mit einem Knoten in RA3.xlplus-Cluster mit einem Knoten als Teil einer instanzübergreifenden Classic Resize-Funktion migrieren. Sie können auch die instanzübergreifende Classic Resize-Funktion als Teil der Reserved Instance (RI) Migration in der Amazon Redshift-Konsole, -CLI oder -API verwenden, um DS2.xlarge-RI-Cluster mit einem Knoten zu RA3.xlplus-RI-Clustern zu migrieren, ohne dass die Start- oder Enddaten des RI-Vertrags geändert werden und ohne dass zusätzliche Gebühren anfallen.
Quelle: aws.amazon.com

Der EBS-CSI-Treiber ist jetzt in den EKS-Add-ons als Vorversion verfügbar

Der Treiber des Container Storage Interface (CSI, Container-Speicherschnittstelle) von Amazon Elastic Block Store (EBS) ist nun bei den Amazon Elastic Kubernetes Service (Amazon EKS)-Add-ons als Vorversion verfügbar und ermöglicht es Ihnen die Amazon-EKS-Konsole, -CLI und -API zu verwenden, um das Add-on zu installieren und zu verwalten. Die Veröffentlichung ist eine Ergänzung zum vorhandenen Support für das Amazon-VPC-CNI-Netzwerk-Plug-In, -CoreDNS und -Kube-Proxy und erleichtert es konsistente Kubernetes-Cluster zu definieren und mit Amazon EKS aktuell zu halten.
Quelle: aws.amazon.com

AWS App2Container (A2C) unterstützt jetzt die Containerisierung von .NET-Core- / .NET-5-Anwendungen

AWS App2Container (A2C) unterstützt jetzt die Containerisierung und Bereitstellung von .NET-Anwendungen, die auf Linux laufen. Mit dieser Veröffentlichung können Kunden A2C verwenden, um die .NET-Core-Laufzeitversion (.NET Core 3.1, .NET 5, .NET 6) zu erkennen und die Anwendung mithilfe der entsprechenden Laufzeit-Base-Images zu containerisieren. Kunden können von den Kosten- und Leistungsnutzen, die von Linux-Containern geboten werden, profitieren. Kunden können mit A2C weiterhin diese containerisierten Anwendungen auf ihrer Wahl der Containerplattformen, Amazon Elastic Container Service (Amazon ECS), Amazon Elastic Kubernetes Service (Amazon EKS), AWS Fargate und AWS App Runner bereitstellen.
Quelle: aws.amazon.com