Enabling and securing ubiquitous compute from intelligent cloud to intelligent edge

Enterprises are embracing the cloud to run their mission-critical workloads. The number of connected devices on and off-premises, and the data they generate continue to increase requiring new enterprise network edge architectures. We call this the intelligent edge – compute closer to the data sources and users to reduce latency. The intelligent cloud, with its massive compute power, storage and variety of services works in concert with the intelligent edge using similar programming models to enable innovative scenarios and ubiquitous compute. Networking is the crucial enabler integrating the intelligent cloud with the intelligent edge.

The Azure Networking mission is to provide the most secure, reliable, and performant network for your workloads, delivered and managed from the intelligent cloud to the intelligent edge. We continue to innovate to help your services connect and extend to the cloud and the edge, be protected, delivered with optimal performance and provide insightful monitoring.

Microsoft global network

Microsoft runs one of the world’s largest Wide Area Network (WAN) that serves all Microsoft cloud services including Azure, Dynamics 365, Microsoft 365, LinkedIn, Xbox, and Bing. The WAN connects all Microsoft datacenters running our cloud services together and to our customers and partners through edge sites. These edge sites are strategically located around the world. This is where we exchange traffic with internet service providers for internet traffic and ExpressRoute partners for private connectivity traffic. We also use the Azure Front Door and Azure Content Delivery Network services at our edge sites to enhance and accelerate the experience of our own services, such as Microsoft 365. To provide global coverage the WAN has over 130,000 miles of subsea, terrestrial, and metro optical fiber and is fully managed by Microsoft using internal software defined networking (SDN) technologies to provide the best networking experience. Industry leaders such as Thousand Eyes have reported on the performance of our global network and in a 2018 study found it to be the most robust and most consistent. One fundamental principle in providing a great experience is to get the traffic onto the Microsoft network as close to the customer as possible and keep it on Microsoft’s network as long as possible. All traffic between Microsoft services and datacenters remains fully in Microsoft’s network and does not traverse the internet.

Figure 1. Core pillars of Azure Networking

Connect and extend

To get the best internet experience, data should enter and exit the Microsoft network as close as possible to you or your users. With over 160 edge sites today, we have an aggressive plan to increase the number of sites, which you can read more about in our edge site expansion blog. We are also increasing the number of ExpressRoute meet-me sites, providing greater flexibility to privately connect to your Azure workloads.

Staying connected to access and ingest data in today's highly distributed application environments is paramount for any enterprise. Many businesses need to operate in and across highly unpredictable and challenging conditions. For example, energy, farming, mining, and shipping often operate in remote, rural, or other isolated locations with poor network connectivity. ExpressRoute for Satellites is now generally available, enabling access to Microsoft cloud services using satellite connectivity. With commercial satellite constellations becoming widely available, new solution architectures offer improved and affordable performance to access Microsoft.

MACsec, an industry encryption standard for point to point connections, is now supported on ExpressRoute Direct as a preview ability. ExpressRoute Direct customers can ensure data confidentiality and integrity between physical connections to the ExpressRoute routers to meet security and compliance requirements. Customers fully own and manage the lifecycle of the MACsec keys using Azure Key Vault.

We have invested in optical technologies to greatly reduce the cost of metro networks. We are passing these savings to you with a new ExpressRoute circuit type called ExpressRoute Local, available via ExpressRoute partners. If you select an ExpressRoute site near our datacenters and only access data from that datacenter then egress prices are included in the ExpressRoute Local circuit price. For connectivity to regions in the same geo you can use ExpressRoute Standard, and to get anywhere in the world you can use ExpressRoute Premium.

The new peering service for the Microsoft cloud, now in preview, enables enterprise-grade internet connectivity to access Azure, Dynamics 365, and Microsoft 365, via partnerships with internet providers and internet exchange providers. Peering service also provides internet latency telemetry, route monitoring, and alerting against hijacks, leaks, and other border gateway protocol misconfigurations.

Figure 2. Launch partners supporting the new Peering Service

We have enhanced our VPN service to support up to 10 Gbps of aggregate encrypted bandwidth, IKE v1 on all our VPN gateway SKUs, and packet capture to help debug configuration issues. We have also enhanced our point-to-site VPN service to support Azure Active Directory and multifactor authentication. We also are making available an OpenVPN client that you can download and run to access your Vnet from anywhere.

Azure Virtual WAN brings together our Azure connectivity services into a single operational interface with major SD-WAN partners. Azure Virtual WAN enables a global transit network architecture by providing ubiquitous connectivity between globally distributed sets of spokes such as VNets, sites, applications, and users. Significant enhancements include the preview of hub-to-hub and any-to-any connectivity. Virtual WAN users can connect multiple hubs for full mesh connectivity to further simplify their network architecture. Additionally, ExpressRoute and point-to-site are now generally available with Virtual WAN.

Figure 3. Azure Virtual WAN full topology overview across customers sites and clients connecting to Azure

We have been working closely with industry leaders to expand the ecosystem support for Virtual WAN. Today, we are announcing that Cisco and Microsoft are partnering to modernize the network for the cloud. Cisco, one of our largest global and strategic partners, is working with Microsoft to integrate Cisco SD-WAN technology with both Azure Virtual WAN and Office 365 to enable seamless, distributed and optimal branch office connectivity to Azure and Office 365.

“At Cisco, we’re helping customers deliver security and application experience as they expand into the cloud. Collaborating with Microsoft to expand the value of Azure Virtual WAN with Cisco SD-WAN, we are creating new opportunities for our mutual customers to accelerate their hybrid cloud strategy.”

Sachin Gupta, SVP, Product Management for Cisco Enterprise Networking Business

Additionally, other partners including Cloudgenix, Fortinet, Nokia-Nuage, and Silver Peak, have finalized their integrations with Virtual WAN and are immediately available.

IPv6

Dual stack (IPv4 + IPv6) VNet will be generally available later this month. As a first in the cloud, Azure will enable customers to bring their own IPv6 private space into the VNet thereby avoiding any need for routing changes. IPv6 enables customers to address IPv4 depletion, meet regulatory requirements, and expand into the growing mobile and IoT markets with their Azure-based applications.

Figure 4. Architectural diagram of an Azure VNet routing with IPv6 between VMs, subnet and Load Balancer

Protect

Achieving Zero Trust networking

Cloud applications and the mobile workforce have redefined the security perimeter. The new perimeter isn’t defined by the physical location(s) of the organization, it now extends to every access point that hosts, stores, or accesses corporate resources and services.

Instead of believing everything behind the corporate firewall is safe, the Zero Trust model assumes breach and verifies each request as though it originates from an uncontrolled network. Regardless of where the request originates or what resource it accesses, Zero Trust teaches us to “never trust, always verify.”

Azure Networking services provide critical controls to enhance visibility and help prevent bad actors from moving laterally across the network. Networks should be segmented, including deeper software-defined micro-segmentation, and real-time threat protection, end-to-end encryption, monitoring, and analytics should be employed.

Azure Private Link – extended to all Azure regions

Azure Private Link brings Azure services into your private virtual network. Supported Azure services such as Storage, SQL Database, and Azure Synapse Analytics can be consumed over a private IP address thereby not opening the access control lists (ACLs) to public internet. The traffic going through Private Link will always be in the Microsoft backbone network and never entering the public internet. The platform as a service (PaaS) resources can also be accessed privately from on-premises through VPN or ExpressRoute private peering thereby keeping the ACLs simple. Starting today, Private Link will be available in all Azure public regions.

Figure 5. Architectural diagram of Private Link deployed cross-premises

Using Azure Private Link, Azure is the first cloud to provide data governance and compliance by implementing built-in data exfiltration protection. This brings us one step closer to our goal for zero trust networking wherein malicious actors within the trusted network can’t exfiltrate data to non-secure accounts, since individual PaaS instances instead of service frontends are mapped as private endpoints. Private Link also empowers software as a service (SaaS) providers in Azure to extend the same capability to their customers. Snowflake is an early adopter to the program, with more partner services to follow.

Azure Firewall Manager is a new security management service that provides central security policy and route management for cloud-based security perimeters. Azure is currently the only cloud provider to offer traffic governance, routing control, and third party integrated security through Azure Firewall and Firewall Manager. Global admins can centrally create hub and spoke architecture and associate security or routing policies with such a hub, referred to as a secured virtual hub.

Figure 6. Diagram of Azure Firewall Manager deployed inside Secured Virtual WAN Hubs

With trusted security partners, you can use your familiar, industry-leading, third-party security as a service (SECaaS) offerings to protect internet access for your users. We are very pleased to announce our partnership with ZScaler, iboss, and Checkpoint (coming soon) as the trusted security partners.

Azure Firewall threat intelligence-based filtering now general available

Using threat intelligence-based filtering, Azure firewall can now be configured to alert and deny traffic to and from known malicious IP addresses and domains in near real-time. The IP addresses and domains are sourced from the Microsoft threat intelligence feed.

We also extended our web application firewall (WAF) with three new features, WAF bot protection, WAF per-site policies, and geo filtering. Azure managed bot protection rule set in Azure Front Door detects different categories of bots and allows customers to set actions accordingly. Customers can block malicious bots at the network edge, allowing good bots to reach application backends, and log or redirect unknown bots to an alternative site. Azure managed bot protection rule set is also offered as a preview on Azure Application Gateway v2 SKU. WAF per site policy with Application Gateway enables customers to specify WAF policies for different web applications hosted on a single Application Gateway. This allows for finer grained security policy and eliminates the need to create additional deployments per site. Azure Application Gateway is introducing geo filters with existing custom rules in preview on v2 SKU. This capability allows you to extend existing IP/IP range based custom rules to also include countries as a matching criterion and take actions accordingly. This allows you to restrict traffic from a given country or only allow traffic from a set of countries.

We recently announced the general availability of Azure Bastion. The Azure Bastion service is provisioned directly in your Virtual Network, enabling seamless remote desktop (RDP) and secure shell (SSH) access to all virtual machines in the VNet without needing a public IP address. Seamless integration and easy one-time setup of ACLs across your subnets eliminates subsequent and continuous management.

Figure 7. Azure Bastion architecture showing SSL access to VNet resources through the Azure portal

Deliver

Today we are also announcing a new feature, the Content Delivery Network Rules Engine, which allows the Azure Content Delivery Network to enable customers to customize how http requests are handled. Rules Engine enables very powerful match conditions like device detection, HTTP protocol, and header values and trigger appropriate actions. All the http rules run at our edge sites near end users which gives significant performance benefits compared to running rules at customer origins.

The Application Gateway Ingress Controller allows Azure Application Gateway to be used as the ingress for an Azure Kubernetes Service (AKS.) The ingress controller runs as a pod within the AKS cluster. It consumes Kubernetes Ingress Resources and converts them to an Azure Application Gateway configuration which allows the gateway to load-balance traffic to Kubernetes pods. Using Application Gateway Ingress Controller enables customers to expose a single internet accessible endpoint to communicate with their AKS clusters. Application Gateway directly interacts with pods using private addresses which eliminates the necessity of additional DNAT incurred by Kube-proxy, thus providing more efficient and performant traffic routing to pods. Application Gateway Ingress Controller provides support for all features of Application Gateway including WAF capabilities to secure access to the AKS cluster.

Figure 8. App Gateway Ingress controller explained relative to AKS

Azure Key Vault is a platform managed service to safeguard cryptographic keys and other secrets used by cloud apps and services. Azure Application Gateway v2 now supports direct integration of Key Vault stored TLS certificates for its HTTPS-enabled listeners. This enables better TLS certificate security by having a clear separation of certificate management process from Application Gateway and backend web application management. Application Gateway polls the Key Vault every few hours for newer version of transport layer security (TLS) certificate, thus enabling automatic renewal of certificates.

Monitor

Azure Internet Analyzer is a new client-side measurement service now available in preview. Internet Analyzer enables A/B testing of networking infrastructures and their impact on your customers’ performance experience. Whether you’re migrating apps and content from on-premises to Azure or evaluating a new Azure service, Internet Analyzer allows you to learn from your users’ data and Microsoft’s rich analytics to better understand and optimize your network architecture with Azure before you migrate. Internet Analyzer is designed to address performance-related questions for cloud migration, deploying to new or additional Azure regions, or testing new application and content delivery platforms in Azure, such as Azure Front Door and Content Delivery Network.

Azure Monitor for Network service is now available in preview. Azure Monitor for Network enables customers to monitor key metrics and health of their network resources, discover issues and get troubleshooting help. Azure Monitor for Network is on by default and doesn’t require any custom setup. Whether it’s about monitoring and troubleshooting the cloud or hybrid networks, Azure Monitor for Network helps you to setup alerts, get resource-specific diagnostics, and visualize the structure and functional dependencies between resources.

Figure 9. Screenshot of Azure Monitor for Network illustrating App Gateway metrics and diagnostics

Multi-access Edge Computing (MEC) in preview

Multi-access Edge Computing offers application developers cloud-computing capabilities at the customer premises. This environment is characterized by very low latency and high bandwidth as well as real-time access to radio networks such as Private LTE and 5G. By integrating MEC capabilities with Azure, we will be offering a continuum of compute and network capabilities from the intelligent cloud to the edge. New critical and immersive scenarios such as smart factory and mixed reality require reliable low-latency and high bandwidth connectivity combined with local compute.

Figure 10. Concept draft of Multi-access and network edge compute with Azure

To address these needs, we are introducing a technology preview of Multi-access Edge Compute based on Azure Stack Edge deployed at the customer’s premises for the best possible latency. Key characteristics of the MEC are:

Enables developers to use GitHub and Azure dev ops CI/CD toolset to write and run container-based applications at the customer’s premises. With a consistent programming-model it is straightforward to develop applications in Azure and then move them to Azure Stack Edge.
Wireless technology integration, including Private Long-Term Evolution (LTE), LTE-based Citizens Broadband Radio Service (CBRS), and forthcoming 5G technologies. As part of our MEC platform, we have partnered with technology innovators to provide mobile virtual network functions (Evolved Packet Core), device integration, SIM management, and radio access networks.
MEC is managed from Azure. Curated virtual network function (VNF) images are downloaded from Azure to simplify deploying and running a private mobile network. The platform also provides support for lifecycle management of the VNFs, such as patching, configuration, and monitoring.
A partner ecosystem including managed service providers to deploy end to end solutions in your network.

For those interested in the early technical preview and options with MEC integration, please reach out to MEC-Networking@microsoft.com.

Figure 11. Overview of Azure Multi-edge Compute (MEC) partner ecosystem

Looking Forward

We are fully committed to helping you connect to Azure, by protecting your workloads, delivering a great networking experience, and providing extensive monitoring to simplify your deployment and operational costs while helping you better support your customers. At Microsoft Ignite we will add more details about our announcements, and you can learn more by viewing our technical sessions. We’ll continue providing innovative networking services and guidance to help you take full advantage of the cloud. We’re excited to learn about your new scenarios enabled by our networking services. As always, we welcome your feedback.

Azure. Invent with purpose.
Quelle: Azure

Azure infrastructure as a service (IaaS) for every workload

This week at Microsoft Ignite, we announced several important additions to our Azure infrastructure as a service (IaaS) portfolio.

Many companies, including GEICO, H&R Block, and CONA Services, rely on Azure to run a very diverse set of business-critical workloads, often requiring dynamic and scalable infrastructure that delivers unparalleled performance.

In order to meet the needs of this diverse and growing set of mission-critical workloads that call Azure home, our infrastructure services continue to evolve to optimize the experience of running these workloads.

Comprehensive infrastructure solutions: Flexibility and choice

We announced several new offerings that expand our portfolio of available virtual machine (VM) instance sizes for general purpose, memory-intensive, and remote visualization scenarios, including the ability to run VMware environments natively and enhancements to the platform that make it even easier to migrate your workloads to Azure.

Ea v4, Eas v4, Da v4, and Das v4 series Microsoft Azure Virtual Machines now available

After being the first global cloud provider to announce the preview of Azure Virtual Machines based on the AMD EPYC™ 7452 processor, we’ve been working together with our technology partners, including AMD, to continue bringing the latest innovation to enterprises. 

This week we’re announcing the availability of the Da v4 and Das v4 Azure Virtual Machine series for general purpose Linux and Windows applications, and the Ea v4 and Eas v4 Azure Virtual Machine series for memory-intensive Linux and Windows workloads.

These new Azure Virtual Machines feature the latest AMD EPYC™ 7452 processor and up to 96 vCPUs, 672 GiBs of RAM, and 2,400 GiBs of SSD-based temporary storage. The Das-series and the Eas-series Virtual Machines support Azure Premium SSDs and will include Ultra Disk support in the near future.

New NVv4 series Azure Virtual Machines preview available

We are also enhancing our compute portfolio for Windows Virtual Desktops and high-performance computing (HPC) workloads with the preview of NVv4. These new Azure Virtual Machines feature the latest AMD EPYC™ 7742 processor and will be the first visualization-optimized Azure Virtual Machine to offer AMD RADEON INSTINCT™ MI25 GPUs. NVv4 (currently in preview) offers enhanced GPU resourcing flexibility, giving customers more choice by offering partitioned GPUs built using industry-standard SR-IOV technology. Customers can select the right size of GPU Virtual Machines with as little as 2GB of dedicated GPU frame buffer for an entry-level desktop in the cloud, and up to the whole GPU with 16GB of frame buffer to provide powerful engineering workstations. This makes entry-level and low-intensity GPU workloads more cost-effective while still giving customers the option to scale up to full-GPU processing power delivered by AMD RADEON INSTINCT™ MI25 GPUs.

Azure VMware Solutions now available in West Europe

We’re also announcing the availability of Azure VMware Solutions in the West Europe Azure region. If you are currently managing an on-premises VMware environment, Azure VMware Solutions delivers the ability to run your VMware environment natively on Azure. This gives you the option to leverage your existing VMware skills and investments while taking full advantage of the scale and automation Azure offers. Azure VMware Solutions is now supported in East US, West US, and West Europe regions.

New Azure Migrate features to streamline migration

Azure Migrate is a central hub for all your migration needs and now delivers new capabilities to accelerate the migration of physical servers and virtual machines. We have also made enhancements to the Server Assessment capabilities that reduce friction through agentless discovery options. And to ensure you have the information you need for migration; we now provide deeper application dependency analysis. Refer to the documentation for more details.

A dynamic and scalable infrastructure for uncompromised performance

One of the most valuable promises of cloud infrastructure is the ability to meet evolving business and IT requirements. In our mission to continuously improve customers’ access to dynamic and scalable infrastructure, we’ve made a couple of important additions to our portfolio.

Azure generation 2 virtual machines now generally available

Generation 2 virtual machines are now generally available on Azure. Generation 2 VMs provide support for Intel Software Guard Extensions (Intel SGX), UEFI boot architecture, and the ability to provision large VMs (up to 12TB) and OS Disks sizes that exceed 2TB.  

Generation 2 VMs are fully supported in the portal, CLI, and PowerShell interfaces, and customers can opt to use them during the provisioning and deployment process, depending on their needs. Please refer to the Windows and Linux documentation for more information.

New Azure Virtual Machine Scale Sets features now in preview

We’re also introducing the preview of new features for Azure Virtual Machine Scale Sets that will greatly simplify the experience of running virtual machines at scale, as well as improve the runtime capabilities and performance of these workloads. 

In addition to supporting a homogeneous set of VMs for a scalable app layer, you can now create an empty virtual machine scale set and add various VMs (even those belonging to different VM series) later during the VM creation process. This will allow you to achieve high availability, for example, by deploying a set of virtual machines to a single availability zone or across different fault domains in an availability zone. You can now use a Virtual Machine Scale Set to deploy a SQL high availability (HA) cluster with high availability in a zone. This will provide the high availability of SQL primary, secondary, and witness VMs in unique fault domains while maintaining the lower inter-VM network latency that is seen within an availability zone.

You can now also provision VMs with custom images using the Azure Shared Image Gallery, which provides a quick, easy and scalable way to share images across different VMs and also accelerates provisioning times.

You can also specify a scale-in policy that gives you control over the order in which VMs should be de-provisioned. Termination notifications now give customers up to 15 minutes to perform any clean-up or other pre-shutdown tasks before VMs are deprovisioned, and you can now use instance protection from scale-in to designate VMs that should not be deprovisioned during a scale-in action. 

All these new features will help you get your applications up and running quickly while giving you additional control over how your applications can scale to meet your requirements. 

HBv2 Azure Virtual Machines for HPC workloads coming soon

HBv2 VMs are designed to deliver supercomputer-class performance, message passing interface (MPI) scalability, and cost efficiency for a variety of real-world HPC workloads. HBv2 Virtual Machines support up to 80,000 cores for single MPI jobs to deliver performance that rivals some of the world’s largest and most powerful bare metal supercomputers.

Updated NDv2 Azure Virtual Machines preview

The NDv2-series Virtual Machines, currently in preview, are the latest, fastest, and most powerful addition to the GPU family, specifically designed for the cutting edge demands of distributed HPC, AI, and machine learning workloads. These VMs feature 8 NVIDIA Tesla V100 NVLINK interconnected GPUs with 32 GB of memory each, 40 non-hyperthreaded Intel Xeon Platinum 8168 processor cores, and 672 GiB of system memory. The NDv2-series Virtual Machines (currently in preview) also feature 100 Gb/sec EDR InfiniBand with support for standard Mellanox OFED drivers and all MPI types and versions. With total of 256 GB of GPU memory and 100 Gb/sec InfiniBand interconnect NDv2-series Virtual Machines are ready for the most demanding machine learning models and distributed AI training workloads utilizing CUDA, TensorFlow, Pytorch, Caffe, and other frameworks.

Proximity placement groups now generally available

A proximity placement group is a logical grouping capability for Azure Virtual Machines that you can use to decrease the network latency between a set of virtual machines. When you assign your virtual machines to a proximity placement group, their placement is optimized to deliver lower latency for your latency-sensitive workloads. We’ve seen robust customer adoption of this new feature during the preview over the last few months, and we’re pleased to now make Proximity Placement Groups generally available in most Azure regions. Please check the documentation for more information.

Azure Spot Virtual Machines

Finally, Azure Spot Virtual Machines, which give you access to unused Azure compute capacity at deep discounts, will be available soon. Spot Virtual Machines will be ideal for workloads that can be interrupted, providing scalability while reducing costs. You will be able to take advantage of Spot Virtual Machine pricing for Azure Virtual Machines or Virtual Machine Scale Sets (VMSS) to deploy opportunistic workloads of all sizes. We expect to preview this by early 2020.

In conclusion, there has never been a better time to run your workloads on, or to migrate to, Azure. We hope you enjoy Microsoft Ignite!

Additional Resources

Da series Azure Virtual Machines Linux and Windows documentation

Ea series Azure Virtual Machines Linux and Windows documentation

Azure Virtual Machine Scale Sets documentation

Azure generation 2 Virtual Machines documentation (Windows and Linux)

Azure webinar series: The Total Economic Impact™ of Azure IaaS

Azure webinar series: Five Critical Areas When Migrating Your Workloads to the Cloud

Computing options for every workload on Microsoft Azure – Video

Azure Virtual Machines webpages

Azure VMware Solutions webpages
Azure Migrate webpages

Azure. Invent with purpose.

Quelle: Azure

New Azure investments deliver unprecedented performance for all your business-critical applications

Technology is being infused into every dimension of our lives, from stadiums to operating theaters to refrigerators to cars, technology is at the center of everything we do. It’s no longer just the unicorns that are digital disruptors. Every business is looking to benefit from technology and increase customer connection, satisfaction, and profitability. Organizations like BP, Lufthansa, and Team Rubicon are optimizing and transforming their businesses with Azure Infrastructure, building new applications to connect customer-service, logistics, and service delivery in novel ways that increase employee productivity and better serve their customers.

This week from Microsoft Ignite, we're highlighting key Azure Infrastructure enhancements that further power our customers’ digital transformation journey.

Increased performance and lower cost for any workload

Azure has the broadest portfolio of compute offerings, ranging from small to the industry’s largest virtual machines (VMs) to purpose-built hardware that is able to support native VMware workloads, enterprise-grade files powered by NetApp, and up to 120 TB SAP scale-out deployments. CONA Services, the service arm for Coca-Cola bottlers, runs a 40 TB mission-critical system on Azure’s purpose-built SAP HANA infrastructure, one of the largest SAP HANA cloud deployments. To complement our compute portfolio, we offer one of the highest performance disks, including one of the fastest disks in the cloud today with Azure ultra disks, delivering up to 160,000 IOPS.

Customers are addressing new, high-performance scenarios that were earlier cost-prohibitive or simply not possible. With our new Azure HB and HC Virtual Machines, Azure is democratizing high-performance computing with unprecedented performance, scalability, and cost-efficiency for large tightly-coupled workloads in the cloud. InfiniBand networking provides the lowest latency and highest bandwidth in the industry and helps power customer workloads up to 23,000 cores for a single MPI-based application, this is 10x higher than what is found anywhere else in the cloud. With HBv2, the first Azure Virtual Machine featuring 200 gigabit InfiniBand, Azure supports workloads up to 80,000 cores per job. 

We are also seeing customers move more Windows Server and Linux workloads to Azure. More than 50 percent of Azure’s compute runs Linux workloads today. When it comes to Windows Server and SQL, 30 percent more enterprises choose Azure over the next major cloud vendor. We offer unparalleled innovation with Azure SQL Managed Instance, App Service and Windows Virtual Desktop along with unmatched security and seamless hybrid capabilities, making Azure the best cloud for Windows and SQL Server workloads. When it comes to performance, Azure SQL Database is the price-performance leader for business-critical workloads while costing up to 86 percent less compared to AWS RDS.

At Microsoft Ignite, we are expanding our compute, storage, and networking offerings to meet an even wider range of customer scenarios. Some highlights include:

 General availability of Ea v4 and Eas v4 Azure Virtual Machine-series for memory-intensive workloads and the Da v4 and Das v4 Azure Virtual Machine-series for general purpose applications. These new Azure Virtual Machines are the first in the cloud to feature the latest AMD EPYC™ 7452 processor.
 Preview of NVv4 and HBv2 VM-series to support virtual desktop and HPC workloads. These new Azure Virtual Machines feature the latest AMD EPYC™ 7742 processor. NVv4 is designed to be the most cost-effective way to do visualization workloads, supporting VMs with fractional GPUs – as little as 1/8th GPU. NVv4 is Azure’s first visualization-optimized VM to offer AMD RADEON INSTINCT™ GPUs, while HBv2 is Azure’s first HPC VM to offer 200 gigabit InfiniBand networking.
 Preview of NDv2 VM-series to support the most demanding machine learning models and distributed AI training workloads. These updated VMs feature eight NVIDIA Tesla V100 NVLINK interconnected GPUs with 32 GB of memory each.
 Preview of new, smaller 4, 8 and 16 GB sizes on Premium SSD, Standard SSD and ultra disks to provide a lower cost for customers migrating workloads with less predictable traffic patterns to the cloud.
 Preview of the new bursting capabilities on applicable Premium SSD with up to 30x performance for spiky workloads.
 Preview of ADLS multi-protocol access which provides core blob features with Azure Data Lake Storage (ADLS) Gen2 including logging, tiering, and event grid integration, enhancing enterprise integration.
 Preview of Azure Peering Service which targets customers with an internet-first network strategy for accessing Azure and SaaS services such as Office 365. Through partnering with internet service providers, customers can now take advantage of our global network to enable reliable and optimized internet connectivity to Microsoft services.
 General availability of satellite support for Azure ExpressRoute to extend services into hard-to-reach areas critical for many customers across industries.
 General availability of Azure Bastion, making Azure the first public cloud to bring this functionality integrated as-a-service into the platform, with fast and super simple deployment of a bastion host to your infrastructure in Azure.

Unmatched security and simplified scalability for any workload

With 54 regions worldwide, we offer more regions than any other cloud provider across six continents. We are continuously investing in Azure to ensure it meets the highest reliability and scalability standards so you can be confident when running your business-critical workloads. When it comes to cloud security, we invest over a billion dollars a year and employ over 3,500 employees focused on security. Just a few weeks ago, we announced the general availability of Azure Sentinel, a built-in cloud-native SIEM that protects your entire enterprise.

This week, we are highlighting some of the enhancements we are making on Azure scalability, reliability, and security:

 General availability of Generation 2 Azure Virtual Machines, improving security with the support for Intel Software Guard Extensions (Intel SGX), and the ability to provide large VMs (up to 12TB) and OS Disks sizes that exceed 2TB.
 Preview of new features for virtual machine scale sets, for Windows and Linux, that will help you more easily manage VMs while improving runtime and performance capabilities. For example, you can now provision custom VM images at scale using the shared image gallery, while accelerating provisioning times.
 Preview of object replication service to support geo-distributed applications with customer-controlled blob replication to different regions.
 Enhanced Azure Security Center capabilities including even richer vulnerability assessment for VMs powered by Qualys, support for Kubernetes containers, and integration of security recommendations from partners including Check Point, Tenable and CyberArk available soon.
 Azure Sentinel enhancements including connectors for Citrix and ZScaler, investigation tools for suspicious URLs, and enriched detections.
 Azure Managed Disks enhanced to provide customers with full control over their compliance needs by enabling server-side encryption with customer-managed keys. This will enable customers to leverage Azure Key Vault and track key usage. This new capability is available in preview for Premium Solid-state drives (SSD), Standard SSD, and Standard hard disk drives (HDD) disk types

Unified hybrid management across all your environments

We are seeing customer IT environments evolve as more workloads move to the cloud and with the rise of edge computing. IT environments are becoming increasingly complex with different types of applications, hardware, multi-cloud, and edge environments, essentially creating an IT resource sprawl. Customers tell us that they are looking for a unified approach to organize, govern, and secure their IT resources wherever they are from a central place, at scale.

At Microsoft Ignite, we are announcing hybrid capabilities to enable cloud innovation anywhere with consistent management across on-premises and multi-could environments. Some of these highlights include:

 Preview of Azure Arc, a set of technologies that extend Azure management and enable Azure data services across on-premises, multi-cloud, and edge. Customers now have a central, unified approach to manage and govern Windows and Linux servers, Kubernetes clusters, and Azure data services wherever they are. Azure Arc also extends the adoption of cloud practices like DevOps, Azure Governance, and Azure security across on-premises, multi-cloud, and edge.
 General availability of Windows Admin Center version 1910 that delivers powerful hybrid capabilities to manage Windows Servers wherever they run. It streamlines integration of on-premises servers to Azure for disaster recovery, backup, patching, and monitoring, and now includes integration with Azure Security Center. Windows Admin Center also enables customers to use Azure Arc to take advantage of unified hybrid management from Azure.
 We are also expanding the Azure Stack portfolio to include Azure Stack Edge. Azure Stack Edge is an Azure managed appliance that brings the compute, storage, and intelligence of Azure at any edge locations. You can manage Azure Stack Edge right from the Azure Portal.

All of these new capabilities can be combined with Azure’s latest developments in application modernization, including our new serverless, container, and functions capabilities.

These are just some of the highlights we’re delivering at Microsoft Ignite this week. We look forward to seeing how our customers integrate these capabilities into their digital transformation journey.

Azure. Invent with purpose.
Quelle: Azure

OpenShift 4.2 vSphere Install Quickstart

OpenShift 4.2 vSphere Install Quickstart
In this blog we will go over how to get you up and running with an OpenShift 4.2 install on VMware vSphere. There are many methods to work with vSphere that allows automating in creating the necessary resources for installation. These include using Terraform and Ansible to help expedite the creation of resources. In this blog, we will focus on getting familiar with the process; so I will be going over how to do the process manually.
Environment Overview
For this installation I am using vSphere version 6.7.0 and ESXi version 6.7.0 Update 3. I will be following the official documentation for installing OpenShift 4 on vSphere. There, you can read more information about prerequisites including the need to set up DNS, DHCP, Load Balancer, Artifacts, and other ancillary services/items. I will be going over the prerequisites for my environment.
Prerequisites
It’s important that you get familiar with the prerequisites by reading the official documentation for OpenShift. I will go over the prerequisites at a high level, and link examples. It’s important to note that, although this is user provisioned infrastructure, the OpenShift 4 installer is specific about how things are named; and what it expects to be there.
vSphere Credentials
I will be using my administrative credentials for vSphere. I will also be passing these credentials to the OpenShift 4 installer and, by extension, to the OpenShift cluster. It’s not a requirement to do so, and you can install without passing the credentials. This will effectively turn your installation into a “Bare Metal” type of installation and you’ll lose the ability to dynamically create VDMKs for your applications at install time. You can set this up post-installation (we will go over that later).
DNS
The first consideration you need to take into account when setting up DNS for OpenShift 4 is the “cluster id”. The “cluster id” uniquely identifies each OpenShift 4 cluster in your domain, and this ID also becomes part of your cluster’s FQDN. The combination of your “cluster id” and your “domain” creates what I like to call a “cluster domain”. For example; with a cluster id of openshift4 and my domain of example.com, the cluster domain (i.e. the FQDN) for my cluster is openshift4.example.com.
DNS entries are created using the $CLUSTERID.$DOMAIN cluster domain FQDN nomenclature. All DNS lookups will be based on this cluster domain. Using my example cluster domain, openshift4.example.com, I have the following DNS entries set up in my environment. Note that the etcd servers are pointed to the IP of the masters, and they are in the form of etcd-$INDEX
[chernand@laptop ~]$ dig master1.openshift4.example.com +short
192.168.1.111
[chernand@laptop ~]$ dig master2.openshift4.example.com +short
192.168.1.112
[chernand@laptop ~]$ dig master3.openshift4.example.com +short
192.168.1.113
[chernand@laptop ~]$ dig worker1.openshift4.example.com +short
192.168.1.114
[chernand@laptop ~]$ dig worker2.openshift4.example.com +short
192.168.1.115
[chernand@laptop ~]$ dig bootstrap.openshift4.example.com +short
192.168.1.116
[chernand@laptop ~]$ dig etcd-0.openshift4.example.com +short
192.168.1.111
[chernand@laptop ~]$ dig etcd-1.openshift4.example.com +short
192.168.1.112
[chernand@laptop ~]$ dig etcd-2.openshift4.example.com +short
192.168.1.113

Also, it’s important to set up reverse DNS for these entries as well (since you’re using DHCP, this is particularly important).
[chernand@laptop ~]$ dig -x 192.168.1.111 +short
master1.openshift4.example.com.
[chernand@laptop ~]$ dig -x 192.168.1.112 +short
master2.openshift4.example.com.
[chernand@laptop ~]$ dig -x 192.168.1.113 +short
master3.openshift4.example.com.
[chernand@laptop ~]$ dig -x 192.168.1.114 +short
worker1.openshift4.example.com.
[chernand@laptop ~]$ dig -x 192.168.1.115 +short
worker2.openshift4.example.com.
[chernand@laptop ~]$ dig -x 192.168.1.116 +short
bootstrap.openshift4.example.com.

The DNS lookup for the API endpoints also needs to be in place. OpenShift 4 expects api.$CLUSTERDOMAIN and api-int.$CLUSTERDOMAIN to be configured, they can both be set to the same IP address – which will be the IP of the Load Balancer.
[chernand@laptop ~]$ dig api.openshift4.example.com +short
192.168.1.110
[chernand@laptop ~]$ dig api-int.openshift4.example.com +short
192.168.1.110

A wildcard DNS entry needs to be in place for the OpenShift 4 ingress router, which is also a load balanced endpoint.
[chernand@laptop ~]$ dig *.apps.openshift4.example.com +short
192.168.1.110

In addition to the mentioned entries, you’ll also need to add SRV records. These records are needed for the masters to find the etcd servers. This needs to be in the form of _etcd-server-ssl._tcp.$CLUSTERDOMMAIN in your DNS server.
[chernand@laptop ~]$ dig _etcd-server-ssl._tcp.openshift4.example.com SRV +short
0 10 2380 etcd-0.openshift4.example.com.
0 10 2380 etcd-1.openshift4.example.com.
0 10 2380 etcd-2.openshift4.example.com.

Please review the official documentation to read more about the prerequisites for DNS before installing.
DHCP
The certificates OpenShift configures during installation is for communication between all the components of OpenShift, and is tied to the IP address and dns name of the Red Hat Enterprise Linux CoreOS (RHCOS) nodes.
Therefore it’s important to have DHCP with address reservation in place. You can do this with MAC Address filtering for the IP reservation. When creating your VMs, you’ll need to take note of the MAC address assigned in order to configure your DHCP server for IP reservation.
Load Balancer
You will need a load balancer to frontend the APIs, both internal and external, and the OpenShift router. Although Red Hat has no official recommendation to which load balancer to use, one that supports SNI is necessary (most load balancers do this today).
You will need to configure port 6443 and 22623 to point to the bootstrap and master nodes. The below example is using HAProxy (NOTE that it must be TCP sockets to allow SSL passthrough):
frontend openshift-api-server
bind *:6443
default_backend openshift-api-server
mode tcp
option tcplog

backend openshift-api-server
balance source
mode tcp
server btstrap 192.168.1.116:6443 check
server master1 192.168.1.111:6443 check
server master2 192.168.1.112:6443 check
server master3 192.168.1.113:6443 check

frontend machine-config-server
bind *:22623
default_backend machine-config-server
mode tcp
option tcplog

backend machine-config-server
balance source
mode tcp
server btstrap 192.168.1.116:22623 check
server master1 192.168.1.111:22623 check
server master2 192.168.1.112:22623 check
server master3 192.168.1.113:22623 check

You will also need to configure 80 and 443 to point to the worker nodes. The HAProxy configuration is below (keeping in mind that we’re using TCP sockets):
frontend ingress-http
bind *:80
default_backend ingress-http
mode tcp
option tcplog

backend ingress-http
balance source
mode tcp
server worker1 192.168.1.114:80 check
server worker2 192.168.1.115:80 check

frontend ingress-https
bind *:443
default_backend ingress-https
mode tcp
option tcplog

backend ingress-https
balance source
mode tcp
server worker1 192.168.1.114:443 check
server worker2 192.168.1.115:443 check

More information about load balancer configuration (and general networking guidelines) can be found in the official documentation.
Web server
A web server is needed in order to hold the ignition configurations to install RHCOS. Any webserver will work as long as the webserver can be reached by the bootstrap, master, and worker nodes during installation. I will be using Apache. I created a directory specifically for the ignition files:
[root@webserver ~]# mkdir -p /var/www/html/ignition/

Artifacts
You will need to obtain the installation artifacts by visiting try.openshift.com, there you can login and click on “VMware vSphere” to get the installation artifacts. You will need:

OpenShift4 Client Tools
OpenShift4 OVA
Pull Secret

You will need to put the client and the installer in your $PATH, in my example; I put mine in my /usr/local/bin path.
[chernand@laptop ~]$ which oc
/usr/local/bin/oc
[chernand@laptop ~]$ which kubectl
/usr/local/bin/kubectl
[chernand@laptop ~]$ which openshift-install
/usr/local/bin/openshift-install

I’ve also downloaded my pullsecret as pull-secret.json and saved it under a ~/.openshift directory I created.
[chernand@laptop ~]$ file ~/.openshift/pull-secret.json
/home/chernand/.openshift/pull-secret.json: JSON data

A ssh-key is needed. This is used in order to login to the RHCOS server if you ever need to debug the system.
[chernand@laptop ~]$ file ~/.ssh/id_rsa.pub
/home/chernand/.ssh/id_rsa.pub: OpenSSH RSA public key

For more information about ssh and RHCOS, visit the official documentation site.
Installation
Once you have the prerequisites in place, you’re ready to begin the installation. The current installation of OpenShift 4 on vSphere must be done in stages. I will go over each stage step by step.
vSphere Preparations
In your vSphere web UI, after you login, navigate to “VMs and Templates” (it’s the icon that looks like a piece of paper). From here right click on your datacenter and select New Folder → New VM and Template Folder. Name this new folder the name of your cluster id. In my case, I named mine openshift4. You should have a new folder that looks like this.

Next, import the OVA by right clicking the folder and select “Deploy OVF Template”. Make sure you select the folder for this cluster as the destination, then click next.

Go ahead and select an ESXi host for the destination compute resource, after that is done it will display the OVA information.

After this is displayed go ahead and click “Next”. This will display the storage destination dialog. Choose the appropriate destination datastore, and set the virtual disk format to “Thin” if you wish.

The next screen asks to select a destination virtual network, I am using the default “VM Network”, so I accept the defaults.

After clicking “Next”, the “Customize Template” section comes up. We won’t be customizing the template here, so leave these blank and click “Next”.

The next page will give you an overview with the title “Ready To Complete”, click “Next” to finish the importing of the OVA.

The OVA template should be in your cluster folder. It should look something like this:

Next, right click the imported OVA and select “Edit Settings”. The “Edit Settings” dialog box appears and should look like this:

Click on the “VM Options” and expand the “Advanced” section. Set “Latency Sensitivity” to “High”.

Next, click on “Edit Configuration…” next to the “Configuration Parameters” section. You will add the following:

guestinfo.ignition.config.data and set the value to chageme
guestinfo.ignition.config.data.encoding set this value to base64
disk.EnableUUID set this value to TRUE

It should look something like this:

Click “OK” to go back to the “VM Options” page and then click “OK” again to save these settings.
Now, right click the imported OVA and select Clone → Clone to Template. The “Clone Virtual Machine To Template” wizard starts. It’ll ask you to name this template and where to store it. I will be creating the master template first so I will name it “master-template” and save it in my “openshift4” folder. You can also convert this OVA to a template as well.

On the next screen select a compute destination. Choose one of your ESXi hosts, and click “Next”.
On the following screen, select the appropriate datastore for your environment (make sure you select “Thin” as the disk format) and click “Next”.

Next, there will be the “Ready to complete” page, giving you an overview.

Click on “Finish” to finish the creation of the master template.
Now you will do the same steps AGAIN, except you’ll be creating a template for the workers/bootstrap nodes. I named this template “worker-bootstrap-template”. When you are finished, you should have something like this.

NOTE: You can also have just one OpenShift 4 template and adjust the CPU/RAM if desired. If you plan on churning lots of nodes for multiple deployments then multiple templates may make more sense.

Generate Install Configuration
Now that you’ve prepped vSphere for installation. You can go ahead and generate the install-config.yaml file. This file tells OpenShift about the environment that you’re going to install. Before you create this file you’ll need an installation directory to store all your artifacts. You can name this directory whatever you like; I’m going to name mine openshift4.
[chernand@laptop ~]$ mkdir openshift4
[chernand@laptop ~]$ cd openshift4/

I’m going to export some environment variables that will make the creation of the install-config.yaml file easier. Please substitute your configuration where applicable.
[chernand@laptop openshift4]$ export DOMAIN=example.com
[chernand@laptop openshift4]$ export CLUSTERID=openshift4
[chernand@laptop openshift4]$ export VCENTER_SERVER=vsphere.example.com
[chernand@laptop openshift4]$ export VCENTER_USER=”administrator@vsphere.local”
[chernand@laptop openshift4]$ export VCENTER_PASS=’supersecretpassword’
[chernand@laptop openshift4]$ export VCENTER_DC=DC1
[chernand@laptop openshift4]$ export VCENTER_DS=datastore1
[chernand@laptop openshift4]$ export PULL_SECRET=$(< ~/.openshift/pull-secret.json)
[chernand@laptop openshift4]$ export OCP_SSH_KEY=$(< ~/.ssh/id_rsa.pub)

Once you’ve exported those, go ahead and create the install-config.yaml file in the openshift4 directory by running the following:
[chernand@laptop openshift4]$ cat < install-config.yaml
apiVersion: v1
baseDomain: ${DOMAIN}
compute:
– hyperthreading: Enabled
name: worker
replicas: 0
controlPlane:
hyperthreading: Enabled
name: master
replicas: 3
metadata:
name: ${CLUSTERID}
networking:
clusterNetworks:
– cidr: 10.254.0.0/16
hostPrefix: 24
networkType: OpenShiftSDN
serviceNetwork:
– 172.30.0.0/16
platform:
vsphere:
vcenter: ${VCENTER_SERVER}
username: ${VCENTER_USER}
password: ${VCENTER_PASS}
datacenter: ${VCENTER_DC}
defaultDatastore: ${VCENTER_DS}
pullSecret: ‘${PULL_SECRET}’
sshKey: ‘${OCP_SSH_KEY}’
EOF

I’m going over the options at a high level:

baseDomain – This is the domain of your environment.
metadata.name – This is your clusterid
Note: this makes all FQDNS in the openshift4.example.com domain.
platform.vsphere – This is your vSphere specific configuration. This is optional and you can find a “standard” install config example in the docs.
pullSecret – This pull secret can be obtained by going to cloud.redhat.com
Note: I saved mine as ~/.openshift/pull-secret.json
sshKey – This is your public SSH key (e.g. id_rsa.pub)

NOTE: The OpenShift installer removes this file during the install process, so you may want to keep a copy of it somewhere.

Create Ignition Files
The next step in the process is to create the installer manifest files using the openshift-install command. Keep in mind that you need to be in the install directory you created (in my case that’s the openshift4 directory).
[chernand@laptop openshift4]$ openshift-install create manifests
INFO Consuming “Install Config” from target directory
WARNING Making control-plane schedulable by setting MastersSchedulable to true for Scheduler cluster settings

Note that the installer tells you the the masters are schedulable. For this installation, we need to set the masters to not schedulable.
[chernand@laptop openshift4]$ sed -i ‘s/mastersSchedulable: true/mastersSchedulable: false/g’ manifests/cluster-scheduler-02-config.yml
[chernand@laptop openshift4]$ cat manifests/cluster-scheduler-02-config.yml
apiVersion: config.openshift.io/v1
kind: Scheduler
metadata:
creationTimestamp: null
name: cluster
spec:
mastersSchedulable: false
policy:
name: “”
status: {}

To find out more about why you can’t run workloads on OpenShift 4.2 on the control plane, please refer to the official documentation.
Once the manifests are created, you can go ahead and create the ignition files for installation.
[chernand@laptop openshift4]$ openshift-install create ignition-configs
INFO Consuming “Master Machines” from target directory
INFO Consuming “Openshift Manifests” from target directory
INFO Consuming “Worker Machines” from target directory
INFO Consuming “Common Manifests” from target directory

Next, create an append-bootstrap.ign ignition file. This file will tell RHCOS where to download the bootstrap.ign file to configure itself for the OpenShift cluster.
[chernand@laptop openshift4]$ cat < append-bootstrap.ign
{
“ignition”: {
“config”: {
“append”: [
{
“source”: “http://192.168.1.110:8080/ignition/bootstrap.ign”,
“verification”: {}
}
]
},
“timeouts”: {},
“version”: “2.1.0”
},
“networkd”: {},
“passwd”: {},
“storage”: {},
“systemd”: {}
}
EOF

Next, copy over the bootstrap.ign file over to this webserver.
[chernand@laptop openshift4]$ scp bootstrap.ign root@192.168.1.110:/var/www/html/ignition/

We’ll need the base64 encoding for each of the ignition files we’re going to pass to VSphere when we create the VMs. Do this by encoding the files and putting the result in a file for later use.
[chernand@laptop openshift4]$ for i in append-bootstrap master worker
do
base64 -w0 < $i.ign > $i.64
done
[chernand@laptop openshift4]$ ls -1 *.64
append-bootstrap.64
master.64
worker.64

You are now ready to create the VMs.
Creating the Virtual Machines
Log back into the vSphere webui to create the virtual machines from the templates you created. Navigate to “VMs and Templates” (the icon that looks like a sheet of paper); and then right click the “worker-bootstrap-template” and select New VM From this Template… This brings up the “Deploy From Template” wizard. Name this VM “bootstrap” and make sure it’s in the openshift4 folder.

After you click next, select one of your ESXi hosts in your cluster as a destination compute resource and click “Next”. On the next page, it’ll ask you to select a datastore for this VM. Select the appropriate store for your cluster and make sure you thin provision the disk.

After clicking next, check off “Customize this virtual machine’s hardware” on the “Select clone options” page.

After you click next, it’ll bring up the “Customize hardware” page. For the bootstrap we are setting 4 CPUs, 8GB of RAM, 120GB of HD space, and I will also set the custom MAC address for my DHCP server. It should look something like this:

On that same screen click on “VM Options” and expand the “Advanced” menu. Scroll down to the “Configuration Parameters” section and click on “Edit Configuration…”. This will bring up the parameters menu. There, you will change the guestinfo.ignition.config.data value from changeme to the contents of your append-bootstrap.64 file.
[chernand@laptop openshift4]$ cat append-bootstrap.64

Here is a screenshot of my configuration:

Click “OK” and then click “Next” on the “Customize Hardware” screen. This will bring you to the overview page.

Click “Finish”, to create your bootstrap VM.
You need to perform these steps at least 5 more times (3 times for the masters and 2 more times for the workers). Use the following table to configure your servers, which is based on the resource requirements listed on the official documentation.

MACHINEvCPURAMSTORAGEguestinfo.ignition.config.data

master416 GB120 GBOutput of: cat openshift4/master.64

worker28 GB120 GBOutput of: cat openshift4/worker.64

Once you’ve created your 3 masters and 2 workers, you should have 6 VMs in total. One for the bootstrap, three for the masters, and two for the workers.

Now boot the VMs. It doesn’t matter which order you boot them in, but I booted mine in the following order:

Bootstrap
Masters
Workers

Bootstrap Process
Back on the installation host, you can now finish the bootstrap complete process for the OpenShift installer.
[chernand@laptop openshift4]$ openshift-install wait-for bootstrap-complete –log-level debug
DEBUG OpenShift Installer v4.2.0
DEBUG Built from commit 90ccb37ac1f85ae811c50a29f9bb7e779c5045fb
INFO Waiting up to 30m0s for the Kubernetes API at https://api.openshift4.example.com:6443…
INFO API v1.14.6+2e5ed54 up
INFO Waiting up to 30m0s for bootstrapping to complete…
DEBUG Bootstrap status: complete
INFO It is now safe to remove the bootstrap resources

Once you see this message; you can safely delete the bootstrap VM and continue with the installation.
Finishing Install
Once the bootstrap process is complete, the cluster is actually up and running; but not in a state where it’s ready to receive workloads. To finish the install process first export the KUBECONFIG environment variable.
[chernand@laptop openshift4]$ export KUBECONFIG=~/openshift4/auth/kubeconfig

You can now access the API. You first need to check if there are any CSRs that are pending for any of the nodes. You can do this by running oc get csr, this will list all the CSRs for your cluster.
[chernand@laptop openshift4]$ oc get csr
NAME AGE REQUESTOR CONDITION
csr-4hn7m 6m36s system:node:master3.openshift4.example.com Approved,Issued
csr-4p6jz 7m8s system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Approved,Issued
csr-6gvgh 6m21s system:node:worker2.openshift4.example.com Approved,Issued
csr-8q4q4 6m20s system:node:master1.openshift4.example.com Approved,Issued
csr-b5b8g 6m36s system:node:master2.openshift4.example.com Approved,Issued
csr-dc2vr 6m41s system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Approved,Issued
csr-fwprs 6m22s system:node:worker1.openshift4.example.com Approved,Issued
csr-k6vfk 6m40s system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Approved,Issued
csr-l97ww 6m42s system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Approved,Issued
csr-nm9hr 7m8s system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Approved,Issued

You can approve any pending CSRs by running the following command (please read more about certificates in the official documentation):
[chernand@laptop openshift4]$ oc get csr –no-headers | awk ‘{print $1}’ | xargs oc adm certificate approve

After you’ve verified that all CSRs are approved, you should be able to see your nodes.
[chernand@laptop openshift4]$ oc get nodes
NAME STATUS ROLES AGE VERSION
master1.openshift4.example.com Ready master 9m55s v1.14.6+c07e432da
master2.openshift4.example.com Ready master 10m v1.14.6+c07e432da
master3.openshift4.example.com Ready master 10m v1.14.6+c07e432da
worker1.openshift4.example.com Ready worker 9m56s v1.14.6+c07e432da
worker2.openshift4.example.com Ready worker 9m55s v1.14.6+c07e432da

In order to complete the installation, you need to add storage to the image registry. For testing clusters, you can set this to emptyDir (for more permanent storage, please see the official doc for more information).
[chernand@laptop openshift4]$ oc patch configs.imageregistry.operator.openshift.io cluster –type merge –patch ‘{“spec”:{“storage”:{“emptyDir”:{}}}}’

Please note that using a VDMK is not supported for the registry.

At this point, you can now finish the installation process.
[chernand@laptop openshift4]$ openshift-install wait-for install-complete
INFO Waiting up to 30m0s for the cluster at https://api.openshift4.example.com:6443 to initialize…
INFO Waiting up to 10m0s for the openshift-console route to be created…
INFO Install complete!
INFO To access the cluster as the system:admin user when using ‘oc’, run ‘export KUBECONFIG=/home/chernand/openshift4/auth/kubeconfig’
INFO Access the OpenShift web-console here: https://console-openshift-console.apps.openshift4.example.com
INFO Login to the console with user: kubeadmin, password: STeaa-LjEB3-fjNzm-2jUFA

Once you’ve seen this message, the install is complete and the cluster is ready to use. If you provided your vSphere credentials, you’ll have a storageclass set.
[chernand@laptop openshift4]$ oc get sc
NAME PROVISIONER AGE
thin (default) kubernetes.io/vsphere-volume 13m

You can use this storageclass to dynamically create VDMKs for your applications.
If you didn’t provide your vSphere credentials, you can consult the VMware Documentation site for how to set up storage integration with Kubernetes.
Conclusion
In this blog we went over how to install OpenShift 4 on VMware using the UPI method using DHCP. We also displayed the vSphere integration that allows OpenShift to create VDMKs for the applications. In my next blog, I will be going over how to install using static IPs. So, stay tuned!
Red Hat OpenShift Container Platform and VMware vSphere are a great combination for running an enterprise container platform on a virtual infrastructure. For the last several years our joint customers have successfully deployed OpenShift on vSphere for their production ready applications.
We invite you to try OpenShift 4 on VMware, and run enterprise ready Kubernetes on vSphere today!
The post OpenShift 4.2 vSphere Install Quickstart appeared first on Red Hat OpenShift Blog.
Quelle: OpenShift

Growing partner opportunity with Azure innovation

At Microsoft Ignite, we are sharing a wealth of new products and business news, across Microsoft’s unique technology stack—spanning on-premises, client, server, and cloud. For Microsoft Azure, we have always believed in building products and programs that help our customers invent with purpose. Our announcements reinforce this belief and deliver on our promises of helping customers be future ready, build on their terms, operate hybrid seamlessly, and do all this with an uncompromising foundation of trust.

To see a full list and details of these Azure announcements, please visit the Microsoft Ignite webpage here. 

These announcements also unlock tremendous opportunities for you, our partners, to acquire new customers and grow Azure projects within your existing customer base. In this blog, we want to dig deeper in two key announcements, highlight the respective opportunities, resources, and how to take action.

Grow your business with Azure services that now run anywhere with new hybrid capabilities

At Microsoft Ignite, we take a leap forward in enabling customers to move from just hybrid cloud to truly deliver innovation anywhere with Azure.

To give customers the benefits of cloud innovation, including always up-to-date data capabilities, we’re delivering the ability for customers to run Azure data services anywhere.
Millions of Azure resources are organized, governed, and secured daily by customers using Azure management. Azure Arc extends these Azure management capabilities to Linux and Windows servers, as well as Kubernetes clusters on any infrastructure across datacenter, multi-cloud, and edge.
We are also expanding our Azure Stack Hub portfolio to offer our customers even more flexibility with the addition of Azure Stack Edge. Azure Stack Edge, previously Azure Data Box Edge, is a managed AI-enabled edge appliance that brings compute, storage, and intelligence to any edge.

As an Azure partner, Azure Arc now enables you to manage a customer’s infrastructure through one consistent and unified set of tools across on-premises, multi-cloud, and at the edge. You can also implement cloud security across a customer’s environment with centralized role-based access control, security policies, and advanced threat protection.

With Azure Lighthouse, you now have the ability to consistently manage a customer's Azure environment, and on-premises resources available via Azure Arc, from a single control plane, applying automation at scale.

Learn more about these exciting new hybrid capabilities.

Expand your analytics practice with Azure Synapse Analytics

We also announced Azure Synapse Analytics, a limitless analytics service, that brings together enterprise data warehousing and big data analytics. Simply put, Azure Synapse Analytics is the next evolution of Azure SQL Data Warehouse, delivering limitless scale, powerful insights, unified experience, and unmatched security. We have taken our industry leading data warehouse to a whole new level of performance and capabilities. Businesses can continue running their existing data warehouse workloads in production today with Azure Synapse Analytics, and will automatically benefit from the new capabilities which are in preview.

If you are a data partner, Azure Synapse Analytics opens up new opportunities to help new and existing customers get more out of their business data. Through the unified experience and unmatched security, you can address the needs of everybody, from those of data engineers managing pipelines to the needs of business analysts trying to securely access datasets. If your practice helps customers garner insights for their business, Azure Synapse Analytics enables quick business insights and machine learning, reducing the time to get the insights for the customer. All this at limitless scale to grow with the needs of your customers. And for any independent software vendor (ISV) apps that worked with Azure SQL Data Warehouse, they will keep working with Azure Synapse Analytics.

Learn more about Azure Synapse Analytics.

We also assembled a curated set of resources for you to learn more about these new capabilities and respond to your customers' needs. These resources are located on our partners page.

Azure. Invent with purpose.
Quelle: Azure

For Liberty Mutual, the Openness and Flexibility of the Cloud Means Better Business Outcomes

We had the chance recently to sit down with the Liberty Mutual Insurance team at their Portsmouth, New Hampshire offices and talk about how they deliver better business outcomes with the cloud and containerization.
At this point, Liberty Mutual has moved about 30 percent of their applications to the cloud. One of big improvements the team has seen with the cloud and Docker is the speed at which developers can develop and deploy their applications. That means better business outcomes for Liberty Mutual and its customers.
Here’s what they told us. You can also catch the highlights in this two-minute video:

On how tech is central to Liberty Mutual’s business
Mark Cressey, SVP and GM, IT Hosting Services: Tech and the digitization it’s allowed has really enabled Liberty Mutual to get deeply ingrained in our customers’ lives and support them through their major life journeys. We’re able to be more predictive of what our customer’s needs and get in front of them as a proactive step. How can we help? How can we assist you? Is this the right coverage? And even to the point where using real time information, we can warn them about approaching windstorms or warn our business customers to get their fleet of vehicles out of the way of a flooding event.
On why moving to the cloud matters
Mark: We’re moving to a multi-cloud or hybrid-cloud environment to get the best set of capabilities for our developers, and in turn our customers. Our goal is to take advantage of the latest innovations in all the major cloud environments, so we need to look at how we can write and deploy our applications in the most portable way possible.
Honey Williams, Director of Engineering: Moving to the cloud has empowered our developers to make decisions about when they’re going to deploy their code, or when they’re going to take this image upgrade that fixes a problem. The fact that they have that control and they’re empowered to do it themselves means less handoffs. And it also means less points of failure.
On balancing technical debt and innovation…
Mark: One of our key challenges is balancing investment between our journey to the cloud and what we need to do to keep our on-premise environments modern. We have many applications that the business relies on that can’t be migrated to cloud or aren’t scheduled to go through a modernization effort anytime soon. We still need to achieve those same goals around digitization agility, speed to market for our existing infrastructure—that we have for our cloud environments.
Eric Drobisewski, Senior Architect: We’ve got this mixed mode in terms of dealing with the technical debt of keeping our existing systems stable and secure, but also innovating and moving things to the cloud in a more digital format so that we can succeed in the future. Balancing both of those worlds and building the bridges between them is a big challenge.
On the journey with Docker…
Eric: For us, Docker first came into our picture back in 2014, so we’ve been at it for roughly five years. In hindsight, we were early adopters of a growing and maturing technology. What we saw was an opportunity to improve application development operations and security, particularly as we looked at the cloud. And then over the last four years, we’ve really seen the transformational value of that.
Mark: At Liberty Mutual, Docker is a key part of our journey to the cloud and application modernization efforts. We’ve deployed over 6,000 business services in Docker to let us drive horizontal scale, allow portability the cloud, and simplify our environment for our developers to get them out of configuring infrastructure and get them into the job of building and deploying business functionality.
Eric: One of the things that stands out to me that containerization and Docker provided for Liberty is the openness and flexibility it’s provided around operating in this cloud native ecosystem. It has allowed us to tap into new technologies and move those quickly and securely into the hands of our dev teams to deliver better business outcomes.
On making it easier for developers…
Mallory Quaintaince, Senior Infrastructure Engineer: Some of our application images can be 5 or 6 GB, and you might say, “Why containerize it then?” But we’re really finding that where we have the biggest gains are with downtime and deploys. Instead of having long outage windows for deploys, we’re able to deploy much faster—on the order of minutes versus hours.
The application density that we can get and the container density that we can get really provide both a lot of performance value. The barrier to entry for developers is very low because being able to write a Docker file, write a Docker image, use a Docker compose file—are something that developers can easily learn in a few hours or less.
Honey: Docker has benefited developers at our company because we’re able to provide the package they need in order to deploy their code easily, really making it seem like magic. That’s really what we want for our development teams. We want them to not have to worry about the extra things associated to where they’re going to put their code and how it’s going to run, and Docker brings that for us.

To learn more about how Docker can help you move your applications to the cloud:

Read the Forrester Research report on Modernizing the Core
Download the Customer Innovation eBook

We interviewed @LibertyMutual about how they are moving 30% of apps to the #cloud with #DockerEnterprise. Here’s what they said:Click To Tweet

The post For Liberty Mutual, the Openness and Flexibility of the Cloud Means Better Business Outcomes appeared first on Docker Blog.
Quelle: https://blog.docker.com/feed/

Bring Azure data services to your infrastructure with Azure Arc

With the exponential growth in data, organizations find themselves in increasingly heterogenous data estates, full of data sprawl and silos, spreading across on-premises data centers, the edge, and multiple public clouds. It has been a balancing act for organizations trying to bring about innovation faster while maintaining consistent security and governance. The lack of a unified view of all their data assets across their environments poses extra complexity for best practices in data management.

As Satya announced in his vision keynote at Microsoft Ignite, we are redefining hybrid by bringing innovation anywhere with Azure. We are introducing Azure Arc, which brings Azure services and management to any infrastructure. This enables Azure data services to run on any infrastructure using Kubernetes. Azure SQL Database and Azure Database for PostgreSQL Hyperscale are both available in preview on Azure Arc, and we will bring more data services to Azure Arc over time.

For customers who need to maintain data workloads in on-premises datacenters due to regulations, data sovereignty, latency, and so on, Azure Arc can bring the latest Azure innovation, cloud benefits like elastic scale and automation, unified management, and unmatched security on-premises. 

Always current

A top pain point we continue to hear from customers is the amount of work involved in patching and updating their on-premises databases. It requires constant diligence from corporate IT to ensure all databases are updated in a timely fashion. A fully managed database service, such as Azure SQL Database, removes the burden of patching and upgrades for customers who have migrated their databases to Azure.

Azure Arc helps to fully automate the patching and update process for databases running on-premises. Updates from the Microsoft Container Registry are automatically delivered to customers, and deployment cadences are set by customers in accordance with their policies. This way, on-premises databases can stay up to date while ensuring customers maintain control.

Azure Arc also enables on-premises customers to access the latest innovations such as the evergreen SQL through Azure SQL Database, which means customers will no longer face end-of-support for their databases. Moreover, a unique hyper-scale deployment option of Azure Database for PostgreSQL is made available on Azure Arc. This capability gives on-premises data workloads an additional boost on capacity optimization, using unique scale-out across reads and writes without application downtime.

Elastic scale

Cloud elasticity on-premises is another unique capability Azure Arc offers customers. The capability enables customers to scale their databases up or down dynamically in the same way as they do in Azure, based on the available capacity of their infrastructure. This can satisfy burst scenarios that have volatile needs, including scenarios that require ingesting and querying data in real-time, at any scale, with sub-second response time. In addition, customers can also scale-out database instances by setting up read replicas across multiple data centers or from their own data center into any public cloud.

Azure Arc also brings other cloud benefits such as fast deployment and automation at scale. Thanks to Kubernetes-based execution, customers can deploy a database in seconds, setting up high availability, backup, point-in-time-restore with a few clicks. Compare this to the time and resource-consuming manual work that is currently required to do the same on-premises, these new capabilities will greatly improve productivity of database administration and enable faster continuous integration and continuous delivery, so the IT team can be more agile to unlock business innovation.

Unified management

Using familiar tools such as the Azure portal, Azure Data Studio, and the Azure CLI, customers can now gain a unified view of all their data assets deployed with Azure Arc. Customers are able to not only view and manage a variety of relational databases across their environment and Azure, but also get logs and telemetry from Kubernetes APIs to analyze the underlying infrastructure capacity and health. Besides having localized log analytics and performance monitoring, customers can now leverage Azure Monitor on-premises for comprehensive operational insights across their entire estate. Moreover, Azure Backup can be easily connected to provide long-term, off-site backup retention and disaster recovery. Best of all, customers can now use cloud billing models for their on-premises data workloads to manage their costs efficiently.

See a full suite of management capabilities provided by Azure Arc (Azure Arc data controller) from the below diagram.

Unmatched security

Security is a top priority for corporate IT. Yet it has been challenging to keep up the security posture and maintain consistent governance on data workloads across different customer teams, functions, and infrastructure environments. With Azure Arc, for the first time, customers can access Azure’s unique security capabilities from the Azure Security Center for their on-premises data workloads. They can protect databases with features like advanced threat protection and vulnerability assessment, in the same way as they do in Azure.

Azure Arc also extends governance controls from Azure so that customers can use capabilities such as Azure Policy and Azure role-based access control across hybrid infrastructure. This consistency and well-defined boundaries at scale can bring peace of mind to IT regardless of where the data is.

Learn more about the unique benefits with Azure Arc for data workloads.

Azure. Invent with purpose.
Quelle: Azure