Hybrid Cloud Management


What is Hybrid Cloud Management?

Hybrid Cloud Management provided by ZStack Cloud integrates the simple, strong, scalable, and smart (4S) features of ZStack Cloud Private Cloud and the advanced, secure, and stable features of Alibaba Cloud Public Cloud. It is a hybrid cloud management solution that seamlessly integrates cloud services and terminals, interconnecting the control panel and data panel.

Concepts

  • ZStack Cloud Hybrid Cloud Management provides the following cloud computing products of Alibaba Cloud:
    • ECS Instance: An elastic compute server (ECS) instance is a VM instance created on Alibaba Cloud.
    • Disk: A disk provides storage space for an ECS instance created on Alibaba Cloud.
    • Image: An image is a template file that is used to create ECS instances. Images are categorized into custom images and Alibaba Cloud images.
    • Security Group: A security group provides security control services for ECS instances on the L3 network layer. It filters the inbound or outbound packets of ECS instances based on specified security rules.
    • VPC: A virtual private cloud (VPC) is a private network used for ECS instances created on Alibaba Cloud.
    • EIP: An elastic IP address (EIP) is an IP address in Alibaba Cloud public networks. You can attach EIPs to ECS instances so the ECS instances can access public networks by using the EIPs.
  • VPN: Establishes a site-to-site IPsec VPN channel to enable communications between private networks in a local data center and Alibaba Cloud VPCs. This section includes the following services:
    • VPN Gateway: A virtual private network (VPN) gateway establishes a secure connection between a local data center and Alibaba Cloud VPC by using an encrypted channel.
    • VPN Customer Gateway: A VPN customer gateway provides services for a local data center.
    • VPN Connection: A VPN connection is an encrypted communication channel established between a VPN gateway and VPN customer gateway.
  • Express Connect: Express Connect uses physical connections (electric cables or optical fibers leased from operators) to connect local data centers with Alibaba Cloud access points and Alibaba Cloud VPCs. This way, private networks on the Cloud and in local data centers can communicate with each other in a fast, stable, and secure manner. This section includes the following services:
    • Router Interface: A router interface is a virtual device that is used to establish communication channels and control their status.
    • Virtual Border Router: A virtual border router (VBR) is virtualized from a switch port that is connected with an Alibaba Cloud physical connection. A VBR forwards data between a VPC and local data center.
  • Alibaba Cloud NAS: Alibaba Cloud NAS is a network-attached file storage service. It provides highly reliable and available distributed file systems that can be accessed by using standard file access protocols. In addition, Alibaba Cloud NAS is scalable in storage space and performance and can be managed in a namespace while shared with multiple users. ZStack Cloud seamlessly integrates with Alibaba Cloud NAS. In ZStack Cloud Private Cloud environments, you can add primary storages of the Aliyun NAS type to the Cloud and thus use Alibaba Cloud distributed storage deployed independently from the Cloud. This section includes the following services:
    • File System: A file system is a backend storage system used for Alibaba Cloud NAS primary storage. Before you add an Alibaba Cloud primary storage, you need to add an NAS file system.
    • Permission Group: A permission group is an allowlist mechanism that Alibaba Cloud provides for IP addresses or ranges. ECS instances of specific IP addresses or in specific IP ranges are granted access to file systems based on specified permission rules.
  • Data Center: Data centers are resources associated with Alibaba Cloud regions and zones. The following describes regions and zones:
    • Region: A region is a physical area where data centers reside. A region in ZStack Cloud Hybrid Cloud corresponds to a region in Alibaba Cloud.
    • Zone: A zone is a physical area in a region that is independent from other zones in the region in terms of electricity and network supplies.
  • Setting: ZStack Cloud Hybrid Cloud provides the following basic settings:
    • AccessKey Management: An AccessKey pair is an identity credential that has access to APIs of Alibaba Cloud or Private Alibaba Cloud. It has full access to the Cloud. An AccessKey pair consists of AccessKey ID and AccessKey secret.
    • Hybrid Cloud Setting: Hybrid cloud setting allows you to configure settings that take effect on the whole platform.

Physical Deployment

ZStack Cloud Hybrid Cloud uses the in-process micro-services architecture and does not include other modules. ZStack Cloud management nodes need to access the Internet so they can call Alibaba Cloud Public Cloud APIs.

Physical connection-based deployment: uses physical connections to establish local-remote inter-connected networks, thereby connecting a local data center with Alibaba Cloud Public Cloud.
Figure 1. Physical Connection-based Deployment


Architecture

ZStack Cloud Hybrid Cloud includes the following modules:

  • Identity Authentication:
    Alibaba Cloud AccessKey: integrates Resource Access Management of Alibaba Cloud Public Cloud or Alibaba Cloud Private Cloud. A user authorized with an Alibaba Cloud AccessKey pair can access remote resources.
    Figure 2. Identity Authentication


  • Network Interconnection:

    You can use IPsec tunnels or Alibaba Cloud Express Connect to connect local Private Cloud to Alibaba Cloud Public Cloud. This way, L3 local-remote networks can access each other. Local-remote network interconnection is the foundation of ZStack Cloud Hybrid Cloud.

    ZStack Cloud Hybrid Cloud allows you to use IPsec tunnels or Alibaba Cloud Express Connect to establish interconnected networks.
    Figure 3. IPsec Tunnel


    Figure 4. Alibaba Cloud Express Connect


  • Resource Management:
    You can authorize a RAM user to manage Alibaba Cloud Public Cloud resources, including ECS instances, VBR, VPC, and virtual switches.

    Resource Management



  • Business Implementation:

    The identity authentication, network interconnection, and resource management mechanisms combined allow for the establishment of a flexible and elastic business system architecture. After the hybrid cloud platform is established, you can deploy flexible and multi-dimensional business modes.

Characteristics

ZStack Cloud Hybrid Cloud have the following characteristics:
  • Seamless integration:

    ZStack Cloud Hybrid Cloud seamlessly integrates Public Cloud with ZStack Cloud hybrid cloud platform, combining the benefits ZStack Cloud Private Cloud. This way, users can manage public clouds and private clouds in a unified platform.

  • Seamless integration:

    ZStack Cloud Hybrid Cloud allows seamless upgrading without affecting business continuity.

  • Ease of use:

    ZStack Cloud Hybrid Cloud seamlessly integrates cloud services and terminals in a unified cloud platform. You can easily manage local private clouds and access various resources on the public cloud based on your business needs.

Scenarios

  • Data backup on the Cloud

    In financial and medical industries, data retention must meet compliance requirements. However, backing up data in local data centers has high data risks, incurs high costs, and is hard for operations and maintenance. In these scenarios, you can use ZStack Cloud Hybrid Cloud to back up data on the Cloud, ensuring stable data storage and lowering the storage cost.

  • Data storage on the Cloud

    Enterprises and institutions need to store large amounts of data. In these scenarios, you can use ZStack Cloud Hybrid Cloud to store data on the Cloud, lowering your investment and management costs and allowing data access from multiple regions and zones.

  • Data migration on the Cloud

    Enterprises and institutions need to exchange data in different places. In these scenarios, you can use ZStack Cloud Hybrid Cloud to migrate data on the Cloud, ensuring that data can be transmitted in a stable manner without data loss.

Download

Already filled the basic info? Click here.

Enter at least 2 characters.
Invalid mobile number.
Enter at least 4 characters.
Invalid email address.
Wrong code. Try again. Send Code Resend Code (60s)

An email with a verification code will be sent to you. Make sure the address you provided is valid and correct.

Download

Not filled the basic info yet? Click here.

Invalid email address or mobile number.

Email Us

contact@zstack.io
ZStack certification training consulting
Enter at least 2 characters.
Invalid mobile number.
Enter at least 4 characters.
Invalid email address.
Wrong code. Try again. Send Code Resend Code (60s)

Email Us

contact@zstack.io

The download link is sent to your email address.

If you don't see it, check your spam folder, subscription folder, or AD folder. After receiving the email, click the URL to download the documentation.

The download link is sent to your email address.

If you don't see it, check your spam folder, subscription folder, or AD folder.
Or click on the URL below. (For Internet Explorer, right-click the URL and save it.)

Thank you for using ZStack products and services.

Submit successfully.

We'll connect soon.

Thank you for choosing ZStack products and services.

Back to Top