cloud IaaS PaaS SaaS virtualisation Docker kubernetes SDN GDPR SLA sistemi-e-reti

Cloud Computing

Reference guide for Networks & Systems — final year. From the IaaS/PaaS/SaaS model to virtualisation with Docker and Kubernetes, from SDN to cloud databases, through to SLA, costs and GDPR.


1. Introduction to Cloud Computing

Cloud Computing is a model for delivering computing services over the Internet. Instead of purchasing and managing physical servers on their own premises (on-premise), a business or individual can rent computational resources — processors, memory, storage, networks — from a specialised provider, paying only for what they actually use.

The National Institute of Standards and Technology (NIST) identifies five essential cloud characteristics:

  • On-demand self-service: resources are provisioned automatically, without human intervention from the provider.
  • Broad network access: accessible from any network-connected device.
  • Resource pooling: physical resources are shared among multiple users (multi-tenancy).
  • Rapid elasticity: resources scale automatically based on demand.
  • Measured service: consumption monitored and billed precisely (pay-as-you-go).

Key concept: The cloud is not «someone else’s computer»: it is a distributed, redundant and scalable infrastructure that often offers levels of reliability and security beyond what an SME could achieve independently.


2. Service Models: IaaS, PaaS, SaaS

The simplest way to distinguish the three models is to ask: «What does the provider manage and what does the customer manage?».

LayerIaaSPaaSSaaS
ApplicationCustomerCustomerProvider
DataCustomerCustomerProvider
Runtime / MiddlewareCustomerProviderProvider
Operating SystemCustomerProviderProvider
VirtualisationProviderProviderProvider
Network / Storage / CPUProviderProviderProvider

2.1 IaaS — Infrastructure as a Service

The provider supplies raw infrastructure: virtual machines, storage, virtual networks and firewalls. The customer is responsible for everything above: operating system, middleware, runtime and applications.

Commercial examples

  • Amazon EC2 (AWS): virtual instances in seconds, available across dozens of global regions.
  • Microsoft Azure Virtual Machines: native integration with Active Directory and Windows Server environments.
  • Google Compute Engine (GCP): optimised for big data and machine learning workloads.
  • Hetzner Cloud: European (German) provider appreciated for value and GDPR compliance.

When to use IaaS: When you already have a structured IT team and want maximum flexibility: migrating a physical data centre, hosting test and development environments, managing seasonal traffic spikes.

2.2 PaaS — Platform as a Service

The provider adds a platform layer: language runtimes (Node.js, Python, Java…), managed databases, message queues, CI/CD pipelines. The customer focuses only on application code and data.

Commercial examples

  • Google App Engine / Firebase: web and mobile app deployment with automatic scaling and a real-time database.
  • Heroku (Salesforce): platform widely used by startups for the simplicity of the git push → deploy workflow.
  • Azure App Service: native support for .NET, PHP, Node.js, Python with DevOps integration.
  • AWS Elastic Beanstalk: automatic orchestration of EC2, load balancers and auto-scaling for web applications.
  • Red Hat OpenShift: enterprise Kubernetes-based PaaS, available on-premise and in hybrid cloud.

When to use PaaS: For development teams that want to focus on the product without managing OS updates, security patches or web server configuration.

2.3 SaaS — Software as a Service

The provider manages the entire technology stack: infrastructure, platform and application. Users access the service directly via a browser or mobile app, without installing anything. It is the most widespread cloud model in everyday life.

Commercial examples

  • Microsoft 365 (formerly Office 365): Word, Excel, Outlook, Teams on a monthly/annual per-user subscription.
  • Google Workspace: Gmail, Drive, Docs, Meet — direct competitor of Microsoft 365.
  • Salesforce CRM: customer and sales pipeline management; pioneer of the enterprise SaaS model.
  • Dropbox / Google Drive: cross-platform file storage and synchronisation.
  • Zoom / Microsoft Teams: video conferencing and collaboration, which exploded during the 2020 pandemic.
  • Notion / Confluence: collaborative knowledge base and documentation.

When to use SaaS: Almost always, for horizontal applications (email, office, CRM, HR) where deep customisation is unnecessary and speed of adoption is the priority.

2.4 IaaS vs PaaS vs SaaS comparison

AspectIaaSPaaSSaaS
ControlMaximumMediumMinimum
FlexibilityHighMediumLow
Skills requiredSysadmin + DevOpsDevelopersEnd users
Time-to-marketSlowMediumImmediate
Initial costLow (OPEX)Very lowMinimal
Lock-in riskMediumHighHigh
ExampleAWS EC2Google App EngineMicrosoft 365

3. Virtualisation in the Cloud

Virtualisation is the technological foundation of cloud computing. It allows multiple operating systems or isolated environments (virtual machines or containers) to run on the same physical hardware, maximising resource utilisation and enabling multi-tenancy.

3.1 Hypervisors and Virtual Machines (VMs)

A hypervisor (or Virtual Machine Monitor, VMM) is the software that abstracts the physical hardware and creates independent virtual machines. Two types exist:

  • Type 1 (bare-metal): runs directly on the hardware (e.g. VMware ESXi, Microsoft Hyper-V, KVM). Offers superior performance; the model adopted in cloud data centres.
  • Type 2 (hosted): runs on top of a host operating system (e.g. VirtualBox, VMware Workstation). Used for local development and testing.

Each VM includes a complete operating system (including the kernel), making it isolated but also heavyweight in terms of memory and boot time (tens of seconds).

3.2 Containers and Docker

Containers share the host operating system kernel and isolate only the application and its dependencies via Linux namespaces and cgroups. This makes them far lighter than VMs:

ContainerVM
StartupMillisecondsTens of seconds
Image sizeA few MBSeveral GB
Density per hostHundredsTens

Docker is the most widely used tool for creating and managing containers. Kubernetes (K8s) is the open-source orchestration system that automates deployment, scaling and management of containers in production.

Note: Cloud providers offer managed Kubernetes services: Amazon EKS, Google GKE, Azure AKS. Teams don’t manage the Kubernetes control plane — only the application workloads.

3.3 Serverless (Function as a Service)

The serverless model takes abstraction to the maximum: the developer writes only stateless functions, without thinking about servers, containers or scalability. The infrastructure activates only when the function is called.

  • AWS Lambda: runs code in response to events (HTTP, S3, DynamoDB…).
  • Azure Functions: native integration with the Microsoft ecosystem.
  • Google Cloud Functions / Cloud Run: ideal for microservices and data processing pipelines.

Cost is calculated per millisecond of execution and number of invocations. For irregular or very low workloads, serverless can be extremely economical.


4. Software Defined Networking (SDN)

Traditional networks consist of devices (routers, switches) that integrate both the control plane (path decision) and the data plane (packet forwarding). SDN separates these two planes, centralising the control logic in software called the SDN controller.

4.1 SDN Architecture

  • Data Plane: hardware or virtual switches forward packets according to rules received from the controller.
  • Control Plane: the SDN controller (e.g. OpenDaylight, ONOS) computes paths and programs the data plane via protocols such as OpenFlow.
  • Management Plane: REST/API interfaces that allow administrators to configure the network via software or scripts.

4.2 SDN in the cloud context

In the cloud, SDN is indispensable for:

  • Creating isolated virtual networks (VPC — Virtual Private Cloud) per customer, in multi-tenancy.
  • Configuring firewalls, routing, VPNs and load balancers via API, without touching physical hardware.
  • Automating network provisioning in seconds (Infrastructure as Code).
  • Implementing microsegmentation: each microservice has its own security perimeter.

4.3 SDN examples in the cloud

ProviderSDN ServiceKey Features
AWSAmazon VPCSubnetting, Security Groups, Route Tables, Transit Gateway
AzureAzure Virtual NetworkNSG, VPN Gateway, ExpressRoute, Azure Firewall
GCPGoogle Cloud VPCGlobal VPC, Cloud Armor, Private Google Access
VMwareNSX-THybrid on-premise + cloud SDN, microsegmentation

NFV (Network Function Virtualisation) is the complement to SDN: it virtualises network functions (firewall, IDS, load balancer) turning them into software instances runnable on commodity hardware.


5. Databases in the Cloud

Cloud databases fall into two major families: relational (SQL) and non-relational (NoSQL). Providers offer both as managed services (DBaaS — Database as a Service), eliminating installation, backup, patching and replication operations.

5.1 Managed relational databases

  • Amazon RDS: supports MySQL, PostgreSQL, MariaDB, Oracle, SQL Server. Automatic backups, Multi-AZ for high availability.
  • Amazon Aurora: cloud-native database compatible with MySQL/PostgreSQL, up to 5× faster, auto-scaling storage.
  • Azure SQL Database: managed SQL Server with built-in AI for query optimisation.
  • Google Cloud SQL / AlloyDB: managed PostgreSQL and MySQL; AlloyDB is the high-performance cloud-native version.

5.2 Managed NoSQL databases

  • Amazon DynamoDB: key-value and document store, sub-millisecond latency, serverless and auto-scaling.
  • Google Firestore / Bigtable: Firestore for real-time mobile/web applications; Bigtable for large-scale time-series and analytics.
  • Azure Cosmos DB: multi-model database (document, graph, key-value, columnar) with 99.999% availability SLA.
  • MongoDB Atlas: leading NoSQL document database, available on AWS, Azure and GCP.

5.3 Data Warehouse and Big Data

  • Amazon Redshift: columnar data warehouse for analysis on petabytes of data.
  • Google BigQuery: serverless data warehouse; pricing based on data scanned ($5/TB per query).
  • Azure Synapse Analytics: integrated platform for data warehouse, data lake and Apache Spark.

Note: Cloud databases offer capabilities impossible on-premise at accessible costs: multi-region replication with automatic failover, point-in-time recovery, at-rest and in-transit encryption included in the base price.


6. Hybrid Cloud and Multi-vendor Strategy

6.1 Hybrid Cloud

The hybrid cloud combines on-premise infrastructure (or private cloud) with one or more public clouds, interconnected to form a unified environment. It is the preferred model for large organisations and public administrations.

Main drivers

  • Compliance and data sovereignty: sensitive data (healthcare, financial, government) stays on-premise or in a private cloud, while less critical workloads go to the public cloud.
  • Legacy investments: organisations already have hardware, licences and on-premise expertise they cannot immediately abandon.
  • Latency: some industrial applications (SCADA, real-time systems) require latencies lower than what a remote public cloud can guarantee.
  • Cloud bursting: during load spikes, the application «overflows» into the public cloud while keeping its base on-premise.

Hybrid technologies and solutions

  • AWS Outposts: physical AWS racks installed in the customer’s data centre, managed via the AWS console.
  • Azure Arc: extends Azure services (Kubernetes, databases, policies) to any infrastructure, on-premise or other clouds.
  • Google Anthos: hybrid Kubernetes platform that unifies cluster management on GCP, on-premise and other clouds.
  • VMware Cloud Foundation: uniform virtualisation stack (compute, storage, network) from the private data centre to AWS/Azure/GCP.

6.2 Multi-cloud and the Lock-in Risk

Vendor lock-in is the condition where an organisation becomes excessively dependent on a single provider, making it costly or technically difficult to switch. In the cloud, lock-in manifests through:

  • Proprietary APIs: provider-exclusive services (e.g. AWS Lambda, DynamoDB) that cannot be replicated on other clouds without rewriting the code.
  • Proprietary data formats: storage or databases with non-standard formats that complicate migration.
  • Egress costs: providers charge for outbound traffic (bandwidth out) but not inbound, making data migration expensive.

Strategies to avoid lock-in

  • Cloud-agnostic architecture: use Kubernetes for containers, Terraform for Infrastructure as Code, PostgreSQL instead of Aurora.
  • Open standards: prefer interoperable protocols and formats (S3-compatible object storage, OpenTelemetry for monitoring).
  • Active multi-cloud: deliberately distribute workloads across providers (e.g. ML on GCP, production on AWS, disaster recovery on Azure).
ToolTypeFunctionOpen Source?
Terraform (HashiCorp)IaCInfrastructure provisioning across 500+ providersYes (BSL)
KubernetesOrchestrationCloud-agnostic container deploymentYes (Apache 2)
Prometheus + GrafanaMonitoringCloud-agnostic metrics and alertsYes
Apache KafkaMessagingHigh-throughput inter-cloud message queuesYes
MinIOStorageS3-compatible on-premise object storageYes (AGPL)

Practical rule: For every cloud-specific service chosen, ask: «Is there an open-source or standard equivalent I could use without changing provider?». If the answer is no, carefully weigh the trade-off between convenience and dependency.


7. Service Level Agreement (SLA)

An SLA (Service Level Agreement) is the contract that defines the quality guarantees offered by the provider: availability, performance, recovery times and penalties for non-compliance.

7.1 Key metrics

  • Uptime / Availability: percentage of time the service is operational. Typically expressed as a «number of nines».
  • RTO (Recovery Time Objective): maximum time within which the service must be restored after an outage.
  • RPO (Recovery Point Objective): maximum tolerable data loss, expressed as a time interval (e.g. max 1 hour of data lost).
  • MTTR (Mean Time To Repair): average time to restore service after a failure.
  • Latency and throughput: performance guarantees for the network and the service.

7.2 Availability levels

AvailabilityDowntime/yearDowntime/monthTypical class
99%3 days 15 hours7 hours 18 minNon-critical services
99.9%8 hours 46 min43 minutesStandard business applications
99.95%4 hours 23 min21 minutesEnterprise SaaS
99.99%52 minutes4 minutesE-commerce, banking
99.999%5 minutes26 secondsTelecoms, critical public sector

7.3 SLAs of major providers

ServiceProviderUptime SLAPenalty if violated
EC2 (VM)AWS99.99%Credit 10–30% of monthly cost
S3 (storage)AWS99.99%Credit up to 25%
Azure VMsAzure99.99%Credit 10–25%
Google Compute EngineGCP99.99%Credit 10–50%
Cosmos DBAzure99.999%Credit up to 25%

Warning: The SLA covers only infrastructure availability, not the correctness of the application. Bugs in the customer’s code are not covered. Always read the exclusions: scheduled maintenance, force majeure, customer misconfiguration.


8. Pricing Models and Cost Estimation

The cloud adopts an OPEX (Operational Expenditure) model replacing the traditional CAPEX (Capital Expenditure): no hardware purchases, but a variable fee based on actual consumption.

8.1 Billing models

  • On-demand / Pay-as-you-go: billed per second or hour, with no commitment. Maximum flexibility, highest unit cost.
  • Reserved Instances (RI): 1 or 3-year commitment with 30–72% discount over on-demand. Suitable for stable and predictable workloads.
  • Spot / Preemptible Instances: provider surplus VMs, interruptible with 2-minute notice, 60–90% discount. Ideal for batch jobs and ML training.
  • Savings Plans (AWS): more flexible than RI: commitment on an hourly spend, not on a specific instance type.
  • Monthly/annual subscription (SaaS): fixed price per user/month. Easy to budget.

8.2 Indicative cost examples (2024–2025)

A) Web startup — small application (IaaS/PaaS)

ResourceServiceConfigurationCost/month (€ approx.)
Application VMAWS EC2 t3.small2 vCPU, 2 GB RAM, Linux~€15
DatabaseAWS RDS db.t3.microMySQL, 20 GB SSD~€20
Static storageAWS S350 GB + 10 GB transfer~€2
DNS + CDNAWS Route53 + CloudFront1 domain, 100 GB transfer~€10
Estimated total~€47/month

B) SME — Enterprise application (20 employees)

ResourceServiceConfigurationCost/month (€ approx.)
Production VMAzure D4s v34 vCPU, 16 GB RAM~€140
Staging VMAzure B2s2 vCPU, 4 GB RAM~€35
Managed databaseAzure SQL Business4 vCore, 20.4 GB RAM~€380
Backup storageAzure Blob (LRS)500 GB~€8
Microsoft 365Business Standard20 users × €10.50~€210
VPN GatewayAzure VPN Gw Gen1S2S VPN on-premise~€120
Estimated total~€893/month

C) Big Data — ML model training (spot instances)

ResourceServiceConfigurationCost
GPU clusterGCP A100 spot8× A100 40 GB, 24h training~€180 (spot) vs ~€900 on-demand
Dataset storageGCP Cloud Storage1 TB dataset~€20/month
BigQuery analysisGCP BigQuery500 GB scanned~€2.50

Free estimation tools: AWS Pricing Calculator, Azure Pricing Calculator, Google Cloud Pricing Calculator. Always verify official prices — they change frequently.

8.3 Hidden costs to consider

  • Egress bandwidth: outbound data traffic from the cloud costs money (typically $0.08–0.09/GB after the first 100 GB free). Transfers between regions of the same provider are cheaper; to the Internet they cost more.
  • Software licences: bringing your own licences (BYOL) can reduce costs, but it is not always permitted or advantageous.
  • Support: the basic support plan is free; the «Business» level (AWS) costs at least $100/month or 3% of spend.
  • Idle resources: VMs sitting idle over the weekend cost the same as active ones. Automate shutdown with a scheduler.

9. GDPR and Cloud Computing

The GDPR (General Data Protection Regulation, EU 2016/679) entered into force on 25 May 2018 and applies to any organisation that processes personal data of EU citizens, regardless of where the cloud provider is based.

9.1 Fundamental concepts

  • Personal data: any information that identifies or makes identifiable a natural person (name, email, IP, biometric data, GPS location…).
  • Data Controller: the entity that determines the purposes and means of processing (the customer company using the cloud).
  • Data Processor: the entity that processes data on behalf of the controller (the cloud provider: AWS, Azure, GCP…).
  • Data Protection Officer (DPO): mandatory role for public administrations, hospitals and organisations processing data at large scale. Oversees GDPR compliance.

9.2 Core GDPR principles

  • Lawfulness, fairness and transparency: data is processed on a valid legal basis (consent, contract, legal obligation…).
  • Purpose limitation: data is collected for specific purposes and not reused for incompatible ones.
  • Data minimisation: only data strictly necessary is collected.
  • Accuracy: data must be kept up to date and correct.
  • Storage limitation: data is deleted when no longer needed (retention policy).
  • Integrity and confidentiality: adequate technical and organisational measures to protect data (encryption, access control, audit logs).
  • Accountability: the controller must be able to demonstrate compliance.

9.3 GDPR impact on the cloud

Using a cloud provider does not exempt the customer from GDPR responsibilities.

Transfers of data outside the EU

If the provider (or its sub-processors) stores or processes data in non-EU countries without «adequate protection», the transfer is unlawful without additional safeguards. Valid solutions include:

  • Standard Contractual Clauses (SCC): model contracts approved by the EU Commission, adopted by all major providers.
  • EU Regions: AWS (Frankfurt, Ireland, Milan, Paris, Stockholm), Azure (many EU regions), GCP (Frankfurt, Paris, Turin, Warsaw) allow data to be confined to Europe.
  • EU Sovereign Cloud: specific offerings such as Azure for Sovereign Clouds, AWS European Sovereign Cloud, T-Systems Open Telekom Cloud guarantee data never leaves EU territory.

Data Processing Agreement (DPA)

The GDPR requires a written contract (DPA) between the controller and the processor. AWS, Azure and GCP all offer downloadable standard DPAs.

Data subject rights

  • Right of access (Art. 15): users can request a copy of their data.
  • Right to data portability (Art. 20): data must be provided in a structured, machine-readable format (JSON, CSV…).
  • Right to erasure — «right to be forgotten» (Art. 17): the provider must guarantee definitive deletion from its storage and backups.

Breach notification

In case of a data breach, the controller must notify the supervisory authority within 72 hours of becoming aware (Art. 33) and, if the breach is severe, also inform the data subjects (Art. 34). Cloud providers offer automated alert systems for security events (AWS GuardDuty, Azure Defender, GCP Security Command Center).

9.4 Penalties

Violation categoryMaximum penalty
Minor violations (e.g. failure to maintain processing records)Up to €10 million or 2% of annual worldwide turnover
Serious violations (e.g. unlawful transfer, breach of core principles)Up to €20 million or 4% of annual worldwide turnover

Real examples: Amazon Luxembourg S.A.R.L. — €746 million (2021, CNPD Luxembourg); Meta Platforms — €1.2 billion (2023, DPC Ireland) for EU→US data transfer. GDPR applies anywhere if the data belongs to EU citizens.

9.5 GDPR checklist for cloud adoption

  • Choose a provider with EU regions and a compliant DPA.
  • Restrict processing of sensitive data to EU regions (region lock).
  • Enable at-rest and in-transit encryption (always included in modern managed services).
  • Configure audit logs (AWS CloudTrail, Azure Monitor, GCP Cloud Audit Logs).
  • Define a retention policy and automate deletion of expired data.
  • Document the processing register (mandatory for organisations with >250 employees and for sensitive data).
  • Audit the sub-processor chain (does the cloud provider in turn use other sub-processors?).

10. Summary and Conclusions

TopicKey concept
IaaS / PaaS / SaaSDifferent abstraction levels: maximum control with IaaS, maximum speed with SaaS
VirtualisationVMs, Docker containers, serverless: from hardware to code, increasingly abstract
SDNThe network becomes software: programmable, automatable, scalable via API
Cloud databasesDBaaS eliminates administration; choose SQL vs NoSQL based on the data model
Hybrid cloudOn-premise + public cloud for compliance, latency and legacy investments
Multi-vendorAvoid lock-in with Kubernetes, Terraform, open standards
SLARead uptime, RTO, RPO and penalties carefully before signing
CostsOn-demand for flexibility, reserved for stability, spot for batch jobs. Watch egress
GDPREU data → EU regions, DPA mandatory, 72 hours to report a breach

The future of cloud is hybrid, edge and AI-driven: computation is moving ever closer to the data source (edge computing), artificial intelligence is integrated into cloud services as a commodity, and growing complexity demands FinOps tools to optimise spending. Whoever can read a cloud architecture, estimate a budget and assess lock-in and compliance risks already has a significant competitive advantage in the job market.

For further learning: AWS Skill Builder (skillbuilder.aws), Microsoft Learn (learn.microsoft.com), Google Cloud Skills Boost (cloudskillsboost.google) — all offer free courses and industry-recognised certifications.