| By Dustin Amrhein | Article Rating: |
|
| July 9, 2009 01:30 PM EDT | Reads: |
16,755 |
A common feature of cloud computing solutions is that they enable self-service access to the services they provide. This enables users to directly procure services from the cloud, and it eliminates the need for more time-consuming, labor-intensive, human-driven procurement processes familiar to many in IT.
That's not to say that a cloud computing solution should provide its services in a free-for-all manner, letting any user take any action within the system. There should be strict controls over the services users have access to and the actions they can perform with those services. This is the only way to ensure that such solutions can actually stand up to the rigors of an enterprise environment.
That being said, the WebSphere CloudBurst Appliance strikes a nice balance between self-service access and security. This balance enables WebSphere CloudBurst users to perform the actions to which they are authorized with the services to which they are authorized.
WebSphere CloudBurst provides this capability by allowing for the definition of users of the system. Each user defined within the WebSphere CloudBurst Appliance has from one to five of the following permission roles:
- Permission to deploy a pattern to the cloud: A pattern is a virtualized WebSphere application environment.
- Permission to create a pattern
- Permission to manage components in the catalog: The WebSphere CloudBurst catalog contains virtual images, scripts, and other artifacts used to create and maintain WebSphere virtual systems in a cloud.
- Permission to administer the cloud
- Permission to administer the appliance
These permissions align nicely with typical organizational IT roles. For instance, members of a team responsible for middleware environments may have the ability to both create and deploy patterns while members of a team responsible for operating system environments would have the ability to manage components in the catalog (the virtual images in the catalog contain a customizable operating system environment).
In addition to defining users with associated sets of permissions, WebSphere CloudBurst also brings with it a notion of fine-grained access controls. For each resource within WebSphere CloudBurst, such as a virtual image, script package, WebSphere pattern, or WebSphere virtual system, there is associated information about which users have access to that resource. In addition, when appropriate there are associated permissions about what level of access a particular user has to the resource (i.e. read, read-write, etc.).
This fine-grained access model is helpful in many situations in a typical enterprise. Consider the case that the middleware team has created a WebSphere pattern that was only meant to run in production environments due to the amount of resource it requires. In order to prevent a test or development user from deploying this pattern to a test cloud (in WebSphere CloudBurst all users have at least the permission to deploy patterns they have access to), the middleware team could leave the test and development users off of the list of users who have access to see the pattern. When a test or development user logs into the appliance and navigates to the page that contains WebSphere patterns, they will not see this production pattern since they were not granted access.
It's understandable why self-service access is such a popular feature of cloud computing solutions. Providing access so users can provision the resources they need without involving numerous other parties means greater efficiency within the organization. However, this access must be tempered with the right security and access control capabilities. The WebSphere CloudBurst Appliance enables self-service access without compromising these important capabilities.
Published July 9, 2009 Reads 16,755
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Dustin Amrhein
Dustin Amrhein joined IBM as a member of the development team for WebSphere Application Server. While in that position, he worked on the development of Web services infrastructure and Web services programming models. In his current role, Dustin is a technical specialist for cloud, mobile, and data grid technology in IBM's WebSphere portfolio. He blogs at http://dustinamrhein.ulitzer.com. You can follow him on Twitter at http://twitter.com/damrhein.
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Best CIO Practices Shared from SHI’s Customers
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud is Changing the Economics of Business
- Building the Case for a Cloud-Based Government
- Cloud Expo NY: Environmental Pressures Drive an Evolution in File Storage
- Convergence and Interoperability Will Define Next-Gen Cloud Architectures
- NIST to Sponsor FFRDC Widespread Adoption of Integrated CyberSecurity
- Solving the Cloud Talent Gap
- Riverbed Strengthens Commitment to Federal Market; Achieves Common Criteria Certification for Network Performance Management Solution
- Cloud Business Solutions, Social Media, and Platform Systems of Engagement Market Shares, Strategies, and Forecasts, Worldwide, 2013 to 2019
- Optimize Your Virtual Environment to Obtain Maximum Business Value
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Best CIO Practices Shared from SHI’s Customers
- Gravitant Supports General Dynamics Information Technology in Offering New Cloud Brokerage Services to Government Entities
- SUSE Receives Common Criteria Security Certifications
- Cloud Expo New York: Time to Mission @ the Speed of Cloud
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Register for the 2013 FOSE Conference
- Cloud is Changing the Economics of Business
- Building the Case for a Cloud-Based Government
- Guest Post: Typical CIO Conversation
- Cloud Expo NY: Environmental Pressures Drive an Evolution in File Storage
- Convergence and Interoperability Will Define Next-Gen Cloud Architectures
- The Top 150 Players in Cloud Computing
- The Top 250 Players in the Cloud Computing Ecosystem
- GDS International: Global Warming Scam?
- Cloud Expo New York Call for Papers Now Open
- Top 50 Bloggers on Cloud Computing
- Industry Experts Discuss the State of Cloud Computing
- The Cloud Computing Kettle Heats Right Up
- The Top 100 Bloggers on Cloud Computing
- The Next Chapter in the Virtualization Story Begins
- Twelve New Programming Languages: Is Cloud Responsible?
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors
- Cloud Expo Announces CloudCamp @ Cloud Expo Silicon Valley


























