Infrastructure & Cloud Topics
40 topics
- Infrastructure & Cloud
Cloud Well-Architected Framework
A vendor-common design governance framework that repeatedly diagnoses and improves cloud architecture risks from the six pillars of operational excellence, security, reliability, performance efficiency, cost optimization, and sustainability.
- Infrastructure & Cloud
Data Center Technologies for Large-Scale AI Services
Low-latency and scaling technologies (RDMA, InfiniBand, NVLink, distributed training) for hyperscale AI data centers, and DCI (DWDM, OTN) technologies.
- Infrastructure & Cloud
Information System Hardware Sizing Guideline (TTAK.KO-10.0292/R3)
A standard guideline that sizes HW capacity for servers, storage, and the like based on performance indicators through workload analysis → method selection → adjustment → calculation and verification.
- Infrastructure & Cloud
Erasure Coding and Data Durability in Distributed Storage
An essay-style overview of erasure coding, an MDS error-correcting technique that encodes data into k data + m parity fragments (n=k+m total) and recovers it from any k of them: principles (generator matrix, GF arithmetic), architecture, (k,m) parameter trade-offs, comparison with replication, rebuild cost with LRC/regenerating codes, integrity scrubbing, f4, S3, Ceph and HDFS-EC case studies, and storage protection policy design from a Professional Engineer's perspective.
- Infrastructure & Cloud
Cloud Service Models and Deployment Models
A comparison of the abstraction and responsibility scope of service models (IaaS, PaaS, SaaS) and the ownership and control forms of deployment models (public, private, hybrid, community) from the perspective of NIST SP 800-145 and the shared responsibility model, outlining how to select combinations suited to workloads and regulations.
- Infrastructure & Cloud
Cloud-Native Traffic Management Based on the Kubernetes Gateway API
A professional-engineer essay-style overview of the role-oriented resource model of GatewayClass, Gateway, HTTPRoute, and GRPCRoute, the controller and data-plane coordination principles, standardization, multi-protocol support, and cross-namespace trust compared to Ingress, and TLS, observability, canary, and gradual-migration strategy.
- Infrastructure & Cloud
Caching Strategy and Distributed Cache Design
A strategy for designing caches from a consistency perspective — the layered structure that holds copies of slow origin data in a fast tier, the read/write paths (Cache-Aside, Write-Through/Back), LRU eviction, TTL/event-based invalidation, and handling distributed-cache failures such as stampede, penetration, and avalanche.
- Infrastructure & Cloud
Financial Cloud SLA
The concept of an SLA and its key metrics (availability, RTO/RPO), and the differences between a general and a financial cloud SLA — domestic data residency, network separation, regulatory compliance, the shared responsibility model, BCP, and exit strategy.
- Infrastructure & Cloud
The Twelve-Factor App
A SaaS design methodology that separates configuration, resources, and execution environment from code and designs processes to be stateless and disposable to ensure portability, scalability, and operational automation, inherited and extended by containers, Kubernetes, and serverless.
- Infrastructure & Cloud
Virtualization
Virtualization, which logically abstracts physical resources — server virtualization (hypervisor), application virtualization, VDI, and containers; the VM/container trade-off; and the foundation of cloud and cloud-native.
- Infrastructure & Cloud
Auto Scaling
A cloud elasticity technology that automatically increases or decreases resources (horizontally and vertically) in response to load to optimize performance and cost.
- Infrastructure & Cloud
Kubernetes Operator Pattern
Organizes the structure, implementation, and operational strategy of the operator pattern, which extends the Kubernetes API with CRDs and controllers to automate application domain knowledge through declarative management and reconciliation loops.
- Infrastructure & Cloud
Cloud Native Architecture
This essay covers the principles, layered structure, security and operations, comparison cases, and phased-migration strategy of cloud native, which combines containers, microservices, declarative APIs, automation, observability, and elasticity to respond repeatably to change and failure.
- Infrastructure & Cloud
SECaaS (Security as a Service)
A model delivering security functions as a cloud subscription service. It provides up-to-date, expert security and collective defense with no upfront investment, while managing shared responsibility, SLAs, data sovereignty, and lock-in, and evolving toward Zero Trust-based SASE/SSE.
- Infrastructure & Cloud
eBPF-Based Kernel Visibility, Security, and Networking
This essay covers the execution model of eBPF, which attaches verifier- and JIT-processed kernel programs to hooks to dynamically extend networking, tracing, and security functions, along with maps, BTF, and CO-RE, its use in XDP, observability, and security, a comparison with traditional approaches, and a safe adoption and operations strategy.
- Infrastructure & Cloud
Disaster Recovery Strategy Based on RPO, RTO, and MTTR
This essay covers a disaster recovery strategy that defines RPO, RTO, MTTR, and MTD based on business impact analysis (BIA) and combines backup, replication, multi-region deployment, and recovery drills to control service disruption and data loss.
- Infrastructure & Cloud
Infrastructure as Code (IaC)
An approach that declares infrastructure's desired state as code for automated provisioning and management. Encompassing declarative and imperative styles, idempotency, state management, and security (secrets, Policy as Code), it forms the foundation of cloud-native operations, extending to DevOps and GitOps.
- Infrastructure & Cloud
Use of Private-Sector Cloud in the Public Sector
Procedures and baseline design for public-sector adoption of private-sector cloud, its usage architecture and CSAP certification, and evaluation criteria by SaaS/PaaS/IaaS type.
- Infrastructure & Cloud
Edge Computing
A distributed computing paradigm that performs computation, storage, and analysis on distributed resources near where data is generated, resolving latency, bandwidth, and privacy problems. This essay covers the layered structure spanning device, edge (on-device, near, far), and cloud and the principle of data gravity, ETSI MEC and 5G local breakout architectures, task-offloading decisions and orchestration based on lightweight Kubernetes (K3s, KubeEdge), hierarchical aggregation and disconnection-tolerant, resilient design, a comparison of latency, cost, and consistency trade-offs with the central cloud, application cases in smart factories, autonomous driving, immersive media, and smart cities, recent trends such as edge AI, federated learning, 6G, edge serverless, and confidential computing, and professional-engineer considerations including selective workload placement, security, operational complexity, and adoption roadmap.
- Infrastructure & Cloud
DaaS (Desktop as a Service)
The architecture of DaaS, which delivers desktop environments virtually from the cloud, its comparison with VDI, and its strengths in mobility, security, and centralized management.
- Infrastructure & Cloud
Sovereign Cloud
A cloud designed so that the storage, processing, operation, and control of data are self-contained within a specific country's laws and jurisdiction, guaranteeing data sovereignty across three layers—data, operations, and technology. An essay-style overview of why data residency alone is insufficient and must be combined with cryptographic-key sovereignty (HYOK/BYOK), access transparency, and open-standard portability; the background of jurisdictional conflicts such as the CLOUD Act and Schrems II; the three-layer sovereignty structure and reference architecture; a comparison of deployment types (domestic region, partner-operated, dedicated isolation, and domestically built standalone); and domestic and international trends and trade-offs such as GAIA-X and CSAP.
- Infrastructure & Cloud
GitOps — A Git-Based Declarative Operations Model
An operations model that declaratively stores the system's desired state in Git and has an in-cluster agent continuously reconcile the actual state (pull, self-healing)—achieving safe, reproducible deployments through curbing configuration drift, full auditability, minimal exposure of cluster credentials, and git-revert rollback, and forming the foundation of autonomous operations when combined with IaC, DevSecOps, and platform engineering.
- Infrastructure & Cloud
RAID (Redundant Array of Independent Disks)
A storage technology that combines multiple disks through striping, mirroring, and parity to gain both performance and fault tolerance—covering the trade-offs of RAID 0/1/5/6/10 levels, the write penalty and rebuild risk, and recent trends such as distributed RAID and erasure coding, and noting that RAID is not a backup and must be paired with DR.
- Infrastructure & Cloud
eBPF (extended Berkeley Packet Filter)
A programmable kernel technology that attaches verified sandboxed programs to kernel events—without recompiling or rebooting the kernel—to handle networking, observability, and security in a unified, high-performance way.
- Infrastructure & Cloud
Platform Engineering
An approach that productizes infrastructure, tools, and standards into a self-service Internal Developer Platform (IDP) and provides golden paths to lower developers' cognitive load and improve software delivery speed and stability—understood as a product and means for realizing DevOps and SRE at organizational scale.
- Infrastructure & Cloud
AIOps (Intelligent IT Operations)
An approach that applies big data and machine learning to IT operations to make anomaly detection, alert correlation, root-cause analysis (RCA), prediction, and automated response intelligent—shifting reactive operations to a predictive, autonomous model and shortening MTTR, where data quality and the design of phased automation and safeguards determine success or failure.
- Infrastructure & Cloud
Observability and OpenTelemetry
The system property of correlating the three signals—metrics, logs, and traces—via trace IDs to investigate even unknown failures after the fact, together with OpenTelemetry standard instrumentation, sampling, and cardinality governance strategies.
- Infrastructure & Cloud
Serverless Computing (Serverless / FaaS)
A model that delegates infrastructure operations to the provider and runs event-driven stateless functions (FaaS) and managed backends (BaaS) with usage-based billing and scale-to-zero—weighing cold-start, execution-constraint, and vendor lock-in trade-offs against workload characteristics.
- Infrastructure & Cloud
Fault-Tolerance Verification Based on Chaos Engineering
Organizes an experimental framework that uses controlled fault injection and steady-state hypotheses to verify and improve the fault tolerance, recovery automation, and observability of distributed systems.
- Infrastructure & Cloud
FinOps (Cloud Cost and Value Optimization)
Studies the FinOps framework, which connects cost to business value through visibility, allocation, optimization, and operation of cloud and technology spend.
- Infrastructure & Cloud
Service Mesh
Organizes the architecture and adoption strategy of a service mesh, which splits inter-microservice communication into a data plane and control plane to deliver traffic management, reliability, mTLS security, and observability consistently.
- Infrastructure & Cloud
Service Reliability Management Based on SLO, SLI, and Error Budget
Organizes how to measure service levels from the user's perspective with SLIs and SLOs and connect the error budget to decisions on deployment, incident response, and reliability investment.
- Infrastructure & Cloud
Key BCP Metrics and DRS Implementation Considerations
The RTO, RPO, RSO, and BIA metrics of BCP and key considerations for a DRS such as recovery level (Mirror to Cold), distance, replication method, and drills.
- Infrastructure & Cloud
Cloud Management Platform (CMP)
The definition, necessity, essential features, selection criteria, and expected benefits of a platform that centrally manages multi- and hybrid clouds from a single console.
- Infrastructure & Cloud
ELK Stack (Elasticsearch, Logstash, Kibana)
An open-source stack that analyzes large-scale logs in real time via Beats/Logstash (collection and transformation) → Elasticsearch (indexing and search) → Kibana (visualization).
- Infrastructure & Cloud
Kubernetes
An orchestration platform that declaratively automates container deployment, scaling, and operation — the Control Plane, Nodes, and core objects.
- Infrastructure & Cloud
Block, File, and Object Storage Access Methods
Comparison of block (SAN, high performance), file (NAS, sharing), and object (HTTP, large-scale archiving) storage in terms of access unit, interface, and scalability.
- Infrastructure & Cloud
Phased Audit of Cloud Migration Projects
Audit methods for the planning, design, migration, and operation phases of cloud migration projects, along with review items for suitability, security, data integrity, and cost.
- Infrastructure & Cloud
Guidelines for SaaS Adoption in the Public Sector
Risk-management principles and criteria (CSAP grades), security measures and security reviews, and service-level agreements (SLA) for safe SaaS use by public institutions.
- Infrastructure & Cloud
Storage Virtualization
A technology that abstracts distributed storage resources into a single logical pool — host-, network-, and array-based types, and block/file levels.