Service Platform
VMware Cloud Director hybrid cloud platform enables the integration of different cloud environments and on-premise vSphere-based data centers, with customers having the freedom to configure them as they please.
In Cloud Director, it is possible to quickly create new vApps, virtual machines, catalogs, and NSX network services with just a few clicks.
The powerful Cloud Director API allows for the automation of management operations. Cloud Director API support is available for popular Infrastructure As Code software, such as Ansible and Terraform.io.
Different privileges, groups, and roles can be assigned to users and configured according to their needs.
Secure two-factor authentication is supported using AzureAD, Cisco DUO, RSA SecureID, or other SAML and OAuth-based authentication solutions.
Servers
Our cloud service is located in our Endla Street data center. To ensure maximum availability, we keep servers in three separate HPE Synergy 12000 Frame systems, with all nodes duplicated. The Synergy Frame system is powered by six redundant power supplies connected to different UPS units, ensuring smooth operation even in case of power outages or failures. The WaveCom cloud uses HPE Synergy 480 G10 servers equipped with Intel® Xeon® Gold 6142 2.6 GHz processors. Data is stored in different next-generation NVMe Gen4 storage systems capable of millions of IOPS. The storage systems are connected to a redundant 32Gb FC SAN network.
The high-availability VMware vSphere Enterprise Plus software-defined data center provides the highest reliability, efficiency, and ease of use, with built-in high security. The WaveCom cloud service has no interruptions even during vSphere host server maintenance and updates. During maintenance, virtual machines automatically move to another server using the VMware vMotion solution, without the operating system noticing or any noticeable impact on services. In case of a failure of a single server or an entire server cabinet, virtual machines are immediately launched on other servers in the cluster without any data loss.
Netrwork
The VMware NSX-T network virtualization and security platform provides a true Software-Defined Data Center (SDDC) experience.
The updated NSX-T uses the GENEVE encapsulation protocol, which allows for better latency in distributed networks compared to VXLAN.
For multi-site networks, the NSX-T two-tiered Tier 0 and Tier 1 distributed routing model keeps latency low, with all network segments provisioned automatically.
The NSX-T security platform combines network and security functions, allowing for the automated management of zero trust model L2 or routed micro-segmented networks and services across different data centers at the virtualization level.
The NSX-T platform has a built-in intelligent vertical Edge gateway firewall that protects against external threats, and a horizontal distributed firewall that protects internal traffic. NSX-T allows for the simultaneous application of security policies to all applications running in the cloud, which helps optimize transport nodes. This can be dynamically applied to each workload based on application attributes and user-based tags.
The NSX-T Edge Gateway allows for the use of SNAT and DNAT functions to route ports and connect to the Internet. L2 and IPSEC VPNs provide secure access to either internal networks or specific applications.
The integrated AVI Advanced Load Balancer solution directs external traffic between internal servers using various algorithms.
Each of our VMware ESXi host servers is connected to an 80GB aggregated network, which is connected to our duplicated Nexus 9300 100 Gbit/s core network switches. The powerful Cisco ASR 9902 routers, which duplicate the core network and balance network traffic, are located in different data centers and are also connected to various transit partners' different submarine cables for traffic out of Estonia. Our network traffic does not interrupt because customers' network gateways use the Cisco HSRP protocol. In addition to being 100 Gbit/s Arelion, each router is also connected to the 40 Gbit/s Citic Telecom external connections and the RTIX internet access point, where domestic traffic occurs.
Our network is protected against DDoS and other congestion attacks, which automatically detects and filters out unwanted and dangerous traffic, allowing servers to operate normally.
All virtual machines have a 20 GbE network connection to both Estonian and international networks.
Backup and instant disaster recovery
The updated Cloud Director Availability is a powerful yet simple tool for backup, replication, migration, and disaster recovery. It provides support against viruses, file system or database failures, and enables real-time management and automation of virtual machine and vApp backups in different data centers. This includes backups from local data centers to the cloud and vice versa, as well as from cloud to cloud.
With a single click, the service allows for the restoration of environments, even in case of a failure that affects an entire server room. The same solution can also be used as an on-premise to cloud DRaaS service, extending on-premise VMware systems to our Cloud data center. The free on-premise Availability software includes an L2 VPN solution for connecting cloud networks.
.
We use VMware's flexible replication technology to back up data to our offsite data center at a frequency determined by the client, with the minimum frequency being one minute. In case of an emergency, the offsite data center takes over from the primary data center.
To restore processes, more than one RPO (recovery point objective) rule can be set simultaneously. Up to five different RPO parameters can be used to build one recovery process. An example of an RPO rule is: 10 points with a 10-minute interval + 10 points with a 1-hour interval + 2 points with a 3-day interval + 2 points with a 2-month interval.
In the offsite location, an entire data center or a single virtual machine can be restored, and the "Rewind" button allows for virtual machines to be moved back in time by weeks. Once a suitable recovery point is found, the virtual machine can be moved back to the onsite location.
In 2021, AS WaveCom was awarded the Disaster Recovery as a Service Provider accreditation after a VMware audit, which is held by only 40 VMware partners worldwide.
Tanzu Kubernetese clusters
VMware Tanzu Kubernetes is a next-generation infrastructure-as-code service that enables the creation and management of high-availability microservices-based clusters and applications, ensures Kubernetes consistency across different environments, and manages all clusters from a single controller.
TKG Standard Runtime is primarily targeted towards end-users and developers and offers an advanced feature set along with simplified cluster lifecycle management. This makes day-to-day operations easier and faster than ever before. Users no longer need to have specialized knowledge of creating and managing Kubernetes clusters. When creating a Kubernetes cluster, all steps are taken at once: network, security, load balancing, etc. At the same time, necessary resources and access policies can be easily set.
The NSX platform provides context-aware security policies for managing virtual routers and firewall rules, ensuring the utmost security in networks.
App Launchpad
End-user applications are becoming increasingly complex, which is why cloud service providers are developing simpler and less time-consuming services. App Launchpad is aimed primarily at cloud service consumers, especially developers who focus less on cloud complexity and more on application creation. In App Launchpad, developers can launch virtual machines with preconfigured applications as well as Kubernetes container applications in just a few seconds.
App Launchpad provides end-users access to a VMware-validated application environment. The user interface displays VMware Marketplace applications, including Bitnami by VMware preconfigured applications, for which there is a detailed user guide on the Bitnami by VMware website. Common applications such as LAMP, Nginx, Tomcat, Node.js, Grafana, Jenkins, RabbitMQ, Cassandra, GitHub, various SQL servers, etc., are all available. In addition, there are many other developer tools, such as content management, customer relationship management, and e-commerce solutions.
App Launchpad also features a collection of operating system templates visible in the Featured Applications section. Clients can also view VMware Marketplace applications and operating system templates from their Cloud Director Libraries page, where they can quickly search for the appropriate application or template.
Veeam Backup Solution
Backing up data is a good way to keep it for a longer period. The Cloud Director Availability solution, which uses VMware vSphere replication technology to replicate virtual machines, offers efficient backup storage for up to a few weeks. For longer periods, we offer our customers to use the Veeam backup solution, which has no time limits for backup storage. To achieve the best fault tolerance for their services, it is recommended to combine backup and replication, ensuring that data/services are protected in case of any incidents.
All our backup repositories are now immutable. This means that our customers' data now has an extra level of protection against ransomware attacks, altering or deleting. Immutability prevents any changes to or deletion of backup files within a certain time period. This period depends on how long the customer has set for backup retention.
We use SSD repositories for backups up to one month, and SSD/SAS hybrid storage for longer periods. This ensures both backup and restoration times are extremely fast.
The solution is very easy to use and is managed through the VMware Cloud Director environment, where the customer can manage their virtual server backups through the Veeam backup solution.
Backups are usually made periodically, for example, every day at a certain time. To create a backup, a "snapshot" of the virtual server is taken, during which the virtual server files and disks are copied to the backup disk array. Backups are generally made for a longer period of time with a 1x "full backup" (for example, on one day of the week) and "incremental backup" for the remaining time, during which only the blocks that have changed on the virtual server disk are backed up. This reduces unnecessary network and disk array load in the infrastructure and saves time required for backup.
If necessary, the customer can restore a single file or an entire virtual machine from their preferred backup point.
In Wavecom's public cloud, you have unlimited resources and opportunities
WaveCom invites you to try the cloud server service free of charge for one month. Applying for one month free service contact us!