Jump to content

Recommended Posts

Posted

If you don't want the niceties of AD and most of your server side software is cloudable this is doable. Just remember if your net goes down you may as well just leave till it comes back up.

 

Don't bother with dhcp in the cloud, certain core stuff can just be run off the core switch. If you are a large site and don't have managed network gear/leave it to Google you get what you deserve.

 

If you have chrome books or o365 with in tune then you can pull this off from a client managment point of view. You do not have the power of ad but you have enough for most things.

 

Some stuff just needs a server if it is not cloudable like papercut print managment, you can rent expensive cpu time to do it off site in the cloud or just deal with it like a sane person and take it into consideration. When replacing the software/solution.

 

All cloud is possible but don't be an idiot, thinking it will solve all problems ever. Many group thinky sheep of schools in NZ lost themselves half a day while Google realized their Gaps platform had melted, given the reliance even if they had a backup net link (they did not) they were stuffed due their complete reliance.

Posted

A previous employer of my other half did this.

 

I am sure it has been said already, but you have to have sufficient bandwidth and you have to have backup line(s) and you need to think about timing.

 

Day 1 switch over was a cockup done just before month end without sufficient bandwidth for the entire accounts department to be hitting it hard.

Posted

Do you really trust your main internet and failover lines? We have an excellent connection, but I really wouldn't want to be completely reliant on it.

 

As it is, all we would lose is internet and external e-mail. Lessons could go on as normal as could admin, planning, financials etc.

 

I'm prepared to go cloud for certain functions, but no servers? Not in the near future.

Posted
We had a massive server failure, I installed a little free dhcp server on a really old desktop while I fixed the server. The staff had no idea we had no server as they could still access their files using Google File Stream. It was a real eye opener, and what with Sims 8 primary being web based, being server-less is the direction we are heading.
Posted
Do you really trust your main internet and failover lines?

Sure. Why not. We use two different companies, both using 1GB/s. One connection goes to the telephone exchange in town and the other goes to another town a few miles away.

If one connection breaks the other fails over. Had 100.00% uptime - more than our servers !

  • Thanks 1
Posted
Do you really trust your main internet and failover lines?

 

We were also offered a 4g hub for next to nothing, obviously would not want the entire school connecting through that, but one or two dotted around the school would be find for teachers to keep teaching, if both lines went down.

Posted
Sounds like you might do yourself out of a job

This sounds very much like the way Microsoft approaches its products, make everything more complicated than it needs, then sell courses and exams to teach everyone how to use your overly complicated systems, and then make sure the certificates expire after a few years. Its a win win win for MS.

 

Sure there will be less back-end stuff like updates and backups, but I hate those parts of my job anyway.

 

Just my opinion.

  • Thanks 1
Posted
Just looking at the AWS Fortigate service, problem a) there's 17093 price options, and that's before you add in data transfer costs, problem b) how much?!?
Posted

I don't think I'm doing myself out of a job, as someone will still need to manage the onsite equipment, support staff with day-to-day questions, maintain user accounts in Mathswatch etc, train staff on new developments, manage strategy, support DPO, etc. I might be doing my technician out of a job though.

 

If the Internet connection were to go down, I agree we would be royally stuffed but that's the situation we're in already - app and print servers are remote, SIMS is remote, Google Mail, most teaching resources in Google Apps, Mintclass, most learning resources online in Mathswatch/Activelearn/GCSEPod, etc.

Posted (edited)

@Norphy and others raise good points about services that will need some kind of local management. Whether or not you need AD is open to interpretation - so many things "just assume you have it" these days that I would wonder.

 

Other than that, I think we're certainly on the cusp of being able to go all-in on cloud. I do know that if I was designing a green-field infrastructure for a new college somewhere it would look quite different to what we have here which is designed about moving a "long tail" of on-site services to a balanced cloud/local setup.

 

There's a risk with going cloudy sure, the whole "what happens if Gapps/O365 fails" concern and that's a risk that should be considered. However there needs to be an honest comparison of that risk to the risk of local services falling over too. I'm pretty good at Exchange, for example, I've supported it since Exchange 5.0 was brand new, I've been a Microsoft MVP for Exchange, I've played with the source code... but you know what, however good I think I am, however good I actually am... Microsoft themselves with Exchange Online in Office 365 are much much better. Microsoft themselves are running it on better infrastructure than the college could ever afford. Microsoft themselves are able to offer my users 100Gb mailboxes that I'm a long way from being able to do locally. Microsoft themselves can provide better experience for my remote users. Microsoft can offer my college a more consistent experience and continuity of service/support that doesn't rely on me never leaving.

 

You'll need to think about things like dual internet connections and as I see people have made comments about "putting yourself out of a job", I'm not worried about that here as we move stuff to the cloud; instead my job and that of my infrastructure team is evolving and that's just fine.

Edited by Roberto
Posted (edited)
Whether or not you need AD is open to interpretation - so many things "just assume you have it" these days that I would wonder.

 

We've been looking at services like Jumpcloud - cloud-based Active Directory / LDAP. My aim is to go "all cloud based" at some point, the issue is in the detail of how we transition our setup and our users to that.

 

My plan at the moment is to have all file areas (both shared folders and user's Windows / Mac Home and Desktop folders) mirrored to Google Drive. I've started doing this with some shared folders (our rather heafty Media drive, containing a decade's worth of photos and videos), mirroring with Insync, and it seems to be working well so far. Hopefully, I'll sort out more shared file areas and user folders over the summer. We'll still need a local file server for this at the moment, of course, but I figure it's the way to start - get people used to the idea that everything they do gets mirrored to Google Drive, then we can start moving functionality to cloud-based services.

Edited by dhicks
Posted

The people who are doing themselves out of jobs are *always* those that don't move with the times.

I've now got loads of experience with running failover services in the cloud and redundant connections. Next I'm learning Kubernetes to get some better value.

Meanwhile the died in the wool Windows Admins will be getting their redundancy emails or retraining to change toner cartridges.

Posted
The people who are doing themselves out of jobs are *always* those that don't move with the times.

I've now got loads of experience with running failover services in the cloud and redundant connections. Next I'm learning Kubernetes to get some better value.

Meanwhile the died in the wool Windows Admins will be getting their redundancy emails or retraining to change toner cartridges.

 

Agreed.

 

Going serverless doesn't mean there's no job, it means the job has changed. "Serverless" means your servers are in the cloud, either running typical services like AD, or moving to container/cloud based solutions using something like Kubernetes or services like Azure AD Premium.

 

I'm working towards a serverless school too - all users are now on OneDrive redirection, mail in Office365, now looking at moving shared drives into SharePoint. The next step will be looking at whether or not to ditch AD for Azure AD, or ship it into Windows Servers hosted in Azure.

 

There's most definitely a job still there.

Posted

Also to those of you who think I'm doing myself out of a job, do you really spend 35 hours a week maintaining your Windows PCs and servers?

 

Just today, I have been setting up Mintclass, prepping for our next GDPR healthcheck audit, assisting Dep Head with timetabling, working with some teachers to put together the new Year 7s' IT induction, training a staff member in using Google Forms, giving a new staff member an IT induction and no doubt 50 other things I've already forgotten. All of those tasks would still need doing even if we go serverless.

Posted

Obviously email should be cloud, no one is crazy enough to run Exchange.

 

My issues are a) bandwidth, I have 4Gbps to each server by default. b) reliability, switch uptime is in years, probably 5 9s (5 min downtime per year), c) cost: buy some drives, put them in a server, no need to worry about cost.

 

You're not saving money on switches or routers, just servers, and it's not magically cheaper to pay to rent someone's server than to buy your own.

 

If 50% of your users aren't in the building, makes sense, but 99% usually are.

 

Makes sense to have cloud VM failover, off site DR etc, and makes sense to containerize your servers, just next step from VMs. Spend time automating everything.

 

Focus on systems that need to scale up and down a lot, not sure what that is for schools, not like most things are taxing, basically your only problem is your database gets larger than your ram/ssd cache and you've already maxed it out.

Posted (edited)
You're not saving money on switches or routers, just servers, and it's not magically cheaper to pay to rent someone's server than to buy your own.

 

I'm not proposing renting someone else's servers, I'm proposing not having any servers.

 

If 50% of your users aren't in the building, makes sense, but 99% usually are.

 

Given our existing reliance on web resources and BYOD, I don't think the percentage of people in the same building is relevant, except for bandwidth and that is an easily-soluble problem.

Edited by enjay
Posted
Obviously email should be cloud, no one is crazy enough to run Exchange.

Obviously. We run our own Exchange server. I've been doing it since 2000.

 

One day we'll move it all to the cloud but I'm in no hurry. It's just swapping one problem set for another.

Posted
I'm not proposing renting someone else's servers, I'm proposing not having any servers.

 

Well, you are renting someone's servers, just not in a direct way, there's a server someone that you're paying to use in some way.

 

At least now Microsoft and Google will try to get kids used to their products by giving them away for free, instead of the old method of Microsoft selling them cheaply to you

Posted
I'd rather Microsoft, Google, and Amazon dealt with all the problems that surround hardware lifecycles, warranties, failures, networking, network security etc personally - there might be a slightly big and scary cost but it's all value added.
Posted
Seems like it's way easier to accidentally configure a cloud server wrong and leave all your data open, at least when it's internal the whole internet can't attack it
Posted (edited)
Seems like it's way easier to accidentally configure a cloud server wrong and leave all your data open, at least when it's internal the whole internet can't attack it

 

If you're in a position where that's a possibility you haven't thought about your cloud design enough - Azure and Google Cloud (and I assume AWS) have very restrictive network security groups by default. If you prefer you can make them private only and force them to go through a cloud-based firewall. There are plenty of vendors (like Palo Alto, Sophos, Cisco) that provide templates for firewalls on Azure for instance.

 

Our NHS org is lifting and shifting as much of our stuff out of our datacenters and into Azure as possible as of about 6 months ago. We're only allowed to purchase datacenter hardware in very specific circumstances now, anything new should be "cloud first" (Azure in our case).

Edited by Blue_Cookeh
Posted (edited)
Also who do you trust to keep hackers out or block nasties, a few techies reading up on what patches and threats they should apply to their servers, or a team of security experts who only deal with these issue. Edited by TwistedHelixis
Posted

Depends how managed your service is. So many reports of massive databases with no security by default.

 

But in general: local server, can be accessed only by people in the building. To accidentally open it up to the world requires config on the router

Remote server: you have to open it to some part of the world to use it. Either you're forcing everyone to use a vpn type system, client certs to connect, or you're 1 bug away from serving your database to anyone who asks for it

Posted
Obviously. We run our own Exchange server. I've been doing it since 2000.

One day we'll move it all to the cloud but I'm in no hurry. It's just swapping one problem set for another.

You'll find you swap one problem set for a problem set a tiny fraction of the size. We moved from Exchange to gmail 9 years ago. I've not replaced a single power supply, disk or server in that time. I've not needed to increase capacity, power it down or call in a warranty. I've not needed to patch it or upgrade it. I've not even needed to pay for it. User training is simplified as people use gmail at home. Moving off Exchange is really a no brainer for schools. At least it was nearly a decade ago.

 

 

Seems like it's way easier to accidentally configure a cloud server wrong and leave all your data open, at least when it's internal the whole internet can't attack it

I'm struggling to think how you got this idea because I've recently setup a cloud SQL service in Google. When I did it a few weeks ago it would only allow login with a security key. You would have to go out of your way to set a password. It won't allow connection from any old ip address - you have to explicitly configure this, it automatically chose a hardened distribution, it automatically configures security updates (pre tested so I don't have to) and it automatically chose the most sensible environment defaults. Could you explain how you found it easier to misconfigure compared to doing it all by yourself?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...