0

The Ultimate Guide to On-Prem, Cloud, and Hybrid Datacenter Architecture

There is a common requirement to migrate datacenter from on-premises to cloud.

During my consulting career, I led several on-premises datacenter migrations. Additionally, these projects targeted financial, utilities, and transportation organizations.

To give you a big-picture view, I outline the datacenter structure.

The datacenter structure includes racks, power bus, cooling towers, networking gear, air handling units, backup generation, and water storage. This layout supports power distribution, environmental control, and resilience. Understanding how these elements interact helps operators plan capacity and respond to changes.

Within each rack, components such as network switches, cable management, servers, and cooling modules exist. Designers also consider cold air intake, cold plates for CPU and GPU cooling, cold liquid supply, and fan modules to optimize airflow and temperature.

The business drivers for datacenter migration include scalability, high availability, disaster recovery, backup and recovery, resilience, security, compliance, and cost optimization.

On-premises datacenter architecture:

  1. Infrastructure layers: storage area network (SAN), network attached storage (NAS); networking; servers and virtualization; high availability (HA) and disaster recovery (DR), backup and recovery, etc.
  2. Security architecture: firewalls, network segmentation, identity access management (IAM), Multi-factor authentication (MFA), Active Directory (AD), Lightweight Directory Access Protocol (LDAP), etc.
  3. Operational model: procurement lifecycle, capacity planning, maintenance & patching, etc.

Cloud datacenter architecture:

  1. Cloud service models: Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS) and more such as DBaaS, iPaaS, etc. SaaS offers everything from infrastructure to applications; PaaS offers platform except applications; IaaS offers infrastructure up to OS, database, security and applications are managed by the client.
  2. Most cloud platforms provides public, private and community cloud services.
  3. Cloud-native infrastructure concepts include elastic compute, object storage, managed services, containers & Kubernetes, serverless, etc.
  4. It’s worth to create datacenter map to outline datacenter distribution of an organization.
  5. Cloud landscape starts from enterprise subscription, tenant AD and management group. A general structure can include corporate management group, core services including network, security, shared services and tools, IT-managed and self-managed management group, etc.
  6. Useful links: Cloud Infrastructure Map, Azure Region Map, Infrastructure as Code (IaC), Terraform and Bicep.

Hybrid and multi-cloud architecture:

  1. Hybrid matters since it gains benefits from both on-premises and cloud. Some of the enterprise services can’t cross the border based on regulation needs, e.g., municipality services, while cloud services offers scalability, standardized HA and DR, backup and recovery services.
  2. Integration pattens includes VPN / Express Route / Direct Connect, identity federation and data synchrization
  3. Multi-cloud strategy may avoid vendor lock-in, better portability but may bring in governance complexity.
  4. Following diagram illustrates a hybrid datacenter structure. Left hand side is on-premises datacenter, including primary site and DR site; right hand side is cloud datacenter, including primary and DR datacenter, along with multi-cloud connectivity.
Hybrid Datacenter Structure

Migration strategy and challenges:

  1. Methodology: Five-step consulting process: Assessment, Planning, Development, Transition and Improvement.
  2. Migration map, HA and DR, backup and recovery, environment consolidation, database upgrade or migration, application upgrade and connection.
  3. Ecosystem migration: API integration, file-based / SFTP integration, streaming / Kafka.
  4. Approaches: re-host, refactor, re-platform, re-purpose.
  5. Challenges: environment consolidation, legacy migration, downtime risks (NZDT), security and organization change management.

Security, governance and compliance:

  1. Identity Access Management (IAM), AD, AAD, MFA, RBAC, Zero Trust architecture, etc.
  2. Network security: hub-spoke architecture, network segmentation, WAF, DDoS, Bastion host, etc.
  3. Data protection: at rest (database encryption, secure storage) and in-transit (TLS 1.2+, https, private link, Express Route, VPN).
  4. Performance and monitoring: SIEM (Splunk, Dynatrace, Datadog), Threat detection, MS Sentinel, MS Defender, etc.
  5. Standardize resources: naming convention, tagging standard, resource lifecycle.
  6. Infrastructure as Code (IaC): auditable, rollabck, consistency

Cost Management:

  1. Cloud cost management maturity level: cost visibility, optimization, rightsizing for VM, storage, snapshot, database, etc.
  2. Cost goverance: FinOps KPI and TCO comparison
  3. Automation resource lifecycle management
  4. Commitment discount
  5. Storage cost optimization: hot, cool and archive

Lionsgate Software consultants have been working on datacenter migration projects for many years and gained experience from both public and private sectors. Should you have any questions on datacenter migration, design and implementation, please feel free to contact us.

Leave a reply