skip to content

Cloud Platform Concepts

What every provider sells under a different name: regions, accounts, identities, managed tiers, a private network and a bill — from the largest platforms to a one-command host.

on this pageshow

explore

questions

272 · 11 sections

An internal platform offers one service on a rented machine, a managed runtime, or a whole managed capability — what does each rung take over?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Each rung hands the provider more of the stack. A rented machine leaves everything above the virtualization layer to you; a managed runtime adds the operating system and runtime; a whole managed capability adds patching, scaling, backups and failover.

open as a page

You rent a virtual machine and separately use a managed database service — who applies operating-system security patches in each case?

level: juniorimportance: must knowfreq 82%
basics
~20 s

On a rented virtual machine you patch the guest operating system and everything above it. On a managed database service the provider patches the host and the engine, while the data, the accounts and the configuration inside it stay yours.

open as a page

A managed store reports that encryption at rest is enabled by default - which risk does that remove, and which does it leave?

level: middleimportance: must knowfreq 66%
basics
~20 s

Default encryption at rest protects bytes on the provider's media against drive loss, disposal or raw block access. It restricts nobody who calls the service: an authorized caller, and the provider holding the key, still get plaintext.

open as a page

A service moves from a rented machine to a managed runtime — why does that rung remove your access along with the work?

level: middleimportance: must knowfreq 64%
basics
~20 s

A provider can only promise an outcome it fully controls. Each duty a rung takes over becomes a guarantee made across many tenants at once, and any change you could still make by hand is state the fleet operator cannot assume.

open as a page

Why does a managed database tier disable certain engine extensions and tuning knobs, and what does that force on your design?

level: middleimportance: must knowfreq 62%
basics
~20 s

A managed tier exposes only what it can operate, persist and support for every tenant at once, so settings that need host access, load foreign code into the engine, or weaken the tier's own promises are withheld, and the work they would have done moves into your application.

open as a page

When choosing the region for a new service's first deployment, which input removes candidates outright and which ones are traded?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A residency obligation filters the candidate list before anything is compared: regions outside the required jurisdiction simply leave. Distance to users, the rate the region charges for the same service, and whether it offers what you need are then traded against each other.

open as a page

An edge location sits in front of your single region for far-away users - what can it absorb, and what must travel back?

level: juniorimportance: must knowfreq 68%
basics
~20 s

An edge location can terminate the connection and TLS, serve a cached response, issue a redirect, and make a cheap decision from the request itself. The authoritative dataset, durable writes and heavy computation still travel back to the region.

open as a page

What separates a region from an availability zone inside it, and what does each boundary isolate?

level: juniorimportance: must knowfreq 88%
basics
~20 s

A region is an independent geographic deployment unit; the availability zones inside it are separate facilities with their own power, cooling and network paths, a metro hop apart. The zone boundary isolates a facility failure, the region boundary isolates everything larger.

open as a page

A mobile backend serves users a continent away and feels slow — what latency floor does that distance set, and what cannot fix it?

level: middleimportance: must knowfreq 70%
basics
~20 s

Distance fixes a round-trip floor: light in fibre travels about 200,000 km per second and real paths are longer than the map, so a far continent costs roughly a tenth of a second per round trip. Bigger machines and more instances cannot shorten it.

open as a page

Why does terminating the client connection at a nearby edge location cut time to first byte for an uncacheable response?

level: middleimportance: must knowfreq 58%
basics
~20 s

Connection setup costs several round trips before any request bytes move. Terminating nearby pays those against the short hop, while the forwarded request crosses the long distance once over a connection the edge already holds warm.

open as a page

A team runs everything on the single provider account they opened - what does that one account bundle together?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A provider account is one container bundling four things at once: one isolation boundary, one bill, one pooled set of usage ceilings, and one set of administrators. Every resource you create lives inside exactly one account.

open as a page

Your staging ledger shares production's account, kept apart only by a name prefix and an environment label — why is that not an isolation boundary?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A name prefix and an environment label are data every caller in the account can read or ignore; nothing enforces them. Isolation, quota and billing attach to the account, so only a separate account makes the split real.

open as a page

A side project's single account now carries three products - which symptoms say that one account has been outgrown?

level: middleimportance: must knowfreq 58%
basics
~20 s

Three symptoms matter: products contending for ceilings counted once for the whole account, a bill nobody can split by product, and a change or mistake in one product reaching the other two. Each follows from the account being one shared container.

open as a page

An internal platform issues each team a new cloud account from a template — what does that account land with before any workload runs?

level: middleimportance: must knowfreq 62%
basics
~20 s

A vended account arrives with its baseline already applied: audit and platform logs delivered to a central collection account, a private address range allocated from the organisation's plan, guardrail policies in force above it, and a named owner recorded.

open as a page

A policy set above the account refuses your action although you hold full administrative permissions inside it - how does that work?

level: middleimportance: must knowfreq 65%
basics
~20 s

A permission ceiling above the account subtracts from everything inside it. The effective permission is the intersection of the ceiling and the account's own grants, so an administrator can only grant within what the ceiling still leaves.

open as a page

A workload on a rented machine stores no platform key anywhere, yet its API calls are authorized — where does its credential come from?

level: juniorimportance: must knowfreq 62%
basics
~20 s

The platform issues it on demand. An identity is attached to the machine, and a credential endpoint reachable only from that machine hands the workload a short-lived credential set, which is replaced before it expires.

open as a page

In a cloud platform's access model, what is a principal, and how do human, group and workload principals differ?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A principal is the identity a platform authenticates and names when it decides whether a call is allowed: a person's login, a workload such as a batch job or service, or a group that holds grants for the humans inside it.

open as a page

A long-lived platform access key is found in a public repository — why is issuing a replacement key not the first move?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Creating a new key does not disable the old one. Revoke the exposed credential first so it stops authenticating immediately, then issue replacements, then read back what the leaked credential actually called before it was stopped.

open as a page

Why do engineers sign in to a production cloud account through the company directory instead of each holding a local platform login?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Federated workforce logins keep one copy of each person, in the company directory: cloud access follows group membership, and disabling the directory account cuts every federated sign-in at once. Local platform logins are extra credentials nobody remembers to delete.

open as a page

A team can create workloads and attach any existing identity to them, but holds no administrator permission — why is that grant administrator access anyway?

level: middleimportance: must knowfreq 58%
basics
~20 s

Attaching an identity to a workload means running your own code as that identity. If any stronger identity can be attached, the team can launch code that borrows its permissions, so the attach grant is worth the strongest identity it reaches.

open as a page

A nightly cleanup job runs about twenty minutes - why does an event-driven runtime rule itself out, and which tier fits?

level: juniorimportance: must knowfreq 70%
basics
~20 s

An event-driven runtime caps how long one invocation may run, so a twenty-minute job is stopped part-way. Put it on a tier that keeps a process alive: a managed container platform running it on a schedule, or a machine that stays up.

open as a page

You are moving a measured search service onto rented machines — which numbers set the machine size, and which do you ignore?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Size from the service's own observed processor, memory, disk and network use over a full demand cycle, taken at a high percentile with headroom added. The specification of the server being replaced records a purchase decision, not the workload, and is ignored.

open as a page

A launch request for a new machine is refused in one zone — how do you tell an empty capacity pool from an administrative ceiling?

level: middleimportance: must knowfreq 62%
basics
~20 s

A refused launch means one of two shortages: the provider has no machine of that shape free in that zone, or your account is not permitted more. A ceiling is a number you can look up; pool depth is never published.

open as a page

Machine families are weighted toward processor, memory, local disk or accelerators — which measurements pick one?

level: middleimportance: must knowfreq 58%
basics
~20 s

The ratio in a measured profile picks the family — which resource saturates first while the others idle. Memory-heavy work wants a memory-weighted family, compute-bound work a processor-weighted one, heavy local input and output a disk-weighted one, dense parallel numeric work an accelerator.

open as a page

A reporting service has a flat weekday base and a sharp month-end peak - which purchase posture suits each part of that demand shape?

level: middleimportance: must knowfreq 62%
basics
~20 s

Buy the always-on base with a term commitment, serve the month-end peak with metered on-demand capacity, and put only interruption-tolerant extra work on reclaimable capacity. Price each layer of the shape separately rather than picking one posture for the fleet.

open as a page

An external scanner reports that your receipts store is readable by anyone on the internet — which grant produces that, and what was not leaked?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A grant written on the store side — at store or object level — naming any caller as allowed to read produces public access. Nothing was leaked: the store is doing exactly what its policy says, so no credential was stolen and no defect was exploited.

open as a page

An object store advertises durability with many nines, but ingest requests fail for an hour - which promise did that figure never make?

level: juniorimportance: must knowfreq 76%
basics
~20 s

Durability is about bytes surviving; availability is about bytes being reachable now. A many-nines durability figure estimates how unlikely it is that the store loses an object, and says nothing about an hour of failed requests.

open as a page

Which storage shape fits a transcoder's scratch space while rendering, and which fits the finished videos many clients fetch?

level: juniorimportance: must knowfreq 84%
basics
~20 s

Scratch belongs on a block volume: it attaches to one machine and behaves like a local disk, so seeks and in-place writes are cheap. Finished videos belong in an object store, fetched by key over HTTP by any number of readers.

open as a page

Weekly-read application logs are moved to the coldest archive storage tier to save money — what goes wrong?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A colder tier discounts rent by charging separately for reads and by making them slow. Data read every week pays a retrieval charge every week and waits for a restore each time, so the bill usually goes up, not down.

open as a page

A job overwrote every document in a versioned object store with a corrupt render — how do you get the originals back?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Versioning kept each pre-overwrite copy as a previous version under the same key, so recovery is promoting that version back to current, key by key. Nothing is restored from a backup, and every retained version keeps being stored and charged.

open as a page

A stateless subnet filter fronts a workload whose own rule set is stateful — what does each need written for return traffic?

level: juniorimportance: must knowfreq 74%
basics
~20 s

The stateful rule set needs only the request direction written; it matches the reply to the flow it already accepted. The stateless subnet filter judges each packet alone, so the reply needs its own rule allowing the client's ephemeral port range.

open as a page

A managed entry point keeps its public address when the machines behind it are replaced, so what makes that address a separate rented resource?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The address is allocated from the platform's pool and held by the entry point resource, not by any machine. It outlives instance replacement, is usually charged while you hold it, and goes back to the pool only when you release it.

open as a page

What actually makes one subnet in your private cloud network public and another one private?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Routing, not the name. A subnet is public when the route table it uses sends traffic for destinations outside the network to a target that reaches the internet. Private means no such route exists. The label itself configures nothing.

open as a page

Why would a team reach a managed store through an endpoint inside its own address range instead of the store's public address?

level: juniorimportance: must knowfreq 58%
basics
~20 s

An endpoint inside your own range keeps the call on the provider's internal network: the workload connects to an address in one of your subnets, so the request does not take the public path and the subnet needs no route to the internet.

open as a page

A batch job in a subnet with no internet route must call partner APIs without ever being reachable — what do you add?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Two things: a default route on that subnet naming an address-translating gateway, and the gateway itself on the routed side. Outbound flows leave translated; unsolicited inbound packets match no translation entry, so nothing outside can open a connection.

open as a page

What does a recovery point objective promise about a managed service, and what does a recovery time objective promise instead?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A recovery point objective caps how much recent work the business accepts losing, measured backwards from the failure. A recovery time objective caps how long the service may stay unavailable, measured forwards from the same moment.

open as a page

A provider publishes an availability commitment for a managed service — is that a guarantee, and what does it pay you when missed?

level: juniorimportance: must knowfreq 72%
basics
~20 s

An availability commitment is a contract term, not a promise the service stays up. If the provider's own measurement falls short, the remedy is a service credit against your bill for that service, which you normally have to claim.

open as a page

A checkout service runs in three availability zones and one zone goes dark at peak — what keeps serving, and what had to be true beforehand?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Instances in the two healthy zones keep serving, but only if the traffic entry point health-checks the dead ones out, the writable data copy is not stranded in the lost zone, and the survivors already had spare capacity.

open as a page

During a provider incident, running workloads keep serving but no new instance launches - which half of the platform is degraded, and what stops?

level: middleimportance: must knowfreq 62%
basics
~20 s

The control plane - the platform's management API that creates, changes and deletes resources - is degraded, while the data plane that carries request traffic keeps serving. Launching, scaling, replacing and failing over stop; already-running capacity does not.

open as a page

Why does a standby replica of a managed store give a near-zero recovery point yet fail to protect against a mistaken bulk delete?

level: middleimportance: must knowfreq 62%
basics
~20 s

A replica copies committed writes, so it reproduces the mistaken delete as faithfully as any other write. Only a point-in-time restore rewinds the data to a moment before the mistake, at the cost of a much longer recovery time.

open as a page

What does a label attached to a cloud resource actually change about the bill, and what does it not change?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A label copies a key-value pair onto the charges a resource generates, so the provider's detailed cost report can be grouped by team, environment or service. It changes reporting only: the rate, the metered quantity and the total are unaffected.

open as a page

A monthly cloud budget threshold is crossed at noon — what does crossing it actually do, and what does it not do?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A budget threshold is a notification rule, not a spending cap. Crossing it emits a message about money already spent. It does not pause running resources, block new ones, or cancel anything, and the figure it fired on lags the usage.

open as a page

On a cloud transfer bill, a service uploads large video masters and ships finished renditions out to viewers — why is only one direction charged?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Transfer is metered by direction. Bytes arriving from outside are normally unmetered; bytes leaving toward the internet are priced per gigabyte after a small monthly allowance. So delivery to viewers is the charge, not the upload of masters.

open as a page

A managed service with no hourly rate is the largest line on your cloud bill — which pricing dimensions does a provider meter?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Providers meter usage along several independent dimensions: running time, requests served, gigabyte-months stored, gigabytes moved, and provisioned capacity units. One service can charge on all of them at once, so a large bill line exists with no hourly rate anywhere.

open as a page

After you delete a virtual machine, the bill barely moves - which charges outlive the machine, and how do you find them?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Storage and reservations outlive the machine. A block volume that was not marked to be deleted with it, the snapshots and images built from it, and a reserved public address all keep billing. Find them by listing resources attached to nothing, not by reading the machine's record.

open as a page

Your create call returns an identifier and reports success in under a second, yet the new resource refuses connections — why?

level: juniorimportance: must knowfreq 74%
basics
~20 s

The call was accepted, not completed. A management API create is asynchronous: it validates and records the request, hands back an identifier immediately, and only then works the resource through build states before anything can serve traffic.

open as a page

A resource created in a provider's web console is identical to one made from the command line — why?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Both are clients of the same management API. The console is a hosted application that turns a form into the same request the command line tool sends; neither has a private path into the platform.

open as a page

Your managed database has a weekly maintenance window - what may the provider do inside it, and what does your application see?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A maintenance window is a recurring slot you nominate in which the provider may patch and restart your managed instance. The application normally sees dropped connections and a short interruption, or a failover to the standby replica, not a seamless change.

open as a page

What separates a soft quota you can ask to have raised from a hard limit, and what does hitting each cost?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A soft quota is a provider ceiling an increase request can raise, so hitting it costs lead time. A hard limit is fixed by the platform's design, and the only way past it is an architecture change.

open as a page

Your deployment tool is rate-limited while the running service it deploys serves user traffic normally - which request rate is being metered?

level: middleimportance: must knowfreq 62%
basics
~20 s

The management API meters requests per account, separately from the traffic your workload serves. Deployment tools, dashboards and scripts all spend that management budget; user requests do not consume it unless the service itself calls the management API.

open as a page

Why would a team run a component itself on rented machines instead of using the provider's managed version?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Running the component yourself keeps the software identical wherever the machines are rented, so a move becomes a reinstall and a restore rather than a rewrite. You pay for that with the patching, backups and on-call the managed tier was doing.

open as a page

A team says it is locked in to its cloud platform "because of the code" — what does lock-in actually mean, and which kinds are not code?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Lock-in is the cost of leaving, not an inability to leave. Code is one bill of four: data that is priced to move, operating knowledge the team has only here, and an unexpired term commitment are the other three.

open as a page

A migration off one platform is budgeted purely as engineer-months to rewrite code — which cost lines does that estimate miss?

level: middleimportance: must knowfreq 64%
basics
~20 s

A rewrite estimate covers one of four exit lines. The others are the outbound data charge plus the weeks the copy takes, both platforms billed through the overlap window, and the months still running on a term commitment.

open as a page

A managed service is wire-compatible with an open interface - what does that compatibility usually not cover?

level: middleimportance: must knowfreq 56%
basics
~20 s

Compatibility with an open interface normally covers the data path your application speaks, and stops at the edges: provisioning, sizing, authentication, backup and restore, telemetry, quotas and error behaviour all stay the provider's own design.

open as a page

Your board asks for multi-cloud after another company's outage, so which three distinct postures can that one word mean?

level: middleimportance: must knowfreq 62%
basics
~20 s

Multi-cloud covers three different architectures: the same workload live on two platforms at once, different workloads split across platforms with one home each, and a single live platform plus a documented exit plan. Each has a different bill and a different failure behaviour.

open as a page