DevOps Pro Europe 2025

Wolfgang Ofner: Unleashing the Potential of Hybrid Cloud

46:31 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

This talk focuses on the management of hybrid cloud environments, specifically utilizing Azure tools to streamline multi-cloud integration and on-premise services. The speaker, a freelance cloud architect, defines hybrid cloud as a mix of public and private cloud services alongside on-premise infrastructure, emphasizing the flexibility, scalability, and cost benefits it offers. They discuss key Azure services and solutions, including Azure Stack and Azure Arc, explaining how these can be leveraged to manage workloads across different environments. Additionally, the speaker shares insights from real-world projects, highlighting the challenges and advantages of hybrid cloud solutions, particularly regarding data sovereignty, security, latency, and infrastructure complexity.

Full transcript

[Music] hello hello I hope everyone had a a good lunch break and we're back with f gang Ofna who's going to tell us about uh how to run multicloud environments with the help of the Native Azure tools F gang over to you yeah thank you uh welcome to my session unleashing the potential of hybrid Cloud streamlining multicloud management and on premise integration I know the title is

quite a mouthful but I hope at the end of my session you'll know what hypercloud is and what advantages it brings before I start um just a couple senten about myself my name is wolner I'm a freelance Cloud architect I'm based in Toronto Canada and I focus on aser and they mostly on communi stops but I also have a net background so I can also help with

programming if you want to get in touch with me uh you can find me on my website on LinkedIn and also on my YouTube channel and today I want to talk about first what hybrid CL is then I'm going to talk about how we can use as AR and kues to implement hybrid crowd then I also going to show you how the integration works then I'm going

to talk about two real world projects I was involved with and then I give you my opinion of hybrid cloud and the whole um Asha process so let's get started with hypercloud uh first off the definition it's one of the definitions I found on the internet so hybrid cloud is a combination of public and private cloud services along with on premise infrastructure creating unified Computing environment that

offers great flexibility scalability and cost Effectiveness so the idea of hybrid cloud is that you mix your on prev infrastructure with the cloud and hopefully use uh the advantages of both environments so the types of hybrid Cloud um there are three types in my opinion although the first one is not really hybrid Cloud so the first one I was thinking about is uh what I see often

is with companies that dis spit the own premise and the cloud environment for example they already have an on premise infrastructure uh so they run the old software there but every new software will be deployed uh on the cloud and there's no link between them so I wouldn't really call it hyb cloud Cloud the next one is when you use on premise but you extend it to

the cloud um this could be for example for simple services so your on premise application uses uses a storage account or a database in the cloud and also what's often done is a connection between on premise and the cloud using a VPN connection or Express rout uh Express rout is a private connection from your own premise data center to the cloud and this allows you to have

a low latency connection and as said a private connection you don't have to encrypt the data because it doesn't go out to the internet and the last one which is a real hybrid Cloud connection is that you connect them or you combine them for example you could have your own premise infrastructure but you run cloud services in your own Data Center and I'm going to explain later

to you how this work so now to the benefits of the cloud uh the first one which is a big one is the data so sovereignity uh many companies have very sensitive data this could be customer data Health Data or just um like Secrets they don't want any other competitors to know so if you use a high Cloud all the data can stay on your own premise

infrastructure so it never leaves your premise and you can make make sure that it stays safe the next thing is security um if I have full control over it I don't give my data especially out to like Microsoft or any other cloud provider I can make sure it's secure and also have full control about the infrastructure so I can make sure nobody has access to it and

I can Implement whatever I need for the security the thir one latency obviously if I run the data on premise there's the lowest latency possible this is useful if you need data processing right in your data center or on premise for example um I work with factories they produce something for example um a cable or a part for a car and then they want to instantly check

the quality so they use cameras to check the part produced and this needs a low L latency um sending this out to the internet waiting for a response might be too slow because they produce so much and so fast that every millisecond counts then obviously the cost cost is always a big factor um here I'm thinking about I already have infrastructure and I just use cloud services

on this infrastructure so I don't have to pay the full cloud services I run my own hardware and therefore I can lower the costs and lastly the resiliency uh this also um with my customers there are in factories that are in rural areas in less developed areas and um it happens that the internet connection is gone for a couple hours so if I only use cloud services

I can't do anything in this time and this could cost like hundreds of thousands or even millions of euros and if I run the application on premise maybe not the full application but enough um to keep running I can just uh keep producing and once the internet is I just connect to the cloud again then obviously with air resolution there are some downsides um or challenges so

the first thing that comes to mind is the complex infrastructure because I don't only have to use um a cloud service or an on premise infrastructure I have to combine them but this also means I have rooting in between I have networking firewalls uh DNS so it gets quite quickly quite complicated then also security and compliance I said security could be an advantage if I only run

on uh if I run on premise but it can also be a disadvantage or at least a challenge because I have to manage um a combination of both worlds so I have to make sure it's secure on premise I have to make sure it's secure in the cloud and also in between and the say with the compliance I have to make sure if I'm compliant especially if

I'm for example Health provider um that's very strict and if I have more environments it's going to be more of a challenge the third one data integration um this is a bit of a processual um problem um what I'm thinking about here is if I have on premise data I have cloud data and I just copy the data around I have to make sure that I know

where the data resides uh where it's processed and that it's encrypted and secure and the last one which is maybe even the biggest one is the skill set of my teams so traditionally if I have on premise infrastructure I have a couple it administrator they know how to set up everything how to manage everything the same if I have the cloud I have a couple Cloud it

administrators they know everything but combining them can be a bit of a challenge because often um the cloud guy knows Cloud stuff don't premise guy knows on premise stuff but they usually don't know both so it's um quite a learning curve for the team and now how we can run this service on premise um first off Microsoft offers a couple hardare Solutions um they're called as stack

Edge as stack Hub and asack HCI so the aure stack Edge um allows you to run aure services in um Ed Edge environments uh that's usually small devices that are in in plants or in um like rural areas where you don't need much processing power then we have the aure stup this allows you to run Azure Services U on your own premise environment and it's almost as

having your own aure environment the only downside is that it doesn't offer all the services and what I want to talk about today is that as HDI so HCI stands for hyperon converge infrastructure and this allows you to have a real hybrid environment and all of this is managed with as AR as is a software solution and this can be combined to create the environment so first

off the aure HCI it's running its own operating system uh it's very creatively named aake HCI operating system and it's based on the Windows Server operating system um just with less features but it also has some features that are used u in previous versions of Windows server but also in the cloud for example hyperv uh so we can create virtual machines we have storage spaces direct which

allows us to create uh storage effic effic efficiently and we have a software Define networking the same as we have in Asia and additionally we can build clusters with a HCI so we can have clusters between one and 16 physical servers this could mean for example in our headquarter where most of our employees are we need more resources so we could have for example eight physical servers

but our in our Branch officers where we only have a handful of employees we only need one physical server and so we can set up the server according to the needs we have and they're also often used in disconnector scenarios this means uh for example on planes or on cruise ships so the planes and the ships have access to the internet when they're in the harbor or

the airport so the software developers can install new updates uh some patches see what's going on and once the plane is in the air or the crew CR ship is uh on the ocean they lose the connection to the internet but the software still uh continues running and so our customers can continue using the entertainment system uh payment systems and everything I have and it's a great

experience for the customers and here you can see how everything works so on the bottom so on this layer we have some Hardware then we install the operating system and then we can use uh different services so for example here on the left we have virtual machines um we can use Windows and uh Linux doesn't matter then we can also use as virtual desktop so that's the

same as in the cloud um I think I just lost my sorry just lost my presentation so now we should back so now it should work again um then we can have aure virtual desktop that's the same as in the cloud and we also can use aure ctive service and this means we can we can run a managed kubernetes service on premise AR I'm going to talk

on the next slides what aser AR is and additionally we can have more services that are we are using already with aser for example the aure keyboard aure monitor aure backups and all this is integrated in the software and here we have an overview um if if you have to decide what hybrid Cloud solution you want to use um that's provided by Microsoft and I don't want

to talk too much about the details um I just want to have this out here so you know that it exists for example if you use a multic cloud this means you're using Asha and gcp ews Alibaba Cloud I you go with this branch and if you're using Asha um you would start out here and then you decide what you want for example um if you have

hyper converged as I said with aake HCI you will add up down here with aure stack HTI and this helps you decide what solution is the best or might be the best and then you can look into it then the second slide I have here is again just an overview what you have and uh first off you have here the aure cloud and obviously that's running the

Asia Data Center and everything is running on premise and what's interesting is here that everything can be managed with asure no matter where it's running it's integrating with asure so you can use the portal but you can also use the management tools you already used um running in the cloud and again I just want to talk too much about the details uh that's just out here so

you heard about it and if you're more interested you you can take a look at it and now let's talk about Asar uh Asar is an awesome Tool uh by Microsoft and it allows you to project your infrastructure that's running outside of Asia this means it can run on a different cloud like gcp or AWS or on premise it doesn't matter um inside of aure this means

uh you can see it in the aure portal and you can manage it as as if it was running in asure and you can match with this Linux and windows VMS and also bare metal server you can manage any Cloud native Computing Foundation certified communities distribution so that's almost all of the popular ones and you can also match your Microsoft SQL server and if you go to

the aser portal we see here um our as instance and on the left side here we can see all the services you can match so on top with h hi what we talked about kubernetes cluster some VMware Microsoft SQL server and down here we can also see we can match aure services with it and I'm going to talk about this at the end of my presentation but

this shows that we can run aure services on infrastructure and the advantage of this approach is that we can use the the same tool we are using if our Hardware is running on aure so we don't have to learn any new tools we can just use the same and match them the same way uh so especially for VMS this could be the update management this means I

can see install Windows or Linux system updates uh on Tuesday at 2 a.m. and they're going to be installed on the asms but also on my on premise infrastructure the same if the configuration management I can configure out all the VMS the same way and I could also run Ser AO services like the Microsoft cloud Defender and as I said we can also match our kubernetes cluster

with as AR and this category is so-called as AR enable communities and this allows us to see the communities cluster in the aure portal but also bring Azure features to the kubernetes cluster and this is done bya extensions uh there's quite a lot of extensions for example for aure monitor uh for gitops asure policy uh asure keyboard integration and today I want to talk about all of

them except the aure policy and another um also feature which I've used in the past is that aure AR allows you to connect to the cluster even though if it's behind the firewall that's blocking every connection that's um incoming into the network the way it does this as AR installs an agent and the agent is running inside the cluster and then the cluster connects to Asher and

therefore the connection is from inside the cluster um going outwards and not the other way now before we can get started with as AR we have to have a couple prerequisites fulfilled so the first one is we have to install Dash CLI and then we have to in install the extension this can be done with a single command so just a curl to install the if you're

Linux and then the AC extension add to add the extension uh if you're on Windows or Mac um you'll find the documentation but also usually a single line command then we have to register a couple a provider this provider allow us to use um certain rest apis as especially the rest apis we're going to use for the integration and that's going to be the Microsoft kubernetes Microsoft

kubernetes Configuration and Microsoft extended location apis and after you did this you only have to do this once um in your tenant you can use the EAS provider show command and then just what name uh you want to show and at the end I use the- o um that's for output and table to just display it nicely and you can see here um all three are registered

this means continue um if they're not registered you have to wait a bit longer uh it takes about 10 to 15 minutes to register them so once we have set this up we can start installing Ash AR and uh to do this we use the Asha CI so we use the AC connected kubernetes connect command then we provide a name so that's the name of our asure

AR instance and in what name space we want it to be running and this also using the same location as the resource Group is running in if you're using a resource Group in a location that's not supported you will get an error message and then you can just add the location as a parameter and this works because I'm connected to my kubernetes cluster so what this command

is does it also reads the cube config file so it knows to which kubernetes cluster you're connected to and executes the command in cluster and this installs all the AR agents um it's around 10 to 12 I don't know the exact number um of applications but they all running in the as namespace so you can easily see what applications have been installed and here you can see

them and also you can see um that I'm now using a windows before I was using abunto it doesn't matter it's just kubernetes you need the cube C the kubernetes CLI and then we can access it and I don't want to go too much into detail because we don't have too much time today but if you look at the names you can already figure out what's going

on so for example if here um some extension applications they're probably going to manage our extensions then here we have cluster identity a cluster connect and some Matrix so just by looking at the names um it's already more or less obvious what this applications are doing so now back to the asop portal um as I said we can manage our aser and the big Advantage is that

we have a so-called single pain of class this means we have One dashboard or one application where you can see all our infrastructure for example if our company is using aure gcp and on premise usually they would have to use at least three dashboards one for each environment but this also means um as has different tools than gcp and probably different tools than on premise so it's

quite complicate for administrator to learn all of these tools and with a AR we just use our aure so if we go back to the as AR um instance we're going to click here on our kubernetes cluster and then we can see all the kubernetes cluster we with so the first one here is um aure cluster and I Can See For example what kuber kuber version is

running on and here I have an on premise k3s cluster and I can also to see what kubernetes version of running on and it's the same um overview or dashboard no matter where they're running and if I click on one of these kuties classers for example the k3s one I can see here um the same menu as as if I was running the aure KU this service

so I I don't have to use or learn a new menu um get to use new features the only difference you can see is here it's not kubernetes or as kubernetes s it's kubernetes as AR and for example if I want to access the resources I don't see them straight away I have to provide an access token that's just an additional security feature and it's out scope

for today but what you would you do is create a token inside your cluster and then use this token to authorize the portal to access so now let's take a look at the Asar extensions and with this as extensions you can bring asure services to your kubernetes cluster and have um already existing asure functionality running in your own premise cluster and also don't have to care much

about the installation process usually it's just a single line command and then asure will take care of the rest so what you're going to take a look at now is the G extension so we can manage our deployments there's a monitor for monitoring and alerting and there's a keybard extension to have a link between our kubernetes cluster and the keyboard so the first extension for kups um

this extension is using the flux operator that's one of two popular open source uh kups the second one would be Aro CD and it can be installed VI the aure CLI or the aure portal I prefer the HT because it's just a single line command and it's very clear what the command does but before we can install it we also have to take a look at the

structure of our repositories because usually we have one repository then we Implement our features there and once we ready we deploy our main or Master Branch from from this repository with gitops Microsoft recommends that we have two repositories one for the application and configuration and this recommended um the um separation of concern principle so the idea behind this is that developers take care of the application and

then I could have some um in infrastructure team member that take care of the configuration of the um this could be y files Helm charts or whatever you need to run your um software and here we can see how this whole process works so if I Implement a feature I create a PO request and this hopefully triggers a pro request pipeline this means uh my P request

is running through a separate PIP plan that's doing some unit testing maybe deploying the application to test if everything is and once that's approved it's being merged to the repository and this this usually triggers the CI pipeline this pipeline runs more unit tests but also creates the container image and push the container image to The Container registry so in this case it's the aure container registry but

you can use any container register you want for example dock Hub and this either automatically triggers the CD pipeline or sometimes it's done manually but uh once the CD pipeline runs it's updating the configuration this could be in the simplest case for example update the version number and then commit these changes to the giops repository and then we have over here inside the kubernetes cluster our Flux

Of flux not sure um agent and this agent sees that there are changes in the Repository so this agent is always monitoring the github's repository and since you just uh committed something new the flux agent downloads these changes and then applies them to the kubernetes cluster and with this approach we uh implemented a fully automated deployment process without having any access to the communi cluster because the

cluster is pulling the changes and you don't have to push them so as I said installing the github's extension is a single line command in the H so let's take a look at this command so it's the H command um the structure is always the same it's AC then the resource you want to use in this case it's KS configuration flux and then what you want to

do in this case we want to do a create and then the parameter are hopefully quite self-explanatory so we provide the cluster name the resource Group it is in uh names a name for the kups deployment namespace then the cluster type in this case we use a connected cluster because for this demo I'm using an as kubernetes service cluster so if you want to try it out

yourself you can just copy this command if you use an on premise for example the k3s cluster you would have to use I think it's manag clusters then the scope we see um that our gitops extension can install um applications in the whole cluster and then you have to configure the access to the git repository so in this case I have my username and a personal access

token so that's the same approach for asops or GitHub then the UR to my as OBS server what branch I'm using so I'm using the master branch and then the path to the customization file um the giab extension is using customize uh that's just another open source tool and I'm going to take a look at this in a couple slides um all you have to know for

now is with this customization you can also create dependencies between between your applications or or between the deployments for example you could say deploy a name space first and once the name space inside the kubernetes class is deployed then deploy my application and as you can see down here it says the extension wasn't found so it's going to install the extension automatically the first time you execute

this command this is going to take a minutes and then you will see it in the aure portal so if you go back to the aure portal to our kubernetes as instance and scroll down a bit and have on the left side here the GitHub section we can see here our gitops operator the one we just installed and everything is green so that's great but not always

everything works so you have to analyze what's going on and what you can do is you can click on this configuration and this will give you more information about uh what's going on and we'll also display some error messages in case any and then if you wait a couple more minutes we can see our application is running inside the kubernetes cluster without us doing anything the kops

operator pulled uh in this case a Helm chart applied the helm chart and the application is running now in the cluster and now let's have a look at the repository so as I said kops extension is using customize and it's using in the simplest way a customer file that's just referencing all the release files uh since we don't have too much time today I want to keep

it as simple as possible so I just have a customers file um you can see here it's of type customization and it's referencing one yamel file and this yam file is called release and this Helm release yam file is just containing all the information about our Helm chart and we can use this uh yaml file to configure the helm chart too so this would be to override

the Val of yaml file the helm chart is using so if you take a look at this file we can see here it's type Helm release then we just have some information for example the name then if you use as kubernetes service you have to provide this label or this annotation otherwise it's not working and then with this back section we can configure the helm chart for

example we can say check every minute if there are any changes uh what's the path to our Helm chart but we can even configure more for example the replicas or I can add some environment variables but to keep it as simple as possible that's all you need for your application running and the last piece of it is to have a kups pipeline and in the project I

was working on we had a pipeline that was reading the newest tag from the aure container registry so we just did this by filtering by date then we replaced the tag we just read in the val. y file in the helm chart and then we committed this change to the master Branch then the flux operator saw the changes pulled them to the cluster and applied them and

so we had the newest version running um in our application and another feature what I think all CD uh tools at least uh gitlab GitHub as devops provide is that developers can also Set uh parameter when they start the pipeline so we use this to set the tag so if a developer wanted to deploy a specific version they could set a tag when they started the pipeline

and if they didn't set a tag then we read the newest one so you are totally flexible to do whatever you need to do for your application then the next extension is the Azure keyboard Secrets provider extension and the idea behind this is um the aure keyword is a great tool to manage your secrets your certificates or everything that should stay hidden or secure uh you have

auditing you have automatic um secret rotation you have alerts access control and so why not use all of this and with this extension you can mount the secrets from the aure keyboard automatically inside your cluster and all of this is done via GPC and here you can see how it works so in the front we have so basically all of this is kubernetes so it's just um

creating a new pod attaching uh The Secret store uh driver and the provider and then all this extension does is configure this Secret store provider to use the Azure keyword and this means that our software Dev velers don't have to change anything application they don't even have to know in theory that we're using the aure keyboard they just uh deploy the application and just and kubernetes takes

care from where the secrets are coming so here we have it a bit more detailed so everything starts with the kubernetes API server this tells the Cub on the worker note to schedule a new Po and when the cuet tries to start a it's telling the Secret store cide driver to create a new Mount so this driver creates a temporary um file system volume and mounts it

to the pot and then it also tells the Secret store provider to get all the secrets and we configured this provider to use aure keyboard so we take a look here here at our as keyword download all the secrets and then give them here to The Secret store driver and the Secret store driver then writes them to the temporary file system and attach this to the Pod

but uh for example in net we use environment variables to configure our application so we can also attach them as variables and this allows as said before that the developers don't have to change the application we just attach the environment variables um net by default reads them and then can use them to run application and the last extension is that a monor extension um so by now

we have the deployments we have the secrets and now you want to know what's going on in our cluster and also if our applications so we use a monitor because we also use this in the cloud and dash monitor extension installs Dash monitor agent um in its own namespace so it's separated from everything else and once the agent is um installed it starts collecting a log and

Metric information and then sends this information to a lock analytics workspace and once we have it in the lock analytics workspace we can use the same tools we are using as if our software is running in the cloud so for example f a monitor we we have buil-in dashboards or we can use our own dashboards we have alerting and we have also insights inside the cluster and

inside into the pods or container and here you can see the dashboards they already built in so I didn't have to do anything I just installed the extension and the dashboards were there and if you take a look at this is um zoom in at around 9:30 a.m. suddenly there was a big spike in CPU usage so we went from around 10% to 70% and then even

higher above 80% and with a monitor you often have alerts if your CPU usage goes above 80% so in this case at around I would say 9:33 the support team was alerted that the CP usage is really high and then you can see over the next two three minutes it increased even further so here we at the Peak at maybe 90% but then the support team got

to work resolved the problem and the CPU usage went back down within like five minutes and our customers didn't see anything that it slowed down that we had errors failures so everything was fine before it became a problem and there also some other um dashboards for example right here with the memory resarch so it's between like 18 and not even 20% everything is fine we can see

the notes how many notes we have and how many pods we have running but you can also take a look at our containers itself so as you can see here on the right the container with the name custom API um barely had any resource usage and suddenly it spiked to 100% and it went red and what's interesting is if you take a look down here we have

a container that's mqtt so that's our messaging service and this already had quite a spike a couple minutes before the custom API went into the red so this could be a hint that maybe we had a lot of messages and then a custom API was trying to process these messages and just ran out of resources and this will help us to identify what the problem is and

this again is everything out of the box so I didn't have to do anything just install the Asar Moor agent and the last thing um maybe even the most interesting one is run aure services with aure ar on our on premise infrastructure so before we do this um there are couple I would call it categories of aure AR so the first one is asure AR and infrastructure

this allows us to manage our own premise infrastructure this could be um server Comm cluster as HCI Microsoft SQL datab base and then the more interesting one is we can run on premise our asure services so this is the first time and the only way to run a service like the as app service um logic apps API management or container apps on premise and we can also

run um soal Asar enal data services this means we can run aure SQL matched instance or aure machine learning also in our own premise Data Center and this means we don't have to give our data to Microsoft we can just run it on premise and use aure services and don't have to take care of a database or machine learning and everything is done with we have a

kubernetes cluster so we have a kubernetes cluster we installed asure AR and once we have the as AR connection we can run the Azure services on premise and the great thing is the developers don't care where the software is running they can use the same tools no matter if it's running on aure or on premise and here you have an overview W said so it doesn't matter

if you're using one of the many Cloud providers if you use on premise infrastructure or some Edge device you just install aure AR so that's the center piece and once you have this you can use as services on it and we about to run out of time so I just quickly want to tell you about two projects I was working on um that used asure AR and

hybrid Cloud infrastructure so the first one is called uh auton autonomous Rie system there was involved in a proof concept and the second project I'm working on right now is for smart machine factory so here you can have a r vehicle so in Switzerland we use this uh literally everywhere in summer for ski uh for hiking in Winter for skiing and the idea of this project is

to automate this uh so you want to make it intelligent um basically to to cut costs cut wear and tear and make it uh more user friendly running 24/7 and the challenges we were facing for this is we had existing hardware and we had some firewalls so we had problems with the connection and we had to use on premise hardware and couldn't connect it to the cloud

and then we used as a kuties cluster and all the tools I explained today um and could matage this and um here you can see uh this is our test center so for me personally this was one of the highlights because as software developer we click through our software and nothing is happening but there I could click a button and suddenly something started to move a door

opened and I felt like a little kid just with big toys and it was great and well thank you very much I think we may need to skip the second project story but the first one was uh exactly what everyone dreams of having a project where they can see the effect from all of the code otherwise it's just like you're constantly working and um I just have

two slides left uh about my opinion of uh the hybrid cloud and then we can go to the questions in case we some uh we don't we have 10 seconds left from the slot oh okay uh um so the conclusion is hybrid cloud is a really powerful Tool uh it's great but it's also complicated so you have to um have the skills and plan it before you

can it and with this uh here on the QR code you can find the slides and if you have any questions just contact me on one of the social media platforms per this was very informative thank you very much V gank and hopefully this will um bring wisdom and and more efficiency to a lot of other Engineers lives um so um we're going into a 10-minute break

see you again in a bit bye bye