A cloud service model describes how much of the technology stack the provider runs for you and how much you still run yourself. Cloud+ expects you to place any service on that spectrum quickly, because the model decides who patches what, who secures what and who gets paged when something breaks.
Infrastructure as a service (IaaS) gives you virtual machines, virtual networks and block storage. The provider runs the data center, the physical hosts and the hypervisor; you install and patch the operating system, the runtime, your applications and your data. Platform as a service (PaaS) moves the operating system and runtime to the provider: you deploy code or a container to a managed application platform or use a managed database, and you manage only the application, its configuration and its data. Software as a service (SaaS) is a finished application such as web email or a CRM system; you manage users, settings and the data you put in it. Function as a service (FaaS), often called serverless compute, runs short pieces of code in response to events. You supply the function code and its configuration, such as memory and timeout, and the provider handles servers, scaling and patching, charging per invocation and execution time.
The shared responsibility model is the agreement that follows from those choices. The provider is always responsible for security of the cloud: physical buildings, hardware, the global network and the virtualization layer. The customer is always responsible for security in the cloud: their data, who has access to it (identity and access management) and how services are configured. The layers in between shift with the model. In IaaS you patch the guest operating system; in PaaS the provider does; in SaaS you still decide who can sign in and what data is shared.
Two points trip people up. First, responsibility for data and identities never moves to the provider, even in SaaS. A publicly readable storage bucket or a user without MFA is a customer failure. Second, managed does not mean unconfigured: a managed database still needs you to choose network exposure, encryption keys, backups and user accounts.
Key terms
- IaaS
- Infrastructure as a service: the provider supplies virtual compute, storage and networking, and the customer manages the operating system and everything above it.
- PaaS
- Platform as a service: the provider also runs the operating system and runtime, so the customer deploys and manages only application code and data.
- SaaS
- Software as a service: a complete application delivered over the internet; the customer manages users, settings and data.
- FaaS
- Function as a service: event-driven code that runs on demand without servers for the customer to manage, billed per execution.
- Shared responsibility model
- The division of security and operational duties between provider and customer, which shifts with the service model.
A company moves its intranet from a self-managed VM to a PaaS web app service. The operations team no longer patches the Windows guest or the web server runtime, but they still configure TLS certificates, restrict who can deploy, store connection strings securely and back up the application's database.
Check yourself
In an IaaS deployment, who applies security patches to the guest operating system?
The customer. In IaaS the provider stops at the hypervisor and physical hosts; the guest OS and everything above it is the customer's job.
A SaaS file-sharing tenant leaks data because a folder was shared publicly. Whose responsibility was that?
The customer's. Data and access configuration remain customer responsibilities in every service model, including SaaS.
Which model charges per invocation and runs code only when an event occurs?
FaaS (serverless functions).