What Is Cloud Computing?
Cloud computing is the on-demand delivery of compute, storage, databases, networking, and higher-level services over the internet, billed on a pay-as-you-go basis. Instead of buying and racking physical servers, you rent capacity from a provider such as Amazon Web Services (AWS), Microsoft Azure, or Google Cloud (GCP) and scale it up or down in minutes.
The US National Institute of Standards and Technology (NIST) defines five essential characteristics that make a service "cloud": on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured (metered) service.
Key idea: CapEx to OpEx
Cloud converts large up-front capital expenditure (buying servers you own for years) into variable operating expenditure (paying only for what you use). This lets teams experiment cheaply and only pay more when a product actually grows.
Service Models: IaaS, PaaS, SaaS
Cloud services are grouped by how much of the stack the provider manages for you. The more they manage, the less operational control (and effort) you have.
| Model | You manage | Provider manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Compute, storage, networking, virtualization | EC2, Azure VMs, Compute Engine |
| PaaS | Apps and data only | OS, runtime, scaling, patching | App Service, Elastic Beanstalk, App Engine |
| SaaS | Only your configuration and data | Everything else | Microsoft 365, Gmail, Salesforce |
| FaaS | Function code only | Servers, scaling, idle scale-to-zero | Lambda, Azure Functions, Cloud Run functions |
FaaS (Functions as a Service) is the core of "serverless" — you deploy code and the platform runs it in response to events, scaling automatically and often billing per millisecond of execution.
Deployment Models
- Public cloud — shared infrastructure operated by a provider (AWS, Azure, GCP). Most common; maximum elasticity, minimum ownership.
- Private cloud — cloud-style infrastructure dedicated to one organization, on-prem or hosted. Chosen for regulatory or data-residency reasons.
- Hybrid cloud — public and private connected together, so workloads and data can move between them (e.g. AWS Outposts, Azure Arc).
- Multi-cloud — using more than one public provider to avoid lock-in, meet compliance, or use best-of-breed services.
Regions, Availability Zones, and Edge
Providers organize their physical footprint into a hierarchy. Choosing the right one affects latency, cost, resilience, and legal compliance.
- Region — a geographic area (e.g.
us-east-1,westeurope) containing multiple isolated data-center clusters. - Availability Zone (AZ) — one or more discrete data centers within a region with independent power, cooling, and networking. Deploy across 2-3 AZs for high availability.
- Edge / Point of Presence (PoP) — smaller locations used by CDNs (CloudFront, Azure Front Door) to cache content close to users.
# List AWS regions
aws ec2 describe-regions --query "Regions[].RegionName" --output table
# List Availability Zones in the current region
aws ec2 describe-availability-zones \
--query "AvailabilityZones[].ZoneName" --output text
# Azure: list all regions
az account list-locations --query "[].name" -o tsv
Data residency matters
Laws like the EU's GDPR may require personal data to stay in-region. Always pick a region that satisfies both latency and compliance before you launch a workload — moving data between regions later is slow and costs egress fees.
The Shared Responsibility Model
Security in the cloud is a partnership. The provider secures the cloud itself; you secure what you put in the cloud. The exact split shifts with the service model — with SaaS the provider handles almost everything, with IaaS you own the OS and above.
| Responsibility | Owner |
|---|---|
| Physical data centers, hardware | Provider |
| Hypervisor, host OS, network fabric | Provider |
| Guest OS patching, firewall rules (IaaS) | Customer |
| Identity, access management (IAM) | Customer |
| Application code and data | Customer |
| Client-side and in-transit encryption config | Customer |
Elasticity and Scaling
Elasticity is the cloud's ability to add or remove capacity automatically as demand changes. Two directions of scaling exist:
- Vertical scaling (scale up) — give a single machine more CPU/RAM. Simple but has a ceiling and usually requires a reboot.
- Horizontal scaling (scale out) — add more machines behind a load balancer. The cloud-native default; near-limitless and fault tolerant.
# A simple Kubernetes Horizontal Pod Autoscaler (works on any cloud's managed K8s)
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: web-hpa
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: web
minReplicas: 2
maxReplicas: 20
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 70 # add pods when avg CPU > 70%
Cloud Economics and Pricing Models
Understanding how you are billed is as important as the tech. Compute is typically offered under several purchasing models with big cost differences.
| Model | How it works | Best for |
|---|---|---|
| On-Demand | Pay per second/hour, no commitment | Spiky or unpredictable workloads |
| Reserved / Savings Plans | 1-3 year commitment, up to ~72% off | Steady baseline usage |
| Spot / Preemptible | Bid on spare capacity, up to ~90% off, can be reclaimed | Fault-tolerant batch, CI, ML training |
Watch out for data egress charges (data leaving the provider's network is billed, ingress is usually free) and idle resources. The FinOps discipline exists to keep cloud spend aligned with business value. Use aws ce get-cost-and-usage or the Azure Cost Management portal to track spend.
The Well-Architected Pillars
All three major providers publish a "Well-Architected Framework" describing what a good cloud design looks like. The pillars are broadly the same:
- Operational excellence — run and monitor systems, improve continuously.
- Security — protect data and systems; least privilege.
- Reliability — recover from failures, scale to meet demand.
- Performance efficiency — use resources efficiently as demand changes.
- Cost optimization — avoid unnecessary spend.
- Sustainability — minimize the environmental impact of workloads.
Practice Exercises
- For each of these products, classify it as IaaS, PaaS, SaaS, or FaaS: a raw Linux virtual machine, Gmail, AWS Lambda, and Heroku. Justify each answer using the "who manages what" table.
- You must keep customer data inside the EU and serve users in Frankfurt and Paris with low latency. Explain which region and how many Availability Zones you would use, and why.
- Using the shared responsibility model, decide who is at fault if a company leaves a database open to the public internet with a default password: the provider or the customer?
- A batch job re-runs nightly and can safely restart if interrupted. Which pricing model minimizes cost, and what is the trade-off?
- Write out the difference between vertical and horizontal scaling and give one real workload that suits each.
- Estimate the monthly cost impact of transferring 10 TB of data out to the internet versus keeping it inside the same region. Which direction is (usually) free?