Sovereign Cloud
- On owning what you run
The Book in Full — Annotated Contents
- Volume 1 — Foundations (Chapters 1-18)
- Appendices
How This Book Is Proven
- The lab behind the book
- What actually happened
- Why you can check any of this
- What this means for you
Chapter 1: The Cost of Renting Your Existence
- Meet Leaf Spine Books — Understanding CloudStack Architecture Through Real-World Needs
- The Story: The Renewal Letter
- Understanding CloudStack: Building Blocks of Your Cloud
- System Virtual Machines: CloudStack’s Control Layer
- The Management Server: Brain of the Cloud
- Network Architecture: The Four Traffic Types
- CloudStack 4.22 LTS: Why This Release
- Basic vs Advanced Networking: A Critical Decision
- Hypervisor Selection: Why KVM?
- Storage Strategy: Why Ceph?
- The Road Ahead: Leaf Spine’s Implementation Journey
- Key Takeaways
- Questions to Answer Before Next Chapter
- Coming in Chapter 2
- Additional Resources
Chapter 2: Designing the Three-City UK Cloud
- From Whiteboard to Blueprint — Planning a Production-Grade Infrastructure
- The Story: Architecture Week
- Design Principles
- Geographic Layout
- Network Architecture
- VLAN and IP Architecture
- Hardware Specifications
- Deployment Overview per Site
- CloudStack Zone Architecture
- Security Architecture
- AI and GPU Strategy
- Automation with Ansible
- Cost Analysis
- Migration Path
- Disaster Recovery Strategy
- Capacity Planning
- Monitoring and Alerting
- Documentation Standards
- Next Steps
- Chapter Recap: 5 Key Takeaways
- Up Next
- References
Chapter 3: Building Your Learning Lab
- From One Second-Hand Server to a Cloud You Can Break
- Why a Lab at All
- The Story: Planning for the Future
- The Three-Phase Roadmap
- Phase 1: The Learning Lab
- The Miniature Estate
- Phase 2: Network Simulation
- Phase 3: Edge Computing
- Done When: the Phase 1 Finish Line
- Evolution to Production
- Key Takeaways
- Coming in Chapter 4
- Additional Resources
Chapter 3: Deployment Guide
- Building Manchester in Miniature — the Step-by-Step Companion
- How to Use This Guide
- Page One: the Setting Everything Depends On
- The Seven Phases
- Pre-Deployment Checklist
- Phase 1: Host Preparation
- Phase 2: Virtual Networks
- Phase 3: Provisioning the Seven VMs
- Phase 4: The Management Plane
- Phase 5: The Storage Cluster
- Phase 6: Secondary Storage
- Phase 7: Building the Manchester Zone
Chapter 3: Lab Exercises
- Graded Workouts for the Manchester Miniature
- How to Use This File
- Exercise 1: Know Your Estate
- Exercise 2: A Template Worth Keeping
- Exercise 3: Offerings and Storage Tags — rbd-dev Earns Its Keep
- Exercise 4: The Done-When Circuit
- Exercise 5: Guest Networks and the Virtual Router
- Exercise 6: Break-and-Rebuild Day
- Exercise 7: The Change-Window Rehearsal
- Challenge Projects
- Completion Criteria
Chapter 3: Troubleshooting Guide
- Diagnosis and Recovery for the Manchester Miniature
- How to Use This Guide
- The Method: Five Steps
- Section 1: First Boot — the Usual Suspects
- Section 2: Host Layer
- Section 3: Network Layer
- Section 4: Staged Drill One — the MTU Mismatch
- Section 5: Staged Drill Two — Losing Monitor Quorum
- Section 6: CloudStack Layer
- Section 7: Ceph Layer — the Lab-Scale WARN Taxonomy
- Section 8: The Diagnostic Sweep
- Section 9: Recovery — the Graduated Ladder
- Section 10: Getting Help
Chapter 3: VM Quick Reference
- The One-Page Card for the Manchester Miniature
- The Estate
- The Networks
- CloudStack Names (the production names, on purpose)
- Where the Secrets Live
- Getting In
- Daily Commands
- Quick Fixes → Troubleshooting Guide
- The Chapter 3 File Set
Chapter 3: The Ampere ARM Build
- The Manchester Miniature on ARM64 Silicon
- Why ARM at All
- The One Difference That Reshapes Everything
- The Other ARM Deltas, Briefly
- The Estate, Inverted
- The Build Sequence
- A Second Host, Later
- The GPUs, Honestly
- Done When, on ARM
- Key Takeaways
- The Chapter 3 File Set
- Additional Resources
Chapter 3: The Laptop Build
- The Manchester Miniature in a Rucksack
- Why a Laptop at All
- The One Constraint That Reshapes Everything
- The Estate, on a Diet
- The Laptop Deltas
- The Build Sequence
- Travelling With a Datacentre
- Network Simulation on the Move
- The Switch OS Question
- Done When, on a Laptop
- Key Takeaways
- The Chapter 3 File Set
- Additional Resources
Chapter 4: Infrastructure Preparation
- Building the Foundation — From Blueprint to Bare Metal
- The Story: Hands on the Hardware
- Part 1: Understanding the Infrastructure Stack
- Part 2: Ubuntu 24.04 LTS Installation
- Part 3: Post-Installation Baseline
- Part 4: Network Configuration with Netplan
- Part 5: Storage Preparation
- Part 6: System Optimisation
- Part 7: Security Hardening from First Boot
- Part 8: Logging Baseline
- Part 9: Documentation as Code
- Part 10: Verification
- Part 11: Replicating to London and Leeds
- 🔑 Chapter 4 — Key Takeaways
- What’s Next?
Chapter 5: MySQL High Availability
- The Database Layer — One Cluster, Two Cities, No Single Point of Failure
- The Story: The Heart of the Cloud
- Part 1: Understanding the Database Layer
- Part 2: The Design — Three Nodes, Two Cities
- Part 3: Preparing the Nodes
- Part 4: Installing MariaDB and Galera
- Part 5: Configuring the Cluster
- Part 6: Bootstrapping the Cluster
- Part 7: Creating the CloudStack Databases
- Part 8: The Single-Writer Routing Layer
- Part 9: Testing What We Built
- Part 10: Backups — for What Clustering Cannot Prevent
- Part 11: Monitoring, Verification, and the Record
- 🔑 Chapter 5 — Key Takeaways
- What’s Next?
Chapter 6: CloudStack Management Server
- The Brain Arrives — Installing the Control Plane on the Nodes That Already Hold Its Memory
- The Story: Switching On the Brain
- Part 1: What the Management Server Actually Is
- Part 2: Pre-Flight Checks and Firewall Doors
- Part 3: Database Housekeeping — Two Honest Reconciliations
- Part 4: Installing CloudStack on the First Node
- Part 5: Initialising the Schema — Without Borrowing Root
- Part 6: First Start — and First Contact
- Part 7: Nodes Two and Three — the Cluster Assembles
- Part 8: First Login
- Part 9: Three Front Doors, One Name
- Part 10: Testing What We Built — the Inherited Standard
- Part 11: Verification and the Record
- 🔑 Chapter 6 — Key Takeaways
- What’s Next?
Chapter 7: Secondary Storage
- The Repository That Rebuilds the Cloud — DRBD and NFS on Refurbished Metal
- The Story: The Library Question
- Part 1: Understanding Secondary Storage
- Part 2: The Design
- Part 3: Building the Replicated Filesystem
- Part 4: The NFS Service
- Part 5: Failover with Keepalived
- Part 6: Verification
- Part 7: Troubleshooting
- 🔑 Chapter 7 — Key Takeaways
- What’s Next?
Chapter 8: Primary Storage
- Where the VMs Actually Live — Ceph RBD on the NVMe Estate
- The Story: The Microseconds Chapter
- Part 1: Understanding Primary Storage
- Part 2: The Design
- Part 3: Deploying the Cluster
- Part 4: OSDs, the Pool, and the Credential
- Part 5: Firewall and Verification
- Part 6: The Drills
- Part 7: Troubleshooting
- 🔑 Chapter 8 — Key Takeaways
- What’s Next?
Chapter 9: Deploying CloudStack — The Zone Goes Live
- The Morning the Cloud Gets a Shape
- Where We Stand
- What This Chapter Is — and Is Not
- Part 1: The Shape of a Zone
- Part 2: The Toolbelt — UI, API, and an Honesty Box About the Wizard
- Part 3: Zone, Physical Network, and the Public Range
- Part 4: Pod and the Guest VLAN Range
- Part 5: The Cluster, Deliberately Empty
- Part 6: The Image Store — and the Auto-Seed Moment
- Part 7: Primary Storage — Staged, Verbatim, and One Honest Step Early
- Part 8: Verification, Then — and Only Then — Enablement
- Troubleshooting the Logical Build
- Chapter 9 Summary: Five Things to Hold On To
- The Values Card for Chapter 10
- What’s Next
Chapter 10: Adding KVM Compute Hosts — The Day the Stage Crew Arrives
- The Morning After the Map
- Where We Stand
- What This Chapter Is — and Is Not
- Part 1: The Shape of the Day
- Part 2: The Bridges — Three Labels on Two Bonds
- Part 3: The Hypervisor Stack
- Part 4: The CloudStack Agent and the Service User
- Part 5: Pre-Flight — Never Assume, Interrogate
- Part 6: Adding the First Host
- Part 7: The Cascade
- Part 8: The GPU Cluster
- Part 9: Verification — Extending the Zone Script
- Part 10: Drills — Break It While It’s Cheap
- Troubleshooting the Join
- Chapter 10 Summary: Five Things to Hold On To
- The Values Card for Chapter 11
- What’s Next
Chapter 11: Deploying Your First Guest VMs — Opening Night
- The Morning the Cloud Earned Its Keep
- Where We Stand
- What This Chapter Is — and Is Not
- Part 1: The Shape of the Day
- Part 2: Compute Offerings — The Shapes a VM May Take
- Part 3: Disk Offerings — Data That Outlives the VM
- Part 4: The GPU Placement Proof — Five Minutes That Retire an Assumption
- Part 5: The Guest Template — The SSVM Does the Fetching
- Part 6: Editorial’s Network — Where
cloudbr2Earns Its Keep - Part 7: Deploying the Three Guests
- Part 8: Everyday Lifecycle — and One Thing the Old Book Got Wrong
- Part 9: Verification — Extending the Zone Script
- Troubleshooting the First Workload
- Chapter 11 Summary: Five Things to Hold On To
- The Values Card for Chapter 12
- What’s Next
Chapter 12: Advanced Networking — The SONiC Leaf-Spine Fabric
- Turning “Trust the Trunk” Into a Tested Data Plane
- The Story: The Promissory Notes Come Due
- Part 1: Why a Fabric, and Why This One
- Part 2: Building the Fabric in the Lab
- Part 3: The Underlay — One Routed Fabric
- Part 4: VLANs, the Host Trunk, and Making 10.100.0.1 Answer
- Part 5: Proving It — Discharging the IOUs
- Part 6: What the Fabric Costs — and Why It Runs Open SONiC
- The Fabric Is Real Now
- Values Card — What Chapter 12 Hands Forward
Chapter 13: Advanced Networking with VPCs — Walls Within the Walls
- Building Multi-Tier Isolation on the Fabric You Just Proved
- The Story: One Network Was Never Going to Be Enough
- Where We Stand
- What This Chapter Is — and Is Not
- Part 1: The Shape of the Day
- Part 2: VPCs, and the One Fact That Trips Everyone
- Part 3: Designing the Catalogue VPC — Addresses Before Anything
- Part 4: The VPC Offering and the VPC
- Part 5: The Tiers — Where the Lanes Multiply
- Part 6: Network ACLs — The Walls, Drawn Both Ways
- Part 7: The VPC as Code — Reproducible Walls
- Part 8: Deploying the Tiers, Proving the Walls, and Balancing the Load
- Part 9: Site-to-Site VPN — Extending the Private Space to Leeds
- Part 10: Verification — Extending the Zone Script
- Part 11: Troubleshooting — The Stateless Traps and Their Friends
- Part 12: Where This Goes — One Pattern, Many Tenants
- Chapter 13 Summary: Five Things to Hold On To
- The Values Card for Chapter 14
- What’s Next
Chapter 14: Multi-Zone Expansion
- The Cloud Grows a Map of the Country — Without Stretching a Single Fiction
- The Story: Three Cities, One Control Plane, No Long-Distance Lies
- Where We Stand
- What This Chapter Is — and Is Not
- Part 1: What “Multi-Zone” Means Here — and the Anti-Pattern It Is Not
- Part 2: The Site Inventories — Canonical Estate, Honest Addressing
- Part 3: Extending the Fabric — Leaf Pairs to the Manchester Spines
- Part 4: London’s Independent Ceph Cluster — the Chapter 8 Pattern, Four Nodes
- Part 5: Leeds’ Independent Ceph Cluster — Three Nodes, the Honest Floor
- Part 6: Bringing Up the London Zone — the Wizard, Now That We Understand It
- Part 7: Bringing Up the Leeds Zone — Building a Zone With No Front Door
- Part 8: The Region-Level VPC — Sharing a Design Without Sharing a Failure Domain
- Part 9: Verification Across Three Zones — Build-Time, Not the Monitoring Chapter
- Troubleshooting the Multi-Zone Build
- Chapter 14 Summary: Five Things to Hold On To
- The Values Card for Chapter 15
- What’s Next
Chapter 15: Monitoring & Operations
- Observability at Scale — One View of Three Zones
- The Story: Seven Dashboards Are Not a Dashboard
- Part 1: The Observability Problem at Estate Scale
- Part 2: The Estate Observability Hub
- Part 3: Instrumenting the Estate
- Part 4: Dashboards That Answer “How Is the Estate?”
- Part 5: Logs — Shipping the Estate’s Diary Somewhere Durable
- Part 6: Alerting Without a SaaS Pager
- Part 7: Incident Response and On-Call — the Runbooks Owe
- Part 8: Capacity Signals for Operations
- Part 9: Lab Exercise — One View of the Lab