2018-06-04
Microsoft to acquire Github??
I was actually quite shocked. There is this article. The first thing that I was surprised by was that Microsoft has bean negotiations with Github for quite some time. If they do buy Github then it could possibly change the world of open source. Almost everybody I know stores their code on Github. There are a few other places where you can store your code, for example, bitbucket, but the main code depository in the world is definitely Github.
If this acquisition actually goes through - I was trying to understand what would this actually mean? Microsoft would now have acess to every single line of code - which if you come to think of it - it actually quite a frightening thought. Bloody scary!! All the insights into the code, everything, the options are pretty much endless. Yes of course there will be terms, stating what exactly they can do with all this data, what data they will have access to and what they will keep private. We are wary of big brother and our privacy - but entrusting all our code to a potential competitor?
Microsoft has traditionally been percieved as the arch-villian of opensource. But that has changed. Microsoft has become one of the biggest open source contributors in the world, largely because of the visual studio code but they also contribute a good number of other opensource projects. There is a culture change within Microsoft, where the direction has become opensource first, and if you don't do open source and you have to justify why this is not the case. I was personally was exposed to this transformation for a few days where I spent at the Microsoft mothership a couple of weeks ago. I participated in a number of briefings from several leading architects, project managers and product managers within the company and was actually pleasantly that they are becoming an open source company themselves.
So the consequences of such an acquisition are not yet clear to me. For the Github people I have to say "Good for you a huge exit, enjoy the fame, the glory that comes with being bought out by Microsoft". Whatever the numbers may be (two - five billion dollars) is not a small sum. For the rest of people in the world who are using Github this might be a difficult situation. There are not very many neutral places like Switzerland left around in the world and definitely not many neutral places like Github left around in the software world any more.
Everybody has an edge. They might not say that they have alterior motives, but it is all about providing revenue for your company. Not to mention what this edge will give Microsoft as a cloud provider that now has access to the biggest code repositry in the world and a huge developer base which can now tie in conveniently to Azure.. The conspiracy theories and reactions on social media - are really amusing...
Something to think about..
Let me ask you readers of my blog. If Microsoft were to acquire Github, would you continue storing your code in a Microsoft owned repository? Yes or no ?
Feel free to leave your comments and thoughts below.
2012-03-14
Don’t Let your Datacenter Turn into a Datayard
Last night I tweeted a poll asking this question – (please feel free to add your vote)
The choices that people left are more or less what I was expecting but I still think that this warrants a post explaining my thoughts – and also to get yours.
Virtualization is a godsend!! We are finally able to decouple the operating system from specific hardware. For as long as I can remember this was emphasized (by myself – I admit as well) as one of the many benefits for using virtual machines. You no longer have to rely on specific hardware.
So there are a large number of benefits – but what people sometimes overlook is that this decoupling also has a downside to it – and that is related to the poll above.
But before that, another side to this post. What about the migration of old physical machines to VM’s? Consolidation? Does that sound familiar? Well it probably will. I cannot count the number of times I have seen on Twitter people tweeting about converting physical servers into VM’s – I myself have done this quite a number of times.
So what are the reasons that we would convert physical servers to VM’s. Well if you are reading this blog – then you probably don’t need me to answer that question. But I would like to dwell on one specific reason.
Old (ancient/dying/no support/no spare parts) hardware.
You have an application running on a old server – which is being used by some part of the company – and it is critical to their day-to-day operations (isn’t everything????) But the hardware is old, perhaps failing, not reliable anymore. And moving this application to new hardware will require a re-install of the software. But alas the company that sold you the software 10 years ago, has since then evaporated.. I am sure this sounds familiar.
So why is this problematic? You, the VIAdmin saved the day – and averted a large risk – and now have this ancient application running on a VM (until eternity) – the department that owns the application – can breathe easier.
But is this a good thing? Look at the results again
I know that not a lot of people voted – But I am pretty sure that the results would stay more or less the same no matter the size of the poll. And the bottom line comes down the following.
Because of the benefits of virtualization – application owners have less of an incentive to update their applications. And I would like to elaborate a little more on this point.
Before the days of virtualization – when you needed to deploy an application – you would purchase a server with its 3 years warranty and service level (and perhaps even extend that service contract for another two years), install an OS and deploy the application. All parties involved were on board with fact that the server, application and usually also the operating system would need to be re-deployed on new hardware, and perhaps on a new operating system in 5 years time.
In comes the wonders of virtualization. You deploy a VM (no need to install the OS of course) and install the application on top of that. Now you start going into that grey area…
How long will that application / Operating system stay active? 3 years? 5 years? 10? 15 years????
Ladies and gentlemen for those of you who are not aware, Windows NT 4 was released on 29 July 1996, and Windows 2000 on 17 February 2000. End of life for support on both operating systems has long gone by – many many years ago!!! And do you know what Windows 2003 is not that far off? Security Patches are no longer being released. You can only dream of getting support from Microsoft. I am sure that the same goes for the older flavors of Linux as well.
There will always be cases that a dying application needs to be moved to a VM and saved, but in the same breath that you take to revive this server – your next immediate action should be how do you retire this server? The sooner the better.
We are all guilty of hosting old applications and operating systems, I know for sure I am as well. There are benefits to virtualization – but there are drawbacks as well. These can be averted with proper planning – defined standards and a strong will. Without those your virtual infrastructure might one day look like this:
I would like to thank @tscalzott @TimStephenson @egrigson @tednorris for joining in on the conversation.
If you would like to share your opinions, ideas or your view on this post, on how you prevent your datacenter from turning into a datayard – please feel free to do so in the comments below.
2012-01-19
System Center 2012 Resources – Say How Much?
**Of course this is not a GA product (yet). Hyper-V 3.0 is not GA (yet). So this is all theoretical and in the future.**
Microsoft is about to starting to push their Private Cloud offering.
The first thing I always look at is what are the components involved.
From the Download Microsoft Private Cloud Evaluation Software page :
- System Center 2012 App Controller provides a common self-service experience across private and public clouds that can help you empower application owners to easily build, configure, deploy, and manage new services.
System Requirements >>- System Center 2012 Configuration Manager provides comprehensive configuration management for the Microsoft platform that can help you empower users with the devices and applications they need to be productive while maintaining corporate compliance and control.
System Requirements >>- System Center 2012 Data Protection Manager provides unified data protection for Windows servers and clients that can help you deliver scalable, manageable, and cost-effective protection and restore scenarios from disk, tape, and off premise.
System Requirements >>- System Center 2012 Endpoint Protection, built on System Center Configuration Manager, provides industry-leading threat detection of malware and exploits as part of a unified infrastructure for managing client security and compliance that can help you simplify and improve endpoint protection.
System Requirements >>- System Center 2012 Operations Manager provides deep application diagnostics and infrastructure monitoring that can help you ensure the predictable performance and availability of vital applications and offers a comprehensive view of your datacenter, private, and public clouds.
System Requirements >>- System Center 2012 Orchestrator provides orchestration, integration, and automation of IT processes through the creation of runbooks that can help you to define and standardize best practices and improve operational efficiency.
System Requirements >>- System Center 2012 Service Manager provides flexible self-service experiences and standardized datacenter processes that can help you integrate people, workflows, and knowledge across enterprise infrastructure and applications.
System Requirements >>- System Center 2012 Virtual Machine Manager provides virtual machine management and services deployment with support for multi-hypervisor environments that can help you deliver a flexible and cost effective private cloud environment.
System Requirements >>
Man - that is a lot of components.
I then went to look at the system requirements (CPU/RAM only) - I only took the recommended values
I would like to say two things regarding this list.
- I probably grossly miscalculated - and I am 100% sure that you can consolidate some of these components onto one machine - but for the sake of the argument - let us say they are all separate instances.
- Are you kidding me???? Do you know how many components that involves? And this is supposed to be "simple" ??
I would like to stress - this is not a price comparison of who is cheaper / better / more handsome. I just took into what are the resources needed to run such a solution.
One last thing. the offering is licensed in two editions Standard / Datacenter.
Tell me someone in their right mind who would only by this for 2 VM's. Which means you go for the Datacenter license - and ahem .. did I mention you need to have and Enterprise Agreement (EA) with Microsoft to be able to use this?
**On a personal note - If people thought that VMware licensing was complicated - just try and understand this document above.**
I actually would like to compare this to the requirements needed for a vCloud solution - it would be interesting to see, if I have forgotten any components below that would provide a parallel solution as the one above please feel free to let me know.
- vCenter
- vCenter Database Server
- vCenter Update Manager
- vCenter Update Manager Database Server
- vCloud
- vCloud Database Server
- vCloud Connector
- vShield Manager
- Orchestrator
- AutoDeploy
- vCOPS Enterprise
- vCenter Configurations Manager
- Site Recovery Manager
- Service Manager
- vFabric Application Performance Manager
Your Feedback is welcome (and let the flaming begin!)
2011-05-17
Why Should you Care about Veeam Support for Hyper-V
I will not go over the details of this announcement that was released today.
Both David Davis and Sean Clark wrote very good articles about the release.
I do want to add a small point of my own, and that is why I think this is a big thing - or at least the start of a big thing.
There is no doubt that:
- VMware is the current market leader.
- Microsoft see VMware as the biggest competitor in the virtualization market.
- vSphere is the more mature product (and depends who you ask, more robust as well).
After this announcement it is clear - Hyper-V is here to stay.
I am a VMware fan (if you haven't noticed then you are not following my blog) but part of my job is to provide the best solution to my customer - and that solution depends on the customer. If the solution that suits them best is not based on VMware technology - then so be it - because it is right for the customer.
A year or two ago - the vendor bashing and FUD from both sides was in abundance, Microsoft said you don't need this feature - and VMware said you cannot live without it. VMware said that Microsoft does provide this - and Microsoft played catch up with the technology race to get those features that VMware has. Bad mouthing - from both sides - but I am happy to say - that it has calmed down as of late - and both parties are focusing on what they have - and not on what the competitor's do not.
So back to Veeam's announcement and why is this a big thing (IMHO)? Veeam is a company that has based 100% of their product (and revenue) on VMware. From day one. I think that it has paid off and they have found a very good place in the market for all of their products. And now the announcement that they will be adding support for Hyper-V. If a company that has based their complete business on VMware - are now opening up to different Hypervisors - then is a turning point. Not only is Microsoft getting part of the customer share - and how much is not the issue - they have started to get into the surrounding companies that make their bread and butter off of virtualization. I have - for a while - been asking any vendor that I have tried their technology, what are your plans for multi-platform support. Be it monitoring solutions, backup solutions capacity management or cloud - and I hearing always the same answer - at present we do not - but it is on the roadmap! Some for Hyper-V some for XEN, some for RHEV and some for all of the above. Veeam is not alone - the ISV's realize that they cannot afford not think about supporting multiple vendors and this is a good thing especially for Microsoft
Veeam is going the extra mile here by developing features that do not even exist for Hyper-V, as you can see the slide below
I will not be going into the debate of what the better/faster/cheaper/sexier product is. I do have to agree though, Microsoft is gaining market share - both with the customer and with the ISV's as well.
I would be happy to hear any comments.
2011-02-28
Cloud Connect - Here is your Chance!!
I received this email on Friday and just received the OK to pass this offer on.
From: A.
Sent: Friday, February 25, 2011 21:09
To: maishsk@…Subject: Thanks for completing that survey on clouds
You're one of the winners (according to the very scientific =randbetween function in Google Spreadsheet.)
If you can make it to Cloud Connect (www.cloudconnectevent.com) on March 7, let me know, and I'll mail you a Flexpass code which will let you attend the whole event for free. If you can't make it, please tell me so I can let the next winner know.
A.
I will not be able to make this conference - I would have really liked to.
And here is where someone gets to benefit. I am giving this pass away to a someone who will be able to use it. This is how it will work.
Post a comment below the post to explain why you would like to go, and what the benefit you expect to receive from participating in this event and how you will use this knowledge to pay something forward to the community.
The winner will be chosen from those who posts a comment below. I will look for a co-judge to determine who that is.
Entries will be accepted until 21.00 (GMT +2) Wednesday, March 2nd, 2011.
Winner will be announced by 23.00 (GMT +2) Wednesday, March 2nd, 2011.
The Winner will receive a full Flex Pass valued at $2,095 - Hotel and Travel arrangements you will have to take care of yourself.
The Speaker List - if very impressive and here is some more info about the conference.
ACCELERATE YOUR CLOUD STRATEGY
Join your colleagues at Cloud Connect, where enterprise IT and cloud providers meet to set the cloud roadmap and explore the latest technologies, platforms and opportunities in the cloud.
Thousands of cloud leaders and technology experts from top companies attend to get the latest on private clouds, industry standards, data storage and CloudSec. Gain insight to move your deployment forward and reap the benefits of the cloud.
Gain comprehensive insight from the experts who are living the disruptive transformation of the cloud every day. Learn high level strategies to craft your utility computing plans, details on how to optimize cost, performance, capacity and risk, and real word end user examples.
Cloud Economics
Hear leading proponents of Cloudonomics provide detailed analytical methods, case studies and benchmark data.
• Cloudonomics: Private, Public or Hybrid?
• Clearing Up Cloud Computing
• The Economics of the Cloud
• How Does ROI Drive Architecture?
CloudSec
Learn how to protect yourself through encryption, auditing, new technologies and proven best practices.
• Attacking and Defending Cloud Computing
• Building Trust and Compliance in the Cloud
• Securing the Cloud—A Cloud Provider’s Perspective
• Private vs. Hybrid vs. Public Cloud Security: Dismissing the Myths
Culture, Risks and Governance
Find out how to address the risks and challenges that arise on your way to cloud adoptation.
• Cloud Risk Factors and Assumptions: Any Different than the Economics of Traditional IT Risk?
• Cloud Regulation: Is Governance Needed or Even on the Horizon?
• Cloud Hedging Debate
• Clouds Beyond Borders: When are Clouds too Big to Fail?
The Future of Utility Computing
Learn how IT strategy will change in the coming years thanks to the new era of democratized IT.
• The Move to Turnkey Computing
• A Global View of Connected Computing
• Cloud Computing and the Internet of Things
Performance and Monitoring
Learn how to measure and manage on-premise and third-party hosted cloud-based workloads.
• Understanding Cloud Performance
• Cloud Performance from the Perspective of Vendors and Users
• Performance Measurement for the Cloud
Data and Storage
Look at the emerging field of “Big Data” and what cloud storage means for IT professionals.
• Running One of the Biggest Transactional Websites in the Cloud: How Reddit Manages their Data
• NoSQL and Big Data in the Cloud
• Everyone Can Now Afford a Disaster Recovery Center
• Creating a Storage Cloud with Ceph
DevOps and Automation
Look at the changing face of application engineering, from the first line of code to the automation of massively distributed systems.
• Moving from “Dev vs. Ops” to “DevOps”
• Automating the Gaps Between Development and Operations
• Ask the Experts: The DevOps Panel
Design Patterns
Learn how to tailor cloud architectures, keep applications fast and reliable, and handle off-the-shelf and home-grown applications as they move to on-demand platforms.
• Scalable Application Design Patterns: 30 Proven Patterns in 30 x 2 Minutes
• Building Highly Scalable Java Applications on Windows Azure
• How to Think Like a Cloud: Architectural Design Patterns in AWS
• Cloud Event Processing
Private Clouds
See hybrid and private cloud architectures, focusing on how cloud models alter infrastructure, network and storage decisions.
• Virtualization On Demand vs. Private Cloud
• Real Barriers and Solutions to Implementing Private Cloud
• Hybrid Cloud Computing: Final Answer or Transitory Architecture?
• Implementing Private Cloud: Open Source vs. Everyone Else
Cloud Connect is the only event to bring together cloud customers and providers in one place to drive cloud computing growth and innovation.
See the latest cloud technologies and learn from thought leaders in Cloud Connect’s comprehensive conference and expo.
Good Luck!!
2010-11-02
List of Free Ebooks
I came across this list of free eBooks that Microsoft has released as of late.
Windows 7 troubleshooting tips
Deploying Windows 7, Essential Guidance
Introducing Windows Server 2008 R2
First Look Microsoft Office 2010
Perhaps you can find something useful here.
2010-07-16
Quest ActiveRoles Management Shell for AD-1.4
Quest just released a new version of there amazing Active Directory Module - Version 1.4
Here is Dmitry’s Post about the release:
There are many new Cmdlets available here are some of the details from the release notes
1.1. New cmdlets
• Get-QADLocalCertificateStore
• New-QADLocalCertificateStore
• Remove-QADLocalCertificateStore
• Get-QADCertificate
• Where-QADCertificate
• Add-QADCertificate
• Import-QADCertificate
• Show-QADCertificate
• Edit-QADCertificate
• Export-QADCertificate
• Remove-QADCertificate
• Remove-QADPrivateKey
• Get-QADCertificateRevocationList
• Add-QADCertificateRevocationList
• Import-QADCertificateRevocationList
• Export-QADCertificateRevocationList
• Remove-QADCertificateRevocationList
• Get-QADPKIObject
• Publish-QADCertificate
• Unpublish-QADCertificate
• Publish-QADCertificateRevocationList
• Unpublish-QADCertificateRevocationList
• Add-QADProxyAddress
• Set-QADProxyAddress
• Remove-QADProxyAddress
• Clear-QADProxyAddress
• Enable-QADEmailAddressPolicy
• Disable-QADEmailAddressPolicy
• Set-QADProgressPolicy
• Get-QADProgressPolicy
• Set-QADInactiveAccountsPolicy
• Get-QADInactiveAccountsPolicy1.2. New parameters
1.3. Multi-value SearchRoot Parameter
The data type of the SearchRoot parameter has been changed to support a search within two or more containers at a time. This parameter now accepts an array of objects rather than a single object as it was with earlier versions. This makes it possible for the cmdlet to search multiple containers identified by the SearchRoot parameter value. For example, you can supply an array of strings each of which
represents the canonical name of a certain container, to retrieve objects from all of the containers specified.2. Bugs fixed
[48939] Cannot work with object that contain round brackets in their names in Proxy mode.
[48941] Command 'Get-QADRootDSE | Format-List *' fails in Proxy mode.
[112742] Command 'Get-QADGroup -ContainsMember <member id>' doesn't work in Proxy mode.
[112870] Command 'Get-QADGroupMember 'Domain Users' | Get-QADUser' renders significant memory leak in Direct mode.
[113168] Set-QADUser can't work with input object of type 'inetOrgPerson'.
[115955] New-QADObject can't create objects with special symbols in name in Proxy mode.
[117478] Cannot set AD LDS user as owner for another AD LDS user.
[114381] ObjectAttributes parameter in New-QAD* cannot be passed by pipeline.
[116033] Get-QARSApprovalTask throws exception if task with status ‘Canceled’ present in result.
[115106] Add-QADGroupMember throws error when trying to add user to it's primary group.
[116484] New-QADObject should continue its execution with -ErrorAction:Continue if the object already exists.
[104161] 'Remove-QADObject -DeleteTree' should work properly for objects in Win 2008 R2 Recycle Bin.
[121356] Set-QADUser works incorrectly with import of multivalued attributes.
As you can see from the release notes there a multitude of new features released.
I find these Cmdlets a necessity in my day to day work in Management of Active Directory.
Download Links Below
ActiveRoles Management Shell for Active Directory 32-bit
ActiveRoles Management Shell for Active Directory 32-bit - Zip
ActiveRoles Management Shell for Active Directory 64-bit
ActiveRoles Management Shell for Active Directory 64-bit - Zip
ActiveRoles Management Shell for Active Directory - Administrator's Guide (PDF)
ActiveRoles Management Shell for Active Directory - User Help Guide
The Zip files include the Build History (Release Notes) Administrator's Guide and the Help Guide.
I am personally looking forward to kicking the tires on this one!
2010-06-20
Virtualization Domain Controllers - #2
I received a number of comments on my previous post and offline as well I want to clear up some things regarding the previous post.
I am not against virtualizing domain controllers - not at all. I am against trying to P2V a domain controller. It seems that was not clear enough from the last post. I do still advise that if your risk analysis - you should do that before virtualizing your domain controllers (or anything else for that matter) comes out that it is more cost effective to keep one Physical DC then do so. There are a number of reasons to go either way - it all depends on your environment and what you are willing to risk.
It will save you so much headache and anguish - if you would just promote a new clean VM to a Domain controller.
Now lets go into a a good reason (or two) why you should actually virtualize your domain controllers
- Domain Controllers do not need that many resources
Of course there is a whole science behind this and a good amount planning guides out there - you can see that a domain controller does not need that many resources. It has relatively stable RAM usage (loading the AD database into RAM is mostly what it does) - CPU usage will depend on the authentication traffic - same with Network and Disk IO.
The resource usage can be predicted very well - so you can plan the resources for such a Machine. - You should have more than one - if you don't then you are not doing your job correctly. But that means if your one of your Domain controllers fail - because your ESX host failed - then you are still up and running - because you have another DC running (either on an ESX host or physical).
- Testing purposes. You need to prepare your AD Schema for the upgrade to Exchange 2010. Even though the schema extension is a Microsoft product, and has probably been tested countless amount of times with all levels of AD Domains. But of course every domain is different. And no matter how many times Microsoft have tested it - it has not been tested on my domain, in my environment, with my applications.
So for this I would need to test the upgrade. So what better way to do it on a replica of my Production Environment.
All I need need to do is to power off the DC, copy the VM to a closed lab environment, power them both back on, fix up a whole bunch of stuff to get it working in the lab without access to the outside world, and hey I have a full replica of my production domain that I can test.
So as you can see there are benefits to virtualizing your DC's - just a few of them above.
What other benefits would you add to the above list? I would appreciate your comments.
2010-06-13
Virtualizing Domain Controllers
One of the frequent questions that come up on the forums is,
"How do I convert (P2V) my Windows Domain Controller (or SBS Server)?"
Let me first start with the following statement.
DON'T!!!!
Now that I have that off my chest - lets explain why and provide some references to back that up.
A Domain Controller could possibly be - and probably is - one of the most important computers on your network. Almost everything relies on Active Directory:
- Authentication
- Web
- File Access
- etc. etc.
If your Domain controller is not functioning - then rest assured - slowly but surely a lot of other things will stop working shortly thereafter.
I was reading a good blog post from the Active Directory Team on their blog - How to Virtualize Active Directory Domain Controllers (Part 1). This is a Hyper-V centric article - but it is relevant to VMware as well .I do advise giving the full article a good read.
This is what I have taken with me from the above article.
- In most environments there is no reason not to virtualize your Domain Controllers. If they are only being used as Domain Controllers (and not File Servers, DHCP, Web Servers) then unless you have a very large or extremely busy environment your DC's will not need an extravagant amount of resources so it can run very nicely as a virtual machine.
- I would always, ALWAYS, leave at at least one physical server running as a domain controller on the network. The reason being, if your virtual infrastructure depends on your Active Directory infrastructure - and it always does then if your DC's are not available due to your Virtual Infrastructure being down, or your storage being down, then you will have a serious chicken and egg situation - with not being able to easily bring up the storage or the Virtual infrastructure because they are dependant on DNS / Active Directory and that cannot come up because the the storage / Virtual infrastructure is not available.
Jason Boche posted an article last week describing a situation where he had a network component fail - which brought down his NFS storage. One of the VM's on that storage was his Domain Controller. Once the failure was fixed, he could not bring up the NFS datastores - because they were relying on Name Resolution - and the DC was a VM on the NFS datastore, which could not be mounted, because there was not Domain Controller. As I said Chicken and Egg. True there are ways to get around it but I sleep better at night spending that extra amount of money on a physical server for a domain controller. - Time Synchronization. A domain controller should always be synchronized with an external time source. do not rely on the internal VMware Tools.
- Do not stop or suspend Domain controllers. Leave them on or power them off.
- Do not restore a Domain Controller from a snapshot. You will run into USN Rollback problems.
- Back up you Domain Controller the same way you would back up a Physical Server, be it NTBACKUP, Windows Backup and Restore (for Windows 2008 and Up) or a 3rd party backup client.
- If you try to P2V a DC you will most likely run into a USN Rollback problem - Knowledge Base Article.
- The Easiest way to migrate a Domain Controller is to install a new VM, DCpromo the VM as a new DC and then remove the old one. The process of migrating the data in Active Directory from one computer to another is really simple and completely taken care of by Windows, so do not try and complicate things.
- VMware KB 1006996 - Virtualizing existing domain controllers.
2010-05-06
MMS 2010 Labs: Powered by Hyper-V -Whatif
No - I have not gone over to the Dark Side. And forgive me for the Powershell pun, but I read an article by Ronald Beekelaar on the Microsoft Virtualization Team Blog - demonstrating the wonders of Virtualization that were used in MMS 2010 Labs: Powered by Hyper-V, System Center & HP...
The numbers are impressive - very impressive - I would suggest that you read the article.
The numbers were as follows:
- 6 half racks - ~7 Servers per rack
- 41 HP Proliant DL380G6 servers (Dual socket, quad-core, Nehalem Processors with SMT, 16 LPs per system) each configured with 128 GB of memory and 4x300 GB SAS drive of local storage striped
- All networking was 1 Gb/E switched (no 10 Gb/E) and demonstrates the efficiency of Remote Desktop Protocol (RDP). Even with hundreds of labs going on simultaneously, network bandwidth was never an issue on 1 Gb/E
- Windows Server 2008 R2 Hyper-V and System Center
- Virtual machines were configured on average with 3-4 GB of memory each and the majority of labs used multiple VMs per lab.
- ~40,000 Hyper-V VMs for ~80 different labs in 5 days
Ok, so I did a bit of math. I came to the conclusion that the most that they could run on 1 server at any given time would be 40 VM's per server.
Let me explain the calculation - and forgive me for my assumptions, and I not sure that they are 100% accurate but you will see where I am getting here.
My assumptions:
- The hosts were not CPU / network / Disk constrained
- RAM Usage on each host should not be higher than 120GB (90%) - I was being conservative.
- The average RAM used per VM that was quoted was 3-4GB, I assumed that it was 3GB .
Using those assumptions I got to the following numbers.
120GB (Host RAM) / 3GB (VM RAM) = 40 VM's per host.
40 (VM's) x 41 (Hosts) = 1640 Virtual machines running simultaneously
So 1640 VM's running simultaneously is a good amount of VM's, now of course not all of them run at the same time. and bringing up labs and down throughout the 5 days - I can imagine how they got to the impressive number of ~40,000 Hyper-V VMs.
But I wanted to try an see what would the comparison be with vSphere.
Again I made assumptions (in addition to the ones above) - which I think are safe and conservative.
- Since almost all the VM's on the host are the same OS, same configuration - the amount of memory that could be reclaimed was 30%.
- I did not calculate any further benefit from the additional shared memory after that.
Using those assumptions I got to the following numbers:
40 (VM's) x 3GB (RAM) = 120GB
30% of that that RAM is Shared - 120*70% = 36GB
36 (GB) / 3 (GB per VM) = 12
40 (VM's) + 12 (VM's - from page sharing) = 52 VM's
1640 (simultaneous VM's) / 52 (VM per host) = 31.5 (Servers)
31.5 (Servers) / 7 (Servers in a rack) = 4.5 (Racks)
10 (servers less) x $20,000 (Cost per server) = $200,000 less using vSphere
This is not taking into account:
- 10 (servers) x 200 (watts per server) = 2000 watts
- Additional charges for shipping costs
- Network Components
- etc.
Perfect example of - even if vSphere is more expensive, it will save you a hell of a lot of money!!!!!! And to quote Microsoft themselves
Still, in the end, the big question to ask yourself is the following: Is it worth all this expense for VMware, when the Microsoft solution offers a comparable or even better feature set for much less cost? Is it worth the extra line item on the invoice, the extra line in the budget, to use VMware virtualization when it's built into Windows? That is a question I think many customers will be asking themselves in the coming months and that is just another reason that you should start using Microsoft Virtualization solutions.
So do you know the answer???
2010-03-07
Quick Powershell tip - Remote Windows Management
Something that I do every now and again (almost every day - many times per day) is to connect to the Event Viewer / Computer Management / Services console of a Remote Windows machine for troubleshooting purposes.
Now of course you could do it like this:
Start -> Run -> compmgmt.msc
Right-Click -> Connect to another computer -> <Computer_Name> -> OK
or you could make it even shorter
Start -> Run -> compmgmt.msc /computer:<Computer_Name>
But after spending some time reading about Powershell today, I decided since I have a Powershell prompt open the whole time would it not be easier to do it in Powershell as well? And maybe also do it one command with switches?
The result is the function below:
function manage-server {
param ()
if ($args.count -eq 0) {
do {
$compname = Read-Host "Which server would you like to connect to?"
} until ($compname -ne $null)
} else {
$Compname = $args[0]
}
if ($args[1] -eq $null) {
do {
$task = read-host "Which task would you like to perform? [Manage/Event/Services]"
} until (($task -match "manage") -OR ($task -match "event") -OR ($task -match "services"))
} else {
$task = $args[1]
}
switch ($task) {
Manage {compmgmt.msc /computer:$compname}
Event {eventvwr.msc /computer:$compname}
Services {services.msc /computer:$compname}
}
}And to make it even shorter you can create an Alias for the command
New-Alias -Name manage -Value manage-server -Description "Quick Remote Manage Server"
3-5. If the Server name is not entered you will be prompted for input.
10-13. If you have not entered which task you would like to perform - you will be prompted.
18-22. A Switch statement on the task variable will perform the correct task.
I am loving Powershell more and more and more!!
2010-02-10
New Hyper-V Security Vulnerability
Many eons ago there was talk about patch footprints - comparing ESXi to Hyper-V, footprints and security patches.
So today I came across this one.
Microsoft Security Bulletin MS10-010 - Important
General Information
Executive Summary
This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
This security update is rated Important for all supported x64-based editions of Windows Server 2008 and Windows Server 2008 R2. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerability by correcting the way Hyper-V server validates encoding on machine instructions executed inside its guest virtual machines. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
So what is so different about this one - I mean Microsoft release patches once a month (and in certain extreme cases - more often).
Read the fine print…
An attacker must have valid logon credentials and be able to log on locally into
a guest virtual machine to exploit this vulnerability.
From the details:
An attacker must have valid logon credentials and be able to log on locally to a Hyper-V virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
What is the scope of the vulnerability?
This is a denial of service vulnerability. An attacker who exploited this vulnerability could cause the affected Hyper-V server to stop responding and require it to be restarted. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.What causes the vulnerability?
This vulnerability is caused by Hyper-V server incorrectly validating the encoding of specific machine instructions executed inside the guest virtual machines. Due to this lack of validation, processing of these instructions may cause the Hyper-V server application to become non-responsive.What might an attacker use the vulnerability to do?
An attacker who successfully exploited this vulnerability could cause a user’s system to become non-responsive until the system is restarted. Note that exploitation of this vulnerability could cause the actual Hyper-V server to stop responding, including all guest virtual machines hosted by that server.How could an attacker exploit the vulnerability?
An attacker would have to be an authenticated user in one of the guest virtual machines hosted by the Hyper-V server and would need to have the ability to execute arbitrary code on the system. An attacker could then run an untrusted executable on the system that invokes a malformed sequence of machine instructions and thereby cause the Hyper-V server to become non-responsive.
And again the importance is the details..
Note that exploitation of this vulnerability could cause the actual Hyper-V server to stop responding, including all guest virtual machines hosted by that server.
And yep..
Restart Requirement
Restart required?
Yes, you must restart your system after you apply this security update.
HotPatching - Not applicable.
Pot calling the kettle black ??
2010-01-15
A bit of housekeeping – Powershell
I have been busy with using Powershell in these past few days.
I would like to share with you two of the scripts that I used lately. They were both used because of a password change that was made on a service account.
Now the thing about service accounts in Windows 2003 is, they are good, they need elevated privileges in some cases, and since the account is used for the specific purpose then you know that you have to change it once in a while and you know where. Problem is though unless you catch them all – and someone – somewhere did not update the password somewhere, then you will start having issues with account lockouts.
First is to get all the services from all the computers in my OU, and change the password
1: $logfile = "c:\temp\results.log"
2: $serviceaccount = "svcmacct"
3: $password = ""
4: 5: $serviceslist = Get-QADComputer -SearchRoot "OU=Public Servers,DC=maishsk,DC=local" -OsName window* -searchscope "subtree" -ErrorAction SilentlyContinue | `
6: ForEach-Object {
7: (Get-WmiObject -Class Win32_Service -ComputerName $_.Name -ErrorAction `
8: SilentlyContinue | where {9: $_.'StartName' -like $serviceaccount
10: } 11: ) 12: } 13: 14: [System.Reflection.Assembly]::LoadWithPartialName('system.serviceprocess')
15: 17: ForEach ($line in $serviceslist) {
18: Write-Host Processing $line.Systemname19: $service = Get-WmiObject win32_Service -ComputerName $line.Systemname -Filter "Name='$($line.Name)'"
20: Write-host Stopping Service $line.Name21: (new-object System.ServiceProcess.ServiceController($($line.Name),$($line.Systemname))).Stop()
22: (new-object System.ServiceProcess.ServiceController($($line.Name),$($line.Systemname))).WaitForStatus('Stopped',(new-timespan -seconds 90))
23: if ($? -eq $true) {
24: $service.Change($null ,$null ,$null ,$null ,$null ,$null , $serviceAccount, $password ) 25: Write-host Starting Service $line.Name26: (new-object System.ServiceProcess.ServiceController($($line.Name),$($line.Systemname))).Start()
27: (new-object System.ServiceProcess.ServiceController($($line.Name),$($line.Systemname))).WaitForStatus('Running',(new-timespan -seconds 40))
28: write-output $(get-date -DisplayHint time)` --` Service` $($line.Caption)` on` $($line.SystemName)` has` been` updated` and` restarted >> $logfile
29: } else {
30: write-output $(get-date -DisplayHint time)` --` Service` $($line.Caption)` on` $($line.SystemName)` update` failed >> $logfile
31: } 32: }Line 5 – get all the computers in the desired OU and get the services.
Line 22 – Here is a wait statement for the service to stop, otherwise this will cause issues with the rest of script. Please remember that the time span is there to ensure that if something goes wrong – then you script will continue, otherwise you will have to close the shell window - Ctrl+C will not work.
Line 28 – logs the results to a file including a time stamp.
Second script was to change the passwords for all the scheduled tasks using this same service account
1: 2: $mycomps = Get-QADComputer -SearchRoot "maishsk.local/Public Servers" -SearchScope Subtree -SizeLimit 0
3: 4: $logfile = "c:\temp\tasklist.csv"
5: $results = "c:\temp\results.log"
6: 7: $report = @()8: $mycomps | ForEach-Object -ErrorAction SilentlyContinue {
9: schtasks.exe /s $_.Name /query /v /fo csv >> $logfile 2>>c:\temp\errors.txt 10: } 11: $report = import-Csv $logfile 12: 13: ##Get all tasks that are run under a certain user
14: $svcaccount = Read-Host "Please Enter Service account Name (Domain\Username)"
15: $mytasks = ""
16: $mytasks = $report | Where-Object {($_."Run As User" -like $svcaccount) -and ($_."Next Run Time" -ne "Disabled")} | select Hostname, TaskName
17: #Remove unwanted Characters18: $mytasks | ForEach-Object {
19: $_.TaskName = ($_.TaskName).Trimstart("\")
20: } 21: 22: ##Change credentials for the task
23: 24: foreach ($task in $mytasks) {
25: schtasks.exe /change /S $($task.HostName) /TN "$($task.Taskname)" /RP $password >> $results 2>>c:\temp\errors.txt
26: }Line 9 – schtasks.exe is the was I decided to go to get the info – I could not find anything else in Powershell that would extract the info.
Line 18-19 – the output came back with an extra “\” in the beginning – I used the Trimstart method to remove it.
Line 25 – This actually took a while to find the exact syntax that I was looking for.
If you have any comments or improvements I would appreciate you input.
2009-12-20
Updating a User attribute in the Enterprise
I was asked to update an attribute of the EmployeeNumber for each and every user in the Enterprise for a new Application that will be using the newly populated attribute for a Global Database application.
I had several examples that I could use for the job utilizing VbScript – but I wanted to use Powershell for the task.
It turned out to be a relatively easy task – using the Quest Active Directory Commandlets.
1: add-PSSnapin quest.activeroles.admanagement
2:
3: Connect-QADService -Service domain.com -Credential (Get-Credential)
4:
5: $infile = Import-Csv "c:\temp\file.csv"
6:
7: $logfile = "c:\temp\logfile.log"
8: foreach ($line in $infile) {
9: set-QADObject ($line.domain +"\" + $line.login) -ObjectAttributes `
10: @{employeeNumber=$line.guid}
11: if ($? -eq $true){
12: Write-output "Updated: $($line.domain)\$($line.login) with employeeNumber: `
13: $($line.guid)" >> $logfile
14: } else {
15: Write-output "Error in updating: $($line.domain)\$($line.login)" >> $logfile
16: }
17: }
18:
19: ##Get Results
20: $results = foreach ($line in $infile) {
21: get-QADObject ($line.domain +"\" + $line.login) -IncludedProperties `
22: Name, employeeNumber | select Name, employeeNumber
23: }
24: $results >> $logfile
25:
26: Disconnect-QADService -Service domain.com
A Quick explanation:
Line 1: Add the Quest Snapin
Line 3: Connect to the domain with acquired credentials
Lines 5-7: import the CSV file that was formatted - domain,login,guid, and create a log file for results
Lines 8-17: Go through each line in the CSV – if successful log to the file and if not then report the error to the log file.
Lines 20-24: Go through the list of users again – retrieving only the Name and EmployeeNumber properties and pipe the results in the same log file.
The script to a longer to write than it did to run.
Hope you enjoyed the ride.


