Architecting within a License constrained world

Tags

, , , ,

In an ideal world software design shouldn’t be driven by software license costs if constraints. But when you can be paying tens or hundreds of thousands of dollars per server for an application or middleware it isn’t an aspect you can ignore. The challenge is when licensing rules are so complex like those for Oracle you either end up with licensing experts reviewing design artefact or you need to find an alternate approach (and the hope of using agile strategies with such a review framework necessary have gone).

For those less aware of Oracle’s licensing you have be licensed by CPU, by users, by profitability and probably will be impacted by atleast 2 of these models. Then each license can also be constrained by usage (unlimited or limited) which says that you can use some products with some things and not others, or use your licenses for only particular activities. Finally you have product dependencies, so the licensing of 1 product and indirectly impact how you can use another. For example I may have unlimited use for Weblogic (on 20 CPUs) but SOA Suite, the components that together allow you to run Process Integration Packs (PIPs) which as a Fusion Middleware offering provide a collection of middleware components to achieve common tasks – for example keep your customer information synchronised between a CRM solution and your accounting solution, which maybe limited to only work with Oracle applications – so extending a PIP to also send one of your own application an event wouldn’t be allowed (unless you’ve built an extension on an approved Oracle application).  Then for fun you have what are called Unlimited License Agreements (ULAs) – although they’re not really unlimited.

Just when you think you’ve got a grip of the licensing story, there is one more mix of the pot.  When you’re negotiating licensing you’re likely to be working through a purchasing team who aren’t technical Oracle product experts, and licensing discussions are likely to be done whilst costing a programme where unless you’re an enterprise mature organisation or operationally very well instrumented to measure this information it isn’t going to be easy to get volumetrics and an ability to determine likely throughput (i.e. how complex and demanding will your custom logic be).  So by the time you get to from your conceptual to-be perspective which told your which products you need to when you’re actually working on the realisation you may well hit  challenges.

With all of this in mind, we’ve arrived with the idea of usage scenarios. We’ve tried to differentiate usage scenarios from design patterns, as their goals also differ; a pattern is typically to provide a means to describe and provide good design approaches to technical problems, think of things facades and factory’s from the Gang of Four (GoF) or composite patterns such as VETO and here we seeking a means to communicate what can or can’t be done. These aren’t use cases either, if for no other reason to avoid the UML notation association.

So how does it work, so we have identified common or likely approaches to using our Oracle technology stack, need them so there is a short hand reference (as you have with design patterns) and then determined of the scenario is permissible by licensing rules. The idea is that an application architect or developer can design a solution and then verify the solution against the scenarios. To start with go for the obvious scenarios, as things go forward when a situation crops up where there isn’t a scenario you can add the the catalogue  and get confirmation as to compliance.  This should mean after a short period of development you’ll reach a point where you’re not consulting licensing experts all the time.  The secret is not to try ‘boil the ocean’ on day 1 as you’ll invest a lot of time, potentially creating representations of things you’ll never do and produce a very bulky artefact for your developers to try and work with.  Oracle’s AIA Developer Guide

With the scenario we document references to the various license and contract documents showing which clauses drove the decision so you don’t have to rework out how you determined the legitimacy of the scenario.  I’ve created a fake representation of a usage scenario below.

There is a further bonus, you can drive into the guidance when there is a need for additional governance attention.

Of course this mechanism doesn’t tackle the question of is there sufficient licensed capacity. As capacity management has its own set of challenges (such as balancing the capacity requirement forecasts for multiple current development programmes that are likely to be taking place vs actual consumption and forecast consumption for business growth).

The following diagram is a mock up of the sort of diagrams produced. Mocked up as I don’t want (and shouldn’t) disclose any information about what specific technologies and approaches we’ve adopted internally.

Usage Scenario with 1 scenario acceptable, another note

Usage Scenario with 1 scenario acceptable, another not

 

Key

 

approval

 

UK Oracle User Group – Special Interest Groups

Tags

, , ,

I am fortunate enough to have an employer who promotes the idea of community participation both internally but also with communities relating to our technology vendors such as Oracle. As a result manage our membership of the UK Oracle User Group.

The original motivation for membership was that membership effectively paid for attendance to the big annual conferences, given the chance of attending Oracle Open World was a lot less likely.

In addition to the conference opportunity, part of our membership is the opportunity to participate in Special Interest Group (SIG) sessions. There are SIGs covering different aspects of Oracle’s portfolio from middleware and development technologies (my specialisms) through to Supply Chain and JD Edwards and obviously database tech. I have to admit I didn’t have great expectations when I attended my first SIG. But actually the first SIG and subsequent ones I have attended have been gold mines of useful information. The sessions cover a range of topics and the presentations come from customers, partners as well as Oracle and are typically very conversational as a result you pickup insight into a lot of practical aspects not just theory as you’d commonly get in say a training session.

As Oracle support the SIGs by having representation at the SIGs which means there is potential opportunities to pick an SME’s brains – 15 minutes of free consultancy over coffee (something that doesn’t come often with Oracle 😉 ). Not to mention time given in the day to chew the fat with partners and other customers. For example on my 2nd SIG session I ended up discussing experiences of working with Packt Publishing with an Oracle Partner (not necessarily directly related, but interesting to see what the experience was like from an author’s perspective).

I know from talking with other colleagues where I work who have attended SIGs have come away feeling that it was a day well used (and have also encouraged other to participate). It would also seem that many people who attend also participate on a regular basis suggesting they to get a lot out of the sessions (all lending towards a bit of a community spirit as well).

Based on my experiences, and those shared with me I would strongly recommend finding an excuse (or making the time as if is for me) to get out of the office a take advantage of your membership (or even joining UKOUG). Justify it as cheap training if need be; but getting yourself along to one of Oracle’s offices (who lend their facilities to support the user group) in London, Reading or Solihull I’m sure you’ll find it will be very worthwhile even if the travel is a bit of a bind.

I would also like to take the time to thank people like  Simon Haslam at Veriton who put their time and effort in organising their particular SIG sessions.

Next book review – Oracle Fusion Applications

Tags

, , , , , ,

The next book up for review is going to be Oracle Fusion Applications Development and Extensibility Handbook (Oracle Press)

I have to declare a slight interest in my reviewing as I have had the good fortune to work with one of the authors- Vladimir Ajvaz; and extremely knowledgeable and talented Application Architect.

Oracle Fusion Applications

Enterprise Security – A Data Centric Approach – A brief review

Tags

, , , , , , ,

So I have previously blogged a series of largely chapter by chapter reviews of Aaron Woody’s book Enterprise Security – A Data Centric Approach. This post tries to provide a brief summarised view pulling my thoughts of the book overall together.

As an Enterprise Architect I took an interest in this book as an opportunity to validate my understanding of security and ensure in the design and guidance work that I do I am providing good insights and directions so that the application architects and developers are both ensuring good security practices and also asking the helpful information available to other teams such as IT Security, operational support and so on.

The book has been overall very well written and extremely accessible to even those not versed in the dark arts of IT Security. Anyone in my position, or fulfilling a role as an application designer or product development manager would really benefit from this book. Even those on the business end of IT would probably benefit in terms of garnering an insight into what IT Security should be seeking to achieve and why they often appear to make lives more difficult (I.e. putting restrictions in, perhaps blocking your favourite websites).

So why so helpful, well Aaron has explained the issues and challenges that need to be confronted in terms of Security from the perspective of the organisations key assets – mainly its data (certainly the asset that is likely to cause most visible problems if compromised). Not only that the book presents a framework to help qualify and quantify the risks as a result device a justifiable approach to securing the data and most importantly make defensible cases for budget spend.

I have to admit that the 1st chapter that that introduces the initial step in the strategy was a bit of a struggle as it seemed to adopt and try to define a view of the world that felt a little too simplistic. The truth is that this the 1st step in a journey, and in hindsight important – so stick with it.

Once the basic framework is in place we start looking at tooling strategies and technologies to start facilitating security. The book addresses categories of product rather than specific solutions so the book isn’t going to date too quickly. The solution examination includes the pros and cons of their use (e.g wifi lock down) which is very helpful.

Finally to really help the book comes with a rich set of appendices providing a raft of references to additional material that will help people translate principles into practice.

To conclude, a little effort maybe needed to get you started but ultimately a well written, informative, information rich book on security.

Previous blog entries:

There is also a supporting website for the book athttp://www.datacentricsec.com/
Enterprise Security - A Data Centric Approach

Enterprise Security – A Data Centric Approach – the final chapter

Tags

, , , , , ,

so I have reached the final chapter of the book which covers the handling of security events and security incidents (the differentiation of the two being the consequences of the event – a piece of malware being detected on a desktop can an event as the consequences are relatively trivial compared to the defacing of an e’tailer’s website).

I have to admit I glossed through this chapter as my role within an organisation doesn’t demand the operational management of issues. That said, the book provides some clear guidance on how to develop a process to support the handling of a security issue – important as you don’t want be figuring these things out when something happens, you want to get on and focus on execution. s with previous chapters, this well written and doesn’t demand knowledge of security dark arts to get to grips with.

The book finishes with a series of appendices which provides some illustrative information for chapters in the book, plus a series of appendices of really useful additional reference information sites cover a spectrum of information from security education resources to security tools.

This series of blogs on this book will wrapped up with a short review of the whole book. But I would like to congratulate Aaron Woody on a fine book rich with helpful additional information.

Previous blog entries:

There is also a supporting website for the book athttp://www.datacentricsec.com/
Enterprise Security - A Data Centric Approach

The Boxer Rebellion @ The Brook Southampton

We got to see the excellent boxer Rebellion last night at the Brook venue in Southampton.

Both the venue (which we’d never been to before) and the band where excellent.

Enterprise Security – A Data Centric Approach – Chapters 7 & 8

Tags

, , , , , , , , ,

Chapters 7 and 8 of the book in many respects are the polar opposites in their nature, with Chapter 7 looking at Wireless networks in the Enterprise and technicalities of different encryption frameworks, authentication and authorization.  Then at the other end is chapter 8 facing into the difficulties of social engineering – the approach of using people’s own nature to divulge sensitive information.  Probably one of the most famous people for this sort of thing is Kevin Mitnick and to acts of social engineering are will illustrated in the influential book  Bruce Stirling’s Hacker Crackdown.

Although Chapter 7 is addressing an area many would view as the dark art of wireless network setup; it is well explained and actually worth reading by anyone who would like to better understand their own home wireless network as lot of the information (not all) is relevant even in that context. For example the benefit of supressing the visibility of the Network ID (SSID) doesn’t make the network invisible – it simply makes it harder to spot as any device such as smart phone will call out yo the network to see if it is present and this information can be picked up just as easily if you know what you’re doing.

Drilling into the social engineering aspect, the book looks at the more obvious and perhaps brute force models such as spam to increasingly subtle takes such using social media communications through the likes of linkedin to send emails loaded with malware and see the end user open them. For example pretending to be an agent with a job offer who has found you via LinkedIn. But beyond that, the amount of information being made available via social sites as it can be a means to establish a organisations’ IT fingerprint and therefore suggest the best routes to attacking IT.  The chapter addresses training, and the pros and cons of different approaches, plus mitigation strategies for the different attack strategies.

Previous blog entries:

There is also a supporting website for the book athttp://www.datacentricsec.com/
Enterprise Security - A Data Centric Approach

Gaps in Oracle’s Cloud Cover? An Update

Tags

, , , ,

So having written my blog entry Gaps in Oracle’s Cloud Cover? to things have popped up on my radar.  Firstly a message via LinkedIn from epmvirtual.com indicating that they could potentially assist (although EPM’s site only currently offer solutions around Hyperion online); and then the news item of Oracle and Verizon offering SOA in the cloud which reports that Verizon’s cloud solution (currently in Beta) offers SOA middleware cloud instances that can be rented by the hour (with bring your own license or rent license as well).  Verizon’s own announcement can be read here.   Bottomline – Verizon have beaten Oracle to the punch of offering Oracle’s own middleware in the cloud.  We’ll write more when there is something to share.

Amazing Documentary on Photo Journalism – Both Uplifting & Tragic

Tags

, , , , , ,

I got to watch Cathy Pearson’s tremendous documentary on Photo Journalism called Get The Picture.  The documentary’s central narrative is around the life of the Picture Editor John G Morris.  The documentary open with John explaining  what his role as a Photo Editor was – essentially the guy who commissions photographers, and then chooses the appropriate photos to be used in a publication.  This in itself doesn’t sound remarkable until you consider both the publications he has worked for – Life, New York Times, Washington Post and the National Geographic, that’s before you even take into account the his association with the Magnum group.  John came to prominence as a Photo Editor during the second world war, and has been involved with Photo Journalism ever since, working with photographers such as Robert Capa, Henri Cartier Bresson and Werner Bischof and his relationship with these photographers and others also contributed to John’s importance. The relationships weren’t simple employer/employee but relationships grounded on mutual respect and trust and as often as not a common set of goals and values in photo journalism – get the truth out to the public of what is happening and let the picture tell its own story.

The documentary from time to time detours to look at important aspects of photo journalism, particularly the work done in conflicts by journalists – reflecting on what motivates these people to go into such dangerous circumstances, the changing conditions – until the 90s journalists where left alone as the protagonists in a conflict saw journalists as means to get their side of a conflict told and now are as much a target as anyone else because they can show the brutalities of conflict and realities of the acts committed. So you can see why I say tragic, but why uplifting?  We John has ben widowed 3 times, but managed to move on and not only find love again but embrace life, and fully appreciate what he has, something that really comes across.

If you have even a passing interest in photography, or world events – this is a very worthwhile documentary to watch. Sadly, not nominated in the Oscar’s Best Documentary Feature category this year – which is a shame as it punches a lot more effective than notable winners such as An Inconvenient Truth. On the happier side it does have some other successes.

For more information:

Robert Capa's Most Famous Photo

Robert Capa’s Most Famous Photo

Vietname Execution

Vietnam Execution

W. Eugene Smith

Henri Cartier Bresson in Russia

Henri Cartier Bresson in Russia

 

 

Gaps in Oracle’s Cloud Cover?

Tags

, , , , , , ,

As an Enterprise Integration Architect I need to get my hands dirty with products such as Oracle’s SOA suite and AIA Foundation Pack.  In the past, I’ve dealt with this by talking with our infrastructure team – obtaining a VM or a laptop with sufficient guts to host SOA Suite (and it doesn’t have a small footprint).  This is all well and fine, but means I have to lug a big old laptop (our current standard laptop spec’s are lovely light machines with SSD’s but just don’t pack the punch for SOA Suite when it comes to memory) or have to leap through a series of security steps to get remote access – again not a problem unless I want to share my skunk works with someone outside the organisation.  Nor, do I really want to invest chunks of time building a SOA Suite environment to work with – I don’t do it enough to be able to throw these things together quickly.  Even Oracle recognise that with the support for a prebuilt VirtualBox with SOA Suite and BPM. The only problem with VirtualBox is I’ve saved on the build time, but still need that heavy laptop or remote access.

Oracle Cloud Java

With the rise of the cloud, particularly Oracle’s big push (announcements at Open World 2013), Amazon offering small footprint dev platforms more or less for free I thought we’d be able to get a PaaS deployment of SOA Suite – after all Oracle offer a range of Fusion Apps in the cloud (built on top of SOA Suite technologies), have launched development of Java and ADF solutions in their cloud and even offer Weblogic on Microsoft’s Azure.  How I wrong could I have been.  So I started looking around, perhaps someone has an AMI ready to go – well sort of if I want 10g.  So I’ve dug around, and found the odd provider who could deliver what was needed (e.g. Titan GS) but we’re talking big bucks – not a low cost dev/skunk works environment.  

This is very surprising really, and sort of ironic, given Oracle’s recent announcement for SaaS Adapters for the likes of SalesForce and WorkDay along with convenience tooling to connect to Oracle Cloud solutions such as HCM.  I say ironic, because to use the cloud adapters you can’t have a SaaS middleware; in fact the whitepaper Oracle published on Simplifying Cloud Integration infers/assumes that you’d be hosting your own middleware.  So if a midsized business has Has HCM, Taleo etc for their staffing management, SalesForce for the Sales/CRM operations and perhaps EBis or JD Edwards to move your business into the cloud you have to either go IaaS and carry the labour of maintaining the middleware platform or self host (one of the things the adoption of SaaS is trying to free you from).

All of this seems to be a really missed opportunity for Oracle.  If the oracle wants to host the world (and I think Larry Ellison would like that) and definitely get into that midmarket sector that JDEwards particularly tries to inhabit they need to make it easy for businesses to cloud all aspects of their IT solution, that includes orchestrating specialist solutions that will be hosted by someone other than Oracle (shock, horror). All of which means SOA Suite (and ideally AIA) need to be in the cloud.

As for my problem, its either the pain of building something on Amazon or setting up several copies of the VirtualBox deployment linked to a common GIT repository, and hope those I would like to collaborate with can also get their hands on the virtualbox and connect to GIT.