Until you factor in the salaries of the new employees you have to hire now, the cost of that hiring process, the compliance and security implications of operating servers on your premises, the ongoing maintenance of the software and operating systems, the new infrastructure to maintain, including but not limited to backup power supply and overall redundancy, the need to manage the lifecycle of the new hard- and software, the documentation for all of this… I could go on for a while.
It's not like these cloud solutions are just solving laziness.
Compliance and security testing does not go away just because you use cloud. The steps and questions will be different, but regulations like NIS and GDPR have extensive requirements regardless if you implement it yourself or buy it from an external supplier.
I would also not recommend to go with a single cloud solution with no backup solution and overall redundancy, unless a $5 voucher is good enough compensation for the service being down a whole day. The general recommendation after the latest waves of outages was for cloud users to use multiple cloud providers and multiple backup solution. It is just like how on-premise solutions need off-premise backups.
That’s a bit disingenuous. If I don’t operate a physical server rack, I also do not need to take care of physical access control, fire suppression policies, camera monitoring, key handling, and a wide range of other measures I would be otherwise obliged to take care of under GDPR. You can absolutely outsource classes of problems. What’s true is that that doesn’t lift the responsibility from you to check your cloud provider fulfils these obligations, but that’s very different from having to fulfil them yourself.
This would be part of the responsibility of the cloud managers, which need to be hired, paid and trained, on top of the cost of paying the cloud providers. There is no free lunch.
What can we definitive say about the difference be in salaries, training, and team size? Can we say anything specific about legal and operational perspective?
I get what you are saying, that responsibility is still yours for making the correct choices, and to know what the cloud providers are doing. In the real world though hardly anybody cares, even though we have threats like the CLOUD act in place. So, yeah, people should care but ultimately they often don't.
However in the same way, it doesn't then matter much if you are using the cloud or not. The work needing to copy the output of an AI to fill in the forms takes similar amount of time.
I'm not sure it will convince the "haters" nor they'll get it, but I'll keep it close to share with some people that are confused but open enough to understand the nuance.
For example micro services. You do not need infrastructure heavy software paradigms for large majority of use cases but it was just blindly accepted as new standart which we are now, again, moving away.
These used to be the skills of a generalist sysadmin for a small-site with on-prem services.
Those skills are no longer available on the market. Students in the local apprenticeship program have one class about hardware, and they don't even touch it, just talk about it.
Please provide a list, no sarcasm. And please don’t put Hetzner on it, as it is not a cloud provider.
It's one thing to say that a lot of AWS/Azure/Google users take advantage of many managed services.
But saying something is not a cloud provider because they don't provide a specific SaaS is kinda weird, especially if you read the NIST definition of cloud computing or when you consider that not every AWS user is using more than a handful of services (does that make AWS a cloud provider only for more "advanced" users?).
Sure, smaller cloud providers don't usually have all those services, but this doesn't mean they are not cloud providers. They cannot attract users who are more familiar with specific managed services, but they can probably satisfy the needs of other users who are more than happy with a smaller feature set.
Also, limiting yourself to a smaller portion of AWS/Azure/GCP services can facilitate migrations to other cloud platforms (think AWS -> Azure or viceversa), because you're less tied to specific proprietary tooling.
I think for most business stakeholders it's not about the number of services but rather the coverage of business-critical needs. When you have access to Azure Entra, you know that you can cover 90%+ of your auth needs with that service. If you have access to AWS S3, you know that your various storage needs would be possible to cover with that. If a managed Postgres is available, you know that most of the IT systems you run would be able to take advantage of that. You look at Azure their IAM/audit/observability offerings and it's the same.
When you look at Hetzner as a business stakeholder, all you see are bare servers and and one object storage service that you are not sure of how battle-tested it is. And then you start thinking: "okay, I will need to run k8s or some other workload orchestration approach, my IT systems need Postgres/MySQL/SQL Server etc, I need auth, I need audit, I will need to build, operate, maintain all of that in-house". I am not saying that this is a wrong path for everyone, but Hetzner essentially leaves you no choice. And many business stakeholders who have been operating their own own-prem infra or colocated or rented IaaS plus a large dev team for decades and have since switched to one of the hyperscalers and reduced their dev/IT headcount - may not want to go back to the old model.
> limiting yourself to a smaller portion of AWS/Azure/GCP services can facilitate migrations to other cloud platforms.
Yes, which is why you insist (where possible/reasonable) on Postgres-compatible DBMS offerings, IdP solutions based on OIDC, observability on OpenTelemetry.
> Sure, smaller cloud providers don't usually have all those services, but this doesn't mean they are not cloud providers
Yes, it could mean that they are not cloud providers.
> but they can probably satisfy the needs of other users who are more than happy with a smaller feature set
Please see the linked article. This is essentially "users who are happy to build some of the furniture themselves".
I agree that there is a difference between "wood" and "furniture".
Although maybe a more apt comparison is IKEA vs another furniture store.
With IKEA you have a relatively basic "style". You'd be hard to pressed a 1800 style table, for example, but if you are a student or someone who just wants to live in a new place, it's a pretty solid store to go. However, they give you the pieces (not just basic wood, already pre-made pieces) and you have to put them together.
Other furnitures have a lot more choices in terms of styles and they allow you to just buy stuff without any DIY needed.
Different offerings in the same space (no one in IKEA is asking you to cut wood and make your own chair legs or whatever), both valid.
Furniture metaphores aside, what I'm saying is that there is a subset of users which is completely fine with those services, which are still provided in a self-service, pay-per-use way without the need to have admin rights over the entire platform. That's a cloud provider. A more limited one, sure, but it can still be a cloud provider.
And when it comes to business stakeholders, coverage is important, but so are other concerns, including the ability to move out when needed (which still requires some sensible technical choice, because if you go "all in" you're complicating your exit strategy), or even concerns like the ones mentioned in the OP.
Obviously, each company has its own risk aversion and its own decision making process, and so far market share heavily favors the Big Three even outside of the US, but this doesn't mean alternative options should be dismissed as "not cloud providers" just because they don't provide all those services.
Hetzner has an S3 compatible offering, a VPS offering and that's it. Their core business is renting physical servers. And I see lately they offer a load balancing service.
I'm talking about IBM mainframes.
Eventually, as the Internet (networking) and open source technologies (like Git and Linux) become more and more widespread, people realized they could build their services by combining products from different vendors (not to mention FOSS). I'm talking about the 1990s-2000s.
Now, after 20-30 years, we're thinking that the same company must provide the entire tech stack or lose relevancy as a provider.
To be clear, AWS and mainframes are pretty different from a technical standpoint, but I do wonder if we're kinda repeating the same cycle over and over. Asking the same company to provide everything and then build stuff with different products, to then find a new company which can provide everything and so on.
In what way are they not a "cloud" provider? Because their managed services portfolio isn't as wide as AWS or Azure? What about Scaleway's services then?