Amazon WorkSpaces
aws.amazon.com
aws.amazon.com
The UX for the account setup and workspace admin is pretty rough, feels MVP (but it works).
It took about 30 minutes for my machine to be provisioned. Then I got an email. Downloaded the OS X client, about 30 megs.
Launched. Took about a minute to login and get my machine booted.
GUI performance for small area updates is great, dragging a window not so great. It is usable, but not fluid.
My connection is showing 70Mbps/10Mbps with 12ms latency on speedtest.net
Using a IE. Oh this is interesting – when going to Google, I am at google.tw
Where is this machine hosted? Showing an IP of 54.85.209.100 (US), odd...
Visiting Youtube, Youtube.tw comes up, video is a bit choppy, audio is fine.
Visiting nytimes.com. Loading is a bit slow, scrolling is very choppy. Text selection is very fast.
Downloaded some CSV, opens in Excel. This is fast, and very usable.
Disconnect.
Log back in, everything is just as I left it (of course).
--- continued ---
I download the client for the iPad, enter the registration code, and login.
There is a 13 part tutorial on gestures (way too many for me to remember) Fortunately you can drag a menu of commands from the left side easily.
I play around a bit, it works fine.
Now I login from my computer, oh bummer, my iPad session was disconnected.
You can only be logged in from device at a time. That is too bad. It would be nice to share.
I wonder if this is to do with licensing.
>Using a IE. Oh this is interesting – when going to Google, I am at google.tw
>Where is this machine hosted? Showing an IP of 54.85.209.100 (US), odd...
I bet Google's GeoIP DB has some flaws, and this is the result of one of them.
ec2-54-85-209-100.compute-1.amazonaws.com
Then I remember the remote freelance job my wife had for a while. They mailed her the employment paperwork, she filled it out, once they processed it they sent her a remote desktop URL, username and password and voila she was "at work". A day or two later she had everything she needed installed by the IT staff and off she went. She never actually went into the office, even once, and never met any of the employees there face-to-face. When she completed her contract they simply nuked the account she was using and reclaimed the licenses. They didn't ship her a laptop to work from and she didn't have to ship it back. If she had ever needed to go into the office, they could have let her use an aging extra machine with Remote Desktop to get back to work. Not a single piece of the company's "property" ever needed to come in contact with my wife's home computer and if she was waiting for her work computer to do something she could just minimize the RDP client and do something else.
I have no idea what they would have been paying for the Terminal server on their end, I've heard it runs north of $100k/year, and this service seems to be competing with that.
Dumb Terminals are great for working environments and we should have never left them.
Ya, just put it on Amazon's servers instead. That's way better.
Well, yes you can, you just document the procedure.
I really can't understand the disconnect between setting a policy that you can't have company data on company owned/controlled desktops but can have all that data sitting in a 3rd party system.
I've got a free year of credit monitoring because a hospital laptop was stolen with patient data on it and they have no idea where it went. Yippee.
But whatever, just hope that Amazon does the right thing, it's not like you or your healthcare provider can check up on it.
When a single system is cheaper (counting total ROI) than distributed systems, the mainframe approach will win. Otherwise, the distributed approach will win. The tradeoffs change from year to year and even company to company.
PS -- internal web apps are essentially dumb terminals as well, and businesses have been making those since the late 90s.
VMware's DaaS has been available since earlier this month - http://www.vmware.com/products/daas
[0]- http://www.citrix.com/products/xendesktop/overview.html
Not sure if Workspaces has any sort of collaboration with Citrix.
Which is _great_ because we're going after the EU market in a little bit.
Then an email is sent to them with all instructions and a validation code.
They do not need to have an AWS account.
And, it can tie into a firm's existing directory of users: http://docs.aws.amazon.com/workspaces/latest/adminguide/conn...
Some of what we do is processing legal files. This involves managing 'our' ftp site, provided by the vendor.
Turns out this is a 'windows' server, connected via iscsi, to a directory where their FTP server dumps the files. This is, judging by the hostname, a vmware host.
I suspect an AWS workspace would be a lot cheaper to run than a VMWare cluster.
http://docs.aws.amazon.com/workspaces/latest/adminguide/clie...
Hm. I wonder if anyone is doing the work to get Android apps runnable on desktop Linux systems. Some googling suggests that at this point, Android-x86 can more or less run in a chroot already...
Here's a discussion about it from a few months ago https://news.ycombinator.com/item?id=6726962
Anyway if it can beat my horrible corporate VDI I am all for it. Although Initech probably wont be switching to some fancy new AWS anytime soon.
Wait…thin clients…virtual reality goggles…are we back in 1995 again?
I can remember doing a case study in College where Larry Ellison was trying to push thin clients to companies sometime in the 90s.
Shit.
VDI, Citrix, et al are less a reaction to how awesome mainframe/terminal architecture is, and more a statement about how utterly horrible it is to maintain an enterprise Windows image.
It's not unlike the architecturally-similar-situation with web apps exploding in popularity in the mid 2000s. People were primarily responding to how great it was to have "their stuff" anywhere they happened to sit down, and how horrible the native client experience was, on Windows.
And we've had a great natural test of that theory, with modern mobile devices: Now that people have their own machine with them, wherever they happen to be, with native client experiences that aren't nearly the hassle that desktop Windows was, web apps are playing second-fiddle.
Similarly, this VDI thing is going to run into trouble as enterprise further adopts BYOD and their desktop images are needed by fewer and fewer people.
BYOD is one of the big drivers behind VDI: VDI allows enterprise IT shops a measure of control over the security of enterprise data when the physical hardware being used to interact with the data is less trusted.
Anyone telling you that you can, is selling something.
VDI and VNC might make a certain class of contemporary malicious use/programs less convenient, but malicious code and habits will change far, far faster than enterprise architecture.
But the "VNC gap" immediately obviates the risk of unsophisticated attacks. No more viruses spreading over SMB. Rather limited bandwidth (preventing raw copies of The Hobbit in 4k from being ripped via VNC).
It isn't bulletproof, but you can't pretend it doesn't help.
Making BYOD work means building an enterprise that needs far, far fewer Windows desktop "seats" than they do today.
VDI has a strong value proposition as a solution for those remaining seats, but that number is going to be very, very small compared to what people deal with today.
Evolutions in sandboxing (broadly construed, everything from what we see with mobile apps up to full virtualization) may give us a point at which an IT department can, for most businesses/purposes, reasonably satisfy itself of the security of the "enterprise apps" running on a non-malicious employee's laptop, without completely taking over the system image.
Are there reasons not to move Windows workloads from EC2 to WorkSpaces?
Everyday ISPs/Content Providers are constricting the pipes more and more.
All the physical equipment and meatspace savings from this will vanish[shift rather] and the network costs will take their place.
Will they add new infrastructure and absorb that cost without price increases?
Netflix's issues with ISPs is actually a counter example to my position?
As time goes on, we'll use less data rather than more?
Video[GUIs are video] require a lot of transfers even when you have good connections/protocols. I do remote work[a lot] and I have a typical uplink and it stinks. I use CLI/SSHFS as much as possible to avoid lags and it is still laborious.
I don't really want to have a Windows 7 Experience.. wonder why they don't provide a linux desktop.
Feel free to imagine Ballmer running around a stage yelling this.
VNC certainly doesn't do it. NX is about as close as I've come, and it can still be laggy at times. I think Spice may be the future on this side, but not sure.
For those of you who run remote Linux desktops in the cloud and actually use a UI, how do you do it and get an adequate desktop experience (sound, video, etc)?
[1] http://technet.microsoft.com/en-us/library/cc772567.aspx
I am thinking about travelling through south-east asia and/or africa for a few months, would this (in addition to ssh) be viable for working/freelancing from remote locations with throwaway hardware?
What if the device a user is logging in from has a keylogger/screencapper that captures everything they do with their 'cloud desktop'? What if they contract malware that specifically pulls data from the 'cloud desktop' (i.e. from a targeted attack)?
At first glance it looks something like Dropbox with S3 as the storage backend. They suggest it being used to keep files in sync between a standard PC and a WorkSpace. I wonder if it can be used without the WorkSpace?
[1] http://docs.aws.amazon.com/cli/latest/reference/s3/sync.html
Edit: Actually this isn't the dropbox functionality. For that you'd have to wrap it in an inotify loop:
"while true; do inotifywait -r -e modify . && aws s3 sync <local> <s3 bucket>; done"
https://en.wikipedia.org/?title=Z/OS
It's just not cool
I know a bit of the mainframe world. One of my tasks at my first job was to do OS/400 daily backups.
In the legal field there are a scatload of organizations that process data. Data is moved by FTP or SFTP. It's organized by case and/or client.
The directories can hold hundreds - or thousands - of files, compressed file sizes nearly 500mb are not uncommon.
To _manage_ this mess o' bytes users are given 'a windows server', login by RDP. The server has (the ones I've seen) a connection via ISCSI to a 'drive' that is (tada) the FTP repository. Move, delete, rename using Windows Explorer.
The several that I've seen are vmware instances. Living - I guess - on a dedicated vmware cluster.
This is _made_ for uses like that.
The _heck_ with paying for, and maintaining, an expensive machine. Boot up a workspace, create the user. Bill them cost. When you're done, shut it down.
This is good because we, ourselves, are aiming to be a data processing org (in part) but we have to do it better and cheaper. Which we can, with workspace.
Assuming, of course, that we can have some control over what is installed, and connections to our already existing ebs volumes.
I guess my point is that "*aas" acronyms are (besides ugly, but that's just my opinion) not always very clear; please consider writing what you mean at least the first time before using an acronym.
Don't assume everyone knows what you know, especially for rather new and up-in-the-air technology terminology such as this.
Much better than buying $100K of hardware for a Terminal Server, and paying $100K of support a year to maintain it ;)
RDP is "smart." The bandwidth requirements can vary from a few KBPS to ~100.
What ends up happening is, if you need more bandwidth in this scenario you're going to need it in general - for downloading files, emails, etc..
Email, usually, takes about the same bandwidth. So, if Amazon is taking that burden, you should be OK.
It's a virtual host that has a terminal server + a few other servers.
Dual monitors are also somewhat common nowadays[vital for actual productivity], how the heck is that gonna do over Comcast lines?
When the day comes[never] that we have ubiquitous/cheap bandwith, this idea is nearly practical. Until then it is DOA for "real work".
This might serve a subset well enough but got would it be painful (as you correctly observe) for anything who is hammering the machine.
Even if they did, Apple restricts OSX to Apple hardware. There are a few companies out there that offer this, but typically you'll pay $25-40 for a fairly anemic setup (say 1-1.5 GB). This is likely a direct product of the hardware cost, as opposed to the ability to use commodity hardware for Windows/Linux.
(T_T) Waaaaah:
REGION UNSUPPORTED
WorkSpaces is not available in Asia Pacific (Tokyo).
Please select another region.