Data centers

07:45 AM
Doug Hazelman
Doug Hazelman
Connect Directly

Don't Get Burned By Virtual Appliances

The Heartbleed bug highlights potential drawbacks of virtual appliances and the flexibility and control offered by installable software.

Virtualization has provided us with packaged appliances that can be deployed as virtual machines (VMs), pre-configured and ready to run on a hypervisor. But threats like the OpenSSL bug Heartbleed coming to light should make you wonder what's running in that virtual appliance.

Heartbleed sent companies in a panic to update their systems, developers scrambling to identify vulnerabilities and patch them immediately, and users rushing to sites to change passwords. And still questions remain.

Virtual appliances are attractive because they're easy to deploy and don't require an operating system (OS) license. Yet, considering the extensive corrective measures triggered by Heartbleed -- and the exposed weaknesses -- some question if the ease and cost of virtual appliances are worth the price they may end up paying.

I am often asked why we don't offer our software as a virtual appliance. I often turn the question around and ask, "Why should we?" The most common reason customers want a virtual product is because of OS licensing -- specifically Microsoft Windows. Customers don't want to allocate additional Microsoft licensing for data center availability, and they often think virtual appliances are free. Besides licensing concerns, customers also view virtual appliances as easier to deploy; just slap them on a host, tweak a few settings, and, theoretically, you're good to go.

Virtual appliances are also attractive to software manufacturers, because they can more easily control the OS and installation of their software. They don't have to worry about conflicts with device drivers, other software applications, or even the service packs applied. Taking all that responsibility away from the customer means that support costs should be lower. There simply shouldn't be installation errors and conflicts.

But what's inside?

This is the biggest question I have for any virtual appliance. Obviously, there's the manufacturer's software, but what else? What's the OS distribution and version? What components have been removed or disabled that aren't needed? Are all the OS components up-to-date and patched? These questions proved especially important with Heartbleed: Does your virtual appliance use a vulnerable version of OpenSSL? Is your virtual appliance open to unauthenticated root attacks because of a patch that hasn't been applied to the OS?

These are difficult questions for a customer to answer, because they typically have no view or ability to control what's inside the virtual appliance. Also, if a vulnerability is discovered by the manufacturer, the customer usually has to wait for the manufacturer to deliver a new appliance or a set of patch instructions, and it could literally take weeks for the vendor to identify, fix, test, and distribute a solution.

Virtual appliances, by their nature, also take resources away from the very infrastructure they're designed to support or protect. An appliance requires a host, which is most likely running other VMs. If the appliance begins a CPU- or IO-intensive operation, like backup, then it must take resources away from other VMs -- and those could be critical production VMs.

Is installable software any better? In my opinion, yes.

If the customer installs software on top of an OS, then the customer is in control. It may require customers to license the OS, but chances are they already have licenses, as well as people familiar with managing that OS. Giving the customer control may require the software manufacturer to perform additional quality assurance, and it might cost a bit more in support due to configuration and installation issues. The important thing is the customer has that control.

In the event of an OS patch or vulnerability, customers can apply the patch themselves without having to wait for the manufacturer. They can also follow their own hardening guides for operating systems. They can close systems down or open them up. Or they can enable only the features needed for the software to run.

The other benefit of this approach is that software can be installed outside the virtual infrastructure. It may seem counterintuitive to have a physical server to protect a virtual workload. However, at least the virtual workload doesn't have to fight for host resources.

Flexibility and choice are important to customers when they have unique situations or rules they must follow. Installable software may not be the easiest route, but it is the most flexible. As we've seen with Heartbleed, it provides the reliability and performance that the "always-on" business needs for the modern data center.

Doug Hazelman is Vice President of Product Strategy for Veeam Software, a provider of backup, replication, and virtualization management solutions for VMware vSphere andMicrosoft Hyper-V. He possesses nearly two decades of experience in IT product strategy, management and ... View Full Bio
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
5/26/2014 | 8:54:51 AM
The premise of this article is dubious at best, and border-line FUD at worst.  The author's point is that appliances are a crapshoot since you don't know what's inside.  I would doubt most customers know what's inside Microsoft Windows, either, and Microsoft does not exactly have a stellar record of nimble patch releases.  Since, by & large, these appliances are really just Linux instances, it's not usually that difficult to look under the hood.  Most Linux appliances that I have used provide shell access, and have standard update mechanisms like apt-get or yum.  He's saying to not use appliances because, if something goes wrong and nobody can help you, you're screwed.  That can happen regardless of whom the vendor is.  Considering Microsoft's record on security in general and the cost of their licenses, I'll stay with my appiiances, thanks.
User Rank: Strategist
5/7/2014 | 6:58:52 PM
virtual appliances vs. installable software
Doug raises interesting points here, but I wonder what do readers think? Do you agree that installable software provides better flexiblity and control? Do you think Heartbleed exposed the downside of virtual appliances?
White Papers
Register for Network Computing Newsletters
Current Issue
Research: 2014 State of the Data Center
Research: 2014 State of the Data Center
Our latest survey shows growing demand, fixed budgets, and good reason why resellers and vendors must fight to remain relevant. One thing's for sure: The data center is poised for a wild ride, and no one wants to be left behind.
Twitter Feed