Post from 2025-03-16 08:39:15

@bob_zim @tasket I've never heard "cloud" used in the context of the techniques you mentioned, but OK. In my world these practices - that have obvious security benefits - are more on the "pet-cattle" axis that apparently (but not surprisingly) also comes from AWS, but not strictly tied to cloud providers:

https://cloudscaling.com/blog/cloud-computing/the-history-of-pets-vs-cattle/

Circling back to security boundaries brought up by @adamshostack, my point here is that modern security and ops paradigms up to level 4. on @bert_hubert's scale are doable on-prem where you don't have to deal with the threats arising from e.g. shared hosting in the first place. IMO from that level any security benefits are less about the mentioned paradigms and more about how security investment scales (e.g. can you afford world-class talent and custom tooling for your 10 rack system), while introducing the problems that triggered this whole discussion about the need for an EU cloud.
permalink | main