Glossary

Infrastructure as a service (IaaS)

Infrastructure as a service (IaaS) is the cloud service model in which a provider supplies compute, storage and networking as on-demand resources, and the consumer installs and runs its own operating systems and applications on them. The provider operates the hardware and virtualization; everything above that line belongs to the consumer.

NIST SP 800-145 places IaaS below platform as a service (PaaS) and software as a service (SaaS). It is the model sold by public cloud providers and service providers, and the one most enterprises replicate internally when they build a private cloud for their own business units.

Why IaaS matters for platform teams and service providers

IaaS sets the expectation that infrastructure arrives in minutes, by API, priced per unit consumed. Once business units have used a public cloud, an internal platform that takes weeks to deliver a volume or a bucket looks broken by comparison. For an enterprise platform team or a regional service provider, offering IaaS means meeting that expectation on its own hardware, often for data that cannot or will not go to a hyperscaler.

Storage is where that is hardest. Compute capacity is released when a virtual machine stops. Stored data stays, accumulates and is billed every month, so the storage layer carries most of the long-term cost and most of the multi-tenancy risk of an IaaS platform.

The division of responsibility

LayerOperated by
Applications and dataConsumer
Runtime, middleware, librariesConsumer
Guest operating system and patchesConsumer
Host firewalls and some network settingsConsumer, within provider limits
Hypervisor, storage platform, physical networkProvider
Servers, drives, facilities, powerProvider

The same split defines security responsibility. The provider secures the hardware, the hypervisor and the storage platform, including the separation between tenants. The consumer secures what runs inside its machines and the data it writes, including access keys and bucket policies.

Storage resource types in IaaS

  • Block volumes: virtual disks attached to one instance, priced per gigabyte provisioned per month whether or not they are full. See block storage.
  • File shares: network file systems mounted by several instances, priced per gigabyte provisioned or used.
  • Object storage: buckets reached through the S3 API, independent of any instance, priced per gigabyte stored per month plus charges per request and for data leaving the provider (see egress fees).
  • Snapshots and images: point-in-time copies and templates, usually held in object storage behind the scenes.

Object storage holds the bulk of data in most IaaS environments because it is the only type that grows without being resized and is not tied to the life of an instance.

Metering and pricing

IaaS is priced per unit of resource per unit of time, and the arithmetic is linear. At a hypothetical rate of $0.02 per gigabyte-month, 1 PB of object storage costs 1,000,000 GB × $0.02 = $20,000 a month, or $240,000 a year, before requests and egress. Compute behaves differently: an instance stopped overnight stops costing. Stored data has no equivalent of switching off, so for data-heavy workloads the storage line grows every month the data is retained.

Purchasing options trade commitment for price. On-demand capacity is billed at list rate and released at will, reserved or committed capacity is cheaper over a one- or three-year term, and spot capacity is discounted spare compute that the provider can reclaim at short notice.

What IaaS means for service providers and platform teams

Building an IaaS offering moves the storage team into the provider column of the table above, with obligations to many tenants at once.

  • Tenant isolation is the product. Each tenant's buckets, keys and usage records have to be separate on shared hardware, in a way an auditor can verify. Weak multi-tenant storage turns one tenant's misconfiguration or compromise into an incident for every tenant.
  • Metering has to be exact. Billing or chargeback depends on per-tenant counts of capacity, requests and transfer. Errors at petabyte scale are invoices that cannot be defended.
  • API compatibility decides adoption. Tenants bring applications and tools written for public cloud S3. Each gap in S3 compatibility is a tool that fails or an application that needs changing.
  • The rent-or-run comparison turns on data. For an enterprise weighing public IaaS against an internal platform, compute bursts favor renting, while large datasets retained for years and read often tend to favor owned capacity, because storage charges and egress compound over the whole retention period.

Scality RING in IaaS platforms

Service providers and enterprises building their own IaaS use Scality RING as the object and file tier alongside block storage. RING is software-defined storage on standard x86 servers; a single RING scales to 300 billion objects, and it supports S3 Object Lock in governance and compliance modes for tenants that keep data under write-once retention. Scality describes RING as multi-tenant by design, with high-concurrency multi-tenancy and hard isolation between tenants, the property a shared IaaS storage tier rests on.