azure_mapping.rst 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. Azure - Labeled Resources
  2. -------------------------
  3. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  4. | Labeled CloudBridge Resource | Azure Resource Type | CB ID | CB Name | CB Label |
  5. +=======================================+========================+=======+========================+====================================+
  6. | AzureInstance | Virtual Machine | ID | Name | tag:Label |
  7. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  8. | AzureMachineImage (Private) | Image | ID | Name | tag:Label |
  9. | AzureMachineImage (Marketplace Image) | VirtualMachineImage | ID | URN | URN |
  10. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  11. | AzureNetwork | Virtual Network | ID | Name | tag:Label |
  12. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  13. | AzureSubnet | Subnet | ID | NetworkName/SubnetName | Network:tag:SubnetLabel_SubnetName |
  14. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  15. | AzureRouter | Route Table | ID | Name | tag:Label |
  16. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  17. | AzureVolume | Disk | ID | Name | tag:Label |
  18. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  19. | AzureSnapshot | Snapshot | ID | Name | tag:Label |
  20. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  21. | AzureVMFirewall | Network security group | ID | Name | tag:Label |
  22. +---------------------------------------+------------------------+-------+------------------------+------------------------------------+
  23. The resources listed above are labeled, they thus have both the `name` and
  24. `label` properties in CloudBridge. These resources require a mandatory `label`
  25. parameter at creation. The `label` will then be used to create the `name`,
  26. which will consist of up to 55 characters from the label, followed by a UUID.
  27. The label property can subsequently be changed, but the name property will
  28. remain unchanged, as it is part of the ID. Finally, labeled resources support
  29. a `label` parameter for the `find` method in their corresponding services.
  30. The below screenshots will help map these properties to Azure objects in the
  31. web portal.
  32. Additionally, although Azure Security Groups are not associated with a
  33. specific network, such an association is done in CloudBridge, due to its
  34. necessity in AWS. As such, the VMFirewall creation method requires a
  35. `network` parameter and the association is accomplished in OpenStack through
  36. a tag with the key `network_id`.
  37. .. figure:: captures/az-label-dash.png
  38. :alt: name and label properties in Azure portal
  39. The CloudBridge `name` property always maps to the unchangeable resource
  40. name in Azure. The `label` property maps to the tag with key 'Label' for
  41. most resources in Azure. By default, this label will appear in the tags
  42. column, but can also be made into its own column, using the feature
  43. pointed out in the screenshot above.
  44. .. figure:: captures/az-net-id.png
  45. :alt: network id in Azure portal
  46. The CloudBridge `ID` property most often maps to the Resource ID in Azure,
  47. which can be found under the properties tab within a resource. The above
  48. screenshot shows where to find a resource's ID in Azure's web portal.
  49. .. figure:: captures/az-net-label.png
  50. :alt: network label in Azure portal
  51. The CloudBridge `label` property most often maps to the tag with key
  52. 'Label' in Azure, which can be found under the tags tab within a resource.
  53. The above screenshot shows where to find a resource's label in Azure's
  54. web portal.
  55. Two labeled resources are exceptions to the general trends presented above,
  56. namely public images (i.e. Azure Marketplace Images) and subnets.
  57. These public images can be found in the Azure Marketplace, and cannot be
  58. found on a user's dashboard. A Marketplace Image can be passed either by URN,
  59. or by public ID, and does not need to be linked to a user. While all
  60. Marketplace images will not be be listed by the find or list methods at the
  61. moment, a pre-set list of popular images is built into CloudBridge for that
  62. purpose. However, one can choose to list all Marketplace Images using the
  63. `list_marketplace_images` function in the azure client. Specifically,
  64. this can be done as follows:
  65. .. code-block:: python
  66. # List all images
  67. # Note that in September 2018, around 10 minutes of wall time were required
  68. # to fetch the entire list
  69. provider.azure_client.list_marketplace_images()
  70. # List all images published by Canonical
  71. provider.azure_client.list_marketplace_images(publisher='Canonical')
  72. # List all Ubuntu images
  73. provider.azure_client.list_marketplace_images(publisher='Canonical',
  74. offer='UbuntuServer')
  75. # List all Ubuntu 16.04 images
  76. provider.azure_client.list_marketplace_images(publisher='Canonical',
  77. offer='UbuntuServer',
  78. sku='16.04.0-LTS')
  79. # The ID of the listed object can then be used to retrieve an instance
  80. img = provider.compute.images.get
  81. ('/Subscriptions/{subscriptionID}/Providers/Microsoft.Compute/\
  82. Locations/{regionName}/Publishers/Canonical/ArtifactTypes/VMImage\
  83. /Offers/UbuntuServer/Skus/16.04.0-LTS/Versions/16.04.201808140')
  84. # The URN can also be used instead if it is already known
  85. # When the latest version is desired, it can be retrieved with the
  86. # keyword 'latest' in the URN without specifying a version
  87. img = provider.compute.images.get(
  88. 'Canonical:UbuntuServer:16.04.0-LTS:latest')
  89. Given that these resources are not owned by the user, they can only be
  90. referenced and all setters will silently pass. CloudBridge properties `name`
  91. and `label` will map to the URN, while the `ID` will map to the public `ID`.
  92. It is also important to note that some of these resources are paid and
  93. required a plan to use, while others are free but likewise require accepting
  94. certain terms before being used. These plans and terms are passed and
  95. accepted silently by CloudBridge in order to keep the code cloud-independent.
  96. We therefore encourage using the `marketplace website<https://azuremarketplace.microsoft.com/en-us>`_
  97. to view image and plan details before using them in CloudBridge.
  98. Additionally, Subnets are a particular resource in Azure because they are
  99. not simply found in the Resource Group like most resources, but are rather
  100. nested within a network. Moreover, Subnets do not support tags in Azure.
  101. However, they remain a labeled resource in CloudBridge, which was
  102. accomplished by creating Network tags holding Subnet labels in Azure. The
  103. below screenshots will show how to find Subnets and their labels in the
  104. Azure web portal.
  105. .. figure:: captures/az-subnet-name.png
  106. :alt: subnet name in Azure portal
  107. The CloudBridge `name` property for Subnets corresponds to the
  108. unchangeable Resource Name in Azure. However, unlike other resources
  109. where the Azure Name maps directly to the `name` property alone, a Subnet's
  110. `name` property returns the Network's name and the Subnet's name,
  111. separated by a slash, thus having the format [networkName]/[subnetName].
  112. Subnets are additionally not found in the default resource list, but are
  113. rather nested within a Network, in the Subnets tab as shown above.
  114. .. figure:: captures/az-subnet-label.png
  115. :alt: subnet label in Azure portal
  116. The CloudBridge `label` property most often maps to the tag with key
  117. 'Label' in Azure, which can be found under the tags tab within a resource.
  118. However, given that Subnets can't hold tags themselves, we set their tags
  119. in the Network with which they are associated. The tag name 'Label' thus
  120. corresponds to the Network's label, while each contained Subnet will have
  121. a corresponding tag with the name 'SubnetLabel_[subnetName]'.
  122. Azure - Unlabeled Resources
  123. ---------------------------
  124. +--------------------+----------------------------------------+-------+---------+----------+
  125. | Unlabeled Resource | Azure Resource Type | CB ID | CB Name | CB Label |
  126. +====================+========================================+=======+=========+==========+
  127. | AzureKeyPair | StorageAccount:Table | Name | Name | - |
  128. +--------------------+----------------------------------------+-------+---------+----------+
  129. | AzureBucket | StorageAccount:BlobContainer | Name | Name | - |
  130. +--------------------+----------------------------------------+-------+---------+----------+
  131. | AzureBucketObject | StorageAccount:BlobContainer:BlockBlob | Name | Name | - |
  132. +--------------------+----------------------------------------+-------+---------+----------+
  133. The resources listed above are unlabeled. They thus only have the `name`
  134. property in CloudBridge. These resources require a mandatory `name`
  135. parameter at creation, which will directly map to the unchangeable `name`
  136. property. Additionally, for these resources, the `ID` property also maps to
  137. the `name` in Azure, as these resources don't have an `ID` in the
  138. traditional sense and can be located simply by name. Finally, unlabeled
  139. resources support a `name` parameter for the `find` method in their
  140. corresponding services.
  141. .. figure:: captures/az-storacc.png
  142. :alt: storage account in Azure portal
  143. Bucket and Key Pair objects are different than other resources in Azure,
  144. as they are not resources simply residing in a resource group, but are
  145. rather found in a storage account. As a result of this difference, these
  146. resources do not support labels, and cannot be seen on the default
  147. dashboard. In order to find these resources in the Azure web portal, one
  148. must head to the storage account containing them, and look in the `Blobs`
  149. and `Tables` services respectively for `Buckets` and `KeyPairs`.
  150. Azure - Special Unlabeled Resources
  151. -----------------------------------
  152. +-------------------------+------------------------+--------------------+--------------------+----------+
  153. | Unlabeled Resource | Azure Resource Type | CB ID | CB Name | CB Label |
  154. +=========================+========================+====================+====================+==========+
  155. | AzureFloatingIP | Public IP Address | ID | [public_ip] | - |
  156. +-------------------------+------------------------+--------------------+--------------------+----------+
  157. | AzureInternetGateway | None | cb-gateway-wrapper | cb-gateway-wrapper | - |
  158. +-------------------------+------------------------+--------------------+--------------------+----------+
  159. | AzureVMFirewallRule | Network Security Rules | ID | name | - |
  160. +-------------------------+------------------------+--------------------+--------------------+----------+
  161. While these resources are similarly unlabeled, they do not follow the same
  162. general rules as the ones listed above. Firstly, they differ by the fact
  163. that they take neither a `name` nor a `label` parameter at creation.
  164. Moreover, each of them has other special properties.
  165. The FloatingIP resource has a traditional resource ID, but instead of a
  166. traditional name, its `name` property maps to its Public IP. Thus, the name
  167. seen in the Azure web portal will not map to the CloudBridge name, but will
  168. rather be auto-generated, while the Azure `IP Address` will map to CloudBridge
  169. name. Moreover, the corresponding `find` method for Floating IPs can thus help
  170. find a resource by `Public IP Address`, and the get method also accepts a
  171. 'Public IP' instead of an 'ID'.
  172. In terms of the gateway, one of the major discrepancies in Azure is the
  173. non-existence of an InternetGateway. In fact, Azure resources are exposed
  174. with no need for an Internet gateway. However, in order to keep resources
  175. consistent across providers, the CloudBridge Gateway resource exists
  176. regardless of provider. For Azure, the gateway object created through
  177. CloudBridge will not appear on the dashboard, but will rather be a cached
  178. CloudBridge-level wrapper object.
  179. For a succinct comparison between AWS Gateways and Azure, see `this answer
  180. <https://social.msdn.microsoft.com/Forums/en-US/
  181. 814ccee0-9fbb-4c04-8135-49d0aaea5f38/
  182. equivalent-of-aws-internet-gateways-in-azure?
  183. forum=WAVirtualMachinesVirtualNetwork>`_.
  184. Finally, Firewall Rules in Azure differ from traditional unlabeled
  185. resources by the fact that they do not take a `name` parameter at creation.
  186. These rules can be found within each Firewall (i.e. Security Group) in the
  187. Azure web portal, and will have an automatically generated `name` of the form
  188. 'cb-rule-[int]'.