F. CLOUD COMPUTING AND NETWORK EVOLUTION
Cloud computing has radically reshaped the architecture of corporate networks. When applications were housed in the company’s data centre, the main purpose of the WAN was to interconnect sites with one another and link them to the central data centre. Today, a company’s applications are spread across several public clouds (AWS, Azure, Google Cloud), SaaS applications (Salesforce, Microsoft 365, ServiceNow) and, in some cases, a few on-premises servers. Networks must adapt to this radical dispersion of resources.
1. The hyperscalers’ backbone networks
The three major hyperscalers—AWS, Microsoft Azure and Google Cloud Platform—have built global private backbone networks that now rival the best infrastructure offered by telecoms operators. These networks represent an investment of tens of billions of dollars each and constitute a significant competitive advantage.
AWS operates 33 geographic regions with 105 availability zones, interconnected by a global private backbone comprising more than 25 dedicated or co-invested submarine cables. AWS Direct Connect enables businesses to connect directly to the AWS network from their premises via dedicated connections (1 to 100 Gbps), bypassing the public internet for their cloud traffic, thereby improving performance and latency predictability. AWS Cloud WAN offers a solution for managing a global hybrid network, remote sites, local data centres and AWS regions, from a unified management console.
Microsoft Azure, with over 60 regions worldwide, has a backbone network comprising some 200,000 km of terrestrial and submarine fibre-optic cables, including the Grace Hopper (connecting the US to Europe and the UK) and AEC (America-Europe-Caribbean) cables. Azure ExpressRoute offers dedicated connections ranging from 50 Mbps to 100 Gbps for businesses. Google Cloud also operates one of the world’s most extensive private networks, including the Equiano (connecting Europe to West Africa) and Dunant (North Atlantic) submarine cables. These massive investments in submarine cables make hyperscalers major players in the physical infrastructure of the internet.
2. Cloud-native network architectures
The widespread adoption of microservices architectures and containers (Docker, Kubernetes) places new demands on networking within application clusters. Whereas a monolithic application had only a few network connections, a microservices application can generate thousands of internal network calls per second between its components. Managing these flows in a reliable, secure and observable manner has become a challenge in itself.
The service mesh (service mesh) addresses this challenge by adding a transparent infrastructure layer that manages all communications between microservices: load balancing, automatic mTLS (mutual TLS) encryption to secure every internal call, timeout and error recovery management (circuit breaker pattern), and collection of distributed traces for observability. Istio, Linkerd and Consul Connect deploy sidecar proxies (auxiliary processes) alongside each microservice instance, intercepting and managing traffic transparently for developers.
eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that is revolutionising network management in cloud-native environments. It enables verified and sandboxed programs to run directly within the Linux kernel space, without modifying the kernel code itself and without the overhead of a userspace process. Cilium uses eBPF to implement Kubernetes network policies with near-native performance, replacing iptables with a much more efficient eBPF data plane. Cloudflare uses eBPF for its load balancing and DDoS protection. Facebook has developed Katran, an eBPF-based L4 load balancer capable of processing millions of packets per second per CPU core.
Infrastructure as Code (IaC) applies software development best practices—such as version control in Git, code reviews, automated testing and continuous deployment—to the management of network infrastructure. Terraform, developed by HashiCorp, has become the go-to tool for declaratively describing the desired cloud infrastructure in configuration files, then automatically provisioning the corresponding resources on AWS, Azure, GCP and network equipment from numerous manufacturers. Ansible, Red Hat’s agentless automation tool, is widely used for configuring physical network equipment: an Ansible playbook can configure hundreds of switches and routers in a consistent and reproducible manner in just a few minutes.