Learning paths / Cloud foundations / What the cloud is

IaaS, PaaS and SaaS: who manages what

Reading · 5 min · Module 1, lesson 2 of 39 min left in this module

Module 1 · What the cloud isLesson 2 of 3

Goal: Place a hosting option on the IaaS, PaaS, SaaS ladder and say which layers you'd still manage.

3:33 · captions and chapters · narrated with an AI-generated voice
Transcript

Narration uses an AI-generated voice.

[00:00] The layers

By the end of this video, you'll be able to place any hosting option on a ladder. And you'll know which parts of it are still your job.

Every app sits on a stack of layers, from hardware at the bottom to your data at the top. At the bottom, the hardware and the network. The machines, and what connects them. On top of that, the operating system, and your language's runtime. Then your app's code. And last, its data. Someone has to look after every layer. The only question is who.

[00:36] The ladder

So let's line up the hosting models side by side, and mark who manages each layer. Start where you own the machines yourself: on-premises. Every layer, top to bottom, is yours. Now watch what happens with each step to the right.

First step, IaaS. That's infrastructure as a service. It rents you a machine, usually a virtual one. The provider now manages the hardware and the network. Everything above is still yours. You patch the operating system, install the runtime, and keep your app running. Full control, and a full to-do list.

[01:20] PaaS and SaaS

Next, PaaS, platform as a service. It takes your code, or a packaged image of it, and runs it. So the provider also takes the operating system and the runtime. You keep just two layers: your app code, and its data. ComputeSphere is a PaaS, so this is the column you'll work in.

And the last step, SaaS, software as a service. That's finished software you log into, like a hosted email or accounting tool. You don't run any code, so the provider manages the app too. What's left is your data, and who can see it. Each step to the right hands another layer to the provider.

[02:04] What managed means

So what does managed really mean? Here's an example. A security fix for the operating system comes out. On IaaS, nothing happens until you install it. On a PaaS, the provider does that for you. That's the trade. You give up choosing every detail of the machine. In return, the tedious, easy-to-forget work isn't yours.

One layer never moves to the provider, even on SaaS. Your data, including who you let at it. A leaked password or a deleted table is your problem, in every column of the ladder.

[02:44] Which one fits

So which one fits you? Shipping a web app or API, and want to spend your time on the product? That's PaaS. Need something the platform can't do, like special hardware? That's IaaS. And if a product you can sign up for already solves it, like email, that's SaaS. Many teams use all three at once.

Here's the one thing to take away. The more layers the provider manages, the less you can change, and the less you have to look after. Now try it. Pick a tool you use every day, and place it on the ladder. Then name the layers you'd still manage. I'll see you in the next lesson.

Key idea

Every hosting option splits the work into layers, from hardware at the bottom to your data at the top. The more layers the provider manages, the less you can change, and the less you have to look after.

Reading the ladder

Pick a column and read it top to bottom: the cells marked You are your job, every day, for as long as the app runs.

  • IaaS (infrastructure as a service) rents you a machine, usually a virtual one. You install and patch the operating system, install your language's runtime, run your app and keep it running. Full control, full to-do list.
  • PaaS (platform as a service) takes your code, or a packaged image of it, and runs it. The provider looks after the machines, the operating system and the runtime. You write the app and own its data.
  • SaaS (software as a service) is finished software you log into, like a hosted email or accounting tool. You don't run any code; you manage your own data and who can see it.

"Managed" still means someone's job

On an IaaS machine, a security fix for the operating system is released, and nothing happens until you install it. On a PaaS, the provider does that for you. That's the trade: you give up choosing every detail of the machine, and in return the tedious, easy-to-forget work isn't yours.

One layer never moves to the provider, even on SaaS: your data, including who you let at it. A leaked password or a deleted table is your problem on every column of the ladder.

Which one fits

  • You're shipping a web app or API and want to spend your time on the product: PaaS.
  • You need something the platform can't do, like a custom operating system setting or special hardware: IaaS.
  • The job is already solved by a product you can sign up for, like email or a CRM: SaaS.

Many teams use all three at once: their own app on a PaaS, a database from a hosting provider, and SaaS for email and payments.

Check yourself

You rent a virtual machine and run your app on it. A security fix for its operating system comes out. Who installs it?
On a PaaS, which of these is still your job?

In the docs