<<

Cloud/DevOps Handbook

EDITOR'S NOTE

AI AND MACHINE LEARNING

ANALYTICS

APPLICATION INTEGRATION

BUSINESS APPLICATIONS

COMPUTE

CONTAINERS

COST CONTROLS

DATABASES

DEVELOPER TOOLS

IoT

MANAGEMENT AND GOVERNANCE

MIGRATION

MISCELLANEOUS

A cloud services cheat sheet for AWS, NETWORKING Azure, and Cloud SECURITY

STORAGE

DECEMBER 2020

 EDITOR'S NOTE

HOME

EDITOR'S NOTE cloud directories—a quick reference sheet for what each AI AND MACHINE A cloud services LEARNING vendor calls the same service. However, you can also use this as a starting point. You'll ANALYTICS cheat sheet for need to do your homework to get a more nuanced under- APPLICATION AWS, Azure and standing of what distinguishes the offerings from one an- INTEGRATION other. Follow some of the links throughout this piece and take that next step in dissecting these offerings. BUSINESS Google Cloud APPLICATIONS That's because not all services are equal—each has its —TREVOR JONES, SITE EDITOR own set of features and capabilities, and the functionality COMPUTE might vary widely across platforms. And just because a CONTAINERS provider doesn't have a designated service in one of these categories, that doesn't mean it's impossible to achieve the COST CONTROLS same objective. For example, Google Cloud doesn't offer an AWS, AND GOOGLE each offer well over 100 cloud explicit disaster recovery service, but it's certainly capable services. It's hard enough keeping tabs on what one cloud of supporting DR. DEVELOPER TOOLS offers, so good luck trying to get a handle on the products Here is our cloud services cheat sheet of the services IoT from the three major providers. available on AWS, Google Cloud and Azure. The list is bro- Even trying to compare what's available in each cloud ken down by category to help you start your cross-cloud MANAGEMENT AND GOVERNANCE can quickly get convoluted, since naming conventions vary analysis. n by vendor and service. For example, you can be forgiven MIGRATION for not knowing AWS Fargate, Container

MISCELLANEOUS Instances and Google Cloud Run all essentially serve the Editor's note: Cloud services are constantly evolving. All infor- same purpose. mation in this cheat sheet is up to date as of publication. We will NETWORKING So, if you ever feel at a loss for what's what, hopefully this periodically update the list to reflect the ongoing changes across SECURITY cloud services cheat sheet will help. Consider it a guide for all three platforms.

STORAGE

COVER IMAGE: METAMORWORKS/GETTYIMAGES A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 2 AI and machine learning HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE AI containers AWS Deep Learning Containers GPU support on AKS Deep Learning Containers

AI AND MACHINE AI machine images AWS Deep Learning AMIs Data Science Virtual Machines Deep Learning VM Image LEARNING Chat bots builder Amazon Lex Azure Bot Service, QnA Maker ANALYTICS Data labeling Amazon SageMaker Ground Truth Azure Machine Learning data labeling Cloud Data Labeling APPLICATION INTEGRATION Document extraction, Amazon Textract Azure Form Recognizer, Ink Vision API image content analysis Recognizer, Computer Vision, BUSINESS Custom Vision APPLICATIONS Image and video Amazon Rekognition Azure Face, Video Indexer Video AI COMPUTE recognition, indexing

CONTAINERS Inference accelerator Amazon Elastic Inference GPUs on AKS Cloud TPU, Edge TPU

COST CONTROLS Language recognition, Amazon Comprehend Language Understanding, Text Natural Language sentiment analysis Analytics

DATABASES Language translation Amazon Translate Speech Translation, Translator Translation

DEVELOPER TOOLS Machine learning AWS Inferentia, AWS Trainium FPGA Cloud TPU hardware (preview*) IoT

Managed machine Amazon SageMaker Azure Machine Learning Cloud AutoML MANAGEMENT learning platform AND GOVERNANCE Online fraud detection Amazon Fraud Detector N /A reCAPTCHA Enterprise MIGRATION Prediction review Amazon Augmented AI, Amazon Azure Content Moderator N /A MISCELLANEOUS and moderation SageMaker Clarify

NETWORKING Recommendation Amazon Personalize Personalizer Recommendations AI integration (preview) SECURITY Amazon Transcribe Speaker Recognition, Speech to Text Cloud Speech-to-Text API STORAGE CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 3 CONTINUED AI and machine learning HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Text-to-speech Amazon Polly Text to Speech Cloud Text-to-Speech API

AI AND MACHINE Time-series forecasting Amazon Forecast N /A N /A LEARNING Vision/speech modeling AWS DeepLens Azure DK N /A ANALYTICS packaged devices

APPLICATION *AWS, GOOGLE AND MICROSOFT USE DIFFERENT TERMINOLOGY TO DESCRIBE SERVICES THAT ARE IN PREVIEW, BETA OR ALPHA. INTEGRATION FOR THE PURPOSES OF THIS PIECE, ANY SERVICE THAT IS NOT GENERALLY AVAILABLE IS LISTED AS BEING IN PREVIEW.

BUSINESS Analytics APPLICATIONS AWS AZURE GOOGLE CLOUD

COMPUTE processing Amazon EMR Azure Databricks, Azure HDInsight Dataproc

CONTAINERS Business analytics Amazon QuickSight Power BI Embedded , COST CONTROLS Data lake creation Amazon HealthLake (preview), Storage DATABASES AWS Lake Formation

DEVELOPER TOOLS Data sharing AWS Data Exchange, AWS Lake Azure Data Share Cloud Dataprep Formation (partnership with Trifacta) IoT Data warehousing Amazon Redshift Azure Synapse Analytics BigQuery MANAGEMENT AND GOVERNANCE ETL AWS Glue, Amazon Kinesis Data Azure Data Factory Cloud Data Fusion, Firehose, Amazon SageMaker Data Dataflow, Dataproc

MIGRATION Wrangler

Hosted Hadoop/Spark Amazon EMR Azure HDInsight Dataproc MISCELLANEOUS

Managed search Amazon CloudSearch, Amazon , Bing Search Cloud Search NETWORKING Elasticsearch Service, Amazon Kendra services

SECURITY Managed Kafka Amazon Managed Streaming Azure Event Hubs for Apache Kafka N/A (available through a for Apache Kafka partnership with Confluent) STORAGE

CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 4 CONTINUED Analytics HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Real-time data streaming Amazon Kinesis Data Analytics, Dataflow, Pub/Sub Amazon Kinesis Data Streams AI AND MACHINE LEARNING Query service, data Amazon Athena, Amazon SQL Server ML Services, Big Data BigQuery exploration Elasticsearch Service, Amazon Clusters (Spark), Data Lake Analytics, ANALYTICS Managed Service SQL Server Analysis Services, for Grafana (preview) APPLICATION INTEGRATION

BUSINESS Application integration APPLICATIONS AWS AZURE GOOGLE CLOUD

COMPUTE API development and Amazon API Gateway, AWS AppSync Azure API Apps API Gateway (preview), management , Cloud Endpoints CONTAINERS Distributed app Amazon Simple Workflow Service, Logic Apps Cloud Tasks coordination AWS Step Functions COST CONTROLS

Event routing, third-party Amazon AppFlow, Amazon Event Grid Pub/Sub DATABASES integration EventBridge, Amazon Simple Notification Service DEVELOPER TOOLS

Messaging Amazon MQ, Amazon Simple Queue Queue Storage, Service Bus Pub/Sub IoT Service

MANAGEMENT Service discovery AWS Cloud Map N /A N /A AND GOVERNANCE Service mesh AWS App Mesh Azure Service Fabric Mesh (preview) Anthos Service Mesh MIGRATION Workflow orchestration AWS Data Pipeline Logic Apps Cloud Composer MISCELLANEOUS

NETWORKING

SECURITY

STORAGE

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 5 Business applications** HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Collaboration tool suite N /A

AI AND MACHINE Document sharing and Amazon WorkDocs Microsoft Word LEARNING storage

ANALYTICS Email and calendar Amazon WorkMail Outlook

APPLICATION Low-code/no-code Amazon Honeycode (preview) Microsoft PowerApps, Project Bonsai AppSheet INTEGRATION (preview)

BUSINESS Video calls and chat Amazon Chime APPLICATIONS Voice assistant Alexa for Business Cortana COMPUTE **SEVERAL GOOGLE AND MICROSOFT SERVICES IN THIS SECTION ARE NOT EXPLICITLY AVAILABLE THROUGH AND MICROSOFT AZURE, RESPECTIVELY. THEY ARE PART OF EACH VENDOR'S BROADER CLOUD PORTFOLIO. CONTAINERS

COST CONTROLS Compute

AWS AZURE GOOGLE CLOUD DATABASES Autoscaling AWS EC2 Auto Scaling Azure Autoscale, Azure virtual Managed instance groups DEVELOPER TOOLS machine scale sets (MIGs)

IoT Batch scheduling, AWS Batch Azure Batch Batch on GKE (preview) executing and processing MANAGEMENT AND GOVERNANCE Functions AWS Lambda Azure Functions Cloud Functions

MIGRATION 5G-based infrastructure AWS Wavelength Azure Edge Zones Global Mobile Edge Cloud (GMEC)

MISCELLANEOUS High performance AWS ParallelCluster Azure CycleCloud N /A computing cluster NETWORKING management

SECURITY Isolated servers Dedicated Instances Azure Dedicated Host Sole-tenant Nodes, Shielded VMs STORAGE

CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 6 CONTINUED Compute HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE PaaS AWS Elastic Beanstalk App Service, Azure Cloud Services, App Engine Azure Spring Cloud, Azure Red Hat AI AND MACHINE OpenShift LEARNING On-premises/edge devices AWS Outposts, AWS Family Azure Stack Hub, Azure Stack HCI N /A ANALYTICS (preview), Azure Stack Edge

APPLICATION Quantum computing Amazon Braket Azure Quantum (preview) N /A INTEGRATION Virtual machines Amazon EC2 Virtual Machines Compute Engine BUSINESS APPLICATIONS Virtual private server Amazon Lightsail N /A N /A

COMPUTE VMware integration VMware Cloud on AWS Azure VMware Solution VMware Engine

CONTAINERS Containers COST CONTROLS AWS AZURE GOOGLE CLOUD DATABASES Container registry Amazon Elastic Container Registry Azure Container Registry Artifact Registry (preview), (ECR), ECR Public Container Registry DEVELOPER TOOLS

Managed container Amazon Elastic Container Service Azure Service (AKS) Google Kubernetes Engine IoT service (ECS), Amazon Elastic Kubernetes (GKE) Service (EKS) MANAGEMENT AND GOVERNANCE Serverless container AWS Fargate Azure Container Instances (ACI) Cloud Run environment MIGRATION

MISCELLANEOUS

NETWORKING

SECURITY

STORAGE

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 7 Cost controls HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Long-term commitment EC2 Reserved Instances, Reservations, Azure Hybrid Benefit Committed use discounts, discount programs Savings Plans sustained use discounts AI AND MACHINE LEARNING Low-cost, interruptible EC2 Spot Azure Spot Virtual Machines Preemptible Virtual VMs Machines ANALYTICS Optimization tools Amazon CodeGuru, Amazon DevOps Azure Advisor, Azure Well-Architected Recommender, Network APPLICATION Guru (preview), AWS Compute Review Intelligence Center, INTEGRATION Optimizer, AWS Trusted Advisor, Cloud Profiler AWS Well-Architected Tool BUSINESS APPLICATIONS Spending tracker and AWS Budgets, AWS Cost Anomaly Azure Cost Management and Billing Cost Management analysis Detection, AWS Cost Explorer, AWS Cost and Usage Report COMPUTE

CONTAINERS

COST CONTROLS Databases

AWS AZURE GOOGLE CLOUD DATABASES Blockchain Amazon Managed Blockchain, Azure Blockchain Service (preview), N /A DEVELOPER TOOLS Amazon Quantum Ledger Azure Blockchain Tokens (preview), (QLDB) Azure Blockchain Workbench (preview) IoT

In-memory caching Amazon ElastiCache (Memcached, Azure Cache for Redis Cloud Memorystore MANAGEMENT Redis) AND GOVERNANCE

NoSQL: Column-family Amazon Keyspaces (for Apache Azure Cosmos DB Cloud MIGRATION Cassandra)

MISCELLANEOUS NoSQL: Document Amazon Document DB (with MongoDB Azure Cosmos DB Cloud Firestore, compatibility), Amazon DynamoDB Realtime Database NETWORKING NoSQL: Graph Amazon Neptune Azure Cosmos DB Gremlin API N /A SECURITY NoSQL: Key-value Amazon DynamoDB, Azure Cosmos DB, storage Cloud Bigtable, Firestore STORAGE Amazon Keyspaces

CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 8 CONTINUED Databases HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Relational database Amazon Aurora, Amazon RDS (MySQL, Azure Database (MySQL, MariaDB, Cloud SQL (MySQL, management system PostgreSQL, Oracle, SQL Server, PostgreSQL), Azure SQL (Database, PostgreSQL, SQL Server), AI AND MACHINE MariaDB), Amazon RDS on VMware Edge, Managed Instance) Cloud LEARNING Time-series database Amazon Timestream Azure Time Series Insights Cloud Bigtable ANALYTICS

APPLICATION INTEGRATION Developer tools

BUSINESS AWS AZURE GOOGLE CLOUD APPLICATIONS App configuration AWS AppConfig App Configuration Cloud Storage parameter storage COMPUTE Artifact management AWS CodeArtifact Azure Artifacts, GitHub Packages Artifact Registry (preview) CONTAINERS Code debugging AWS X-Ray Cloud Debugger, Firebase COST CONTROLS Crashlytics

DATABASES CI/CD AWS CodeBuild, AWS CodeDeploy, Azure DevOps, Azure Pipelines Cloud Build, Tekton AWS CodePipeline, AWS CodeStar DEVELOPER TOOLS Development kits AWS Cloud Development Kit, Amazon Azure SDKs Cloud SDK IoT Corretto

MANAGEMENT IDEs and other tools AWS Cloud9, AWS CLI, Azure CLI, Azure PowerShell, Azure Cloud Code, Tools for AND GOVERNANCE for interacting with AWS CloudShell, Amazon EMR Studio Cloud , Visual Studio, Visual zEclipse, Tools for cloud resources Studio Code, Visual Studio Codespaces PowerShell

MIGRATION Lab environment N /A Azure Lab Services N /A

MISCELLANEOUS Mobile and Web app AWS Amplify App Service, Mobile Apps, Google Firebase development with Azure, Web Apps, Static Web NETWORKING Apps (preview)

SECURITY Mobile and web AWS Device Farm Visual Studio App Center Test, Azure Google Firebase Test Lab app testing Test Plans STORAGE Private Git repository AWS CodeCommit Azure Repos Cloud Source Repositories

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 9 IoT HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Cloud-device connections, AWS IoT Analytics, AWS IoT Core, Azure IoT Central, Azure IoT Hub, Cloud IoT Core data collection and AWS IoT Device Defender, AWS IoT Azure Defender for IoT, AI AND MACHINE management Device Management, AWS IoT Events, LEARNING AWS IoT SiteWise

ANALYTICS IoT edge compute AWS Greengrass Azure IoT Edge Edge TPU

APPLICATION Microcontroller OS FreeRTOS Azure RTOS N /A INTEGRATION Virtual modeling AWS IoT Things Graph Azure Digital Twins (preview) N /A BUSINESS APPLICATIONS

COMPUTE Management and governance

CONTAINERS AWS AZURE GOOGLE CLOUD

Automation AWS CloudFormation, AWS Proton Azure Resource Manager, Azure Cloud Deployment COST CONTROLS (preview), AWS OpsWorks Automation Manager, Cloud Scheduler

DATABASES Anomaly detection CloudWatch Anomaly Detection Anomaly Detector Anomaly Detection

DEVELOPER TOOLS Application portfolio AWS Service Catalog Azure Managed Applications, Azure Private Catalog governance Blueprints (preview) IoT Automated Windows Server N /A Azure Automanage (preview) N /A MANAGEMENT management AND GOVERNANCE Configuration management AWS Config Azure App Configuration Cloud Asset Inventory MIGRATION Health dashboard Personal Health Dashboard Resource Health, Azure Service Health Cloud Monitoring

MISCELLANEOUS Hybrid and multi-cloud Amazon EKS Anywhere (preview), Azure Arc Google Anthos management Amazon ECS Anywhere (preview) NETWORKING

License management AWS License Manager N /A N /A SECURITY

CONTINUED STORAGE

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 10 CONTINUED Management and governance HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Monitoring Amazon CloudWatch, Amazon Azure Monitor, Network Watcher, Operations, Cloud CloudWatch Logs, AWS Transit Log Analytics Operations for GKE AI AND MACHINE Gateway Network Manager, Amazon (formerly Stackdriver), LEARNING Lookout for Metrics (preview), Network Intelligence Amazon Managed Service for Center ANALYTICS Prometheus (preview)

APPLICATION Multi-account AWS Control Tower, Azure Management Groups, N /A INTEGRATION management AWS Organizations Azure Lighthouse

BUSINESS Policy management AWS Organizations Azure Policy Organization Policy Service APPLICATIONS Telemetry collection AWS Systems Manager Azure Monitor Service Monitoring and response (preview) COMPUTE

Web-based user AWS Management Console Azure Portal Cloud Console CONTAINERS interface

COST CONTROLS

DATABASES Migration

DEVELOPER TOOLS AWS AZURE GOOGLE CLOUD

Database migration AWS Database Migration Service Azure Database Migration Service Database Migration Service IoT (preview)

MANAGEMENT Data transfer appliance Snow Family Data Transfer Appliance AND GOVERNANCE Disaster recovery CloudEndure Disaster Recovery Azure Site Recovery N /A MIGRATION Online data transfer AWS DataSync, AWS Transfer Family Azure File Sync BigQuery Data Transfer MISCELLANEOUS Service, Cloud Data Transfer NETWORKING On-premises application AWS Application Discovery Service, Azure Migrate, Movere, Azure N /A SECURITY analysis Migration Evaluator Resource Mover (preview)

STORAGE CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 11 CONTINUED Migration HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE On-premises and cloud Storage Gateway StorSimple N/A (offered by partner storage integration Cloudian) AI AND MACHINE LEARNING Migration tracker AWS Migration Hub Azure Migrate N /A

ANALYTICS Server migration AWS App2Container, AWS Server Azure Migrate Migrate for Anthos, Migrate Migration Service, CloudEndure for Compute Engine, APPLICATION Migration VM migration INTEGRATION

BUSINESS APPLICATIONS Miscellaneous

COMPUTE AWS AZURE GOOGLE CLOUD

Customer engagement Amazon Connect, Contact Lens for Azure Communication Services Contact Center AI CONTAINERS Amazon Connect (preview)

COST CONTROLS End user communications Amazon Pinpoint, Amazon Simple Azure Notification Hubs Email Service DATABASES Gaming Amazon GameLift, Amazon Game Stack Game Servers DEVELOPER TOOLS Lumberyard

IoT Geolocation and Amazon Maps API, Amazon Location Azure Maps Platform services Service (preview)

MANAGEMENT AND GOVERNANCE Genomics N /A Microsoft Genomics Cloud Life Sciences (preview)

MIGRATION Industrial and other Amazon Lookout for Vision, Azure IoT Vision AI workplace monitoring tools Amazon Lookout for Equipment, MISCELLANEOUS Amazon Panorama, Amazon Monitron

NETWORKING Media services Amazon Elastic Transcoder, Azure Media Player, Content OpenCue AWS Elemental suite, Amazon Protection, Encoding, Live and SECURITY Interactive Video Service, Amazon On-Demand Streaming, Live Video Kinesis Video Streams Analytics (preview), Media Services STORAGE

CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 12 CONTINUED Miscellaneous HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Mobile access to internal Amazon WorkLink N /A Identity-Aware Proxy web apps AI AND MACHINE LEARNING Robotics application AWS RoboMaker N /A Cloud Robotics Core development ANALYTICS Satellite ground stations AWS Ground Station Azure Orbital (preview) N /A APPLICATION INTEGRATION Virtual desktop Amazon WorkSpaces, Amazon Windows Virtual Desktop N /A AppStream 2.0 BUSINESS APPLICATIONS Virtual reality, mixed reality Amazon Sumerian Azure Digital Twins (preview), Kinect Google VR app development DK, Remote Rendering (preview),

COMPUTE Spatial Anchors

CONTAINERS

COST CONTROLS Networking

AWS AZURE GOOGLE CLOUD DATABASES Build, deploy and manage Amazon API Gateway Azure API Apps, API Management Apigee API Management DEVELOPER TOOLS APIs Platform

IoT Content delivery network Amazon CloudFront Content Delivery Network (CDN) Cloud CDN

MANAGEMENT Dedicated fiber connection AWS Direct Connect Azure ExpressRoute Cloud Interconnect AND GOVERNANCE between VPCs and private network

MIGRATION Amazon Route 53 Azure DNS Cloud DNS

MISCELLANEOUS Load balancing Elastic Load Balancing (ELB) Application Gateway, Load Balancer, Cloud Load Balancing Traffic Manager NETWORKING

Network accelerator AWS Global Accelerator Accelerated Networking Premium Network Service SECURITY Tier

STORAGE Network area translation NAT Gateway Virtual Network NAT Cloud NAT

CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 13 CONTINUED Networking HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Satellite ground station AWS Ground Station Azure Orbital (preview) N /A

AI AND MACHINE Service discovery Amazon ECS, AWS Cloud Map N /A Service Discovery (preview) LEARNING Traffic control plane AWS App Mesh Azure Front Door, Azure Service Fabric Traffic Director ANALYTICS Virtual WAN N /A Virtual WAN N /A APPLICATION INTEGRATION VPC Amazon VPC Azure Virtual Network

BUSINESS VPC/VM secure connector AWS Transit Gateway, AWS VPN Azure Bastion, Azure Private Link, Cloud VPN, Direct Peering APPLICATIONS Azure VPN gateway

COMPUTE

CONTAINERS Security

AWS AZURE GOOGLE CLOUD COST CONTROLS Audit and compliance AWS Artifact, AWS Audit Manager Service Trust Portal N /A DATABASES reports

DEVELOPER TOOLS Centralized security AWS Security Hub Security Center Security Command Center management

IoT Certificate management AWS Certificate Manager App Service Certificates Certificate Authority Service (preview) MANAGEMENT AND GOVERNANCE Confidential computing AWS Nitro Enclaves Azure Confidential Computing Confidential Computing (preview) MIGRATION

Container deploy-time N /A N /A Binary Authorization MISCELLANEOUS security control

NETWORKING Data discovery and Amazon Macie Data Discovery & Classification Data Catalog, classification (feature of Azure SQL Database, Cloud Data Loss Prevention SECURITY Azure SQL Managed Instance and Azure Synapse Analytics) STORAGE CONTINUED

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 14 CONTINUED Security HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Distributed denial-of- AWS Shield Azure DDoS Protection Google Cloud Armor service (DDoS) protection AI AND MACHINE LEARNING End-user identity Amazon Cognito Azure B2C Firebase Authentication management ANALYTICS Firewall management AWS Firewall Manager, AWS WAF Azure Firewall, Web Application Cloud Armor, Cloud APPLICATION Firewall firewalls INTEGRATION Identity and access AWS Identity and Access Azure Active Directory, role-based Identity and Access BUSINESS management Management access control (Azure RBAC) Management, Identity APPLICATIONS Platform, Identity-Aware Proxy

COMPUTE Key management AWS Key Management Service, Key Vault, Azure Dedicated HSM Cloud Key Management AWS CloudHSM CONTAINERS

Multifactor AWS Multi-Factor Authentication Azure MFA Google , COST CONTROLS authentication Titan Security Key

DATABASES Microsoft Active Directory AWS Directory Service for Microsoft Azure Active Directory Domain Managed Service for compatible directory Active Directory Service Microsoft Active DEVELOPER TOOLS service Directory

IoT Resource access AWS Resource Access Manager Azure Resource Manager Resource Manager management MANAGEMENT AND GOVERNANCE Security data analysis Amazon Detective Security Center Chronicle

MIGRATION Secrets management AWS Secrets Manager Azure Key Vault Secret Manager

MISCELLANEOUS Single sign-on AWS Single Sign-On Azure Active Directory single Cloud Identity single-on NETWORKING Signoff for cloud provider N /A Customer Lockbox Access Transparency

SECURITY data access requests

CONTINUED STORAGE

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 15 CONTINUED Security HOME AWS AZURE GOOGLE CLOUD

EDITOR'S NOTE Threat Detection Amazon GuardDuty Advanced Threat Protection, Chronicle, Phishing Azure Defender Protection, Web Risk, AI AND MACHINE Event Threat Detection LEARNING (preview)

ANALYTICS Vulnerability scanning Amazon Inspector Security Center Web Security Scanner

APPLICATION INTEGRATION Storage BUSINESS APPLICATIONS AWS AZURE GOOGLE CLOUD

Archival storage S3 Glacier, S3 Glacier Deep Archive Archive Storage Archive Storage COMPUTE

Backup AWS Backup Azure Backup N /A CONTAINERS Block storage Amazon Block Store (EBS) Disk Storage Persistent Disk, Local SSD COST CONTROLS File storage Amazon Elastic File Service (EFS), File Storage, Azure NetApp Filestore DATABASES Amazon FSx for Windows File Server, Amazon FSx for Lustre DEVELOPER TOOLS Object storage Amazon S3 Blob storage Cloud Storage, Cloud IoT Storage for Firebase

MANAGEMENT AND GOVERNANCE

MIGRATION

MISCELLANEOUS

NETWORKING

SECURITY

STORAGE

A CLOUD SERVICES CHEAT SHEET FOR AWS, AZURE AND GOOGLE CLOUD • DECEMBER 2020 16