IBM Application Framework for e-business
Systems Management
The Application Framework for e-business architecture provides a full
range of services for developing, deploying and managing e-business applications.
This paper focuses on the systems management aspects of the Framework.
Refer to the IBM
Application Framework for e-business - Architecture Overview white
paper for information on the other aspects of the architecture.
The
advent of e-business presents unique management problems for today's leading
edge companies. Management of existing Information Technology (IT) infrastructure
has never been more important, but at the same time controls must be placed
around the combination of internal and external systems that form the basis
of the e-business model. Intranet e-business applications provide broader
employee access to internal business information, potentially straining
the existing IT infrastructure with new traffic. Internet e-business applications,
such as e-commerce, provide business partners and customers access to business
information, creating more traffic for the IT infrastructure and introducing
more stringent security, reliability and availability requirements.
The Framework's systems management component defines the services and
tools to manage e-business applications and the underlying infrastructure
as a single entity. For intranet environments, Enterprise Systems Management
integrates the management aspects of e-business applications to provide
a consolidated view of an enterprise's business solutions, the applications
they use and the underlying IT resources. For the Internet environment,
the Framework introduces
Cross-Enterprise Systems Management supporting
a collaborative management approach that extends management functions to
environments that span company boundaries.
Systems Management Architecture
The
Framework's systems management services were developed within the context
of a systems management model that defines a set of management functions
to be applied at each layer of the application stack.
As shown in the figure, the application stack consists of four layers:
network, system, middleware and application. Managing e-business applications
requires effective management of each of these layers. To achieve this,
each layer supports a broad set of management functions that adhere to
enterprise defined policies and procedures. The management functions include
deployment, availability, operations and administration, and security.
The Framework's systems management architecture defines the structure
and services to integrate the management functions across the layers of
the application stack. The architecture is composed of the following key
elements:
-
Management
agents that monitor and control the resources used by an e-business
application. These agents run on the same machine as the resource they
manage, respond to specific requests from management applications and collect
management information for the resources. Managed resources and their agents
exist at each layer of the application stack.
-
A management framework that supports communication between management
agents and management applications, provides a storage mechanism for collected
management information, and supports a mechanism to apply policies and
procedures to the management environment.
-
Management applications that analyze data collected from agents
and initiate commands to agents for problem resolution. Management applications
may focus on a particular function, such as a software distribution application,
or they may focus on the management aspects of a particular resource, such
as a database management application.
-
A management console that provides a consolidated, central view
of resources and management applications.
The remainder of this section will describe the systems management architecture
in more detail. First, the supported management functions will be described
within the context of an e-business application lifecycle. Then, the management
aspects of each layer of the application stack will be addressed.
Management Functions
The complete lifecycle of software is fundamental to the management of
e-business applications - from initial development and distribution to
operation and subsequent upgrades. The Application Framework for e-business
defines the development environment, tools and management platform to ensure
that mission-critical e-business applications are easy to deploy and manage.
The systems management services supported by the Framework:
-
efficiently deploy software to the right users, on the right platform at
the right time,
-
monitor the availability and performance of hardware and software,
-
control access to and usage of e-business applications and their resources,
-
support management operations for e-business applications and their resources.
The Framework provides a flexible, policy-based management platform that
allows administrators to apply management functions to individual resources
or to collections of resources. For example, updates to an e-business application
may be applied concurrently to an entire group of machines or the update
may be applied to individual machines on an "as needed" basis.
Deployment
One of the greatest challenges of any computing environment is ensuring
the successful deployment of application software. First, IT staff must
setup the deployment environment by coordinating the location of application
files and modifications of system files with different application versions
to ensure that applications are installed properly for each target machine.
Then, IT staff must verify that sufficient system resources, such as memory,
are available and the proper versions of operating systems and middleware
configurations are installed. Finally, IT staff must be able to flip
the switch on all the application components across geographically
dispersed systems without overloading network bandwidth.
In many environments, this first and last deployment steps discussed
above apply primarily to application deployment on one or more server machines.
The Framework supports a server-managed deployment model in which applications
and application components are installed and configured on a server and
dynamically downloaded on-demand to requesting client machines. As a result,
applications are not deployed on individual client machines thereby reducing
the costs of client management significantly.
To address these deployment requirements, the Framework promotes the
Tivoli-lead, industry supported Application Management Specification (AMS)
as the way to capture the details necessary to effectively deploy e-business
applications. Tools are provided to build AMS files that describe an e-business
application.
Availability
Now more than ever, the availability and performance of mission-critical
applications is crucial to business transactions, regardless of where the
components reside. Businesses can suffer unrecoverable loss of profit and
productivity when customers, suppliers, and employees lack access to critical
applications. For this reason, availability and performance characteristics
of e-business applications and their resources must be provided by management
agents.
The Framework's management agents monitor the various resources used
by an application and send event messages to one or more management applications.
Agents adhere to enterprise defined policies and procedures which can,
for example, define performance thresholds as well as dictate which management
system should receive which messages. The Open Group standard Application
Response Measurement (ARM) APIs can be used by management agents to measure
e-business application response time.
Security
Mission critical e-business applications must be deployed in an environment
that provides authentication, access control, and auditing capabilities
to ensure the integrity and privacy of business critical information. Although
the Framework promotes the use of public key infrastructures that use X509v3
certificates and SSL, many of the applications and data in business systems
today use proprietary mechanisms or private key infrastructures. In fact,
different security systems may be utilized at each layer of the application
stack.
To support these environments, the Framework defines the tools and services
that allow administrators to manage different security schemes in an integrated
fashion. Once a user is authenticated to use an e-business application
then all security needs of lower layers are automatically handled by the
system. This is sometimes referred to as single signon. In addition, the
Framework's system management services provide a flexible, role-based security
model to assign the appropriate rights to users of the various e-business
application components.
Administration and Operations
Mission critical e-business applications must be able to adapt to changes
in their environment, such as location of temporary storage, and recover
from problems encountered during usage, such as data that is out of date.
To perform these functions, e-business applications must issue event messages
when problems are encountered and provide access (e.g. via command line
interfaces) to features and functions so that changes can be made or problems
fixed.
The Framework supports a rules-based event monitoring system that enables
administrators to invoke application management operations, such as backup
and restore, in response to specific events or at scheduled intervals.
The Framework supports a number of event formats including SNMP.
Management of the Application Stack
As discussed above, effectively managing e-business applications in an
integrated fashion requires the coordinated management of the underlying
resources the applications utilize. To achieve this, the systems management
services must be supported at each layer of the application stack.
Network Management
Network management maintains the underlying physical connections of an
enterprise's systems. Network management primarily involves the installation,
configuration and monitored operation of hardware such as bridges, routers,
and servers, and ensures that systems and data remain available. The Framework
promotes the use of SNMP for this layer of management.
Systems Management
Systems management maintains the underlying logical connections of an enterprise's
systems. Systems management primarily involves the installation, configuration,
administration and monitored operation of operating systems and infrastructure
services, such as file, directory and security services that support an
application. To meet its business needs, an enterprise will most likely
support a mix of operating systems, such as UNIX, Windows NT and OS/390,
which leads to a variety of directory and security schemes to be supported.
Middleware Management
Middleware management primarily involves the installation, configuration,
administration and monitored operation of HTTP servers, database
and transaction services, mail and community services, and groupware services.
The Framework treats these application server software
components as specialized applications and therefore promotes the same
management technology used at the application layer discussed below.
Applications Management
Applications
management is the highest layer of the stack with the ultimate management
responsibility of keeping mission critical applications and data both available
and secure. Applications management primarily involves the installation,
configuration, administration and monitored operation of e-business applications.
For this layer, the Framework promotes the Tivoli-led, industry-supported,
Application Management Specification. AMS addresses the full lifecycle
of an e-business application by supporting software distribution, application
monitoring, event management and task automation.
AMS provides a non-intrusive (i.e. no code required) method to define
management characteristics of an application using the Common Information
Model (CIM) defined by the Desktop Management Task Force (DMTF). Software
development tools are provided to build CIM based files associated with
an application. Management events and ARM transactions used by monitor
agents may be referenced in AMS files. The systems management services
interpret these AMS files to provide secure, efficient deployment, policy
based monitoring and event driven problem resolution. AMS also includes
a number of additional management functions such as user administration
and security, inventory management, and performance management.
Enterprise Systems Management
Enterprise
systems management integrates the management functions across all the layers
of the application stack to provide a consolidated view of an enterprise's
business solutions, the applications they use and the underlying IT resources.
The integrated management of applications, middleware, systems and networks
using a single, comprehensive management system is important to maintain
service levels and to keep the enterprise running efficiently. Consider
a scenario where the failure of a network router causes apparent database
and application failures. Determining the root cause of the failure using
separate, non-integrated management tools results in additional effort
on the part of both the database and application administrators.
To support a centralized view of the enterprise, the Framework provides
a management console that is easy to extend. In addition, a systems management
framework based on distributed object technologies is provided that allows
for the addition of new management applications and managed resources.
This flexibility is critical for the fast-paced, global dynamics of today's
large scale enterprises as well as for the small to medium businesses that
are growing rapidly.
Cross-Enterprise Systems Management
Cross-enterprise systems management extends the integrated enterprise systems
management environment to span company boundaries across the Internet.
Businesses are rushing to take advantage of the benefits offered by
the Internet: extended reach to new customers, improved service for existing
customers, reduced cost of doing business, and continuous availability
7 days a week, 24 hours a day. However, doing business on the Internet
forces companies to rely on systems, networks, and people that they do
not control, and that do not necessarily function together.
The
complex infrastructure of Internet e-business applications, such as e-commerce,
presents challenging management problems. Attempts to manage Internet e-business
applications are further complicated by the existence of multiple, independently
managed networks or administrative domains. For example, each participant
in an e-commerce transaction controls a separate administrative domain
- a collection of interconnecting hosts and routers, managed by a single
administrative authority. This often results in a loss of visibility that
clouds the issues of accountability and control as applications move across
the Internet. The failure of an application in one administrative domain
might be the result of a problem in another administrative domain, but
detecting and fixing the problem can be difficult when the cause lies outside
the area to which the administrator has visibility and control.
To address this, the Framework has extended its systems management architecture
to embrace the collaborative management approach being pioneered
by Tivoli. At the core of this paradigm
shift in systems management is the collaboration between enterprises, establishing
and following policies and procedures to share management information and
coordinate problem resolution.
Extending the Framework for Collaborative Management
The success of e-business requires a new generation of management services
and tools that provide end-to-end solutions designed specifically to manage
widely dispersed, e-business applications. As activities cross administrative
domains, the ability to synchronize application updates, manage availability,
and ensure security is compromised. The systems management services have
been extended to address collaborative management. In general, this means
that the distributed object framework used by the various systems management
services is extended to support formats and protocols that work across
Internet firewalls in a secure fashion.
Deployment
By their very nature, Internet e-business applications allow for pieces
of the application to reside in multiple locations; components may be deployed
not only at the hosting site, but also on customer's and supplier's sites.
As more applications reside beyond controlled firewalls, traditional management
tools are not sufficient to ensure that applications are secure, properly
deployed, and available to all end users.
To address these collaborative deployment requirements, the Framework
utilizes Internet software distribution technology whereby end users receive
the appropriate applications and information by subscribing to channels.
Channels are simply an abstraction that represents the executable and data
files that comprise applications. The deployment server and deployment
client work together to automatically keep channels current and to reduce
the complexity of delivering and maintaining applications across devices,
platforms and networks. To integrate with existing enterprise deployment
schemes, channels may also be used to distribute AMS files.
Availability
Internet e-business applications also introduce another level of management
complexity in the area of availability. Since the connection to partners
and customers is through the Internet, performance problems due to bandwidth
bottlenecks, or availability problems due to improper server configuration
or node failures can bring business to a standstill. Determining whose
network or system is causing the problem requires collaborative collection
and analysis of management information.
The Framework's monitoring agents used in the enterprise systems management
environment are extended to adhere to cross-enterprise defined policies
and procedures which can, for example, define agreed to performance thresholds
as well as dictate which administrative domain and management system receives
which messages.
Security
Ensuring the security of business-critical applications once they shift
beyond an IT organization's control is also an important concern for the
Internet e-business community. It is critical to safeguard information
assets and protect the privacy of all parties in an e-commerce transaction
because fraud, viruses, illegal intrusions, and unintentional corruption
all pose serious threats. Even the perception of a lack of security can
cause businesses and consumers to become reluctant to use e-business.
The Framework's systems management security services are extended to
provide an enforceable security policy that ensures the extended enterprise
remains inviolable. The Framework's extensions for collaboration enables
each partner to manage its own security and, optionally, collaborate with
key on-line business partners to manage access to their extranets. The
extensions include:
-
An agent that detects external scans and intrusions (intrusion detector)
-
A policy-based management console that scans the security infrastructure,
collects data from intrusion detectors, initiates responses to security
breaches, and provides extensive reporting capabilities
Summary
The Application Framework for e-business systems management services provide
a complete set of APIs and tools to add management capabilities to e-business
applications as well as the middleware, systems and networks these applications
use. The Framework also defines an extensible management platform that
integrates management applications and managed resources to provide a comprehensive
view of e-business solutions running both within and across enterprises.
References
Refer to the Application Framework for e-business Web site (www.ibm.com/software/ebusiness)
for more specific information on the Framework.
Refer to the Tivoli Web site (www.tivoli.com)
for specific Tivoli information. The Download Area contains detailed information
about AMS.
Refer to the Desktop Management Task Force Web site (www.dmtf.org)
for more information about CIM and DMTF.
Refer to the Open Group Web site (www.opengroup.org)
for more information about ARM and The Open Group.
Refer to the Operations and Management area of the active IETF working
groups page (www.ietf.org/html.charters/wg-dir.html)
for more information about SNMP.
|