A–C
Auto-Scaling
Automatically adjusting compute capacity based on demand. Scale out (add instances) during peak load; scale in (remove instances) during low load. Enables cost optimization for variable workloads and ensures performance during traffic spikes.
Availability Zone (AZ)
A physically separate data center within a cloud region, with independent power, cooling, and networking. Deploying across multiple AZs provides high availability — a failure in one AZ does not affect workloads in other AZs. AWS, Azure, and GCP all use AZ-based availability architecture.
Cloud Bursting
Running workloads on-premises during normal operations and bursting to the cloud during peak demand. Requires workloads that can run in both environments. Common for batch processing, development/test, and seasonal workloads.
Cloud Native
Applications designed specifically for cloud environments, taking advantage of cloud capabilities: microservices architecture, containers, serverless functions, managed services, and auto-scaling. Cloud-native applications are more scalable and resilient than applications simply moved to the cloud.
Cloud Repatriation
Moving workloads from public cloud back to on-premises or colocation infrastructure. Driven by cost, performance, or compliance requirements. A legitimate workload optimization strategy, not a failure of cloud strategy.
Committed Use Discount (CUD)
GCP's term for reserved capacity discounts. Committing to use specific resources for 1 or 3 years provides 40–70% discount vs. on-demand pricing. Similar to AWS Reserved Instances and Azure Reserved VM Instances.
Container
A lightweight, portable unit of software that packages an application and its dependencies. Containers run consistently across different environments (development, test, production, cloud). Docker is the dominant container format; Kubernetes is the dominant container orchestration platform.
CSPM (Cloud Security Posture Management)
Tools that continuously monitor cloud environments for misconfigurations, compliance violations, and security risks. Provides visibility across multiple cloud providers. Leading tools: Wiz, Prisma Cloud, Orca Security.
D–F
Direct Connect / ExpressRoute
Dedicated network connections between on-premises infrastructure and cloud providers: AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect. Provide lower latency and consistent bandwidth compared to VPN over the public internet.
Egress
Data leaving a cloud environment. Cloud providers charge for data egress (data transferred out of their network). Egress costs can be significant for data-intensive workloads and are a common source of unexpected cloud costs.
Elasticity
The ability to automatically scale resources up or down based on demand. A fundamental cloud characteristic that enables cost optimization for variable workloads. Distinct from scalability (the ability to scale, not necessarily automatically).
FinOps
Financial Operations — a cultural practice that brings financial accountability to cloud spending. Combines engineering, finance, and business to optimize cloud costs while maintaining performance. Organizations with mature FinOps practices achieve 30–50% lower cloud costs.
FaaS (Function as a Service)
Serverless computing where code runs in response to events without managing servers. AWS Lambda, Azure Functions, GCP Cloud Functions. Charges only for actual execution time. Cost-effective for event-driven, variable workloads.
G–I
GitOps
An operational model where infrastructure and application configurations are managed through Git repositories. Changes are made via pull requests, reviewed, and automatically applied by a GitOps operator (ArgoCD, Flux). Provides version control, audit trail, and consistent deployments across environments.
Hybrid Cloud
An IT architecture combining on-premises infrastructure (or private cloud) with public cloud services, connected by networking and unified by management tools. The dominant enterprise architecture — over 80% of enterprises operate hybrid cloud environments.
IaaS (Infrastructure as a Service)
Cloud service model providing virtualized computing infrastructure (VMs, storage, networking). Customer manages OS, middleware, and applications; provider manages physical infrastructure. AWS EC2, Azure Virtual Machines, GCP Compute Engine.
Identity Federation
Extending on-premises identity (Active Directory) to cloud environments, enabling single sign-on across both. Azure AD Connect, AWS IAM Identity Center, and third-party IdPs (Okta) enable identity federation for hybrid cloud environments.
Infrastructure as Code (IaC)
Managing cloud infrastructure through code (Terraform, Pulumi, CloudFormation) rather than manual configuration. Enables consistent, repeatable deployments; version control for infrastructure changes; and automated testing.
J–M
Kubernetes (K8s)
An open-source container orchestration platform that automates deployment, scaling, and management of containerized applications. The dominant platform for running containers in production. Managed Kubernetes services: EKS (AWS), AKS (Azure), GKE (GCP).
Landing Zone
The foundational cloud infrastructure that all migrated workloads use: account structure, networking, identity and access management, security controls, and monitoring. A well-designed landing zone prevents security and compliance issues that are expensive to fix after migration.
Lift and Shift
Migrating an application to the cloud with minimal changes — running the same virtual machine in the cloud that was running on-premises. Also called "rehost." Fastest migration strategy; delivers the least cloud value. Appropriate for time-constrained migrations or applications that will be refactored later.
Multi-Cloud
Using services from multiple public cloud providers (AWS + Azure + GCP). Provides flexibility and avoids vendor lock-in but introduces significant operational complexity. Most large enterprises are multi-cloud reactively (acquisitions, shadow IT) rather than strategically.
N–P
PaaS (Platform as a Service)
Cloud service model providing a platform for developing and deploying applications without managing underlying infrastructure. Customer manages applications and data; provider manages OS, middleware, and infrastructure. AWS Elastic Beanstalk, Azure App Service, GCP App Engine.
Private Cloud
Cloud infrastructure operated exclusively for a single organization, either on-premises or in a colocation facility. Provides cloud-like capabilities (self-service provisioning, elasticity) with the control and security of on-premises infrastructure. VMware vSphere, OpenStack, and Nutanix are common private cloud platforms.
Public Cloud
Cloud infrastructure operated by a third-party provider and shared among multiple customers. AWS, Azure, and GCP are the dominant public cloud providers. Provides elastic capacity, global reach, and access to managed services without capital investment.
Q–S
Region
A geographic area containing multiple availability zones. Cloud providers have regions in major markets worldwide. Data residency requirements may mandate that data stays within a specific region. Latency to end users is minimized by deploying in the nearest region.
Reserved Instance (RI)
A commitment to use specific cloud resources for 1 or 3 years in exchange for a significant discount (40–60%) vs. on-demand pricing. AWS Reserved Instances, Azure Reserved VM Instances, GCP Committed Use Discounts. Most impactful cost optimization for predictable workloads.
SaaS (Software as a Service)
Cloud-delivered software accessed via browser or API. Provider manages everything — infrastructure, platform, and application. Customer manages only data and user access. Salesforce, Microsoft 365, Workday, ServiceNow.
Serverless
A cloud execution model where the provider manages server infrastructure and automatically scales based on demand. Developers deploy code (functions) without managing servers. Charges only for actual execution time. AWS Lambda, Azure Functions, GCP Cloud Functions.
Shared Responsibility Model
The division of security responsibilities between cloud provider and customer. Provider secures the underlying infrastructure (physical security, hypervisor, network). Customer secures workloads (OS patching, application security, data encryption, access controls). Most cloud security incidents result from customer misconfiguration.
Spot Instance
AWS term for unused cloud capacity available at 60–80% discount vs. on-demand. Can be terminated with 2-minute notice when the provider needs the capacity. Azure equivalent: Spot VMs. GCP equivalent: Preemptible VMs. Appropriate for fault-tolerant batch workloads.
T–Z
Terraform
An open-source infrastructure-as-code tool by HashiCorp. Supports all major cloud providers and hundreds of third-party services. Uses declarative configuration files to define infrastructure. The dominant IaC tool for multi-cloud environments.
VPC (Virtual Private Cloud)
A logically isolated network within a public cloud. Provides network isolation, custom IP addressing, and control over routing and security. AWS VPC, Azure Virtual Network (VNet), GCP VPC. The foundation of cloud network architecture.
VPN (Virtual Private Network)
An encrypted tunnel over the public internet connecting on-premises infrastructure to cloud environments. Lower cost than dedicated connectivity (Direct Connect/ExpressRoute) but higher latency and variable bandwidth. Appropriate for non-latency-sensitive hybrid workloads.
Zero-Trust Network Access (ZTNA)
A security model that provides application access based on identity and context, rather than network location. Replaces VPN for remote access in many organizations. Users authenticate and are granted access to specific applications, not the entire network. Appropriate for hybrid cloud environments where the network perimeter is no longer meaningful.