Home / Cloud / Hybrid cloud
Cloud guide

Hybrid cloud that works like one environment

Most hybrid projects do not fail with an outage. They stall at 60 percent, because connectivity, identity or data movement was assumed instead of designed. This guide covers the four things that have to be right before workloads start moving between your data centre and a public cloud.

Connect withDirect Connect, ExpressRoute, FastConnect
IdentityOne directory, synced
DNSForwarding both ways
Moves inWaves, not big bang
Reference architecture

How the two sides connect

Scroll sideways to see the whole diagram →
On-premisesPublic cloud landing zoneUsers and branchesone login, one set of namesCore systemsERP, databases, legacy appsActive Directorysource of identityDNSon-premises zonesData platformlarge datasets stay hereCloud applicationsweb, APIs, analyticsCloud identitysynced from AD, single sign-onDNS resolverforwards to on-premises zonesShared serviceslogging, security, backupPrivate connectivitydedicated link, with VPN as backup12354
Numbered lines show what crosses between the two environments. Everything crosses over the private link, never the open internet.
PartWhat it does
1 Application trafficCloud applications call core systems and the other way round. Keep these calls few and coarse: chatty traffic across a WAN link is slow and, in the cloud, billed.
2 Identity syncUsers and groups are synced from Active Directory to the cloud identity service, so people use one account and one password everywhere.
3 DNS forwardingEach side can resolve the other's names. Without this, applications break in confusing ways after migration.
4 Private connectivityA dedicated link such as AWS Direct Connect, Azure ExpressRoute or OCI FastConnect, with an IPsec VPN as backup. Sized from measured traffic, not guessed.
5 Data copiesLarge datasets stay where they are used. Only what is needed is copied, on a schedule, with egress cost in mind.

Four things to get right first

  • Classify every workload. Decide for each application whether it stays, moves as-is, or is rebuilt for the cloud. Moving a VM unchanged is fine for some systems and expensive for others.
  • Design connectivity early. A VPN added late becomes the bottleneck and single point of failure for every hybrid workload. Order dedicated links early: provisioning can take weeks.
  • One identity, not two. If on-premises and cloud accounts are managed separately, you get two logins, two audit trails and a clean-up project nobody planned.
  • Respect data gravity. Large databases cannot move overnight. Plan how data is synced, how long the first copy takes, and what the final cutover window looks like.

Typical tools

LayerCommon choices
Private linksAWS Direct Connect, Azure ExpressRoute, OCI FastConnect, IPsec VPN as backup
IdentityActive Directory with Microsoft Entra Connect, AWS IAM Identity Center, OCI Identity Domains
DNSRoute 53 Resolver endpoints, Azure DNS Private Resolver, conditional forwarders on-premises
Landing zoneSee landing zones
MigrationCloud provider migration services, database replication, storage sync tools

Planning a cloud move or a VMware exit?

Send us a VM inventory export (RVTools is fine) and a line on what is driving the change. We will come back with a plain first view: what could move where, in what order, and roughly what it would cost to run.