<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cloud-Infrastructure on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/cloud-infrastructure/</link><description>Recent content in Cloud-Infrastructure on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 10:15:21 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/cloud-infrastructure/index.xml" rel="self" type="application/rss+xml"/><item><title>Single-Region vs Multi-Region: One Deployment Footprint vs Many</title><link>https://comparison.metacog.co.kr/posts/2026-09-06-single-region-vs-multi-region-one-deployment-footprint-vs-ma/</link><pubDate>Sun, 06 Sep 2026 10:15:21 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-09-06-single-region-vs-multi-region-one-deployment-footprint-vs-ma/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Single-region deployments run all infrastructure and data in one geographic location, keeping operations simple but exposing the system to regional outages and higher latency for distant users. Multi-region deployments replicate infrastructure and data across multiple geographic locations, trading &lt;strong class="kw"&gt;operational simplicity&lt;/strong&gt; for &lt;strong class="kw"&gt;resilience and locality&lt;/strong&gt;. The right choice depends on your availability targets, compliance needs, and how much complexity your team can absorb.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="36" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;Single-Region&lt;/text&gt;&lt;text x="480" y="36" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;Multi-Region&lt;/text&gt;&lt;g&gt;&lt;rect x="40" y="70" width="240" height="230" rx="10" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="160" y="92" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;us-east-1&lt;/text&gt;&lt;rect x="70" y="110" width="180" height="36" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="133" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Load Balancer&lt;/text&gt;&lt;rect x="70" y="160" width="180" height="36" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="183" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;App Servers&lt;/text&gt;&lt;rect x="70" y="210" width="180" height="36" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="233" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Primary Database&lt;/text&gt;&lt;text x="160" y="270" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Region outage = full downtime&lt;/text&gt;&lt;/g&gt;&lt;g&gt;&lt;rect x="340" y="60" width="130" height="120" rx="10" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="405" y="78" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;eu-west-1&lt;/text&gt;&lt;rect x="355" y="90" width="100" height="26" rx="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.2"/&gt;&lt;text x="405" y="107" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;App Servers&lt;/text&gt;&lt;rect x="355" y="128" width="100" height="26" rx="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.2"/&gt;&lt;text x="405" y="145" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;DB Replica&lt;/text&gt;&lt;rect x="480" y="60" width="130" height="120" rx="10" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="545" y="78" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;ap-south-1&lt;/text&gt;&lt;rect x="495" y="90" width="100" height="26" rx="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.2"/&gt;&lt;text x="545" y="107" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;App Servers&lt;/text&gt;&lt;rect x="495" y="128" width="100" height="26" rx="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.2"/&gt;&lt;text x="545" y="145" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;DB Replica&lt;/text&gt;&lt;rect x="410" y="200" width="130" height="36" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="475" y="223" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Global Router&lt;/text&gt;&lt;line x1="475" y1="200" x2="405" y2="116" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="475" y1="200" x2="545" y2="116" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="405" y1="154" x2="545" y2="154" style="stroke:var(--compare-b)" stroke-width="1" stroke-dasharray="3 3"/&gt;&lt;text x="475" y="170" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;data sync&lt;/text&gt;&lt;text x="475" y="270" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;One region fails, others serve traffic&lt;/text&gt;&lt;/g&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Single-Region&lt;/th&gt;
&lt;th&gt;Multi-Region&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Request entry point&lt;/td&gt;
&lt;td&gt;Single DNS/load balancer target in one region&lt;/td&gt;
&lt;td&gt;Global load balancer or DNS routing to nearest healthy region&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data placement&lt;/td&gt;
&lt;td&gt;One primary datastore, one location&lt;/td&gt;
&lt;td&gt;Data replicated or partitioned across regions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Consistency model&lt;/td&gt;
&lt;td&gt;Straightforward strong consistency within one datastore&lt;/td&gt;
&lt;td&gt;Trade-offs between strong and eventual consistency across replicas&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Latency for global users&lt;/td&gt;
&lt;td&gt;High latency for users far from the region&lt;/td&gt;
&lt;td&gt;Low latency via routing to the closest region&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure blast radius&lt;/td&gt;
&lt;td&gt;Regional outage takes down the entire system&lt;/td&gt;
&lt;td&gt;Regional outage degrades capacity but other regions keep serving&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deployment and rollout complexity&lt;/td&gt;
&lt;td&gt;Single pipeline, single environment to manage&lt;/td&gt;
&lt;td&gt;Coordinated rollouts, versioning, and config across regions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost profile&lt;/td&gt;
&lt;td&gt;Lower infrastructure and data transfer cost&lt;/td&gt;
&lt;td&gt;Higher cost from duplicated infrastructure and cross-region transfer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compliance and data residency&lt;/td&gt;
&lt;td&gt;Limited to rules of the single region&lt;/td&gt;
&lt;td&gt;Can satisfy data residency laws by keeping data in-region&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Single-region has one &lt;strong class="kw"&gt;failure domain&lt;/strong&gt;; multi-region isolates failures so an outage in one region doesn&amp;rsquo;t take the whole system down&lt;/li&gt;
&lt;li&gt;Multi-region requires solving &lt;strong class="kw"&gt;data replication&lt;/strong&gt; and consistency across distant datastores, which single-region avoids entirely&lt;/li&gt;
&lt;li&gt;Multi-region cuts &lt;strong class="kw"&gt;latency&lt;/strong&gt; for geographically dispersed users by serving requests from the nearest region&lt;/li&gt;
&lt;li&gt;Multi-region needs a &lt;strong class="kw"&gt;global router&lt;/strong&gt; or DNS-based traffic manager, adding a layer absent in single-region setups&lt;/li&gt;
&lt;li&gt;Operational and infrastructure &lt;strong class="kw"&gt;cost&lt;/strong&gt; scales up sharply with each additional region&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Single-Region&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Auto Scaling vs Manual Scaling: Who Adjusts Capacity?</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-auto-scaling-vs-manual-scaling-who-adjusts-capacity/</link><pubDate>Mon, 03 Aug 2026 06:33:25 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-auto-scaling-vs-manual-scaling-who-adjusts-capacity/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Auto scaling and manual scaling both change how much compute capacity an application has, but they differ in who — or what — decides when that change happens. Auto scaling relies on an &lt;strong class="kw"&gt;automated feedback loop&lt;/strong&gt; that watches metrics and reacts on its own, while manual scaling depends on &lt;strong class="kw"&gt;human intervention&lt;/strong&gt; to notice load and issue the change. That difference in decision-maker drives everything else: reaction speed, cost efficiency, and how much ongoing attention the system needs.&lt;/p&gt;</description></item><item><title>NAT Gateway vs Internet Gateway: Who Gets to Talk to the Internet</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</link><pubDate>Mon, 03 Aug 2026 06:27:51 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Both connect a VPC to the internet, but they serve opposite purposes: an &lt;strong class="kw"&gt;Internet Gateway&lt;/strong&gt; lets public-facing resources send and receive traffic directly, while a &lt;strong class="kw"&gt;NAT Gateway&lt;/strong&gt; lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="160" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;Internet Gateway&lt;/text&gt;&lt;text x="480" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;NAT Gateway&lt;/text&gt;&lt;rect x="110" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="160" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;rect x="430" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="480" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;line x1="160" y1="82" x2="160" y2="109" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="110" x2="480" y2="82" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;circle cx="560" cy="95" r="10" style="fill:none;stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;line x1="553" y1="88" x2="567" y2="102" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;text x="560" y="120" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;no inbound&lt;/text&gt;&lt;rect x="110" y="110" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="134" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;IGW&lt;/text&gt;&lt;rect x="430" y="110" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="134" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;NAT Gateway&lt;/text&gt;&lt;line x1="160" y1="150" x2="160" y2="189" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="190" x2="480" y2="151" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;rect x="70" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="160" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Public Subnet&lt;/text&gt;&lt;rect x="110" y="228" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="160" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;has public IP&lt;/text&gt;&lt;rect x="390" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="480" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Private Subnet&lt;/text&gt;&lt;rect x="430" y="228" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="480" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;private IP only&lt;/text&gt;&lt;text x="160" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;bidirectional traffic&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;outbound only&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Internet Gateway&lt;/th&gt;
&lt;th&gt;NAT Gateway&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Enables communication between a VPC and the internet in both directions&lt;/td&gt;
&lt;td&gt;Enables outbound-only internet access for resources without public IPs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Traffic direction&lt;/td&gt;
&lt;td&gt;Bidirectional — accepts inbound connections and sends outbound&lt;/td&gt;
&lt;td&gt;Outbound only — inbound traffic allowed only as replies to established connections&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Placement&lt;/td&gt;
&lt;td&gt;Attaches directly to the VPC as a whole&lt;/td&gt;
&lt;td&gt;Deployed inside a specific public subnet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IP address handling&lt;/td&gt;
&lt;td&gt;1:1 NAT between a private IP and an Elastic/public IP&lt;/td&gt;
&lt;td&gt;Many-to-one PAT — many private IPs share the gateway&amp;rsquo;s public IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Which resources use it&lt;/td&gt;
&lt;td&gt;Instances with a public/Elastic IP routed via a public subnet route table&lt;/td&gt;
&lt;td&gt;Instances with only private IPs routed via a private subnet route table&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scaling and availability&lt;/td&gt;
&lt;td&gt;Managed, horizontally scaled, highly available with no bandwidth cap&lt;/td&gt;
&lt;td&gt;Bandwidth-bounded per gateway; needs one per AZ for high availability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost model&lt;/td&gt;
&lt;td&gt;No hourly charge and no data processing fee&lt;/td&gt;
&lt;td&gt;Hourly charge plus per-GB data processing fee&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure impact&lt;/td&gt;
&lt;td&gt;Loss cuts off all direct internet reachability for the public subnet&lt;/td&gt;
&lt;td&gt;Loss cuts off outbound internet access for the private subnet only&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet Gateway provides &lt;strong class="kw"&gt;bidirectional&lt;/strong&gt; access; NAT Gateway only permits &lt;strong class="kw"&gt;outbound&lt;/strong&gt; connections.&lt;/li&gt;
&lt;li&gt;Internet Gateway attaches to the whole &lt;strong class="kw"&gt;VPC&lt;/strong&gt;; NAT Gateway lives inside a specific &lt;strong class="kw"&gt;subnet&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Internet Gateway does 1:1 &lt;strong class="kw"&gt;Elastic IP&lt;/strong&gt; mapping; NAT Gateway does many-to-one &lt;strong class="kw"&gt;PAT&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;NAT Gateway bills per &lt;strong class="kw"&gt;GB processed&lt;/strong&gt;; Internet Gateway is &lt;strong class="kw"&gt;free&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Internet Gateway&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Availability Zone vs Region: Scope of Cloud Infrastructure Isolation</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-availability-zone-vs-region-scope-of-cloud-infrastructure-is/</link><pubDate>Mon, 03 Aug 2026 06:26:19 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-availability-zone-vs-region-scope-of-cloud-infrastructure-is/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An &lt;strong class="kw"&gt;Availability Zone&lt;/strong&gt; is one or more physically isolated data centers with independent power, cooling, and networking, while a &lt;strong class="kw"&gt;Region&lt;/strong&gt; is a broader geographic area made up of multiple such zones connected by low-latency links. The distinction matters because it determines what kind of failure your architecture survives — a single data-center outage versus a region-wide disaster — and what compliance jurisdiction your data falls under.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="150" y="30" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Availability Zone&lt;/text&gt;&lt;rect x="50" y="50" width="200" height="250" rx="6" style="fill:none;stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="5 4"/&gt;&lt;rect x="75" y="100" width="70" height="90" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="175" y="140" width="70" height="90" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="110" y="148" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;DC&lt;/text&gt;&lt;text x="210" y="188" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;DC&lt;/text&gt;&lt;text x="150" y="280" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;1+ data centers,&lt;/text&gt;&lt;text x="150" y="296" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;independent power &amp;amp; network&lt;/text&gt;&lt;text x="475" y="30" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Region&lt;/text&gt;&lt;rect x="330" y="50" width="260" height="250" rx="6" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="5 4"/&gt;&lt;line x1="385" y1="115" x2="515" y2="115" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;line x1="385" y1="115" x2="450" y2="225" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;line x1="515" y1="115" x2="450" y2="225" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;rect x="350" y="80" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="480" y="80" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="415" y="190" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="385" y="120" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="515" y="120" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="450" y="230" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="460" y="280" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;Multiple AZs,&lt;/text&gt;&lt;text x="460" y="296" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;low-latency links&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Availability Zone&lt;/th&gt;
&lt;th&gt;Region&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Definition&lt;/td&gt;
&lt;td&gt;One or more discrete data centers with independent power, cooling, and networking&lt;/td&gt;
&lt;td&gt;A geographic area containing multiple availability zones&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Physical composition&lt;/td&gt;
&lt;td&gt;Typically 1+ physical data center buildings&lt;/td&gt;
&lt;td&gt;Multiple AZs (often 3 or more) plus regional network backbone&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Inter-node latency&lt;/td&gt;
&lt;td&gt;Sub-millisecond to a few milliseconds over private links between AZs&lt;/td&gt;
&lt;td&gt;Tens to hundreds of milliseconds over public/backbone links between regions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure isolation&lt;/td&gt;
&lt;td&gt;Isolates against power, cooling, or single data-center failures&lt;/td&gt;
&lt;td&gt;Isolates against natural disasters or systemic events affecting an entire geography&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Redundancy pattern used for&lt;/td&gt;
&lt;td&gt;High availability within one geographic area&lt;/td&gt;
&lt;td&gt;Disaster recovery and global latency reduction across geographies&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data residency &amp;amp; compliance&lt;/td&gt;
&lt;td&gt;No effect — all AZs in a region share the same jurisdiction&lt;/td&gt;
&lt;td&gt;Determines the legal jurisdiction and data residency boundary&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data transfer cost&lt;/td&gt;
&lt;td&gt;Low intra-region rate for traffic between AZs&lt;/td&gt;
&lt;td&gt;Higher inter-region or egress rate for traffic between regions&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An Availability Zone is one or more &lt;strong class="kw"&gt;data centers&lt;/strong&gt;, while a Region is the &lt;strong class="kw"&gt;geographic area&lt;/strong&gt; that groups several AZs together&lt;/li&gt;
&lt;li&gt;Inter-AZ traffic uses low-latency &lt;strong class="kw"&gt;private links&lt;/strong&gt;; inter-region traffic crosses &lt;strong class="kw"&gt;public backbone&lt;/strong&gt; networks with far higher latency&lt;/li&gt;
&lt;li&gt;Multi-AZ deployments protect against &lt;strong class="kw"&gt;data-center outages&lt;/strong&gt;; multi-region deployments protect against &lt;strong class="kw"&gt;regional disasters&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Region choice fixes your &lt;strong class="kw"&gt;data residency&lt;/strong&gt; and compliance jurisdiction — AZ choice does not&lt;/li&gt;
&lt;li&gt;Cross-AZ transfer is cheap; cross-region transfer incurs higher &lt;strong class="kw"&gt;egress costs&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Availability Zone&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Declarative vs Imperative IaC: Describing the End State vs Scripting the Steps</title><link>https://comparison.metacog.co.kr/posts/2026-08-02-declarative-vs-imperative-iac-describing-the-end-state-vs-sc/</link><pubDate>Sun, 02 Aug 2026 08:55:05 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-02-declarative-vs-imperative-iac-describing-the-end-state-vs-sc/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Declarative IaC (e.g. Terraform, CloudFormation) has you specify the desired end state of infrastructure and lets an engine figure out how to get there. Imperative IaC (e.g. shell scripts, Chef recipes, raw CLI calls) has you write the exact sequence of commands to execute. The distinction matters because it determines who — you or the tool — is responsible for ordering, idempotency, and reconciling drift.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="28" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Declarative&lt;/text&gt;&lt;rect x="40" y="50" width="240" height="55" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="72" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Desired State&lt;/text&gt;&lt;text x="160" y="90" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;"3 servers, 1 LB"&lt;/text&gt;&lt;line x1="160" y1="105" x2="160" y2="130" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="160,140 155,130 165,130" style="fill:var(--compare-a)"/&gt;&lt;rect x="40" y="145" width="240" height="55" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="167" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Engine Computes Diff&lt;/text&gt;&lt;text x="160" y="185" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;plan + dependency graph&lt;/text&gt;&lt;line x1="160" y1="200" x2="160" y2="225" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="160,235 155,225 165,225" style="fill:var(--compare-a)"/&gt;&lt;rect x="40" y="240" width="240" height="55" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="262" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Infrastructure&lt;/text&gt;&lt;text x="160" y="280" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;converges to match state&lt;/text&gt;&lt;text x="160" y="320" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Engine decides how &amp;amp; in what order&lt;/text&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4,4"/&gt;&lt;text x="480" y="28" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Imperative&lt;/text&gt;&lt;rect x="360" y="45" width="240" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="70" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Step 1: Create VPC&lt;/text&gt;&lt;line x1="480" y1="85" x2="480" y2="100" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="480,110 475,100 485,100" style="fill:var(--compare-b)"/&gt;&lt;rect x="360" y="115" width="240" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="140" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Step 2: Launch Servers&lt;/text&gt;&lt;line x1="480" y1="155" x2="480" y2="170" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="480,180 475,170 485,170" style="fill:var(--compare-b)"/&gt;&lt;rect x="360" y="185" width="240" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="210" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Step 3: Attach LB&lt;/text&gt;&lt;line x1="480" y1="225" x2="480" y2="240" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="480,250 475,240 485,240" style="fill:var(--compare-b)"/&gt;&lt;rect x="360" y="255" width="240" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="280" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Infrastructure&lt;/text&gt;&lt;text x="480" y="320" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Author decides exact steps &amp;amp; order&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Declarative&lt;/th&gt;
&lt;th&gt;Imperative&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Authoring model&lt;/td&gt;
&lt;td&gt;Write a &lt;strong class="kw"&gt;desired-state spec&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Write an &lt;strong class="kw"&gt;ordered command list&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution engine&lt;/td&gt;
&lt;td&gt;Resolves a &lt;strong class="kw"&gt;dependency graph&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Runs a &lt;strong class="kw"&gt;sequential interpreter&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;State tracking&lt;/td&gt;
&lt;td&gt;Maintains a &lt;strong class="kw"&gt;state file&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Stateless&lt;/strong&gt; execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Applying changes&lt;/td&gt;
&lt;td&gt;Single &lt;strong class="kw"&gt;apply&lt;/strong&gt; command&lt;/td&gt;
&lt;td&gt;Run the &lt;strong class="kw"&gt;script/playbook&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ordering &amp;amp; dependencies&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Auto-resolved&lt;/strong&gt; by engine&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Manually sequenced&lt;/strong&gt; by author&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Idempotency&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Guaranteed&lt;/strong&gt; by design&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Developer-enforced&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Drift detection&lt;/td&gt;
&lt;td&gt;Built-in &lt;strong class="kw"&gt;plan diff&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Not built-in&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure handling&lt;/td&gt;
&lt;td&gt;Partial apply, &lt;strong class="kw"&gt;replan&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong class="kw"&gt;Manual rollback&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Declarative code answers &amp;lsquo;what&amp;rsquo;, imperative code answers &lt;strong class="kw"&gt;&amp;lsquo;how&amp;rsquo;&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Declarative tools rely on a &lt;strong class="kw"&gt;state file&lt;/strong&gt; to know current vs. desired infrastructure; imperative scripts have no memory of prior runs.&lt;/li&gt;
&lt;li&gt;Idempotent re-runs are &lt;strong class="kw"&gt;automatic&lt;/strong&gt; in declarative tools but must be hand-coded (checks, conditionals) in imperative scripts.&lt;/li&gt;
&lt;li&gt;Declarative engines build a &lt;strong class="kw"&gt;dependency graph&lt;/strong&gt; to order operations; imperative code hardcodes that order line by line.&lt;/li&gt;
&lt;li&gt;Drift correction in declarative IaC is a matter of re-running &lt;strong class="kw"&gt;plan/apply&lt;/strong&gt;; imperative approaches require re-running or rewriting the exact script.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Declarative&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>