Files
knowledge-base/DATACENTERS.md
Stanislav Hubacek 3fa11ef0f6 comiiit
2026-06-11 15:27:28 +02:00

789 lines
39 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 🏭 Datová centra
## Tier klasifikace (TIA-942 / Uptime Institute)
| Tier | Dostupnost | Downtime / rok | Redundance |
|------|-----------|----------------|------------|
| **Tier I** | 99.671 % | 28.8 h | N — bez redundance |
| **Tier II** | 99.741 % | 22.7 h | N+1 — redundantní komponenty |
| **Tier III** | 99.982 % | 1.6 h | N+1 — současně udrĆŸovatelnĂ© |
| **Tier IV** | 99.995 % | 26.3 min | 2N+1 — fault tolerant |
## KlíčovĂ© subsystĂ©my
| Systém | Popis |
|--------|-------|
| **Power** | UPS, generátory (diesel), ATS, PDU, redundantní pƙívody (A/B feed) |
| **Cooling** | CRAC/CRAH, chilled water, free cooling, containment (hot/cold aisle) |
| **FyzickĂĄ bezpečnost** | KamerovĂœ systĂ©m, biometric access, mantrap, bezpečnostnĂ­ zĂĄmky rackĆŻ |
| **Cabling** | Structured cabling (Cat6A/7/8, OM3/OM4 single-mode fiber), patch panely |
| **Fire suppression** | Poplach, inertnĂ­ plyny (Novec, FM-200), VESDA (very early smoke detection) |
| **Monitoring** | DCIM (Data Center Infrastructure Management), SNMP, BMS (Building Management System) |
## Aisle containment
```
┌────────────────────────────────────┐
│ Rack Row │
│ ┌──┐ ┌──┐ ┌──┐ ┌──┐ ┌──┐ ┌──┐ │
Cold │ │ │ │ │ │ │ │ │ │ │ │ │ │ Cold
Aisle <──│ └──┘ └──┘ └──┘ └──┘ └──┘ └──┘ ──> Aisle
│ ┌──┐ ┌──┐ ┌──┐ ┌──┐ ┌──┐ ┌──┐ │
Hot │ │ │ │ │ │ │ │ │ │ │ │ │ │ Hot
Aisle ──>│ └──┘ └──┘ └──┘ └──┘ └──┘ └──┘ <── Aisle
└────────────────────────────────────┘
```
## Environmental tƙídy (ASHRAE TC 9.9)
ASHRAE Technical Committee 9.9 definuje teplotní a vlhkostní obálky pro IT zaƙízení v DC.
| Tƙída | Teplota (doporučeno) | Teplota (allowable) | PouĆŸitĂ­ |
|-------|---------------------|---------------------|---------|
| **A1** | 18-27 °C | 15-32 °C | Enterprise DC, pƙísná kontrola |
| **A2** | 18-27 °C | 10-35 °C | BÄ›ĆŸnĂ© DC |
| **A3** | 18-27 °C | 5-40 °C | Volnějơí prostƙedí |
| **A4** | 18-27 °C | 5-45 °C | MaximĂĄlnĂ­ Ășspora chlazenĂ­ |
| **H1** | 18-22 °C | 5-25 °C | High-density air-cooled (AI/ML) |
- 5. edice (2021) pƙidala tƙídu H1 pro high-density a rozơíƙila liquid cooling W-tƙídy (W17, W27, W32, W40, W45, W+)
- 2024: novĂ© S-tƙídy pro Technology Cooling System (TCS) chlazenĂ­ kapalinou
- Vlhkost: doporučeno −9 °C DP aĆŸ 70 % RH (pƙi nĂ­zkĂœch polutantech); max 50 % RH pƙi vysokĂ© korozivitě
## Power
### Power chain
```
Grid ──> Transformer ──> UPS ──> PDU ──> Rack PDU ──> Server PSU
│
├──> Generator (ATS pƙepĂ­nĂĄ pƙi vĂœpadku)
└──> STS/ATS (Static Transfer Switch)
```
A/B feed topology:
```
Grid A ──> UPS A ──> PDU A1 ──> Rack PDU A ──> PSU A (server)
│
Grid B ──> UPS B ──> PDU B1 ──> Rack PDU B ──> PSU B (server)
```
KaĆŸdĂœ server mĂĄ 2 PSU — kaĆŸdĂĄ napĂĄjena z jinĂ© větve (A/B). Pƙi vĂœpadku jednĂ© větve server pokračuje bez pƙeruĆĄenĂ­.
### UPS typy
| Klasifikace | IEC 62040-3 | Popis | Pƙepínání | Use case |
|-----------|-------------|-------|-----------|----------|
| **VFD** (Voltage & Frequency Dependent) | Passive standby | UPS v bypassu, pƙi vĂœpadku pƙepne na invertor | 4-10 ms | SOHO, edge |
| **VI** (Voltage Independent) | Line-interactive | Regulace napětí pƙes autotransformátor | 2-4 ms | Menơí racky, office |
| **VFI** (Voltage & Frequency Independent) | Double-conversion | AC → DC → AC, plnĂĄ izolace, ĆŸĂĄdnĂœ pƙepĂ­nacĂ­ čas | 0 ms | Enterprise DC, Tier III/IV |
Pro DC je standard **VFI (double-conversion)** — online UPS, nulovĂœ pƙepĂ­nacĂ­ čas, plnĂĄ izolace od sĂ­tě.
### Battery technologies
| Typ | Hustota (Wh/L) | Ćœivotnost (cykly) | Ćœivotnost (roky) | Teplota | Cena/kWh | PoznĂĄmka |
|-----|---------------|-------------------|------------------|---------|----------|----------|
| **VRLA** (AGM/Gel) | 50-80 | 200-500 | 3-5 | 20-25 °C | ~$150-200 | LevnĂ©, velkĂ©, tÄ›ĆŸkĂ©, citlivĂ© na teplotu |
| **Li-ion (LFP)** | 200-350 | 3000-5000 | 10-15 | 0-40 °C | ~$300-500 | MalĂ©, lehkĂ©, dlouhĂĄ ĆŸivotnost, BMS nutnĂœ |
| **Li-ion (NMC)** | 250-400 | 1000-2000 | 8-12 | 0-40 °C | ~$250-400 | Vyƥƥí hustota, riziko thermal runaway |
| **NiCd** | 80-150 | 1000-2000 | 10-15 | −20-50 °C | ~$400-600 | ExtrĂ©mnĂ­ teploty, paměƄovĂœ efekt |
| **Flow battery** (V/Zn/Br) | 20-40 | 10,000+ | 20+ | 10-35 °C | ~$500-800 | Neomezené cykly, velké, dlouhodobé zålohovåní |
Li-ion (LFP) se stĂĄvĂĄ standardem pro novĂ© DC dĂ­ky delĆĄĂ­ ĆŸivotnosti, menĆĄĂ­mu pĆŻdorysu a lepĆĄĂ­mu chovĂĄnĂ­ pƙi vysokĂœch teplotĂĄch.
### Generator sizing
| Varianta | Velikost | Fuel | Start time | Run time | Use case |
|----------|---------|------|-----------|----------|----------|
| **Diesel** | 500-2500 kVA | Diesel (Nafta) | 10-30 s | 24-72 h (dle nĂĄdrĆŸe) | Standard pro enterprise DC |
| **Nat. gas** | 200-1500 kVA | ZemnĂ­ plyn | 10-30 s | Neomezeno (plynovod) | MĂ©ně častĂ©, niĆŸĆĄĂ­ emise |
| **CHP** (cogeneration) | 500-2000 kVA | ZemnĂ­ plyn | 5-15 min | Neomezeno | Kombinace power + cooling (absorption chiller) |
Sizing: Generator by měl pokrĂœt 100 % IT loadu + 100 % cooling loadu (vč. chillerĆŻ) — typicky 1.3-1.8× IT load. DieselovĂĄ nĂĄdrĆŸ min. na 24 h provozu, bÄ›ĆŸně 48-72 h. DennĂ­ spotƙeba ~0.3-0.4 L/kWh.
### ATS vs STS
| Vlastnost | ATS (Automatic Transfer Switch) | STS (Static Transfer Switch) |
|-----------|-------------------------------|-----------------------------|
| **PƙepĂ­nĂĄnĂ­** | 4-10 ms (mechanickĂ© relĂ©) | < 4 ms (tyristorovĂ©) |
| **Ćœivotnost** | ~10,000 pƙepnutĂ­ | NeomezenĂĄ (solid-state) |
| **Cena** | Nízká | Vysoká (~3-5× ATS) |
| **Use case** | GenerĂĄtor → UPS feed | Mezi dvěma UPS vĂœstupy |
### PDU typy
| Typ | Popis | Use case |
|-----|-------|----------|
| **Basic** | Pasivní rozbočení (no monitoring) | Edge, office |
| **Metered** | MěƙenĂ­ proudu na Ășrovni PDU | Standard DC |
| **Monitored** | Měƙení per outlet, SNMP, web GUI | Enterprise DC |
| **Switched** | On/off per outlet, remote reboot | Enterprise DC, colo |
| **High-density** | 3-phase, 60-100 A, C19 outlets | GPU/HPC/AI racky |
### Power calculation
```
Total Power = ÎŁ(P_server + P_storage + P_network + P_cooling + P_losses)
P_server = P_idle + (P_max - P_idle) × Utilization%
P_cooling = P_IT / PUE
Pƙíklad:
100 serverƯ × 500 W (avg) = 50 kW IT load
PUE = 1.5 → celkem 75 kW
UPS + generátor → dimenzováno na 75 kW × 1.2 (safety factor) = 90 kW
```
### PUE (Power Usage Effectiveness)
```
PUE = Total Facility Energy / IT Equipment Energy
```
| PUE | Efektivita | Typ |
|-----|-----------|-----|
| 1.0-1.1 | VynikajĂ­cĂ­ | Hyperscale (Google, Meta) |
| 1.1-1.3 | Velmi dobrĂœ | ModernĂ­ DC |
| 1.3-1.6 | DobrĂœ / prĆŻměr | Enterprise DC |
| 1.6-2.0 | PodprƯměr | Starơí DC |
| >2.0 | Ć patnĂœ | Legacy |
PUE se měƙí na Ășrovni celĂ©ho DC, nikoliv per rack. Zahrnuje: UPS ztrĂĄty, chlazenĂ­, osvětlenĂ­, ztrĂĄty v rozvodu. Nezahrnuje: vĂœrobu paliva (well-to-tank), embodied carbon. CĂ­l pro modernĂ­ DC: PUE < 1.2.
### WUE a CUE
| Metrika | Popis | Vzorec | CĂ­l |
|---------|-------|--------|-----|
| **WUE** (Water Usage Effectiveness) | Spotƙeba vody na IT energii | WUE = Annual Water Usage / IT Energy (L/kWh) | < 0.5 L/kWh |
| **CUE** (Carbon Usage Effectiveness) | CO₂ emise na IT energii | CUE = Total CO₂ / IT Energy (kg CO₂/kWh) | < 0.2 kg CO₂/kWh |
WUE je kritickĂœ v suchĂœch oblastech (jihozĂĄpad USA, AustrĂĄlie, StƙednĂ­ vĂœchod). AdiabatickĂ© chlazenĂ­ spotƙebuje vĂœrazně vĂ­ce vody neĆŸ chlazenĂ­ s uzavƙenĂœm okruhem.
### 3-phase vs Single-phase
| Vlastnost | Single-phase (230 V) | 3-phase (400 V) |
|-----------|---------------------|-----------------|
| **Napětí** | 230 V (L-N) | 230/400 V (L-N/L-L) |
| **VĂœkon per feed** | ~7.4 kW (32 A) | ~22 kW (32 A, 3-f) |
| **Efektivita** | NiĆŸĆĄĂ­ (vĂ­ce ztrĂĄt) | VyĆĄĆĄĂ­ (niĆŸĆĄĂ­ proud) |
| **Use case** | MenĆĄĂ­ racky, office | Standard v DC, high-density |
| **PDU** | Single-phase (C13/C19) | 3-phase (C13/C19, 3-f monitoring) |
| **Balancovåní** | Automatické | Nutné balancovat fåze (L1/L2/L3) |
### Rack power density
| Kat. | Typ | kW/rack | NapĂĄjenĂ­ | Cooling |
|------|-----|---------|----------|---------|
| NĂ­zkĂĄ | Office, storage | 1-3 kW | 1-f, 16 A | Air (free cooling) |
| Stƙední | Standard compute | 5-10 kW | 3-f, 32 A | Air (CRAC/CRAH) |
| VysokĂĄ | GPU, HPC | 15-30 kW | 3-f, 60 A | Air + liquid assist |
| Ultra | AI/ML clusters | 40-100+ kW | 3-f, 100+ A | Direct-to-chip / immersion |
### Rack PDU konektory
| Konektor | Max proud | Typ zaƙízení |
|----------|-----------|-------------|
| **C13** | 10 A (250 V) | Servery, switche, 1U |
| **C19** | 16 A (250 V) | Servery s vyĆĄĆĄĂ­m vĂœkonem, UPS |
| **IEC 60309** (3-f) | 16-125 A | Rack PDU vstupy |
| **NEMA L6-30** | 30 A (250 V) | US spec |
## Cooling
### Chlazení — pƙehled technologií
| Technologie | Typ | VĂœkon (kW/rack) | PUE typickĂœ | CAPEX | Use case |
|-----------|------|----------------|-------------|-------|----------|
| **Free air cooling** | Air | < 5 | 1.05-1.15 | NĂ­zkĂœ | Klimaticky vhodnĂ© lokality |
| **CRAC (DX)** | Air | 5-10 | 1.4-1.8 | Stƙední | Menơí DC, retrofit |
| **CRAH (CW)** | Air | 5-15 | 1.2-1.5 | VysokĂœ | Enterprise DC |
| **In-row cooling** | Air | 10-25 | 1.2-1.4 | VysokĂœ | High-density racky |
| **Rear-door HX** | Hybrid | 15-30 | 1.1-1.3 | Stƙední | Retrofity, GPU |
| **Direct-to-chip** | Liquid | 40-100+ | 1.05-1.15 | VysokĂœ | AI/ML, HPC |
| **Immersion (single-phase)** | Liquid | 50-100+ | 1.03-1.10 | VysokĂœ | Bitcoin, hyperscale |
| **Immersion (two-phase)** | Liquid | 100-200+ | 1.03-1.08 | Velmi vysokĂœ | Extreme density |
### Chilled water vs Direct Expansion (DX)
| Vlastnost | Chilled water (CW) | Direct Expansion (DX) |
|-----------|-------------------|----------------------|
| **Medium** | Voda + glycol | Freon (R134a, R410A, R454B) |
| **CRAC/CRAH** | CRAH (Coolant-based) | CRAC (refrigerant compressor) |
| **Efektivita** | VyĆĄĆĄĂ­ (COP 5-7) | NiĆŸĆĄĂ­ (COP 2-4) |
| **Teplota vody** | 7-12 °C (standard), 18-22 °C (high-temp) | −5-10 °C (evaporator) |
| **Komplexita** | VyĆĄĆĄĂ­ (chillers, pumps, pipes, cooling tower) | JednoduĆĄĆĄĂ­ |
| **ÚdrĆŸba** | VyĆĄĆĄĂ­ (vodnĂ­ Ășprava, prevence legionely) | NiĆŸĆĄĂ­ |
| **Use case** | Velké DC > 500 kW, enterprise | Menƥí DC, edge, retrofit |
### Containment typy
| Typ | Popis | Efektivita | Implementace |
|-----|-------|-----------|-------------|
| **Cold aisle containment (CAC)** | UzavƙenĂĄ studenĂĄ ulička, teplĂœ vzduch se vracĂ­ do mĂ­stnosti | VysokĂĄ | Dveƙe na koncĂ­ch uličky, stropnĂ­ panely |
| **Hot aisle containment (HAC)** | UzavƙenĂĄ teplĂĄ ulička, teplĂœ vzduch jde pƙímo do zpĂĄtečky | VyĆĄĆĄĂ­ | Dveƙe + stropnĂ­ panely, zpĂĄtečka do CRAH |
| **Chimney / rear duct** | KaĆŸdĂœ rack mĂĄ vlastnĂ­ vĂœfukovĂœ komĂ­n do stropu | NejvyĆĄĆĄĂ­ | SamostatnĂ© ducty per rack, nĂĄkladnĂ© |
| **Open aisle** | Bez containmentu, studenĂœ a teplĂœ vzduch se mĂ­sĂ­ | NĂ­zkĂĄ | Legacy, levnĂ© |
DoporučenĂ­: CAC/HAC pƙi hustotě > 5 kW/rack. HAC je o 5-10 % efektivnějĆĄĂ­ neĆŸ CAC (teplĂœ vzduch je pƙímo odvĂĄděn, nemĂ­sĂ­ se s mĂ­stnostĂ­).
### CFD modeling
Computational Fluid Dynamics (CFD) simuluje proudění vzduchu v DC pƙed fyzickou implementací:
- Identifikace hot spots (recirkulace teplĂ©ho vzduchu do studenĂ© uličky)
- Optimalizace pozice perforovanĂœch dlaĆŸdic
- Nåvrh bypass airflow (kabelové otvory, nezakryté pozice)
- Simulace vĂœpadku CRAH jednotky (what-if scĂ©náƙe)
- NĂĄstroje: Future Facilities (6Sigma DC), Ansys Fluent, OpenFOAM
### Free cooling
- **Air-side** — nasĂĄvĂĄnĂ­ venkovnĂ­ho vzduchu pƙi vhodnĂ© teplotě (filtrace, humidifikace)
- **Water-side** — vyuĆŸitĂ­ chladnĂ© vody z venkovnĂ­ch chillerĆŻ (strainer cycle) bez kompresoru
- **KlimatickĂ© pĂĄsmo** — free cooling vyuĆŸitelnĂœ ~2000-8000 hodin/rok podle lokality
- SkandinĂĄvie: 7000-8000 h/rok
- Stƙední Evropa: 4000-6000 h/rok
- JiĆŸnĂ­ Evropa: 2000-4000 h/rok
- **Hybrid** — kombinace free cooling + mechanical cooling (nejbÄ›ĆŸnějĆĄĂ­)
- **Economizer types**: Class A1 (dry cooler), Class A2 (evaporative), Class B (air-side)
### Liquid cooling detail
| Typ | Teplota vstupu | Kapacita (kW/rack) | Medium | Instalace |
|-----|---------------|-------------------|--------|-----------|
| **Cold plate (D2C)** | 20-45 °C | 40-100+ | Voda, propylenglykol | CDU per rack nebo per row |
| **Rear-door HX** | 18-27 °C | 15-30 | Voda | PasivnĂ­, bez Ășpravy serveru |
| **Immersion (1-f)** | 35-50 °C | 50-100+ | DielektrickĂœ olej | NĂĄdrĆŸ, CDU, heat exchanger |
| **Immersion (2-f)** | 25-35 °C | 100-200+ | Dielektrikum (var) | NĂĄdrĆŸ + kondenzĂĄtor |
**CDU (Coolant Distribution Unit)**:
- ZajiƥƄuje teplotu a tlak chladiva do rackƯ
- PrimĂĄrnĂ­ okruh (facility water) + sekundĂĄrnĂ­ okruh (rack coolant)
- DimenzovĂĄnĂ­: 1 CDU na 4-8 rackĆŻ (40-100 kW per CDU)
- Redundance: N+1 CDU, dual coolant loops
**Water quality requirements**:
- Vodivost: < 1 ”S/cm (demineralizovanå voda)
- pH: 6.5-8.0
- Částice: < 50 ”m (filtrace)
- Prevence koroze: inhibitory, glykol (10-30 %)
- Prevence biologického rƯstu: UV, biocidy
### Adiabatic cooling
VyuĆŸitĂ­ odpaƙovĂĄnĂ­ vody pro ochlazenĂ­ vzduchu:
- **Direct adiabatic** — vzduch prochází vodou (media pad), ochlazuje se a zvlhčuje
- **Indirect adiabatic** — vzduch se ochlazuje pƙes heat exchanger bez pƙímĂ©ho kontaktu s vodou
- **Spotƙeba vody**: 3-5 L/kWh (direct), 1-2 L/kWh (indirect)
- Účinnost zĂĄvisĂ­ na vlhkosti vzduchu — v suchĂ©m klimatu efektivnějĆĄĂ­
## KabelĂĄĆŸ a structured cabling
### TIA-942 cabling hierarchy
```
Entrance Room (ER)
│
├── Backbone cabling (fiber single-mode / multi-mode)
│ │
│ ├── Main Distribution Area (MDA)
│ │ │
│ │ ├── Horizontal Distribution Area (HDA)
│ │ │ │
│ │ │ └── Equipment Distribution Area (EDA) → rack
│ │ │
│ │ └── Intermediate Distribution Area (IDA) — volitelnĂœ
│ │
│ └── Telecommunication Room (TR) — pro office
│
└── Backbone cabling (fiber / copper)
```
### Copper cabling categories
| Kategorie | Frekvence | Rychlost | Délka | Konektor | Use case |
|-----------|----------|----------|-------|----------|----------|
| **Cat5e** | 100 MHz | 1 GbE | 100 m | RJ45 | Legacy, voice |
| **Cat6** | 250 MHz | 1 GbE (10 GbE do 55 m) | 100 m (10 GbE: 55 m) | RJ45 | BÄ›ĆŸnĂ© DC, enterprise |
| **Cat6A** | 500 MHz | 10 GbE | 100 m | RJ45 | Standard pro nové DC |
| **Cat7** (GG45) | 600 MHz | 10 GbE | 100 m | GG45/TERA | Niche, nahrazen Cat6A/8 |
| **Cat8.1** | 2000 MHz | 25/40 GbE | 30 m | RJ45 | Top-of-rack, storage |
| **Cat8.2** | 2000 MHz | 25/40 GbE | 30 m | GG45/TERA | Top-of-rack, storage |
V DC se standardně pouĆŸĂ­vĂĄ **Cat6A** (10 GbE do 100 m) pro horizontĂĄlnĂ­ rozvody. Cat8 pouze pro propojky v rĂĄmci racku (do 30 m).
### Fiber optic typy
| Typ | Core | Modal BW | Rychlost | Max délka | Use case |
|-----|------|----------|----------|-----------|----------|
| **OS1** (SM) | 9 ”m | — | 100 GbE - 800 GbE | 10-80 km | Backbone, campus, WAN |
| **OS2** (SM) | 9 ”m | — | 100 GbE - 800 GbE | 2-80 km (CWDM/DWDM) | Backbone, DWDM |
| **OM1** (MM) | 62.5 ”m | 200 MHz·km | 1 GbE | 275 m | Legacy |
| **OM2** (MM) | 50 ”m | 500 MHz·km | 10 GbE | 82 m | Legacy |
| **OM3** (MM) | 50 ”m | 2000 MHz·km | 10 GbE do 300 m, 100 GbE do 100 m | 300 m (10G) | Standard DC, VCSEL |
| **OM4** (MM) | 50 ”m | 4700 MHz·km | 100 GbE do 150 m, 400 GbE do 100 m | 550 m (10G) | VĂœkonnĂœ standard DC |
| **OM5** (MM) | 50 ”m | 4700+ MHz·km | 200/400 GbE SWDM | 150 m (100G) | Emerging, SWDM |
Pro novĂ© DC: **OM4** jako standard pro multi-mode, **OS2** pro single-mode backbone (LR, DWDM). OM5 nenĂ­ ĆĄiroce nasazen — OM4 + paralelnĂ­ optika (SR4) je bÄ›ĆŸnějĆĄĂ­.
### Connector types
| Konektor | Typ | Insertion loss | Počet vláken | Use case |
|----------|-----|---------------|-------------|----------|
| **LC** | Duplex | < 0.15 dB | 2 | Standard pro SFP/SFP+/QSFP |
| **SC** | Duplex | < 0.2 dB | 2 | StarĆĄĂ­ instalace, patch panely |
| **MPO/MTP** (12-f) | Multi-fiber | < 0.35 dB | 12/24 | 40/100/400 GbE paralelnĂ­ |
| **MPO/MTP** (24-f) | Multi-fiber | < 0.5 dB | 24 | 400 GbE (SR4.2, DR4) |
| **SN** | Duplex (mini) | < 0.15 dB | 2 | High-density (QSFP-DD, OSFP) |
| **CS** | Duplex (mini) | < 0.15 dB | 2 | High-density (QSFP-DD, OSFP) |
### MPO/MTP polarity
| Metoda | Popis | Use case |
|--------|-------|----------|
| **Type A** (Straight) | Vlákno 1→1, 2→2, ... | Duplex aplikace s cross-over na obou koncích |
| **Type B** (Crossed) | Vlákno 1→12, 2→11, ... | Paralelní optika (SR4, SR8) — standard |
| **Type C** (Pairs crossed) | Páry 1-2→2-1, 3-4→4-3 | 40 GbE SR4 (4×10G) |
### Breakout kazety
```
MPO (12-f) ──> Breakout kazeta ──> 6× LC duplex (12 vláken = 6× duplex)
MPO (24-f) ──> Breakout kazeta ──> 12× LC duplex (24 vláken = 12× duplex)
```
Use case: Propojení MPO portu (switch) s LC porty (servery, storage). Kazety jsou v patch panelu, ne v aktivní cestě.
### Copper vs fiber decision
| Kritérium | Copper (Cat6A/8) | Fiber (OM4/OS2) |
|-----------|-----------------|-----------------|
| **Dosah** | 30-100 m | 100 m - 80 km |
| **Rychlost** | 1-40 GbE | 1-800 GbE |
| **Cena transceiveru** | NiĆŸĆĄĂ­ (RJ45) | VyĆĄĆĄĂ­ (SFP+/QSFP) |
| **Cena kabelu** | NiĆŸĆĄĂ­ | VyĆĄĆĄĂ­ (patch cord) |
| **Spotƙeba portu** | 2-5 W (25 GbE) | 1-3 W (25 GbE SR) |
| **ElektromagnetickĂ© ruĆĄenĂ­** | CitlivĂœ | ImunnĂ­ |
| **VĂĄha (100 m)** | ~3-4 kg | ~0.5-1 kg |
| **Doporučení** | Do 30 m, server→ToR switch | Backbone, storage, >30 m |
### Cabling best practices
- **Horizontal cabling**: max 90 m permanent link + 10 m patch cords (TIA-942)
- **Fiber management**: slack spools, cable managers, minimální poloměr ohybu 10× prƯměr kabelu
- **Color coding**: OS1/OS2 (yellow), OM3 (aqua), OM4 (magenta/purple), OM5 (lime green)
- **Labeling**: oba konce, patch panely, faceplates — standard ANSI/TIA-606-B
- **Overhead vs underfloor**: overhead (ladder rack) je preferován v DC (lepơí airflow, jednoduơơí změny)
- **MPO cassettes**: plánovat 15-20 % rezervu vláken pro budoucí potƙeby
## Fyzická bezpečnost
### Multi-layer security model (defense in depth)
```
Layer 1: Perimeter (plot, brĂĄna, strĂĄĆŸe)
Layer 2: Building (zdi, zámky, CCTV, čtečky karet)
Layer 3: DC hall (biometrie, mantrap, CCTV, detekce pohybu)
Layer 4: Rack / Cage (elektronické zåmky, senzory)
Layer 5: Data (ĆĄifrovĂĄnĂ­, HSM, access control)
```
### Access control
| Metoda | Faktor | Úroveƈ | Poznámka |
|--------|--------|--------|----------|
| **RFID / proximity card** | Něco, co mĂĄte | Standard | ZĂĄkladnĂ­ pƙístup, levnĂ© |
| **Smart card (PKI)** | Něco, co máte + PIN | Stƙední | Certifikát na kartě, anti-passback |
| **Biometric (fingerprint)** | Něco, co jste | VysokĂĄ | RychlĂœ, hygienickĂœ (čtečky bez dotyku) |
| **Biometric (palm/finger vein)** | Něco, co jste | Velmi vysokĂĄ | TÄ›ĆŸko falĆĄovatelnĂœ, bezkontaktnĂ­ |
| **Biometric (iris/retina)** | Něco, co jste | NejvyĆĄĆĄĂ­ | Velmi pƙesnĂœ, pomalĂœ, drahĂœ |
| **Multi-factor** | 2+ faktory | Nejvyơơí | Karta + biometrie + PIN — Tier IV DC |
### Mantrap design
```
Vnějơí dveƙe ──> Mantrap (prostor) ──> Vnitƙní dveƙe
│
├── Weight sensor (anti-tailgating)
├── CCTV (obě dveƙe)
├── Intercom (nouzovĂœ vĂœchod)
└── Motion detector (v mantrapu)
```
- OtevĂ­rĂĄ se vĆŸdy jen jedny dveƙe
- Anti-tailgating: vĂĄhovĂœ senzor detekuje vĂ­ce osob
- VĂœstup (exit) pƙes breakout button + detekce pohybu
- NouzovĂœ vĂœchod: panic bar + alarm
### CCTV
| Prvek | Doporučení |
|-------|-----------|
| **Rozliơení** | Min. 1080p, ideálně 4K (6 MP+) |
| **FPS** | 15-30 FPS (zĂĄznam), 30+ FPS (realtime monitoring) |
| **Retence** | Min. 30 dnĂ­ (90 dnĂ­ pro audit) |
| **Storage** | NVR (on-prem), cloud (AWS KVS, Azure Video Indexer) |
| **AI analytics** | Detekce obličeje, ANPR (poznávací značky), object detection |
| **ZornĂ© pole** | KaĆŸdĂ© dveƙe, kaĆŸdĂĄ ulička — bez slepĂœch mĂ­st |
### Asset tracking
| Technologie | Pƙesnost | Cena | Use case |
|-----------|----------|------|----------|
| **Barcode** | Rack-level | Velmi nĂ­zkĂĄ | ManuĂĄlnĂ­ inventura |
| **RFID (passive)** | Rack-level (door sweep) | Nízká | Automatická detekce otevƙení racku |
| **RFID (active, UWB)** | 10-30 cm | StƙednĂ­ | Real-time tracking v reĂĄlnĂ©m čase |
| **Bluetooth BLE** | 1-3 m | Nízká | Orientační pozice |
| **GPS** | 1-10 m | Stƙední | Venkovní tracking |
## DC layout a design
### Raised floor vs Slab
| Vlastnost | Raised floor | Slab (pevnĂĄ podlaha) |
|-----------|-------------|----------------------|
| **Airflow** | Underfloor air distribution (zvednutå podlaha jako plénum) | Overhead air, in-row cooling |
| **Flexibilita** | SnadnĂ© pƙidĂĄnĂ­ perforovanĂœch dlaĆŸdic | OmezenĂ© (nutnĂ© overhead cooling) |
| **Hmotnost** | Limit 500-1000 kg/mÂČ (zĂĄvisĂ­ na vĂœĆĄce) | NeomezenĂ© |
| **Cena** | VyĆĄĆĄĂ­ (~$200-400/mÂČ) | NiĆŸĆĄĂ­ (~$100-200/mÂČ) |
| **VĂœĆĄka** | 600-900 mm (standard), 900-1200 mm (high-density) | — |
| **Trend** | KlesajĂ­cĂ­ (pƙechod na in-row/overhead cooling) | RostoucĂ­ (novĂ© DC, high-density) |
ModernĂ­ high-density DC (AI/ML, GPU) se odklĂĄnějĂ­ od raised floor k slab + overhead/in-row cooling — vyĆĄĆĄĂ­ hmotnost rackĆŻ (1000-2000 kg), nemoĆŸnost dostatečnĂ©ho airflow podlahou.
### Rack layout a rozměry
| Parametr | Standard | High-density | PoznĂĄmka |
|----------|----------|-------------|----------|
| **Rack ơíƙka** | 600 mm (19") | 600-750 mm | 750 mm pro GPU (kabelĂĄĆŸ, chlazenĂ­) |
| **Rack hloubka** | 1000-1200 mm | 1200-1500 mm | GPU servery, delĆĄĂ­ kabely |
| **Rack vĂœĆĄka** | 42U | 48U / 52U | VyĆĄĆĄĂ­ rack = lepĆĄĂ­ power density |
| **Ulička ơíƙka (studená)** | 1200-1500 mm | 1500-1800 mm | Servisní pƙístup, airflow |
| **Ulička ơíƙka (teplĂĄ)** | 900-1200 mm | 1200-1500 mm | UĆŸĆĄĂ­ neĆŸ studenĂĄ |
| **Max zatĂ­ĆŸenĂ­ racku** | 500-800 kg | 1000-2000 kg | NutnĂ© podlahovĂ© nosnĂ­ky |
### Space planning
```
Pro Tier III DC (pƙíklad):
IT prostor: 1000 mÂČ
└── 20 ƙad × 10 rackƯ = 200 rackƯ pƙi 42U
└── 200 rackƯ × 5 kW avg = 1 MW IT load
└── PUE 1.4 → 1.4 MW facility
PodpƯrné prostory:
└── UPS + baterie: 200 mÂČ
└── GenerĂĄtory: 100 mÂČ (venkovnĂ­)
└── ChlazenĂ­ (chillery, cooling tower): 300 mÂČ
└── Kanceláƙe, sklady, loading dock: 400 mÂČ
Celkem: ~2000 mÂČ (50% IT, 50% support)
```
### Zone approach (TIA-942)
| Zóna | Popis | Pƙístup | Security |
|------|-------|---------|----------|
| **Z1** (VeƙejnĂĄ) | Recepce, kanceláƙe | VolnĂœ | MinimĂĄlnĂ­ |
| **Z2** (KanceláƙskĂĄ) | Administrativa, NOC | Zaměstnanci + hostĂ© | RFID |
| **Z3** (DC support) | UPS, generátory, chlazení | DC operátoƙi | RFID + biometrie |
| **Z4** (DC hall) | Servery, storage, networking | DC operátoƙi + schválení | RFID + biometrie + mantrap |
| **Z5** (Rack/cage) | KonkrĂ©tnĂ­ rack nebo cage | Pouze oprĂĄvněnĂœ personĂĄl | ElektronickĂœ zĂĄmek |
## Fire suppression
### Detekce
| Systém | Typ | Doba detekce | Faleƥné poplachy | Use case |
|--------|-----|-------------|------------------|----------|
| **VESDA** (Very Early Smoke Detection) | AspiračnĂ­, laserovĂ© čidlo | < 30 s (4 stupně alarmu) | Velmi nĂ­zkĂ© | Standard pro DC |
| **Spot detection** | IonizačnĂ­ / optickĂœ kouƙovĂœ detektor | 2-5 min | StƙednĂ­ | Legacy, menĆĄĂ­ DC |
| **Heat detection** | TepelnĂœ detektor (teplota / rychlost nĂĄrĆŻstu) | 5-10 min | Velmi nĂ­zkĂ© | ZĂĄloha za VESDA |
| **Line-type (LHD)** | LineĂĄrnĂ­ tepelnĂœ kabel | 2-5 min | NĂ­zkĂ© | Cable trays, nad stropem |
VESDA je standard — aktivnĂ­ aspirace nasĂĄvĂĄ vzduch z DC, laserovĂ© čidlo detekuje částice kouƙe ve 4 ĂșrovnĂ­ch (Alert → Action → Fire 1 → Fire 2). UmoĆŸĆˆuje zĂĄsah jeĆĄtě pƙed viditelnĂœm kouƙem.
### Suppression systémy
| SystĂ©m | Medium | VĂœhody | NevĂœhody | Typ DC |
|--------|--------|--------|----------|--------|
| **Novec 1230** (FK-5-1-12) | Plyn | BezpečnĂœ pro lidi, nulovĂœ ODP, krĂĄtkĂœ atmospheric lifetime (5 dnĂ­) | VyĆĄĆĄĂ­ cena | Enterprise DC |
| **FM-200** (HFC-227ea) | Plyn | RychlĂœ (10 s), ĂșčinnĂœ | VysokĂœ GWP (3220), ODP nemĂĄ | Legacy DC |
| **Inergen** (IG-541) | InertnĂ­ plyn (52% N₂, 40% Ar, 8% CO₂) | Zcela bezpečnĂœ, pƙírodnĂ­ plyn | VelkĂ© mnoĆŸstvĂ­ (objem), vysokĂœ tlak | Enterprise DC |
| **Argonite** (IG-55) | 50% Ar, 50% N₂ | BezpečnĂœ, pƙírodnĂ­ | VelkĂ© mnoĆŸstvĂ­, vyĆĄĆĄĂ­ tlak | Enterprise DC |
| **Water mist** | Voda (jemná mlha) | Chlazení, potlačení kouƙe, nízká cena | Voda v DC (riziko), jen local application | Retrofity |
| **Pre-action sprinkler** | Voda | DvojĂ­ spuĆĄtěnĂ­ (detekce + sprinkler) | Riziko vody, nutnĂ© odvodněnĂ­ | Tier I-II |
**Koncentrace**: Novec (4-6 % objemu), FM-200 (7-9 %), Inergen (35-50 %). Novec a Inergen jsou bezpečnĂ© pro dĂœchĂĄnĂ­ (min. 5-7 min evakuace).
### Detekční zóny
```
DC hall ──> zĂłny po ~200 mÂČ (max)
│
├── VESDA (kaĆŸdĂĄ zĂłna vlastnĂ­ aspirĂĄtor)
├── KouƙovĂ© detektory (podhled + podlaha)
└── Heat detection (zĂĄloĆŸnĂ­)
```
## DCIM (Data Center Infrastructure Management)
### Co DCIM pokrĂœvĂĄ
| Oblast | Metriky | VĂœstup |
|--------|---------|--------|
| **Power** | Per PDU, per outlet, per rack, celkem | Capacity planning, PUE, kW/rack |
| **Cooling** | Teplota, vlhkost, airflow (senzory per rack) | Hot spot mapy, airflow optimalizace |
| **Asset** | Co je v kterém racku, U pozice, serial, warranty | Asset inventory, lease management |
| **Network** | Port utilization, patch panel propojenĂ­ | Patch management, port tracking |
| **Space** | Volné U v racku, volné racky | Capacity planning, "what-if" simulace |
### NĂĄstroje
| NĂĄstroj | Typ | Platforma | Cena | PoznĂĄmka |
|---------|-----|-----------|------|----------|
| **Nlyte (Carrier)** | Enterprise DCIM | On-prem / Cloud | $$$ | TrĆŸnĂ­ leader, complex |
| **Sunbird DCIM** | Enterprise DCIM | Cloud | $$$ | Power monitoring, asset tracking |
| **Device42** | DCIM + IPAM | On-prem / Cloud | $$ | IntegrovanĂœ IPAM, CMDB |
| **NetBox** | Open source DCIM | On-prem | Zdarma | IPAM, DCIM, asset tracking |
| **OpenDCIM** | Open source | On-prem | Zdarma | ZĂĄkladnĂ­ DCIM, asset management |
| **RackTables** | Open source | On-prem | Zdarma | JednoduchĂœ, asset + networking |
| **Vendor-specific** | Dell OME, HPE OneView | On-prem | Součást hw | Pouze danĂœ vendor |
## Site selection
### KritĂ©ria pro vĂœběr lokality DC
| Kategorie | Kritérium | Våha |
|-----------|-----------|------|
| **Power** | Dostupnost elektƙiny (grid capacity), cena/kWh, moĆŸnost dvou nezĂĄvislĂœch pƙívodĆŻ | VysokĂĄ |
| **Connectivity** | Dostupnost fiber backbone, počet poskytovatelƯ konektivity, latency k major POP | Vysoká |
| **PƙírodnĂ­ rizika** | ZemětƙesenĂ­, povodně, hurikĂĄny, tornĂĄda, lesnĂ­ poĆŸĂĄry — historickĂĄ data + predikce | VysokĂĄ |
| **Klima** | PrƯměrná teplota, vlhkost (free cooling potenciál) | Stƙední |
| **PracovnĂ­ sĂ­la** | Dostupnost technikĆŻ, DC operĂĄtorĆŻ, network/admin inĆŸenĂœrĆŻ | StƙednĂ­ |
| **Daně a regulace** | DaƈovĂ© pobĂ­dky, environmental regulations, stavebnĂ­ povolenĂ­ | StƙednĂ­ |
| **Bezpečnost** | Kriminalita, politickĂĄ stabilita, teroristickĂ© riziko | VysokĂĄ |
| **Dopravní dostupnost** | Blízkost letiơtě, dálnice (pro dodávky HW, personál) | Nízká |
### Pƙírodní rizika — mapování
| Riziko | Oblasti | Mitigace |
|--------|---------|----------|
| **Zemětƙesení** | Pacific Ring of Fire (CA, Japonsko, Chile) | Base isolation, seismic bracing, flexibilní propojení |
| **HurikĂĄny** | Karibik, jihovĂœchod USA, jihovĂœchodnĂ­ Asie | ZesĂ­lenĂĄ konstrukce, generĂĄtory nad ĂșrovnĂ­ zĂĄplav |
| **Povodně** | ƘíčnĂ­ ĂșdolĂ­, pobƙeĆŸnĂ­ oblasti | UmĂ­stěnĂ­ mimo zĂĄplavovou zĂłnu, bariĂ©ry |
| **LesnĂ­ poĆŸĂĄry** | Kalifornie, AustrĂĄlie, Stƙedomoƙí | DefenzivnĂ­ zĂłny, filtrace vzduchu, monitoring |
### Power availability po regionech
| Region | Grid reliability | Cena/kWh (industriĂĄlnĂ­) | PoznĂĄmka |
|--------|-----------------|------------------------|----------|
| **Severní Evropa** (SE, NO, FI) | Vysokå (99.99 %) | $0.04-0.08 | Levnå zelenå energie, chladné klima |
| **Stƙední Evropa** (DE, NL, CZ) | Vysoká (99.99 %) | $0.10-0.20 | Stabilní, renewables rostou |
| **VĂœchodnĂ­ USA** (VA, NC) | VysokĂĄ | $0.05-0.08 | NejvětĆĄĂ­ DC hub (Ashburn, VA) |
| **Západní USA** (CA, OR) | Stƙední (PG&E issues) | $0.10-0.15 | CALISO grid, blackout risk |
| **Singapur** | VysokĂĄ | $0.15-0.20 | Moratorium na novĂĄ DC (2023), voda |
| **Dubai / UAE** | VysokĂĄ | $0.06-0.10 | LevnĂĄ energie, vysokĂĄ teplota (cooling) |
## Compliance a certifikace
| Standard / Certifikace | Oblast | Popis |
|----------------------|--------|-------|
| **TIA-942** (Rated 1-4) | DC design | Klasifikace redundance, kabelĂĄĆŸe, bezpečnosti (analogickĂœ k Uptime Tier) |
| **Uptime Institute** (Tier I-IV) | DC design | Provozní certifikace, konstrukční dokumentace |
| **ISO 27001** | ISMS | Informační bezpečnost, ƙízení rizik |
| **ISO 27701** | Privacy | Rozơíƙení ISO 27001 pro GDPR compliance |
| **SOC 2** (Type I/II) | Service org | Controls: Security, Availability, Confidentiality, Integrity, Privacy |
| **PCI DSS** | Platební karty | Fyzická bezpečnost, pƙístup k cardholder data |
| **HIPAA** | ZdravotnictvĂ­ | USA, ochrana zdravotnĂ­ch dat |
| **FedRAMP** | US government | Cloud service authorization, DC security |
| **GDPR** | EU | Ochrana osobnĂ­ch ĂșdajĆŻ, data residency |
| **NIST SP 800-53** | DC security | Security control catalog pro US federal |
| **ISO 14001** | EMS | Environmental management, sustainability |
## Sustainability
### UhlĂ­kovĂĄ stopa DC
```
CelkovĂ© emise = Scope 1 (pƙímĂ©) + Scope 2 (energie) + Scope 3 (dodavatelskĂœ ƙetězec)
Scope 1: GenerĂĄtory (diesel), Ășniky chladiva
Scope 2: Nakoupená elektƙina (grid mix)
Scope 3: VĂœroba HW, transport, EOL recyklace (~60-80 % celkovĂœch emisĂ­)
```
### Redukce emisĂ­
| OpatƙenĂ­ | Dopad na PUE | SnĂ­ĆŸenĂ­ emisĂ­ | NĂĄvratnost |
|----------|-------------|---------------|------------|
| **ZvĂœĆĄenĂ­ teploty** (22→27 °C) | −0.1-0.2 | 10-20 % chlazenĂ­ | Ihned |
| **Free cooling** | −0.1-0.3 | 20-40 % chlazení | 1-2 roky |
| **Liquid cooling** | −0.2-0.4 | 30-50 % chlazení | 2-4 roky |
| **LED osvětlení + senzory** | −0.01-0.02 | < 1 % | 1 rok |
| **PPA (Power Purchase Agreement)** | — | 100 % Scope 2 | Variabilní |
| **ObnovitelnĂ© zdroje** (solĂĄrnĂ­ na stƙeĆĄe) | — | 5-15 % spotƙeby | 5-10 let |
| **ZelenĂœ generĂĄtor** (HVO biodiesel) | — | 90 % CO₂ redukce | +30 % fuel cost |
### Certifikace udrĆŸitelnosti
| Certifikace | Popis |
|-----------|-------|
| **LEED** (BD+C: DC) | U.S. Green Building Council — design a konstrukce |
| **BREEAM** | UK, European sustainability assessment |
| **Climate Neutral Data Centre Pact** (EU) | Self-regulatory, PUE < 1.4 do 2030 |
| **ISO 50001** | Energy management system |
| **Energy Star** | EPA, energetickĂĄ Ășčinnost (jen US) |
## Decision diagram — návrh DC topologie
```mermaid
flowchart TD
Start(["DC design"]) --> TIER{"PoĆŸadovanĂœ Tier?"}
TIER -->|"Tier I / II"| T1["N / N+1 redundance<br/>JednoduchĂ© napĂĄjenĂ­, single path<br/>CRAC/CRAH, free cooling<br/>PUE 1.4-1.6, cena 1×"]
TIER -->|"Tier III"| T3["N+1, současně udrĆŸovatelnĂ©<br/>Dual path (A/B feed)<br/>Hot aisle containment<br/>PUE 1.2-1.4, cena 2×"]
TIER -->|"Tier IV"| T4["2N+1, fault tolerant<br/>Dual redundant + STS<br/>Hot + cold containment<br/>PUE 1.1-1.3, cena 3×"]
TIER --> POWER{"Power chain"}
POWER -->|"UPS"| UPS{"UPS typ"}
UPS -->|"Enterprise DC"| UPS1["VFI double-conversion<br/>Li-ion (LFP), 10-15 let<br/>N+1 nebo 2N modulĂĄrnĂ­"]
UPS -->|"Edge / office"| UPS2["VI line-interactive<br/>VRLA, 3-5 let"]
POWER -->|"GenerĂĄtor"| GEN["Diesel 500-2500 kVA<br/>NĂĄdrĆŸ na 24-72 h<br/>ATS 4-10 ms pƙepnutĂ­"]
POWER -->|"PDU"| PDU["3-phase 400 V<br/>Monitored/Switched<br/>A/B feed do rackĆŻ"]
Start --> DENS{"Hustota vĂœkonu"}
DENS -->|"< 10 kW/rack"| COOL1["Air cooling<br/>CRAC/CRAH, raised floor<br/>Hot aisle containment<br/>ASHRAE A1-A2"]
DENS -->|"10-25 kW/rack"| COOL2["Hybrid<br/>In-row cooling<br/>Rear door HX<br/>ASHRAE A1-H1"]
DENS -->|"> 25 kW/rack"| COOL3["Liquid cooling<br/>CDU, direct-to-chip<br/>Immersion single/two-phase<br/>ASHRAE W-tƙídy"]
Start --> CLIM{"KlimatickĂĄ zĂłna"}
CLIM -->|"Mírná (ČR, DE)"| FC1["Free cooling 4000-6000 h/rok<br/>Chiller + economizer<br/>PUE saving 0.2-0.3"]
CLIM -->|"Teplá (ES, US South)"| FC2["Chiller celoročně<br/>Adiabatic cooling<br/>PUE 1.3-1.6"]
CLIM -->|"ChladnĂĄ (SE, NO)"| FC3["Free cooling 7000+ h/rok<br/>Air-side economizer<br/>PUE < 1.2"]
```
## Monitoring diskƯ — S.M.A.R.T.
Self-Monitoring, Analysis and Reporting Technology — prediktivní monitoring HDD/SSD.
| KlíčovĂœ atribut | ID | Popis |
|----------------|----|-------|
| Reallocated Sectors Count | 5 | Počet pƙemapovanĂœch sektorĆŻ (nĂĄrĆŻst = konec disku) |
| Power-On Hours | 9 | CelkovĂĄ doba provozu v hodinĂĄch |
| Reported Uncorrectable Errors | 187 | NekorigovatelnĂ© chyby (červenĂĄ kontrolka) |
| CRC Error Count | 199 | Chyby na SATA lince (kabel/controller) |
| SSD Life Left | 231 | % zbĂœvajĂ­cĂ­ ĆŸivotnosti SSD |
| Media Wearout Indicator | 233 | CelkovĂœ zĂĄpis do NAND |
NĂĄstroje: `smartmontools` (smartctl, smartd), Prometheus exporter (`node_exporter`), OTeL collector.
## Zdroje
Odkazy, knihy a standardy: [sources/infrastructure/sources.md](sources/infrastructure/sources.md)
### Doporučená literatura
| Kniha | Autoƙi | ISBN | Popis |
|-------|--------|------|-------|
| The Data Center as a Computer (4th ed., 2025) | Barroso, Hölzle, Ranganathan | 978-3-031-99488-3 | KomplexnĂ­ vĂœvoj designu warehouse-scale computer (WSC) od Google architektĆŻ. PokrĂœvĂĄ hardware, software, power, cooling, networking a 25 let zkuĆĄenostĂ­ s WSC. KlíčovĂĄ publikace pro architekturu datovĂœch center. |
| Electronics Cooling: From the Chip to the Datacenter (Vol. 62) | Abraham et al. | 978-0-443-47084-4 | PraktickĂœ prĆŻvodce tepelnĂœm managementem od Ășrovně tranzistoru po datovĂ© centrum. Zahrnuje conduction, convection, liquid immersion a phase change cooling. NezbytnĂœ zdroj pro nĂĄvrh chlazenĂ­ DC. |
## PĂĄteƙnĂ­ sluĆŸby datovĂ©ho centra
Pƙi stavbě novĂ©ho DC je potƙeba nejdƙíve nasadit zĂĄkladnĂ­ infrastrukturnĂ­ sluĆŸby — bez nich nelze provozovat vyĆĄĆĄĂ­ vrstvy:
### DNS
| Role | SluĆŸba | Popis |
|------|--------|-------|
| **Authoritative** | Bind, PowerDNS, NSD | Primårní DNS zóna pro interní domény |
| **Recursive** | Unbound, Bind (caching), CoreDNS | Resolver pro internĂ­ + externĂ­ dotazy |
| **Anycast** | DNS anycast (BGP) | Redundance, niĆŸĆĄĂ­ latence |
| **Integrace** | Infoblox, BlueCat, dnsmasq | IPAM + DNS + DHCP v jednom |
Best practices: oddělenĂ© auth a recursive resolvery, DNSSEC, split-horizon (internĂ­ vs externĂ­ pohled), TSIG pro pƙenos zĂłn, monitoring (DNS query latency, NXDOMAIN rate).
### NTP (časová synchronizace)
- **Primary**: GPS-disciplinované NTP servery (Microchip S600, Meinberg)
- **Secondary**: Stratum 1/2 NTP (ntpd, chrony, NTPsec)
- **All nodes**: chrony (modernĂ­ nĂĄhrada ntpd), lokĂĄlnĂ­ NTP server na kaĆŸdĂ©m rack switchi (boundary clock)
- **Precision**: PTP (IEEE 1588) pro telco/fintech — sub-microsecond accuracy
- **DC topologie**: GPS antĂ©na → Grandmaster (PTP) → Boundary clock (rack switch) → Ordinary clock (server)
### DHCP + IPAM
| NĂĄstroj | Popis |
|---------|-------|
| **ISC DHCP** | Legacy, stĂĄle ĆĄiroce nasazen |
| **Kea** | ModernĂ­ nĂĄhrada ISC DHCP (ISC + Linux Foundation) |
| **Infoblox / BlueCat** | Enterprise IPAM + DHCP + DNS |
| **NetBox / phpIPAM** | Open-source IPAM |
### LDAP / Identity Management
| NĂĄstroj | Popis |
|---------|-------|
| **FreeIPA** | IntegrovanĂ© IDM (LDAP + Kerberos + DNS + CA) — Linux |
| **Active Directory** | Microsoft, LDAP + Kerberos + Group Policy |
| **389 Directory Server** | Open-source LDAP (Red Hat) |
| **OpenLDAP** | KlasickĂœ open-source LDAP |
| **Keycloak / Authentik** | ModernĂ­ OIDC/SAML/LDAP brĂĄny |
### PKI a certifikĂĄty
- **Enterprise CA**: EJBCA, Smallstep, HashiCorp Vault (PKI engine)
- **ACME**: Cert-Manager (Kubernetes), certbot (Let's Encrypt)
- **mTLS**: Vault PKI, spire (SPIFFE), Cilium
- **Best practices**: root CA offline, intermediate CA per prostƙedí, certifikáty s krátkou platností (max 90 dní), revocation (CRL/OCSP)
### Monitoring a observabilita
Viz [MONITORING.md](MONITORING.md). Pƙed spuơtěním prvních workloadƯ musí DC mít:
- Sběr metrik (Prometheus, Zabbix)
- Centralizované logy (Loki, ELK)
- Alerting (Alertmanager, PagerDuty)
- Uptime monitoring (heartbeat checky)
### Logistika nasazení — poƙadí krokƯ
```
1. DNS (alespoƈ recursive + local resolver)
2. NTP (časová synchronizace)
3. DHCP + IPAM (prvnĂ­ servery dostanou IP)
4. LDAP / IAM (uĆŸivatelĂ©, skupiny, pƙístupovĂĄ prĂĄva)
5. PKI (certifikĂĄty pro ĆĄifrovĂĄnĂ­)
6. Configuration management (Ansible, Puppet)
7. Monitoring + logging (vidět co se děje)
8. Container registry / Package repo (docker registry, apt/yum mirror)
9. Load balancer (pro sluĆŸby)
10. Storage backend (Ceph, NFS, SAN)
11. Orchestrace (Kubernetes, OpenStack)
```
## OpenStack v datacentru
OpenStack pƙinĂĄĆĄĂ­ do DC softwarovou abstrakčnĂ­ vrstvu, kterĂĄ umoĆŸĆˆuje multi-tenancy a self-service:
### Control plane architektura
- **Controller nodes** — management sluĆŸby (Keystone, Nova API, Neutron API, Horizon, RabbitMQ, DB)
- **Compute nodes** — hypervisor (KVM), Nova Compute, Neutron agent
- **Storage nodes** — Ceph OSD, Cinder volumes, Swift object storage
- **Network nodes** — Neutron L3 router, DHCP agent, DVR
### PoĆŸadavky na DC infrastrukturu
| Komponenta | PoĆŸadavek |
|------------|-----------|
| **Controller** | 3-5 node HA cluster, 16+ vCPU, 32+ GB RAM, SSD |
| **Compute** | HustĂœ vĂœkon na rack (GPU, high-core), NUMA-aware design |
| **Storage (Ceph)** | 10-25 GbE networking, NVMe/SSD OSD, 3+ replica |
| **Network** | 25/100 GbE spine-leaf, L3 BGP underlay, VXLAN overlay |
| **Rack power** | 10-30 kW/rack pro GPU compute |
### Use cases
- PrivĂĄtnĂ­ cloud pro enterprise (multi-tenant, self-service Horizon)
- NFVI pro telco (DPDK, SR-IOV, low-latency)
- Akademické / HPC clustery (Ironic, Cyborg, Manila)
- Government / regulated prostƙedí (on-prem, audit trail)
*PoslednĂ­ revize: 2026-06-03*