Skip to main content

Shared Responsibility Model — VM instances

Here is the RACI model defining the allocation of responsibilities between the client and Cloud Temple for the use of the VM instances service (shared virtual machines).

VM instances offering specifics
Unlike the dedicated IaaS offering, the VM instances service relies on a computing infrastructure that is shared and fully managed by Cloud Temple. Cloud Temple handles the complete management of the hypervisor, system images, and the infrastructure layer. The client retains full responsibility for what runs inside their instances: guest operating system, applications, data, and application security.


Role Definitions

RoleDescription
(R) Executes__E__xecutes the process
(A) Approves__A__pproves the execution of the process
(C) Consulted__C__onsulted during the process
(I) Informed__I__nformed of the process results (via tooling, the portal, or messaging)

Physical Infrastructure & Hypervisor

Cloud Temple is fully responsible for the infrastructure and hypervisor layers. The client has no access to this layer.

ActivityClientCloud Temple
Ensure the implementation and maintenance of physical datacentersRA
Ensure the implementation and maintenance of shared compute infrastructureIRA
Ensure the implementation and maintenance of storage infrastructureIRA
Ensure the implementation and maintenance of backbone network connectivityIRA
Manage, update, and maintain in a secure state the hypervisors (1)IRA
Ensure high availability of the hypervisor platformIRA
Manage incidents, issues, and capacity for the infrastructure and hypervisor layersIRA
Acquire and maintain the licenses essential for platform operationRA

(1) Hypervisors and the virtualization layer are entirely under the responsibility of Cloud Temple. The client has no access to the hypervisor or the underlying management layer.


Images, templates & catalog

ActivityClientCloud Temple
Build, publish, and maintain the official images of the catalog (2)IRA
Apply security patches and updates to the catalog imagesRA
Validate the compliance and security of images published in the catalogRA
Derive an official catalog image to create a custom image (3)RAI
Ensure compliance, licenses, and security of any derived custom imageRA
Maintain and update derived custom images (OS patches, built-in tools)RA

(2) The official catalog images (Linux distributions, Windows Server, etc.) are built, maintained, and updated by Cloud Temple. Their initial security level is the responsibility of Cloud Temple.
(3) The client can derive an official catalog image to create a custom image. From that point on, full responsibility for this image lies with them: compliance, licenses, security updates, presence and updating of tools, and hardening. Cloud Temple does not support the maintenance of these derived images.


Instance Provisioning & Lifecycle

ActivityClientCloud Temple
Create, start, stop, and delete VM instancesRAI
Choose the instance flavor and base imageRA
Resize an instance (flavor change) (4)RAI
Manage metadata and tags associated with instancesRA
Manage the lifecycle of instances (creation, modification, decommissioning)RA
Make the decision to add or reduce resources.RA

*(4) Resizing may require an instance restart. The availability of the hosted application during this operation is the client's responsibility.


Guest Operating System (Guest OS) & tools

The client has full control and full responsibility for the operating system inside their instances.

SLA Validity Condition — Required Tools

The VM instance tools (hypervisor management agents) are pre-installed by Cloud Temple when deploying the instance from the catalog. These agents are essential for the proper functioning of the platform and for measuring availability.

If the client disables or removes these tools, the SLA is immediately void. Cloud Temple can no longer guarantee or measure the instance's availability without these agents. The presence and proper functioning of the tools are under the client's sole responsibility during operation.

ActivityClientCloud Temple
Pre-install the tools (hypervisor agents, PV drivers) during deployment from the catalog (5)RA
Ensure that the tools remain installed, enabled, and up-to-date throughout the instance's lifecycle (6)RA
Apply security patches and updates to the guest operating systemRA
Harden the operating system configuration (CIS, ANSSI recommendations, etc.)RA
Manage user accounts, passwords, and SSH keys inside the instance (7)RA
Install and configure monitoring agents (OS metrics, system logs)RA
Maintain regulatory compliance applicable to OS and hosted dataRA

(5) Cloud Temple provides an initial image at catalog release state with tools pre-installed. The responsibility for configuration, hardening, and subsequent operating system updates rests entirely with the client from the first connection to the instance.
(6) The removal or disabling of tools by the client results in the immediate suspension of service level commitments (SLA) for the affected instance. Cloud Temple cannot be held responsible for malfunctions related to the absence of these agents.
(7) The security of access to the instance (password strength, SSH key management, principle of least privilege) is under the client's sole responsibility. Cloud Temple cannot be held responsible for a compromise resulting from an insufficiently secure access configuration.


Instance Security & Internet Exposure

Customer Security Responsibility

Cloud Temple only ensures inter-tenant isolation at the platform level. The protection of each instance against network threats (Internet, internal traffic) is entirely the customer's responsibility. An instance connected to the Internet without adequate filtering or with weak credentials exposes the customer to compromise risks for which Cloud Temple cannot be held liable.

ActivityCustomerCloud Temple
Ensure inter-tenant network isolation at the platform levelRA
Protect instances exposed to the Internet (filtering rules, security groups, firewalls) (A)RA
Ensure no service is exposed to the Internet without an explicit filtering ruleRA
Implement and maintain an application firewall (WAF, IDS/IPS) if required by the criticality levelRA
Configure strong passwords and secure SSH keys on all instances (B)RA
Apply the principle of least privilege to OS accounts and remote access (SSH, RDP)RA
Implement an incident detection and response solution (EDR, SIEM) if requiredRA
Perform configuration hardening for instance network and OS (disabling unnecessary services)RA
Notify Cloud Temple in case of suspected compromise affecting the shared platformRAC

(A) Any instance connected to the Internet via a public IP or NAT rule without adequate filtering is the sole responsibility of the customer. Cloud Temple does not inspect or filter tenant inbound or outbound traffic.
(B) The use of weak passwords, compromised SSH keys, or unrestricted root access constitutes a breach of security best practices. Cloud Temple cannot be held liable for a compromise resulting from insufficiently secure access configuration by the customer.


Applications & Middleware

ActivityClientCloud Temple
Install, configure, and maintain applications and middleware in instancesRA
Apply security patches for applications and middlewareRA
Acquire and hold software licenses for hosted applicationsRA
Implement an antivirus strategy on instancesRA
Manage application continuity (load balancing, réplication, clustering)RA

Network & Connectivity

ActivityClientCloud Temple
Maintain the backbone network and shared network infrastructureIRA
Configure the network interfaces of instancesRA
Manage the IP addressing plan within the tenantRAI
Configure and manage security groups (security groups / filtering rules) (6)RA
Subscribe to and configure Internet access (public IPs, NAT)RA
Manage incidents on backbone network links (Cloud Temple layer)IRA

(6) The configuration of network filtering rules applicable to instances is the responsibility of the client. Cloud Temple ensures only inter-tenant isolation at the platform level.


Instance Storage

ActivityClientCloud Temple
Ensure the operational availability of the shared storage infrastructureIRA
Ensure the security readiness of the storage infrastructureIRA
Create, attach, and manage additional storage volumesRAI
Ensure data consistency of data stored in instancesRA
Define and apply a data encryption policy within instances (7)RA

(7) Encryption at rest for the underlying storage infrastructure is provided by Cloud Temple. Application-level data encryption (at the file system or database level) is the client's responsibility.


Backup & Snapshots

ActivityClientCloud Temple
Ensure the operational readiness of the backup infrastructureIRA
Enable and configure the backup policy associated with an instanceRA
Trigger manual snapshots of an instanceRA
Verify the consistency and restorability of performed backupsRA
Perform periodic restoration testsRA
Manage storage capacity dedicated to backupsRC
Define the business continuity or disaster recovery strategy for hosted applicationsRA

Monitoring & Performance

ActivityClientCloud Temple
Monitor the proper functioning of the physical infrastructure and hypervisorsIRA
Monitor the performance of shared resources (compute, storage, network)IRA
Monitor instance performance (CPU, RAM, disk I/O, guest-level network)RA
Implement a metrics and alerting solution for hosted applicationsRA

Access & Identity Management

ActivityClientCloud Temple
Ensure accessibility of the Cloud Temple Console and the APIRA
Manage permissions for Cloud Temple teams accessing the SecNumCloud-qualified infrastructureRA
Administer access to the Cloud Temple Console (utilisateurs, rôles, IAM)RA
Manage access within instances (comptes OS, clés SSH, bastion)RA
Configure an external authentication repository (SSO, LDAP) for the ConsoleRAC

Logs

ActivityClientCloud Temple
Retain and make available platform logs for VM instances (8)RA
Collect, retain, and analyze system and application logs for instancesRA

(8) The retention period for platform logs is specified in the VM instances service agreement.


Documentation & Contractual

ActivityClientCloud Temple
Ensure commercial and contractual management (quotes, orders, invoicing)IRA
Ensure contractual tracking of the service (deliveries, invoicing)RAI
Ensure maintenance and availability of the service technical documentationIRA
Keep the CMDB up to date for instances deployed in its tenantRA
Keep the Console and API access policy up to dateRA

Reversibility

ActivityClientCloud Temple
Plan the reversibility project and select target infrastructuresRAI
Export data and instance images via the API or provided toolsRAI
Proceed with decommissioning configurations following contract terminationIRA
Perform secure data erasure on storage media and provide an attestationIRA

Professional services are available if you wish to delegate all or part of the responsibilities listed as being the client's responsibility. Contact your Cloud Temple sales representative.