Content Thief – -redacted-

I woke up this morning to discover that someone had stolen one of my ATG Performance blog posts, word for word, and published it on his blog, as if he’d written it.

My post about Improving JSP Serving Time for an ATG Application was copied and pasted into a new post on the….

UPDATE: The individual in question has removed all non-original content from his site, so I’m removing any personally identifying information from this post. Consider this a PSA about respecting copyright and bloggers and your mother (don’t forget Mother’s Day!).

Spark::red 2011 Review and 2012 Preview

2011 has been an amazing year for Spark::red ATG Oracle Commerce Hosting.

  • We’ve added several new clients (including a well known member of the Fortune 1000!)
  • We’ve added 101 new dedicated servers and over 20 cloud computing instances
  • We’ve opened an office in Boston
  • We’ve earned our PCI Level 1 MSP Certification
  • We’ve hired several employees, a large number of contractors, and even picked up an intern!
  • We’ve gone from 3 data centers in the USA to 13 data centers and 16 points-of-presence including several international facilities
  • While our competitors have raised prices, we’ve managed to keep prices the same or actually reduce them in many places.  All this while providing newer more powerful hardware across the board
  • We’ve introduced a new Oracle ATG Commerce Standard Hosting Package which provides excellent performance, stability, and security, for a very affordable package price
  • Served well over 200 TB of content
  • Partnered with JBoss/Redhat, Oracle, Akamai, Keynote, Knowledge Path, and many other industry leaders in order to provide the absolute best hosting, support, and related services
  • More more!
We’ve grown a lot in 2011 in every measurable dimension.  Clients, revenue, employees, contractors, servers, bandwidth, offices, processes, every aspect of the business has been growing nicely.
2012 is looking like it will be even bigger!  We have lots of prospective clients, two new international data centers opening in Australia and South America, international clients, new hires, a site redesign, a big sales and marketing push, new free ATG modules and open source code, and lots more!
I’m very excited about the upcoming year and what it will bring.  If you’d like to talk to us about what we can do to help you in 2012 give us a call or email us about your ATG Hosting needs!

What Oracle/ATG Could Do With Licensing

This is a follow-up to my post earlier this week: ATG Licensing – One Step Forward, Two Steps Back.

I feel like Oracle has really shot themselves in the foot on this. They’ve changed up how many licenses need to be sold as a minimum to small and medium customers, and they’ve done this without adequate training for their sales staff. They’ve dramatically increased the mid-market entry level costs, pricing themselves out of many deals – even with aggressive discounting. They’ve also really failed to take care of their existing customers. There’s a huge number of existing ATG customers out there, who were sold a bundle of licenses which prevents them from upgrading without spending a significant amount out of pocket. Those customers have been paying annual support fees against a broken promise of free upgrades.

The problem will get worse as future generations of processors start shipping with hex- and octo- core base configurations. In short Oracle’s licensing policy does not work with modern CPUs and ATG software pricing and infrastructure architecture.

So what could they do? I have a few solutions:

  1. Allow for software disabling of cores. This is simple. Just add an “ATG Licensing Addendum” to the contracts that allows for this. Problem solved now and in the future.
  2. Use the Oracle Standard Database licensing model based on “Sockets” not “Processors”. This is really a clean solution, has precedent in Oracle’s licensing practices, and scales well in the future.
  3. Automatically allow all MC4 bundle customers to upgrade to 6 “Processors” of Commerce and 6 “Processors” of Search on ATG 10, for free. They were sold a small but deployable bundle of Production and Staging licenses. They’ve been paying their support fees. They deserve to still be able to run a small but deployable setup of Production and Staging.
  4. Automatically upgrade any customers who have been sold ATG 10 with less than 6 “Processors” of Commerce and Search to 6+6. These customers have been sold an impossible to deploy list of licenses. Through ignorance (most likely) their ATG Sales rep sold them a lie. Make it right.

What do you think is most fair?

ATG Licensing – One Step Forward, Two Steps Back

This is my fourth post on the subject of ATG Licensing. You may want to read the previous three posts: Rant About Core-Based Licensing, Why ATG’s Core Based Licensing is Stupid, and the latest The True Cost of ATG’s Core Based Licensing.

Oracle bought ATG at the end of last year. ATG 10 was released in a similar timeframe. ATG 10 introduced some great licensing changes. In ATG 9 and earlier, ATG’s License Manager enforced the license limitations encoded in the license files provided by ATG by checking the number of “CPUs” reported by the OS. Unfortunately this number captured cores + HyperThreaded logical cores, and as I talked about in earlier posts, this number increased in each new generation of chip causing issues with license costs. The typical solution was to disable HyperThreading in the BIOS and/or disable CPU cores within the OS in order to limit the server CPU resources to match the licenses. I’m not sure there was ever written policy around this, but it was common practice and many sales reps and sales engineers explicitly okayed this approach during pre-sales architecture planning.

In ATG 10 the licensing stopped being technically enforced via the License Manager and changed over to be enforced by audits. This means that HyperThreading is no longer a 2x penalty. This is the upside! It also means you can setup servers, or change IPs, without waiting for ATG to issue you new license files all the time. This is also handy.

Now comes the bad news.

I’ve just found out that Oracle’s (new) policy is that disabling cores is not permitted to meet license limits. That means you need valid ATG licenses for every physical core installed in any of your ATG servers. They’ve also dropped the “Staging” licenses which means you now need full price production licenses for your Staging environment hardware as well.

The current generation of Intel server CPUs are Westmere 56XX and they come in quad-core models on the low end, and hex-core models on the high end. The previous generation of CPUs are Nehalem 55XX and they come only in quad-core models. The generation before that were 54XXs and they also came only in quad-core models. The generation before that were 53XX, again quad-core only.

What this means is that the smallest ATG setup is basically two production app servers for failover/redundancy with single quad-core CPUs, and one staging app server, also with a single quad-core CPU. That’s 12 cores of ATG Commerce you need licensing for (or 6 ATG Commerce “processor” licenses – which is how they sell it now: Intel chips have a .5 core multiplier to convert from “processors” to physical cores). You also need ATG Search licenses. Given how most ATG 10 sites are massively reliant on Search for facets and site navigation you really need two production Search servers, again for failover/redundancy, and another Search box in stage. You *can* run Stage Search on the Stage App server, but you still need Search licenses for it. So again, you’re looking at 12 cores/6 “processors” minimum. Plus BCC and CSC Seats, etc…

So right now, anything less than 6 “Processors” of ATG Commerce and 6 “Processors” of ATG Search, isn’t actually deployable into a production + stage setup. Unfortunately some in-flight sales proposal out there right now are smaller than that. If you’re involved in an ATG deal with fewer licenses make sure you carefully go over your architecture and deployment plan with your ATG Sales rep and your hosting team.

Here’s another fun fact: when upgrading from a previous version to ATG 10, your currently licensed cores will get you ATG 10 “Processor” credits based on the same core multiplier. I’m not sure if your staging licenses will help at all, but if they do, they won’t count 100% or even close. What this means is that all of the MANY MANY customers out there who were sold MC4 bundles (4 cores of ATG Commerce + Search + Merch + CSC, etc…) have a truly terrible upgrade path. Those 4 cores of Commerce will get them 2 “Processors” of Commerce. Leaving them 4 “processors” short. Ditto for Search. That’s well over $1,000,000 to upgrade, although you’ll probably get some discounts from your sales rep.

That’s right: after paying hundreds of thousands of dollars a year in Support fees, entitling you to “free upgrades”, you’ll have to pony up somewhere in the six-figures range to upgrade to ATG 10.

Oracle’s Enterprise licensing practices do not apply well to standard small/medium deal ATG licensing levels and certainly not to existing ATG customers.

Spark::red is PCI Level 1 Certified!

image from Purpleslog

I’m happy to announce that Spark::red ATG Hosting has received our PCI DSS 1.2 Level 1 Certification as an eCommerce MSP.  We have been Level 2 certified for a while, but completing our Level 1 certification with TrustWave as our third-party auditor is a huge milestone for us.

PCI DSS is the Payment Card Industry’s Data Security Standard.  It is a set of requirements and guidelines designed to ensure merchants who handle or process credit cards, do so securely.  There are different levels based on transaction volume and Level 1 is the highest level, required for the largest volume merchants.  Level 1 is also the most difficult certification to gain, requiring the strictest security protections, the strongest policies, and a very in depth audit by a certified auditing company, such as TrustWave.  Our certification process has taken many months and the completion of our Level 1 Report of Compliance (RoC) is a testament to our dedication to providing the highest level of secure environments to our clients and safeguarding their systems and information, as well as the information of all our clients’ customers.

At Spark::red we focus strongly on Security and Performance beyond the core ATG hosting services.  We handle more PCI DSS requirements than any other ATG Hosting provider out there.  If you are looking for an ATG Hosting provider to help manage your ATG web application, we can offer PCI Level 1 compliant hosting and handle many of your security needs.