Cloud Deployment Models: Public, Private, Community and Hybrid with a 60-VM Worked Example
Learn a four-question method to classify cloud deployment models, then carry one 60-VM workload through public, private, community, and hybrid designs.
KnowledgeGate Team
Exam prep & CS education

Learners often memorise four definitions but still misclassify scenarios. They focus on location, provider count, or "secure" instead of who may use the cloud and how environments connect. Classify deployment models by access, connection, capacity, and elimination rules for exams and interviews.
Related reading: cloud computing fundamentals and cloud storage.
Cloud deployment models answer who can use and control the infrastructure
A deployment model describes infrastructure access, ownership, governance, and interconnection. It is separate from IaaS, PaaS, and SaaS service models.
Model | Permitted users | Control or governance | Where it may run | Decisive clue |
|---|---|---|---|---|
Public | General customers | Provider | Provider infrastructure | Broad customer offering |
Private | One organisation | Organisation or operator | On or off its premises | Exclusive use |
Community | Defined organisation group | Members or operator | On or off members' premises | Shared needs and membership |
Hybrid | Users of each component | Coordinated across distinct clouds | Connected locations | Workload or data portability |
Location is not decisive. A third party may run an off-premises private cloud, while local machines are not automatically a private cloud.
Cloud deployment model classification in four questions
Ask in order:
Exclusive to one organisation? Private.
Restricted to named organisations with shared concerns? Community.
Distinct clouds deliberately connected for workload or data portability? Hybrid.
Capacity broadly offered by a provider? Public.
Apply the test:
A startup rents 60 VMs from a provider's shared platform. The answer is public.
One bank alone uses a dedicated cloud at a third-party data centre. The answer is private.
Four state universities share a cloud that only those universities may access. The answer is community.
A bank keeps its normal workload private and sends excess demand to a public cloud. The answer is hybrid.
A government community is community because access is restricted to members with shared concerns, not because the users are public institutions.

Hybrid cloud worked example with 24 baseline VMs and 60 at peak
Consider a retail analytics workload that needs 24 VMs normally and 60 VMs on three peak days. Each VM has 4 vCPU and 16 GB RAM.
Load | VM calculation | vCPU calculation | RAM calculation |
|---|---|---|---|
Baseline | 24 VMs |
|
|
Peak | 60 VMs |
|
|
Burst |
|
|
|
Subtraction confirms the burst: 240 - 96 = 144 vCPU and 960 - 384 = 576 GB.
A 60-slot private cloud uses 24 normally: 24 / 60 x 100 = 40% utilisation. Its 60 - 24 = 36 idle slots equal 36 / 60 x 100 = 60%. Public cloud requests 24 or 60 slots, subject to quota. Hybrid fully uses 24 private slots and bursts 36 VMs, 144 vCPU, and 576 GB RAM publicly.
In community cloud, four universities reserve 6 slots each: 4 x 6 = 24. The remaining 60 - 24 = 36 serve one scheduled peak. Two simultaneous 36-slot requests create 24 + 36 + 36 = 96 demand and a 96 - 60 = 36 shortfall, requiring admission and priority rules.

Public, private, community and hybrid are trade-offs, not a security ranking
Model | Access | Governance | Scaling and isolation | Coordination burden |
|---|---|---|---|---|
Public | Broad customers | Provider | Provider capacity and quotas, logical tenant separation | Customer configuration |
Private | One organisation | Organisation | Dedicated pool and boundary | Internal capacity planning |
Community | Defined members | Shared rules | Member pool and restricted boundary | Admission and priority |
Hybrid | Per component | Coordinated | Connected pools with distinct boundaries | Networking, identity, monitoring, data movement |
"Public is insecure, private is secure" fails. Public needs correct identity, encryption, and configuration, while poor controls can expose private cloud. Deployment boundary is not a security verdict.
A public cloud front end and private cloud database are hybrid only when intentionally connected. Unrelated environments are not hybrid merely because one organisation owns both.
Deployment model is not service model, hosting location, or multi-cloud
Deployment and service models are independent axes:
Deployment model | Service model | Exact combination |
|---|---|---|
Public | IaaS | The startup receives its 60 VMs |
Private | PaaS | A platform serves only the bank's developers |
Community | SaaS | An application serves the four universities |
Hybrid | Private IaaS plus public PaaS | An application joins both environments |
An on-premises server room is not automatically a private cloud. Two unconnected public providers are multi-cloud, not necessarily hybrid. Cloud Computing Concepts and Evolution provides the broader map of service models, architecture, evolution, and capacity planning. A deployment-model question instead turns on permitted users, exclusivity, and whether distinct environments exchange workloads or data.
Cloud deployment model questions test classification, assertions, and capacity
Single answer: A platform limited to six member hospitals is community cloud because they share a requirement. "Hospital" does not imply private, nor does third-party operation imply public.
MSQ-style assertions:
A. A private cloud must be on the owner's premises. False. Exclusivity matters, not location.
B. A community cloud serves a defined group with shared concerns. True.
C. Any use of two cloud providers is hybrid. False. The environments must be bound together.
D. Deployment and service models are independent classification axes. True.
The correct choices are B and D.
Numerical: With a 24-VM private base and 60-VM peak, public burst is 60 - 24 = 36 VMs, or 36 x 4 = 144 vCPU and 36 x 16 = 576 GB RAM.
Cloud deployment model traps and a one-minute elimination checklist
Trap | Why it fails | Replacement rule |
|---|---|---|
Private means on premises | Location is not access | Look for one organisation's exclusive use |
Community means public sector | Industry is not membership | Look for named organisations with shared concerns |
Hybrid means two vendors | Providers can remain unconnected | Look for distinct clouds bound by workload or data flow |
Public means no isolation | Access differs from logical isolation | Look for a broad provider offering |
Underline only our organisation, named member organisations, general customers, private baseline plus public burst, and workload portability. Cross out building location, industry label, and protocol name.
For a 20-second check, identify users, exclusivity, distinct environments, and boundary crossing. Re-run it on the startup, bank, universities, and bursting bank. Access gives the first three models; connection gives hybrid.
Cloud deployment models and related study
Public means capacity offered broadly by a provider.
Private means exclusive use by one organisation.
Community means restricted shared use by a defined group.
Hybrid means distinct cloud environments intentionally connected.
Service model and deployment model are separate axes.
For the surrounding cloud, operating-system, networking, and software-engineering sequence, see Computer Science Fundamentals for Placements by Sanchit Sir, whose live curriculum includes Cloud Computing. For university and placement routes, explore the CS Fundamentals category.
Keep learning

Computer Networks Hardware Basics: Devices, Domains and Worked Examples
Learn what hubs, switches, routers, gateways and access points actually do, then count network domains and trace frames through a two-LAN topology.

Data Link Layer Framing Explained: Byte Stuffing, Bit Stuffing and a Cross-Concept Numerical
Frame one four-byte payload in two ways, decode it, and then reuse the verified frame sizes in link-load and Stop-and-Wait calculations.

Byte Stuffing in Computer Networks: Worked Framing Example and Exam Traps
Learn a precise byte-stuffing convention, trace a payload containing both FLAG and ESC, reverse it safely, and calculate frame overhead and transmission time.

Go-Back-N Protocol Explained: Sliding Windows, Worked Numericals and Exam Traps
Trace Go-Back-N through a lost frame, calculate its legal window and link utilisation, and avoid the ACK and wrap-around traps that spoil numericals.