Security as Code: Devsecops Patterns with Aws
暫譯: 安全即代碼:AWS 的 DevSecOps 模式
Das, Bk, Chu, Virginia
- 出版商: O'Reilly
- 出版日期: 2023-02-07
- 定價: $1,880
- 售價: 9.0 折 $1,692
- 語言: 英文
- 頁數: 119
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1098127463
- ISBN-13: 9781098127466
-
相關分類:
Amazon Web Services、資訊安全
立即出貨 (庫存 < 3)
相關主題
商品描述
DevOps engineers, developers, and security engineers have ever-changing roles to play in today's cloud native world. In order to build secure and resilient applications, you have to be equipped with security knowledge. Enter security as code.
In this book, authors BK Sarthak Das and Virginia Chu demonstrate how to use this methodology to secure any application and infrastructure you want to deploy. With Security as Code, you'll learn how to create a secure containerized application with Kubernetes using CI/CD tooling from AWS and open source providers.
This practical book also provides common patterns and methods to securely develop infrastructure for resilient and highly available backups that you can restore with just minimal manual intervention.
- Learn the tools of the trade, using Kubernetes and the AWS Code Suite
- Set up infrastructure as code and run scans to detect misconfigured resources in your code
- Create secure logging patterns with CloudWatch and other tools
- Restrict system access to authorized users with role-based access control (RBAC)
- Inject faults to test the resiliency of your application with AWS Fault Injector or open source tooling
- Learn how to pull everything together into one deployment
商品描述(中文翻譯)
DevOps 工程師、開發人員和安全工程師在當今雲原生世界中扮演著不斷變化的角色。為了構建安全且具韌性的應用程式,您必須具備安全知識。這就是「安全即代碼」的概念。
在這本書中,作者 BK Sarthak Das 和 Virginia Chu 展示了如何使用這種方法來保護您想要部署的任何應用程式和基礎設施。透過《Security as Code》,您將學會如何使用 AWS 和開源提供者的 CI/CD 工具,創建一個安全的容器化應用程式,並使用 Kubernetes。
這本實用的書籍還提供了安全開發基礎設施的常見模式和方法,以便為韌性和高可用性的備份提供支持,您可以在僅需最少手動干預的情況下進行恢復。
- 學習使用 Kubernetes 和 AWS Code Suite 的行業工具
- 設置基礎設施即代碼,並運行掃描以檢測代碼中配置錯誤的資源
- 使用 CloudWatch 和其他工具創建安全的日誌模式
- 通過基於角色的訪問控制 (RBAC) 限制系統訪問僅限授權用戶
- 使用 AWS Fault Injector 或開源工具注入故障以測試應用程式的韌性
- 學習如何將所有內容整合到一個部署中