際際滷

際際滷Share a Scribd company logo
L棚 Minh Ch鱈
Nguy畛n S董n T湛ng
N畛i dung th畉o lu畉n
   I. Cloud Computing
        Gi畛i thi畛u v畛 Cloud Computing
        Virtualization
   II. Amazon Web Services
        L畛ch s畛 ph叩t tri畛n
        C叩c d畛ch v畛 c畛a AWS
   III. Openstack
        L畛ch s畛 ph叩t tri畛n
        C叩c thnh ph畉n 界鞄鱈稼鞄
        N畛i dung th畛 nghi畛m
   IV. Cloud computing security
        CSA, NIST, 
        Security solutions
        OpenStack security
I. Cloud Computing


              internet
Xu h動畛ng IT
What is the cloud?
 IT as a service


                         What is
 Cloud allows access to services without user technical knowledge or control of
  supporting infrastructure

                    Cloud Computing?
 Best described in terms of what happened to mechanical power over 100 yrs
  ago

 Now computers are simple devices connected to the larger cloud

 Data processing, storage and software applications that used to run locally
  are now being supplied by big central computing stations. They're becoming,
  in essence, computing utilities.
Cloud computing
              Cloud Computing  t畉t c畉 c叩c d畛ch v畛
              v l動u tr畛 tr棚n cloud c坦 th畛 truy c畉p
              畛 b畉t k畛 但u ch畛 c畉n k畉t n畛i internet
Why Cloud Computing
Khai th叩c t畛i a hi畛u nng, 畉c bi畛t c畛a Data Center
     Ph畉n l畛n c叩c Data Center 畛u ch畛 畛nh ti nguy棚n v動畛t nhu c畉u
Chia s畉 ti nguy棚n
T畉p trung h坦a c董 s畛 h畉 t畉ng
Ti畉t ki畛m ph畉n c畛ng
Ti畉t ki畛m, gi畉m chi ph鱈 畉u t動
a ph動董ng ti畛n
Kh畉 nng linh ho畉t cao
Tr畉 theo nhu c畉u th畛c t畉
畛nh ngh挑a Cloud Computing

 C叩c t鱈nh nng



 M担 h狸nh tri畛n khai



 M担 h狸nh d畛ch v畛
畛nh ngh挑a Cloud Computing (tt)
 C叩c t鱈nh nng
 1. Thu h畛i v c畉p ph叩t ti nguy棚n
 2. Truy c畉p th担ng qua c叩c
chu畉n m畉ng
 3. o l動畛ng d畛ch v畛
 4. T畛 ph畛c v畛 theo nhu c畉u
 5. Chia s畉 ti nguy棚n
 M担 h狸nh tri畛n khai
 1. 叩m m但y ri棚ng
 2. 叩m m但y c担ng c畛ng
 3. 叩m m但y lai
 4. 叩m m但y c畛ng 畛ng
畛nh ngh挑a Cloud Computing (tt)

 M担 h狸nh d畛ch v畛
1. SaaS: Software as a
   Service
2. PaaS: Platform as a
   Service
3. IaaS: Infrastructure
   as a service
畛ng d畛ng Cloud Computing
        Chuy畛n sang s畛 d畛ng d畛ch v畛 CRM package c畛a
SaaS     m畛t SaaS provider nh動 Salesforce.com thay v狸
         ph畉i d畛ng 1 CRM system
        Chuy畛n sang s畛 d畛ng exchange server thay v狸 ph畉i
         x但y d畛ng mail server.

PaaS    C畉n m畛t kh担ng gian l動u tr畛 l畛n 畛 l動u tr畛 s畛
         l動畛ng l畛n files - s畛 d畛ng d畛ch v畛 S3 c畛a amazon.
        C畉n m畛t m担i tr動畛ng 畛 ph叩t tri畛n 畛ng d畛ng Java


        Ch畉y m畛t batch job - S畛 d畛ng Amazon EC2.
IaaS    Host m畛t website, nh動ng trong m畛t th畛i gian
         ng畉n  thay v狸 畉u t動 chi ph鱈 ban 畉u, s畛 d畛ng
         Flexiscale.
Customer IT management
IaaS  PaaS - SaaS
   Cloud Infrastructure   Cloud Infrastructure   Cloud Infrastructure
                                                        IaaS            Software as a Service
                                 PaaS                   PaaS                   (SaaS)
          SaaS                   SaaS                   SaaS                Architectures



   Cloud Infrastructure   Cloud Infrastructure
                                 IaaS             Platform as a Service (PaaS)
          PaaS                   PaaS                     Architectures




   Cloud Infrastructure
          IaaS                Infrastructure as a Service (IaaS)
                                         Architectures
Virtualization Technologies - Background

 Mode Switching
   Kernel mode
   User mode

 VMM (Virtual Machine Monitor)
   VMM 坦ng vai tr嘆 nh動 m畛t ph畉n m畛m trung gian ch畉y tr棚n HH 畛
    chia s畉 ti nguy棚n v畛i HH. V鱈 d畛: VMware workstation, Virtual PC,
    KVM.
   VMM 坦ng vai tr嘆 l m畛t hypervisor ch畉y tr棚n ph畉n c畛ng. V鱈 d畛:
    VMware ESXi, Hyper-V, Xen.

 Hypervisor
   Monolithic: ESXi
   Micro hypervisor: Hyper-V
Monolithic vs Micro-kernelized
     Monolithic hypervisor
     Driver ri棚ng bi畛t 畛 truy c畉p ti
      nguy棚n ph畉n c畛ng b棚n d動畛i.
     C叩c VMs truy c畉p ti nguy棚n h畛
      th畛ng th担ng qua drivers c畛a
      hypervisor.
     働u i畛m: hi畛u su畉t cao
     Nh動畛c i畛m: khi driver tr棚n
      hypervisor b畛 s畛 c畛 th狸 c畉 h畛 th畛ng
      ng動ng ho畉t 畛ng, ho畉c ph畉i 畛i m畉t
      v畛i v畉n 畛 an ninh khi drivers c坦 th畛
      b畛 gi畉 d畉ng b畛i malware, m畛t r畛i ro
      trong m担i tr動畛ng 畉o h坦a.

.Micro-kernelized hypervisor: kh担ng c坦 driver b棚n trong hypervisor m ch畉y tr畛c
   ti畉p tr棚n m畛i partition. M畛t VM l partition cha qu畉n l箪 memory, l動u tr畛 drivers, v
   kh畛i t畉o c叩c partition con.
     働u i畛m: s畛 an ton v tin c畉y.
     Nh動畛c i畛m: 畛 s畉n sng (availability) khi partition cha g畉p s畛 c畛.
C叩c lo畉i 畉o h坦a
 Full-virtualization
 Cung c畉p m叩y 畉o m担 ph畛ng
  c畛a 1 m叩y ch畛 th畉t v畛i 畉y 畛
  t畉t c畉 c叩c t鱈nh nng bao g畛m
  input/output operations,
  interrupts, memory access, 
 Nh動畛c i畛m: Hi畛u nng th畉p
  (mode switching).
 Xen, VMWare workstation,
  Virtual Box, Qemu/KVM, v
  Microsoft Virtual Server h畛 tr畛
  lo畉i 畉o h坦a ny
C叩c lo畉i 畉o h坦a
Para-virtualization
 K畛 thu畉t 畉o h坦a 動畛c h畛 tr畛 v
  i畛u khi畛n b畛i 1 hypervisor
  nh動ng c叩c Oss c畛a guest th畛c
  thi c叩c l畛nh kh担ng ph畉i th担ng qua
  Hypervisor (hay b畉t k畛 1 tr狸nh
  qu畉n l箪 m叩y 畉o no) n棚n kh担ng
  b畛 h畉n ch畉 v畛 quy畛n h畉n.
 働u i畛m: hi畛u su畉t cao
 Nh動畛c i畛m: c叩c OS bi畉t ang
  ch畉y tr棚n 1 n畛n t畉ng ph畉n c畛ng
  畉o v kh坦 c畉u h狸nh ci 畉t.
 Xen, VMware, Hyper-V, v UML
C叩c lo畉i 畉o h坦a
OS-level virtualization
 (Isolation)
 T畉o v ch畉y 動畛c nhi畛u m叩y 畉o
  c叩ch ly v an ton (secure) d湛ng
  chung 1 HH.
 働u i畛m: b畉o tr狸 nhanh ch坦ng
  n棚n 動畛c 畛ng d畛ng r畛ng r達i
  trong c叩c l挑nh v畛c hosting.
 Ch畛 c坦 tr棚n HH Linux.
 OpenVZ, Virtuozzo, Linux-
  VServer, Solaris Zones, v
  FreeBSD Jails.
Cloud vs Virtualization
Cloud vs Virtualization
Virtualization                   Cloud
 Infrastructure                  Application
 Hypervisor & related tools.     Services.
 Computer OS.                    Service catalog.
 Compute, network, and storage.  IaaS, PaaS, SaaS.
 IT manager, IT administrator    Business app owner, developer,
                                   end users.
                                  Pay as you go
 Provision resource
II. Amazon Web Services


      http://aws.amazon.com
Amazon.com:
a digital shop around the corner
... and a digital colossus.
Customers in 190 Countries
Zynga.com
Farmville, Mafia Wars, Treasure Isle...
12,000 servers on AWS
More than 230 million monthly users
100% on AWS


Netflix
9 Billion USD market cap
Migrating 100% on Amazon Web Services
10 M subscribers, 100k DVD titles
Cloud computing and OpenStack
Cloud computing and OpenStack
際際滷 about EC2
what it is?
Amazon S3
Cloud computing and OpenStack
Cloud computing and OpenStack
Scenario
III. Openstack
OpenStack?


Open source software for building private and
                public clouds
OpenStack, A Kernel of the Cloud OS
Open Source
Apache 2.0 license, NO enterprise version
Open Design
Open Design Summit
Open Development
Anyone can involve development process
Open development management via Launchpad &
 Github
Open Community
OpenStack Foundation in 2012
Openstack History

  July 2010 - Initial announcement
  October 2010 - Austin Release
  April 2011 - Cactus Release
  October 2011 - Diablo Release
  April 2012 - Essex Release
  October 2012 - Folsom Release
H董n 160 畛i 岳叩界
M畛t s畛 c担ng ty ang s畛 d畛ng Openstack
C叩c thnh ph畉n 界鞄鱈稼鞄
Openstack Compute - Nova


Thnh ph畉n qu畉n l箪 h畉 t畉ng ti nguy棚n.
S畛 d畛ng c叩c ph畉n m畛m 畉o h坦a 畛 cung c畉p c叩c
 m叩y 畉o (instance)
畉c i畛m 界鞄鱈稼鞄
H畛 tr畛 c叩c Hypervisor
   KVM - Kernel-based Virtual Machine
   LXC - Linux Containers (through libvirt)
   QEMU - Quick EMUlator
   UML - User Mode Linux
   VMWare ESX/ESXi 4.1 update 1
   Xen - XenServer 5.5, Xen Cloud Platform (XCP)
Cloud computing and OpenStack
Nova Networking
C坦 2 ki畛u IP trong Nova:
Fixed IPs: 動畛c g叩n cho instance khi kh畛i t畉o, kh担ng thay 畛i
  動畛c (private IP)
Floating IPs: 動畛c g叩n th棚m cho instance sau khi kh畛i t畉o b畛i
  admin, c坦 th畛 thay 畛i (public IP)

C坦 3 ki畛u c畉u h狸nh cho Fixed IPs:
Flat mode: c叩c instance 動畛c g叩n 畛a ch畛 theo m畛t bridge
  interface br100.
Flat DHCP mode: t動董ng t畛 nh動 Flat mode nh動ng br100 動畛c
  c畉u h狸nh nh動 m畛t DHCP server s畉 g叩n IP cho c叩c instance
Vlan DHCP mode: m畛i project s畉 動畛c g叩n cho m畛t VLAN ri棚ng.
Thnh ph畉n 界鞄鱈稼鞄
Thnh ph畉n 界鞄鱈稼鞄
   Cloud Controller - qu畉n l箪 v t動董ng 岳叩界 v畛i t畉t c畉 c叩c thnh ph畉n c畛a
    Nova
   API Server - gi畛ng nh動 m畛t Web service 畉u cu畛i c畛a Cloud Controller
   Compute Controller - cung c畉p, qu畉n l箪 ti nguy棚n t畛 c叩c instance
          Object Store - cung c畉p kh畉 nng l動u tr畛, thnh ph畉n ny i c湛ng
          v畛i Compute Controller
   Auth Manager - d畛ch v畛 x叩c th畛c cho user.
   Volume Controller - l動u tr畛 theo block- level - gi畛ng nh動 Amazon EBS
   Network Controller - t畉o qu畉n l箪 c叩c k畉t n畛i trong virtual network 畛 c叩c
    server c坦 th畛 t動董ng 岳叩界 v畛i nhau v v畛i public network
   Scheduler - ch畛n ra compute controller th鱈ch h畛p nh畉t 畛 l動u instance.
Users & Projects (Tenants)
Cloud Administrator (admin): Global role. Ton quy畛n trong h畛
th畛ng.
IT Security (itsec): Global role. IT security. C叩ch ly b畉t c畛 instance

no trong b畉t k狸 project no.
Project Manager (projectmanager): Projecrole. M畉c 畛nh cho ng動畛i

s畛 h畛u project. Th棚m b畛t user vo proj, t動董ng 岳叩界 v畛i c叩c img, ch畉y
instance.
Network Administrator (netadmin): Project role. C畉u h狸nh t動畛ng

l畛a, v c叩c rule cho network, g叩n public IP cho instance.
Developer (developer): Project role. M畉c 畛nh cho user.
Openstack Storage  Swift
L動u tr畛 d畛 li畛u (object) linh ho畉t 畉n hng Petabytes tr棚n c叩c c畛m
  server.
Gi畉m thi畛u s畛 d動 th畛a.
N但ng cao hi畛u su畉t, kh畉 nng t動董ng 岳叩界 v畛i ng動畛i d湛ng.
http://swift.openstack.org/
Thnh ph畉n 界鞄鱈稼鞄
Proxy Server - nh畉n c叩c request v
ch畛ng th畛c user.
Object Server - l動u tr畛, qu畉n l箪 c叩c 畛i
t動畛ng 動畛c l動u.
Container Server - l動u tr畛 th担ng tin v
tr畉 v畛 danh s叩ch c叩c object ang 動畛c
l動u b棚n Object Store.
Account Server - c滴ng gi畛ng nh動
Container Server nh動ng nhi畛m v畛 c畛a
n坦 l qu畉n l箪 danh s叩ch c叩c Container
The Ring - Thnh ph畉n ny s畉 t畉o m畛t
叩nh x畉 gi畛a t棚n c畛a c叩c th畛c th畛 動畛c
l動u tr棚n 挑a c畛ng v 畛a ch畛 v畉t l箪 c畛a
n坦.
Cloud computing and OpenStack
畉c i畛m 界鞄鱈稼鞄
Swift Operations
   Managing the rings (adding/removing devices, zones,
    search for devices, rebalance the ring)
   Upgrading services (one zone at a time)
   Handling driver failure (unmount; optionally remove it
    from the ring, mount a new EMPTY drive)
   Zone failure (temporal: nothing!)
   Detecting failing disks (device audit)
   Object auditor (manually after a system crash)
Openstack Image Service -
Glance

 Glance cung c畉p c叩c d畛ch v畛 khai b叩o, l動u tr畛, qu畉n l箪
              c叩c virtual machine images.
H畛 tr畛 nhi畛u 畛nh d畉ng: raw, vhd, vmdk, vdi, iso, qcow2,
                       aki, ari, ami

             http://glance.openstack.org/
Thnh ph畉n 界鞄鱈稼鞄

Glance API server - nh畉n
  c叩c hm g畛i API
Glance Registry server - l動u
  v cung c畉p c叩c th担ng tin
  (metadata) v畛 image
Image Storage - l動u tr畛 c叩c
  file image
畉c i畛m 界鞄鱈稼鞄
H畛 tr畛 c叩c 畛nh d畉ng
Openstack Identity - Keystone
Cung c畉p kh畉 nng ch畛ng th畛c, 畉t c叩c 界鞄鱈稼鞄 s叩ch ph但n
 quy畛n cho c叩c project trong Openstack.
Cloud computing and OpenStack
C叩c ki畛u d畛 li畛u trong Keystone
User: c坦 c叩c credential li棚n k畉t v畛i c叩c 'tenant' t動董ng
  畛ng.
Tenant (project) ch畛a m畛t ho畉c nhi畛u user.
Role: X叩c 畛nh c叩c quy畛n trong tenant t動董ng 畛ng cho
  c叩c user.
Token: x叩c 畛nh c叩c credential li棚n k畉t gi畛a user v
  tenant.
C叩c thao 岳叩界 ci 畉t
Add tenants
Add users
Add roles
Grant roles to users
Add endpoint templates
Map endpoint templates to zones
Openstack Dashboard  Horizon
Dashboard cung c畉p m畛t giao di畛n web nh畉m t動董ng 岳叩界 qu畉n l箪 c叩c
  thnh ph畉n c嘆n l畉i c畛a Openstack.
K畉t h畛p v畛i Keystone 畛 ch畛ng th畛c user.
http://horizon.openstack.org/
Horizon


                     "Stateless"
 Ch動a h畛 tr畛 m畛t s畛 thao 岳叩界: 畉y img l棚n glance, di
                chuy畛n instance...
          Ch動a h畛 tr畛 t畛t (t畉t c畉) c叩c API
IV. Cloud Computing Security




                               64
Security is the Major Issue




                              65
CSA - Cloud Security Alliance
    Cloud management v Operation
    Cloud management
    Qu畉n l箪 v ph叩t hi畛n c叩c m畛i nguy hi畛m
    Qu畉n l箪 v b畉o m畉t th担ng tin, d畛 li畛u
    Di chuy畛n data gi畛a c叩c nh cung c畉p, ho畉c sang m担 h狸nh truy畛n
     th畛ng
    Cloud operation
    C叩c nguy c董 security truy畛n th畛ng, v畉n 畛 recovery khi c坦 thi棚n tai
     Data Center Operations
    Kh畉 nng ph畉n 畛ng v畛i c叩c s畛 c畛 x畉y ra
    B畉o m畉t 畛ng d畛ng
    M達 h坦a v qu畉n l箪 kh坦a (Key Management)
    Qu畉n l箪 vi畛c nh畉n d畉ng, quy畛n h畉n, v truy c畉p vo h畛 th畛ng
    畉o h坦a
    Security as a Service
NIST (National Institude of Standard and Technology)
 Qu畉n l箪 v ki畛m so叩t
 S畛 h畛u d畛 li畛u, insider threats v risk management
 Ki畉n tr炭c cloud
    Cloud computing software - OpenStack, OpenNebula, 
    Hypervisor (VMM)
    Virtual traffic v VM images
    Client-side v Server-side protection
 Qu畉n l箪 vi畛c truy c畉p v ch畛ng th畛c
 Software Isolation
 Data Protection
 Availability (DDoS)
 Kh畉 nng ph畉n 畛ng v畛i c叩c s畛 c畛 x畉y ra
Security requirements
 Availability management: 畛 s畉n sng c畛a h畛 th畛ng trong m畛i
    tr動畛ng h畛p
   Access control management: qu畉n l箪 vi畛c truy c畉p
   Vulnerability and problem management: kh畉 nng ngn c畉n
    c叩c l畛 h畛ng v th但m nh畉p
   Patch and configuration management: update h畛 th畛ng
    th動畛ng xuy棚n ngay khi c坦 b畉n v叩 v c畉u h狸nh
   Countermeasure: c叩c bi畛n ph叩p 畛i ph坦 khi g畉p s畛 c畛 v畛
    security
   Cloud system using and access monitoring: qu畉n l箪 vi畛c s畛
    d畛ng v truy c畉p c畛a user v畛i cloud.
Security solutions
 i畛u khi畛n vi畛c truy c畉p vo th担ng tin, d畛 li畛u
 Qu畉n l箪 quy畛n truy c畉p c畛a users
 Qu畉n l箪 v gi叩m s叩t truy c畉p v c叩c d畛ch v畛 m畉ng, c叩c Oss, v c叩c
  畛ng d畛ng.
 SaaS:
    t畉p trung vo qu畉n tr畛 ng動畛i d畛ng, c叩c c董 ch畉 ch畛ng th畛c m畉nh v s畛 d畛ng
     one-time password, Single Sign On, qu畉n l箪 quy畛n h畉n, 
 PaaS:
    tr畛ng t但m vo t畉ng network, servers, v c叩c platform h畉 t畉ng 畛ng d畛ng.
     Ng動畛i d湛ng ch畛u tr叩ch nhi畛m qu畉n l箪 c叩c 畛ng d畛ng 畉t tr棚n platform PaaS.
 IaaS:
    truy c畉p vo c叩c server 畉o, network 畉o, h畛 th畛ng l動u tr畛 畉o, v 畛ng d畛ng
     tr棚n m畛t IaaS platform 動畛c thi畉t k畉 v qu畉n l箪 b畛i kh叩ch hng. Vi畛c qu畉n
     l箪 truy c畉p 畛 m担 h狸nh IaaS bao g畛m 2 ph畉n 界鞄鱈稼鞄: qu畉n l箪 host, network, v
     畛ng d畛ng thu畛c s畛 h畛u c畛a cloud provider trong khi ng動畛i d湛ng ph畉i qu畉n
     l箪 vi畛c truy c畉p 畉n c叩c server 畉o, l動u tr畛 畉o, networks 畉o, v c叩c 畛ng d畛ng
     ch畉y tr棚n c叩c virtual servers
Security solutions

 Partitioning: n但ng cao hi畛u su畉t t鱈nh to叩n c畛a c叩c 畛ng
  d畛ng.
 Migration: S畛 linh ho畉t v kh畉 nng d畛ch chuy畛n c叩c h畛
  th畛ng CSDL nh動ng v畉n 畉m b畉o trong su畛t.
 Workload analysis and allocation
 DDoS
OpenStack Security
 Keystone (hay OpenStack Identity) 界鞄鱈稼鞄 l thnh ph畉n
  界鞄鱈稼鞄 cho security v畛i c叩c ch畛c nng ch畛ng th畛c, 界鞄鱈稼鞄
  s叩ch, 
 User v Project: vi畛c t畉o c叩c user v project c滴ng 畉m
  b畉o vi畛c truy c畉p ch畛ng th畛c khi user kh担ng th畛 truy c畉p
  vo c叩c project kh担ng thu畛c ch畛 qu畉n c畛a m狸nh  ch畛c
  nng User v Project trong Nova.
 Keypairs: T畉o c叩c kh坦a 畛 g叩n cho instance khi kh畛i t畉o
  c滴ng l 1 c担ng c畛 畉m b畉o security khi ch畛 c坦 user 動畛c
  c畉p kh坦a m畛i 畛 th畉m quy畛n truy c畉p instance.
Keystone
 C叩c thnh ph畉n c畛a Keystone
    Endpoints - Nova, Swift, Glance ch畉y tr棚n 1 port v URL
     x叩c 畛nh g畛i l endpoint
    Regions  v湛ng server v畉t l箪 ch畉y c叩c d畛ch v畛 OpenStack
    User - A keystone authenticated user.
    Services  c叩c d畛ch v畛 qu畉n l箪 b畛i keystone.
    Role  g叩n quy畛n cho users.
    Tenant  c滴ng 界鞄鱈稼鞄 l project, bao g畛m c叩c d畛ch v畛
     endpoint, role g叩n cho user thu畛c project.
Keystone
 Keystone cung c畉p 2 ph動董ng th畛c ch畛ng th畛c:
    username/password
    token based
 Keystone cung c畉p c叩c d畛ch v畛 b畉o m畉t sau
    Token Service (th担ng tin ch畛ng th畛c 1 user)
    Catalog Service (c叩c d畛ch v畛 dnh cho 1 user)
    Policy Service (qu畉n l箪 v h畉n ch畉 vi畛c truy c畉p 畉n c叩c
     d畛ch v畛 畛i v畛i t畛ng user hay group).
Demonstration
 Thank you !

More Related Content

What's hot (20)

B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛pB叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
Le Trung Hieu
畛 ti: Ti棚u chu畉n IEEE 802.11 v c担ng ngh畛 Wifi, HAY
畛 ti: Ti棚u chu畉n IEEE 802.11 v c担ng ngh畛 Wifi, HAY畛 ti: Ti棚u chu畉n IEEE 802.11 v c担ng ngh畛 Wifi, HAY
畛 ti: Ti棚u chu畉n IEEE 802.11 v c担ng ngh畛 Wifi, HAY
D畛ch v畛 vi畉t bi tr畛n g坦i ZALO: 0909232620
Gi畛i thi畛u v tri畛n khai private cloud
Gi畛i thi畛u v tri畛n khai private cloudGi畛i thi畛u v tri畛n khai private cloud
Gi畛i thi畛u v tri畛n khai private cloud
Tue Nguyen Dinh
Lu畉n vn t狸m hi畛u Spring
Lu畉n vn t狸m hi畛u SpringLu畉n vn t狸m hi畛u Spring
Lu畉n vn t狸m hi畛u Spring
An Nguyen
Presentation i畛n to叩n 叩m m但y
Presentation   i畛n to叩n 叩m m但yPresentation   i畛n to叩n 叩m m但y
Presentation i畛n to叩n 叩m m但y
xKinAnx
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Vi畉t thu棚 tr畛n g坦i ZALO 0934573149
T狸m hi畛u v畛 OpenStack
T狸m hi畛u v畛 OpenStackT狸m hi畛u v畛 OpenStack
T狸m hi畛u v畛 OpenStack
lanhuonga3
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ngBi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
jackjohn45
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
nataliej4
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
The Boss
Cloud computing and OpenStack
Cloud computing and OpenStackCloud computing and OpenStack
Cloud computing and OpenStack
Minh Le
T狸m hi畛u v畛 Vmware
T狸m hi畛u v畛 VmwareT狸m hi畛u v畛 Vmware
T狸m hi畛u v畛 Vmware
Bich Tuyen
T畛ng quan v畛 DoS - DDoS - DRDoS
T畛ng quan v畛 DoS - DDoS - DRDoST畛ng quan v畛 DoS - DDoS - DRDoS
T畛ng quan v畛 DoS - DDoS - DRDoS
Thieu Mao
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ngB叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
jackjohn45
Gioi thieu-chung-ao-hoa
Gioi thieu-chung-ao-hoaGioi thieu-chung-ao-hoa
Gioi thieu-chung-ao-hoa
anhhaibi
Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
 Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ... Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
hieu anh
Gi叩o tr狸nh Qu畉n tr畛 m畉ng
Gi叩o tr狸nh Qu畉n tr畛 m畉ngGi叩o tr狸nh Qu畉n tr畛 m畉ng
Gi叩o tr狸nh Qu畉n tr畛 m畉ng
Tran Tien
C担ng ngh畛 畉o h坦a
C担ng ngh畛 畉o h坦aC担ng ngh畛 畉o h坦a
C担ng ngh畛 畉o h坦a
SrbIT
M担 h狸nh i畛n to叩n 叩m m但y
M担 h狸nh i畛n to叩n 叩m m但yM担 h狸nh i畛n to叩n 叩m m但y
M担 h狸nh i畛n to叩n 叩m m但y
PhamTuanKhiem
畛 ti: Thi畉t k畉 h畛 th畛ng m畉ng m叩y t鱈nh, HAY, 9 - t畉i qua zalo=> 0909232620
畛 ti: Thi畉t k畉 h畛 th畛ng m畉ng m叩y t鱈nh, HAY, 9 - t畉i qua zalo=> 0909232620畛 ti: Thi畉t k畉 h畛 th畛ng m畉ng m叩y t鱈nh, HAY, 9 - t畉i qua zalo=> 0909232620
畛 ti: Thi畉t k畉 h畛 th畛ng m畉ng m叩y t鱈nh, HAY, 9 - t畉i qua zalo=> 0909232620
D畛ch v畛 vi畉t bi tr畛n g坦i ZALO: 0909232620
B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛pB叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
B叩o c叩o t hi畉t k畉 m畉ng doanh nghi畛p
Le Trung Hieu
Gi畛i thi畛u v tri畛n khai private cloud
Gi畛i thi畛u v tri畛n khai private cloudGi畛i thi畛u v tri畛n khai private cloud
Gi畛i thi畛u v tri畛n khai private cloud
Tue Nguyen Dinh
Lu畉n vn t狸m hi畛u Spring
Lu畉n vn t狸m hi畛u SpringLu畉n vn t狸m hi畛u Spring
Lu畉n vn t狸m hi畛u Spring
An Nguyen
Presentation i畛n to叩n 叩m m但y
Presentation   i畛n to叩n 叩m m但yPresentation   i畛n to叩n 叩m m但y
Presentation i畛n to叩n 叩m m但y
xKinAnx
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Lu畉n vn: Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng ...
Vi畉t thu棚 tr畛n g坦i ZALO 0934573149
T狸m hi畛u v畛 OpenStack
T狸m hi畛u v畛 OpenStackT狸m hi畛u v畛 OpenStack
T狸m hi畛u v畛 OpenStack
lanhuonga3
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ngBi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
Bi gi畉ng thi畉t k畉, x但y d畛ng m畉ng
jackjohn45
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
X但y d畛ng, thi畉t k畉 h畛 th畛ng m畉ng c畛c b畛 (Th畛c t畉) 2225926
nataliej4
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
B叩o c叩o 畛 叩n t畛t nghi畛p "畛ng d畛ng tr鱈 tu畛 nh但n t畉o nh畉n d畉ng ch畛 vi畉t tay x但...
The Boss
Cloud computing and OpenStack
Cloud computing and OpenStackCloud computing and OpenStack
Cloud computing and OpenStack
Minh Le
T狸m hi畛u v畛 Vmware
T狸m hi畛u v畛 VmwareT狸m hi畛u v畛 Vmware
T狸m hi畛u v畛 Vmware
Bich Tuyen
T畛ng quan v畛 DoS - DDoS - DRDoS
T畛ng quan v畛 DoS - DDoS - DRDoST畛ng quan v畛 DoS - DDoS - DRDoS
T畛ng quan v畛 DoS - DDoS - DRDoS
Thieu Mao
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ngB叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
B叩o c叩o ph但n t鱈ch thi畉t k畉 m畉ng
jackjohn45
Gioi thieu-chung-ao-hoa
Gioi thieu-chung-ao-hoaGioi thieu-chung-ao-hoa
Gioi thieu-chung-ao-hoa
anhhaibi
Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
 Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ... Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
Nghi棚n c畛u v tri畛n khai h畛 th畛ng Private Cloud cho c叩c 畛ng d畛ng o t畉o v ...
hieu anh
Gi叩o tr狸nh Qu畉n tr畛 m畉ng
Gi叩o tr狸nh Qu畉n tr畛 m畉ngGi叩o tr狸nh Qu畉n tr畛 m畉ng
Gi叩o tr狸nh Qu畉n tr畛 m畉ng
Tran Tien
C担ng ngh畛 畉o h坦a
C担ng ngh畛 畉o h坦aC担ng ngh畛 畉o h坦a
C担ng ngh畛 畉o h坦a
SrbIT
M担 h狸nh i畛n to叩n 叩m m但y
M担 h狸nh i畛n to叩n 叩m m但yM担 h狸nh i畛n to叩n 叩m m但y
M担 h狸nh i畛n to叩n 叩m m但y
PhamTuanKhiem

Viewers also liked (14)

Tim hieu ve cloud computing
Tim hieu ve cloud computingTim hieu ve cloud computing
Tim hieu ve cloud computing
lanhuonga3
Cloud computing
Cloud computingCloud computing
Cloud computing
0011001178988
Bao cao th畛c t畉p i畛n to叩n 叩m m但y
Bao cao th畛c t畉p i畛n to叩n 叩m m但yBao cao th畛c t畉p i畛n to叩n 叩m m但y
Bao cao th畛c t畉p i畛n to叩n 叩m m但y
Vn n Ph畉m
Code Camp #1
Code Camp #1Code Camp #1
Code Camp #1
Dat Le Viet
Ghi nh畉n v畛 OpenStack - Nguy畛n Hong
Ghi nh畉n v畛 OpenStack - Nguy畛n HongGhi nh畉n v畛 OpenStack - Nguy畛n Hong
Ghi nh畉n v畛 OpenStack - Nguy畛n Hong
Vu Hung Nguyen
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
Phong Lam
Luan van finish
Luan van finishLuan van finish
Luan van finish
Le Luan
Bao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但yBao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但y
Van Pham
B叩o c叩o th畛c t畉p (slide power point)
B叩o c叩o th畛c t畉p (slide power point)B叩o c叩o th畛c t畉p (slide power point)
B叩o c叩o th畛c t畉p (slide power point)
Hai Te
Seminar on cloud computing by Prashant Gupta
Seminar on cloud computing by Prashant GuptaSeminar on cloud computing by Prashant Gupta
Seminar on cloud computing by Prashant Gupta
Prashant Gupta
Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing ppt
Datta Dharanikota
Cloud computing simple ppt
Cloud computing simple pptCloud computing simple ppt
Cloud computing simple ppt
Agarwaljay
Introduction of Cloud computing
Introduction of Cloud computingIntroduction of Cloud computing
Introduction of Cloud computing
Rkrishna Mishra
Tim hieu ve cloud computing
Tim hieu ve cloud computingTim hieu ve cloud computing
Tim hieu ve cloud computing
lanhuonga3
Bao cao th畛c t畉p i畛n to叩n 叩m m但y
Bao cao th畛c t畉p i畛n to叩n 叩m m但yBao cao th畛c t畉p i畛n to叩n 叩m m但y
Bao cao th畛c t畉p i畛n to叩n 叩m m但y
Vn n Ph畉m
Ghi nh畉n v畛 OpenStack - Nguy畛n Hong
Ghi nh畉n v畛 OpenStack - Nguy畛n HongGhi nh畉n v畛 OpenStack - Nguy畛n Hong
Ghi nh畉n v畛 OpenStack - Nguy畛n Hong
Vu Hung Nguyen
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
3Wings Open Mesh Cloud Wifi - Gi畉i ph叩p x但y d畛ng h畛 th畛ng wifi di畛n r畛ng tr棚n...
Phong Lam
Luan van finish
Luan van finishLuan van finish
Luan van finish
Le Luan
Bao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但yBao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但y
Van Pham
B叩o c叩o th畛c t畉p (slide power point)
B叩o c叩o th畛c t畉p (slide power point)B叩o c叩o th畛c t畉p (slide power point)
B叩o c叩o th畛c t畉p (slide power point)
Hai Te
Seminar on cloud computing by Prashant Gupta
Seminar on cloud computing by Prashant GuptaSeminar on cloud computing by Prashant Gupta
Seminar on cloud computing by Prashant Gupta
Prashant Gupta
Cloud computing simple ppt
Cloud computing simple pptCloud computing simple ppt
Cloud computing simple ppt
Agarwaljay
Introduction of Cloud computing
Introduction of Cloud computingIntroduction of Cloud computing
Introduction of Cloud computing
Rkrishna Mishra

Similar to Cloud computing and OpenStack (20)

Report amazon web services
Report amazon web servicesReport amazon web services
Report amazon web services
lanhuonga3
i棚n to叩n 叩m m但y
i棚n to叩n 叩m m但yi棚n to叩n 叩m m但y
i棚n to叩n 叩m m但y
Tue Nguyen Dinh
c畉u h狸nh cloudstack
c畉u h狸nh cloudstackc畉u h狸nh cloudstack
c畉u h狸nh cloudstack
vietbm9
Dien toan dam may Dien toan dam may Dien toan dam may
Dien toan dam may Dien toan dam may Dien toan dam mayDien toan dam may Dien toan dam may Dien toan dam may
Dien toan dam may Dien toan dam may Dien toan dam may
diepcantorusvn
Docker 101
Docker 101Docker 101
Docker 101
L但m o
畉o h坦a
畉o h坦a畉o h坦a
畉o h坦a
PhamTuanKhiem
Morden data center technology
Morden data center technologyMorden data center technology
Morden data center technology
Thnh Th動 Th叩i
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉nAzure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
bbaa50
Cac hang noi tieng Cac hang noi tieng Cac hang noi tieng
Cac hang noi tieng Cac hang noi tieng Cac hang noi tiengCac hang noi tieng Cac hang noi tieng Cac hang noi tieng
Cac hang noi tieng Cac hang noi tieng Cac hang noi tieng
diepcantorusvn
technolugy of amazon web services intro.pdf
technolugy of amazon web services intro.pdftechnolugy of amazon web services intro.pdf
technolugy of amazon web services intro.pdf
0353252309h
X但y d畛ng extension portal cho nimbus
X但y d畛ng extension portal cho nimbusX但y d畛ng extension portal cho nimbus
X但y d畛ng extension portal cho nimbus
Vu Hung Nguyen
Amazon Cloud for High Performance Websites
Amazon Cloud for High Performance WebsitesAmazon Cloud for High Performance Websites
Amazon Cloud for High Performance Websites
Trung Phan Thai
Final report for cloud computing course.pptx
Final report for cloud computing course.pptxFinal report for cloud computing course.pptx
Final report for cloud computing course.pptx
Samm877816
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NGGI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
PMC WEB
Netlogistics
NetlogisticsNetlogistics
Netlogistics
Tien Hoang
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但yLu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
lop11vn
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdfKinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Stringee JSC
Bao cao-cloud-linux-hosting
Bao cao-cloud-linux-hostingBao cao-cloud-linux-hosting
Bao cao-cloud-linux-hosting
laonap166
Phat trien ung dung tren dien toan dam may
Phat trien ung dung tren dien toan dam mayPhat trien ung dung tren dien toan dam may
Phat trien ung dung tren dien toan dam may
diepcantorusvn
Gi畛i thi畛u ASP.NET Core 2.0
Gi畛i thi畛u ASP.NET Core 2.0Gi畛i thi畛u ASP.NET Core 2.0
Gi畛i thi畛u ASP.NET Core 2.0
Hu但n B湛i 狸nh
Report amazon web services
Report amazon web servicesReport amazon web services
Report amazon web services
lanhuonga3
i棚n to叩n 叩m m但y
i棚n to叩n 叩m m但yi棚n to叩n 叩m m但y
i棚n to叩n 叩m m但y
Tue Nguyen Dinh
c畉u h狸nh cloudstack
c畉u h狸nh cloudstackc畉u h狸nh cloudstack
c畉u h狸nh cloudstack
vietbm9
Dien toan dam may Dien toan dam may Dien toan dam may
Dien toan dam may Dien toan dam may Dien toan dam mayDien toan dam may Dien toan dam may Dien toan dam may
Dien toan dam may Dien toan dam may Dien toan dam may
diepcantorusvn
Docker 101
Docker 101Docker 101
Docker 101
L但m o
Morden data center technology
Morden data center technologyMorden data center technology
Morden data center technology
Thnh Th動 Th叩i
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉nAzure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n Azure c董 b畉n
bbaa50
Cac hang noi tieng Cac hang noi tieng Cac hang noi tieng
Cac hang noi tieng Cac hang noi tieng Cac hang noi tiengCac hang noi tieng Cac hang noi tieng Cac hang noi tieng
Cac hang noi tieng Cac hang noi tieng Cac hang noi tieng
diepcantorusvn
technolugy of amazon web services intro.pdf
technolugy of amazon web services intro.pdftechnolugy of amazon web services intro.pdf
technolugy of amazon web services intro.pdf
0353252309h
X但y d畛ng extension portal cho nimbus
X但y d畛ng extension portal cho nimbusX但y d畛ng extension portal cho nimbus
X但y d畛ng extension portal cho nimbus
Vu Hung Nguyen
Amazon Cloud for High Performance Websites
Amazon Cloud for High Performance WebsitesAmazon Cloud for High Performance Websites
Amazon Cloud for High Performance Websites
Trung Phan Thai
Final report for cloud computing course.pptx
Final report for cloud computing course.pptxFinal report for cloud computing course.pptx
Final report for cloud computing course.pptx
Samm877816
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NGGI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
GI畛I THI畛U V畛 M HNH 畛NG D畛NG M畉NG
PMC WEB
Netlogistics
NetlogisticsNetlogistics
Netlogistics
Tien Hoang
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但yLu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
Lu畉n vn Nghi棚n c畛u c董 ch畉 chia s畉 ti nguy棚n m叩y 叩o trong i畛n to叩n 叩m m但y
lop11vn
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdfKinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Kinh nghie味m trien khai K8s ta味i Stringee - Mr Tran Tien.pdf
Stringee JSC
Bao cao-cloud-linux-hosting
Bao cao-cloud-linux-hostingBao cao-cloud-linux-hosting
Bao cao-cloud-linux-hosting
laonap166
Phat trien ung dung tren dien toan dam may
Phat trien ung dung tren dien toan dam mayPhat trien ung dung tren dien toan dam may
Phat trien ung dung tren dien toan dam may
diepcantorusvn
Gi畛i thi畛u ASP.NET Core 2.0
Gi畛i thi畛u ASP.NET Core 2.0Gi畛i thi畛u ASP.NET Core 2.0
Gi畛i thi畛u ASP.NET Core 2.0
Hu但n B湛i 狸nh

More from Minh Le (9)

Blackstone
BlackstoneBlackstone
Blackstone
Minh Le
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da NangDien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Minh Le
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT  N畉ng - M畉ng 担 th畛 (MAN) v Tr...Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT  N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Minh Le
際際滷 nagios
際際滷 nagios際際滷 nagios
際際滷 nagios
Minh Le
Infosec cert service
Infosec cert serviceInfosec cert service
Infosec cert service
Minh Le
SK infosec company profile
SK infosec company profileSK infosec company profile
SK infosec company profile
Minh Le
Custom defense - Blake final
Custom defense  - Blake finalCustom defense  - Blake final
Custom defense - Blake final
Minh Le
Sing Tel - Designing security into datacenter - Gerald Tang
Sing Tel - Designing security into datacenter - Gerald TangSing Tel - Designing security into datacenter - Gerald Tang
Sing Tel - Designing security into datacenter - Gerald Tang
Minh Le
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Minh Le
Blackstone
BlackstoneBlackstone
Blackstone
Minh Le
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da NangDien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Dien toan dam may nguon mo - Ung dung trung tam du lieu Da Nang
Minh Le
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT  N畉ng - M畉ng 担 th畛 (MAN) v Tr...Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT  N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Chia s畉 kinh nghi畛m ph叩t tri畛n h畉 t畉ng CNTT N畉ng - M畉ng 担 th畛 (MAN) v Tr...
Minh Le
際際滷 nagios
際際滷 nagios際際滷 nagios
際際滷 nagios
Minh Le
Infosec cert service
Infosec cert serviceInfosec cert service
Infosec cert service
Minh Le
SK infosec company profile
SK infosec company profileSK infosec company profile
SK infosec company profile
Minh Le
Custom defense - Blake final
Custom defense  - Blake finalCustom defense  - Blake final
Custom defense - Blake final
Minh Le
Sing Tel - Designing security into datacenter - Gerald Tang
Sing Tel - Designing security into datacenter - Gerald TangSing Tel - Designing security into datacenter - Gerald Tang
Sing Tel - Designing security into datacenter - Gerald Tang
Minh Le
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Empowering the business while efficiently mitigating risks - Eva Chen (Trend ...
Minh Le

Cloud computing and OpenStack

  • 2. N畛i dung th畉o lu畉n I. Cloud Computing Gi畛i thi畛u v畛 Cloud Computing Virtualization II. Amazon Web Services L畛ch s畛 ph叩t tri畛n C叩c d畛ch v畛 c畛a AWS III. Openstack L畛ch s畛 ph叩t tri畛n C叩c thnh ph畉n 界鞄鱈稼鞄 N畛i dung th畛 nghi畛m IV. Cloud computing security CSA, NIST, Security solutions OpenStack security
  • 5. What is the cloud? IT as a service What is Cloud allows access to services without user technical knowledge or control of supporting infrastructure Cloud Computing? Best described in terms of what happened to mechanical power over 100 yrs ago Now computers are simple devices connected to the larger cloud Data processing, storage and software applications that used to run locally are now being supplied by big central computing stations. They're becoming, in essence, computing utilities.
  • 6. Cloud computing Cloud Computing t畉t c畉 c叩c d畛ch v畛 v l動u tr畛 tr棚n cloud c坦 th畛 truy c畉p 畛 b畉t k畛 但u ch畛 c畉n k畉t n畛i internet
  • 7. Why Cloud Computing Khai th叩c t畛i a hi畛u nng, 畉c bi畛t c畛a Data Center Ph畉n l畛n c叩c Data Center 畛u ch畛 畛nh ti nguy棚n v動畛t nhu c畉u Chia s畉 ti nguy棚n T畉p trung h坦a c董 s畛 h畉 t畉ng Ti畉t ki畛m ph畉n c畛ng Ti畉t ki畛m, gi畉m chi ph鱈 畉u t動 a ph動董ng ti畛n Kh畉 nng linh ho畉t cao Tr畉 theo nhu c畉u th畛c t畉
  • 8. 畛nh ngh挑a Cloud Computing C叩c t鱈nh nng M担 h狸nh tri畛n khai M担 h狸nh d畛ch v畛
  • 9. 畛nh ngh挑a Cloud Computing (tt) C叩c t鱈nh nng 1. Thu h畛i v c畉p ph叩t ti nguy棚n 2. Truy c畉p th担ng qua c叩c chu畉n m畉ng 3. o l動畛ng d畛ch v畛 4. T畛 ph畛c v畛 theo nhu c畉u 5. Chia s畉 ti nguy棚n M担 h狸nh tri畛n khai 1. 叩m m但y ri棚ng 2. 叩m m但y c担ng c畛ng 3. 叩m m但y lai 4. 叩m m但y c畛ng 畛ng
  • 10. 畛nh ngh挑a Cloud Computing (tt) M担 h狸nh d畛ch v畛 1. SaaS: Software as a Service 2. PaaS: Platform as a Service 3. IaaS: Infrastructure as a service
  • 11. 畛ng d畛ng Cloud Computing Chuy畛n sang s畛 d畛ng d畛ch v畛 CRM package c畛a SaaS m畛t SaaS provider nh動 Salesforce.com thay v狸 ph畉i d畛ng 1 CRM system Chuy畛n sang s畛 d畛ng exchange server thay v狸 ph畉i x但y d畛ng mail server. PaaS C畉n m畛t kh担ng gian l動u tr畛 l畛n 畛 l動u tr畛 s畛 l動畛ng l畛n files - s畛 d畛ng d畛ch v畛 S3 c畛a amazon. C畉n m畛t m担i tr動畛ng 畛 ph叩t tri畛n 畛ng d畛ng Java Ch畉y m畛t batch job - S畛 d畛ng Amazon EC2. IaaS Host m畛t website, nh動ng trong m畛t th畛i gian ng畉n thay v狸 畉u t動 chi ph鱈 ban 畉u, s畛 d畛ng Flexiscale.
  • 13. IaaS PaaS - SaaS Cloud Infrastructure Cloud Infrastructure Cloud Infrastructure IaaS Software as a Service PaaS PaaS (SaaS) SaaS SaaS SaaS Architectures Cloud Infrastructure Cloud Infrastructure IaaS Platform as a Service (PaaS) PaaS PaaS Architectures Cloud Infrastructure IaaS Infrastructure as a Service (IaaS) Architectures
  • 14. Virtualization Technologies - Background Mode Switching Kernel mode User mode VMM (Virtual Machine Monitor) VMM 坦ng vai tr嘆 nh動 m畛t ph畉n m畛m trung gian ch畉y tr棚n HH 畛 chia s畉 ti nguy棚n v畛i HH. V鱈 d畛: VMware workstation, Virtual PC, KVM. VMM 坦ng vai tr嘆 l m畛t hypervisor ch畉y tr棚n ph畉n c畛ng. V鱈 d畛: VMware ESXi, Hyper-V, Xen. Hypervisor Monolithic: ESXi Micro hypervisor: Hyper-V
  • 15. Monolithic vs Micro-kernelized Monolithic hypervisor Driver ri棚ng bi畛t 畛 truy c畉p ti nguy棚n ph畉n c畛ng b棚n d動畛i. C叩c VMs truy c畉p ti nguy棚n h畛 th畛ng th担ng qua drivers c畛a hypervisor. 働u i畛m: hi畛u su畉t cao Nh動畛c i畛m: khi driver tr棚n hypervisor b畛 s畛 c畛 th狸 c畉 h畛 th畛ng ng動ng ho畉t 畛ng, ho畉c ph畉i 畛i m畉t v畛i v畉n 畛 an ninh khi drivers c坦 th畛 b畛 gi畉 d畉ng b畛i malware, m畛t r畛i ro trong m担i tr動畛ng 畉o h坦a. .Micro-kernelized hypervisor: kh担ng c坦 driver b棚n trong hypervisor m ch畉y tr畛c ti畉p tr棚n m畛i partition. M畛t VM l partition cha qu畉n l箪 memory, l動u tr畛 drivers, v kh畛i t畉o c叩c partition con. 働u i畛m: s畛 an ton v tin c畉y. Nh動畛c i畛m: 畛 s畉n sng (availability) khi partition cha g畉p s畛 c畛.
  • 16. C叩c lo畉i 畉o h坦a Full-virtualization Cung c畉p m叩y 畉o m担 ph畛ng c畛a 1 m叩y ch畛 th畉t v畛i 畉y 畛 t畉t c畉 c叩c t鱈nh nng bao g畛m input/output operations, interrupts, memory access, Nh動畛c i畛m: Hi畛u nng th畉p (mode switching). Xen, VMWare workstation, Virtual Box, Qemu/KVM, v Microsoft Virtual Server h畛 tr畛 lo畉i 畉o h坦a ny
  • 17. C叩c lo畉i 畉o h坦a Para-virtualization K畛 thu畉t 畉o h坦a 動畛c h畛 tr畛 v i畛u khi畛n b畛i 1 hypervisor nh動ng c叩c Oss c畛a guest th畛c thi c叩c l畛nh kh担ng ph畉i th担ng qua Hypervisor (hay b畉t k畛 1 tr狸nh qu畉n l箪 m叩y 畉o no) n棚n kh担ng b畛 h畉n ch畉 v畛 quy畛n h畉n. 働u i畛m: hi畛u su畉t cao Nh動畛c i畛m: c叩c OS bi畉t ang ch畉y tr棚n 1 n畛n t畉ng ph畉n c畛ng 畉o v kh坦 c畉u h狸nh ci 畉t. Xen, VMware, Hyper-V, v UML
  • 18. C叩c lo畉i 畉o h坦a OS-level virtualization (Isolation) T畉o v ch畉y 動畛c nhi畛u m叩y 畉o c叩ch ly v an ton (secure) d湛ng chung 1 HH. 働u i畛m: b畉o tr狸 nhanh ch坦ng n棚n 動畛c 畛ng d畛ng r畛ng r達i trong c叩c l挑nh v畛c hosting. Ch畛 c坦 tr棚n HH Linux. OpenVZ, Virtuozzo, Linux- VServer, Solaris Zones, v FreeBSD Jails.
  • 20. Cloud vs Virtualization Virtualization Cloud Infrastructure Application Hypervisor & related tools. Services. Computer OS. Service catalog. Compute, network, and storage. IaaS, PaaS, SaaS. IT manager, IT administrator Business app owner, developer, end users. Pay as you go Provision resource
  • 21. II. Amazon Web Services http://aws.amazon.com
  • 22. Amazon.com: a digital shop around the corner
  • 23. ... and a digital colossus.
  • 24. Customers in 190 Countries
  • 25. Zynga.com Farmville, Mafia Wars, Treasure Isle... 12,000 servers on AWS More than 230 million monthly users 100% on AWS Netflix 9 Billion USD market cap Migrating 100% on Amazon Web Services 10 M subscribers, 100k DVD titles
  • 34. OpenStack? Open source software for building private and public clouds
  • 35. OpenStack, A Kernel of the Cloud OS
  • 36. Open Source Apache 2.0 license, NO enterprise version Open Design Open Design Summit Open Development Anyone can involve development process Open development management via Launchpad & Github Open Community OpenStack Foundation in 2012
  • 37. Openstack History July 2010 - Initial announcement October 2010 - Austin Release April 2011 - Cactus Release October 2011 - Diablo Release April 2012 - Essex Release October 2012 - Folsom Release
  • 38. H董n 160 畛i 岳叩界
  • 39. M畛t s畛 c担ng ty ang s畛 d畛ng Openstack
  • 40. C叩c thnh ph畉n 界鞄鱈稼鞄
  • 41. Openstack Compute - Nova Thnh ph畉n qu畉n l箪 h畉 t畉ng ti nguy棚n. S畛 d畛ng c叩c ph畉n m畛m 畉o h坦a 畛 cung c畉p c叩c m叩y 畉o (instance)
  • 43. H畛 tr畛 c叩c Hypervisor KVM - Kernel-based Virtual Machine LXC - Linux Containers (through libvirt) QEMU - Quick EMUlator UML - User Mode Linux VMWare ESX/ESXi 4.1 update 1 Xen - XenServer 5.5, Xen Cloud Platform (XCP)
  • 45. Nova Networking C坦 2 ki畛u IP trong Nova: Fixed IPs: 動畛c g叩n cho instance khi kh畛i t畉o, kh担ng thay 畛i 動畛c (private IP) Floating IPs: 動畛c g叩n th棚m cho instance sau khi kh畛i t畉o b畛i admin, c坦 th畛 thay 畛i (public IP) C坦 3 ki畛u c畉u h狸nh cho Fixed IPs: Flat mode: c叩c instance 動畛c g叩n 畛a ch畛 theo m畛t bridge interface br100. Flat DHCP mode: t動董ng t畛 nh動 Flat mode nh動ng br100 動畛c c畉u h狸nh nh動 m畛t DHCP server s畉 g叩n IP cho c叩c instance Vlan DHCP mode: m畛i project s畉 動畛c g叩n cho m畛t VLAN ri棚ng.
  • 47. Thnh ph畉n 界鞄鱈稼鞄 Cloud Controller - qu畉n l箪 v t動董ng 岳叩界 v畛i t畉t c畉 c叩c thnh ph畉n c畛a Nova API Server - gi畛ng nh動 m畛t Web service 畉u cu畛i c畛a Cloud Controller Compute Controller - cung c畉p, qu畉n l箪 ti nguy棚n t畛 c叩c instance Object Store - cung c畉p kh畉 nng l動u tr畛, thnh ph畉n ny i c湛ng v畛i Compute Controller Auth Manager - d畛ch v畛 x叩c th畛c cho user. Volume Controller - l動u tr畛 theo block- level - gi畛ng nh動 Amazon EBS Network Controller - t畉o qu畉n l箪 c叩c k畉t n畛i trong virtual network 畛 c叩c server c坦 th畛 t動董ng 岳叩界 v畛i nhau v v畛i public network Scheduler - ch畛n ra compute controller th鱈ch h畛p nh畉t 畛 l動u instance.
  • 48. Users & Projects (Tenants) Cloud Administrator (admin): Global role. Ton quy畛n trong h畛 th畛ng. IT Security (itsec): Global role. IT security. C叩ch ly b畉t c畛 instance no trong b畉t k狸 project no. Project Manager (projectmanager): Projecrole. M畉c 畛nh cho ng動畛i s畛 h畛u project. Th棚m b畛t user vo proj, t動董ng 岳叩界 v畛i c叩c img, ch畉y instance. Network Administrator (netadmin): Project role. C畉u h狸nh t動畛ng l畛a, v c叩c rule cho network, g叩n public IP cho instance. Developer (developer): Project role. M畉c 畛nh cho user.
  • 49. Openstack Storage Swift L動u tr畛 d畛 li畛u (object) linh ho畉t 畉n hng Petabytes tr棚n c叩c c畛m server. Gi畉m thi畛u s畛 d動 th畛a. N但ng cao hi畛u su畉t, kh畉 nng t動董ng 岳叩界 v畛i ng動畛i d湛ng. http://swift.openstack.org/
  • 50. Thnh ph畉n 界鞄鱈稼鞄 Proxy Server - nh畉n c叩c request v ch畛ng th畛c user. Object Server - l動u tr畛, qu畉n l箪 c叩c 畛i t動畛ng 動畛c l動u. Container Server - l動u tr畛 th担ng tin v tr畉 v畛 danh s叩ch c叩c object ang 動畛c l動u b棚n Object Store. Account Server - c滴ng gi畛ng nh動 Container Server nh動ng nhi畛m v畛 c畛a n坦 l qu畉n l箪 danh s叩ch c叩c Container The Ring - Thnh ph畉n ny s畉 t畉o m畛t 叩nh x畉 gi畛a t棚n c畛a c叩c th畛c th畛 動畛c l動u tr棚n 挑a c畛ng v 畛a ch畛 v畉t l箪 c畛a n坦.
  • 53. Swift Operations Managing the rings (adding/removing devices, zones, search for devices, rebalance the ring) Upgrading services (one zone at a time) Handling driver failure (unmount; optionally remove it from the ring, mount a new EMPTY drive) Zone failure (temporal: nothing!) Detecting failing disks (device audit) Object auditor (manually after a system crash)
  • 54. Openstack Image Service - Glance Glance cung c畉p c叩c d畛ch v畛 khai b叩o, l動u tr畛, qu畉n l箪 c叩c virtual machine images. H畛 tr畛 nhi畛u 畛nh d畉ng: raw, vhd, vmdk, vdi, iso, qcow2, aki, ari, ami http://glance.openstack.org/
  • 55. Thnh ph畉n 界鞄鱈稼鞄 Glance API server - nh畉n c叩c hm g畛i API Glance Registry server - l動u v cung c畉p c叩c th担ng tin (metadata) v畛 image Image Storage - l動u tr畛 c叩c file image
  • 57. H畛 tr畛 c叩c 畛nh d畉ng
  • 58. Openstack Identity - Keystone Cung c畉p kh畉 nng ch畛ng th畛c, 畉t c叩c 界鞄鱈稼鞄 s叩ch ph但n quy畛n cho c叩c project trong Openstack.
  • 60. C叩c ki畛u d畛 li畛u trong Keystone User: c坦 c叩c credential li棚n k畉t v畛i c叩c 'tenant' t動董ng 畛ng. Tenant (project) ch畛a m畛t ho畉c nhi畛u user. Role: X叩c 畛nh c叩c quy畛n trong tenant t動董ng 畛ng cho c叩c user. Token: x叩c 畛nh c叩c credential li棚n k畉t gi畛a user v tenant.
  • 61. C叩c thao 岳叩界 ci 畉t Add tenants Add users Add roles Grant roles to users Add endpoint templates Map endpoint templates to zones
  • 62. Openstack Dashboard Horizon Dashboard cung c畉p m畛t giao di畛n web nh畉m t動董ng 岳叩界 qu畉n l箪 c叩c thnh ph畉n c嘆n l畉i c畛a Openstack. K畉t h畛p v畛i Keystone 畛 ch畛ng th畛c user. http://horizon.openstack.org/
  • 63. Horizon "Stateless" Ch動a h畛 tr畛 m畛t s畛 thao 岳叩界: 畉y img l棚n glance, di chuy畛n instance... Ch動a h畛 tr畛 t畛t (t畉t c畉) c叩c API
  • 64. IV. Cloud Computing Security 64
  • 65. Security is the Major Issue 65
  • 66. CSA - Cloud Security Alliance Cloud management v Operation Cloud management Qu畉n l箪 v ph叩t hi畛n c叩c m畛i nguy hi畛m Qu畉n l箪 v b畉o m畉t th担ng tin, d畛 li畛u Di chuy畛n data gi畛a c叩c nh cung c畉p, ho畉c sang m担 h狸nh truy畛n th畛ng Cloud operation C叩c nguy c董 security truy畛n th畛ng, v畉n 畛 recovery khi c坦 thi棚n tai Data Center Operations Kh畉 nng ph畉n 畛ng v畛i c叩c s畛 c畛 x畉y ra B畉o m畉t 畛ng d畛ng M達 h坦a v qu畉n l箪 kh坦a (Key Management) Qu畉n l箪 vi畛c nh畉n d畉ng, quy畛n h畉n, v truy c畉p vo h畛 th畛ng 畉o h坦a Security as a Service
  • 67. NIST (National Institude of Standard and Technology) Qu畉n l箪 v ki畛m so叩t S畛 h畛u d畛 li畛u, insider threats v risk management Ki畉n tr炭c cloud Cloud computing software - OpenStack, OpenNebula, Hypervisor (VMM) Virtual traffic v VM images Client-side v Server-side protection Qu畉n l箪 vi畛c truy c畉p v ch畛ng th畛c Software Isolation Data Protection Availability (DDoS) Kh畉 nng ph畉n 畛ng v畛i c叩c s畛 c畛 x畉y ra
  • 68. Security requirements Availability management: 畛 s畉n sng c畛a h畛 th畛ng trong m畛i tr動畛ng h畛p Access control management: qu畉n l箪 vi畛c truy c畉p Vulnerability and problem management: kh畉 nng ngn c畉n c叩c l畛 h畛ng v th但m nh畉p Patch and configuration management: update h畛 th畛ng th動畛ng xuy棚n ngay khi c坦 b畉n v叩 v c畉u h狸nh Countermeasure: c叩c bi畛n ph叩p 畛i ph坦 khi g畉p s畛 c畛 v畛 security Cloud system using and access monitoring: qu畉n l箪 vi畛c s畛 d畛ng v truy c畉p c畛a user v畛i cloud.
  • 69. Security solutions i畛u khi畛n vi畛c truy c畉p vo th担ng tin, d畛 li畛u Qu畉n l箪 quy畛n truy c畉p c畛a users Qu畉n l箪 v gi叩m s叩t truy c畉p v c叩c d畛ch v畛 m畉ng, c叩c Oss, v c叩c 畛ng d畛ng. SaaS: t畉p trung vo qu畉n tr畛 ng動畛i d畛ng, c叩c c董 ch畉 ch畛ng th畛c m畉nh v s畛 d畛ng one-time password, Single Sign On, qu畉n l箪 quy畛n h畉n, PaaS: tr畛ng t但m vo t畉ng network, servers, v c叩c platform h畉 t畉ng 畛ng d畛ng. Ng動畛i d湛ng ch畛u tr叩ch nhi畛m qu畉n l箪 c叩c 畛ng d畛ng 畉t tr棚n platform PaaS. IaaS: truy c畉p vo c叩c server 畉o, network 畉o, h畛 th畛ng l動u tr畛 畉o, v 畛ng d畛ng tr棚n m畛t IaaS platform 動畛c thi畉t k畉 v qu畉n l箪 b畛i kh叩ch hng. Vi畛c qu畉n l箪 truy c畉p 畛 m担 h狸nh IaaS bao g畛m 2 ph畉n 界鞄鱈稼鞄: qu畉n l箪 host, network, v 畛ng d畛ng thu畛c s畛 h畛u c畛a cloud provider trong khi ng動畛i d湛ng ph畉i qu畉n l箪 vi畛c truy c畉p 畉n c叩c server 畉o, l動u tr畛 畉o, networks 畉o, v c叩c 畛ng d畛ng ch畉y tr棚n c叩c virtual servers
  • 70. Security solutions Partitioning: n但ng cao hi畛u su畉t t鱈nh to叩n c畛a c叩c 畛ng d畛ng. Migration: S畛 linh ho畉t v kh畉 nng d畛ch chuy畛n c叩c h畛 th畛ng CSDL nh動ng v畉n 畉m b畉o trong su畛t. Workload analysis and allocation DDoS
  • 71. OpenStack Security Keystone (hay OpenStack Identity) 界鞄鱈稼鞄 l thnh ph畉n 界鞄鱈稼鞄 cho security v畛i c叩c ch畛c nng ch畛ng th畛c, 界鞄鱈稼鞄 s叩ch, User v Project: vi畛c t畉o c叩c user v project c滴ng 畉m b畉o vi畛c truy c畉p ch畛ng th畛c khi user kh担ng th畛 truy c畉p vo c叩c project kh担ng thu畛c ch畛 qu畉n c畛a m狸nh ch畛c nng User v Project trong Nova. Keypairs: T畉o c叩c kh坦a 畛 g叩n cho instance khi kh畛i t畉o c滴ng l 1 c担ng c畛 畉m b畉o security khi ch畛 c坦 user 動畛c c畉p kh坦a m畛i 畛 th畉m quy畛n truy c畉p instance.
  • 72. Keystone C叩c thnh ph畉n c畛a Keystone Endpoints - Nova, Swift, Glance ch畉y tr棚n 1 port v URL x叩c 畛nh g畛i l endpoint Regions v湛ng server v畉t l箪 ch畉y c叩c d畛ch v畛 OpenStack User - A keystone authenticated user. Services c叩c d畛ch v畛 qu畉n l箪 b畛i keystone. Role g叩n quy畛n cho users. Tenant c滴ng 界鞄鱈稼鞄 l project, bao g畛m c叩c d畛ch v畛 endpoint, role g叩n cho user thu畛c project.
  • 73. Keystone Keystone cung c畉p 2 ph動董ng th畛c ch畛ng th畛c: username/password token based Keystone cung c畉p c叩c d畛ch v畛 b畉o m畉t sau Token Service (th担ng tin ch畛ng th畛c 1 user) Catalog Service (c叩c d畛ch v畛 dnh cho 1 user) Policy Service (qu畉n l箪 v h畉n ch畉 vi畛c truy c畉p 畉n c叩c d畛ch v畛 畛i v畛i t畛ng user hay group).