Hashicorp Vault: Open Source Secrets Management at #OPEN18Kangaroot
?
HashiCorp Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. We'll show how this works.
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...Amazon Web Services
?
Come to this session to learn how Amazon DynamoDB was built as the hyper-scale database for internet-scale applications. In January 2012, Amazon launched DynamoDB, a cloud-based NoSQL database service designed from the ground up to support extreme scale, with the security, availability, performance, and manageability needed to run mission-critical workloads. This session discloses for the first time the underpinnings of DynamoDB, and how we run a fully managed nonrelational database used by more than 100,000 customers. We cover the underlying technical aspects of how an application works with DynamoDB for authentication, metadata, storage nodes, streams, backup, and global replication.
1. The document discusses microservices architecture and how Netflix transitioned from a monolithic architecture to microservices. Key aspects discussed include breaking the monolith into many small, independent services that are loosely coupled.
2. Netflix's microservices architecture is composed of hundreds of microservices running on thousands of servers. Each service focuses on doing a small, well-defined piece of work. Services communicate through well-defined APIs and share no code or databases.
3. The document provides examples of how other companies like Samsung and Vingle have also adopted microservices architectures on AWS, breaking monolithic applications into independent, scalable services. This allows for independent deployments, rapid innovation, and improved resilience.
The document discusses redundancy connections between on-premises environments and AWS. It introduces AWS Network Solutions Architect Kikuchi Nobuaki and the agenda which includes why redundancy is needed, options for redundancy, achieving higher availability, operating securely, and conclusions. Redundancy is important to ensure reliable connectivity between on-premises networks and AWS VPCs. The document reviews example outages and AWS' efforts to ensure availability. Common redundancy options with AWS include connecting with multiple Direct Connect circuits or using a combination of Direct Connect and VPN connections.
Amazon DynamoDB Under the Hood: How We Built a Hyper-Scale Database (DAT321) ...Amazon Web Services
?
Come to this session to learn how Amazon DynamoDB was built as the hyper-scale database for internet-scale applications. In January 2012, Amazon launched DynamoDB, a cloud-based NoSQL database service designed from the ground up to support extreme scale, with the security, availability, performance, and manageability needed to run mission-critical workloads. This session discloses for the first time the underpinnings of DynamoDB, and how we run a fully managed nonrelational database used by more than 100,000 customers. We cover the underlying technical aspects of how an application works with DynamoDB for authentication, metadata, storage nodes, streams, backup, and global replication.
1. The document discusses microservices architecture and how Netflix transitioned from a monolithic architecture to microservices. Key aspects discussed include breaking the monolith into many small, independent services that are loosely coupled.
2. Netflix's microservices architecture is composed of hundreds of microservices running on thousands of servers. Each service focuses on doing a small, well-defined piece of work. Services communicate through well-defined APIs and share no code or databases.
3. The document provides examples of how other companies like Samsung and Vingle have also adopted microservices architectures on AWS, breaking monolithic applications into independent, scalable services. This allows for independent deployments, rapid innovation, and improved resilience.
The document discusses redundancy connections between on-premises environments and AWS. It introduces AWS Network Solutions Architect Kikuchi Nobuaki and the agenda which includes why redundancy is needed, options for redundancy, achieving higher availability, operating securely, and conclusions. Redundancy is important to ensure reliable connectivity between on-premises networks and AWS VPCs. The document reviews example outages and AWS' efforts to ensure availability. Common redundancy options with AWS include connecting with multiple Direct Connect circuits or using a combination of Direct Connect and VPN connections.
1. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
? ? ?
AWS Korea / Solutions Architect
AWS KMS? ???? ???
AWS ??? ???? ??
??
2. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??
AWS ??? ??
? ?? ? ??? ???
? ?? ? ??? ???
KMS ?? ????
? Infrastructure ??
? IAM ??
? ?? ?? ??
? ??? ?? ??
? ?? ?? ??
3. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ??? ??
4. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??????? ???
???? ??:
? ?? ??? ??
? ?? ????? ??? ??
? ???? ?????? ? ???? ???? ??
? ???? ???? ?? ???? ?? ? ???? ???? ??
IT ?? ??
? ??
?? ??
????? ??? ?? ???
?? ? ??
??? ??
??? ???
?? ??? ??
5. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ???? ???? ?? ??? ??
??? ??
? ??? ??
? ???? ?? ?? C ??? ??
??? ??, TLS, IPsec
? ??/?? ?? - AWS Snowball
? ??? ??
? ??? ?? ??? ????
? ?? ??? C ??? ??, ??,
????, ?? ???, ?? ???
? ??? ??
? ??? ?? ??? ???? - CCTV
??? ??
? ??? ??
? ???? ???? C VPC, Security
Groups, NACL ?
? ?? ??? C TLS, IPsec
? ??? ??
? ??? ???? ?? ??? ?? ??
? ??? ??? C ?? ???? ??
??? ??, ??, ????, ?? ???,
?? ??? ???
? ??? ??
? ???? ?? ??? ???? C FIPS
140-2 ?? ??
6. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ? ??? ???
7. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??? ??? ? ???? ?? TLS??
??? ?? ??? ???? ????? ??:
Amazon EC2? ???? ?? ????????
Elastic Load Balancing (CLB/ALB) ???
Amazon CloudFront ???
Amazon API Gateway ???
8. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS Certificate Manager (ACM)
? ??? AWS ????? ?? TLS??? ??:
? Elastic Load Balancing (CLB/ALB)
? Amazon CloudFront
? Amazon API Gateway
? AWS Elastic Beanstalk
??? ??/??/??/?? ??? AWS? ???
? ? ??? ???? ?? ?? ?? ??
? ??? ??? ? ??? ?? ??
? ??? ??? ?? ??
DNS ?? ? ??? ??? ?? ??? ??(DV)
Transparency Log ?? ??
9. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
AWS ACM Private Certificate Authority
?? SSL/TLS ??? ????(CA)? ????? ??
? ?? ??? ???, API G/W, SSL VPN, IoT ?? ?
???? ??? ????
? RSA 2048 / RSA 4096 / ECDSA P256 / ECDSA P384
??? ???? PKI ??? AWS? ???
? ??CA ???? ???? ??
? ???? ??? ??(FIPS 140-2 Level 3? ???? HSM)
? ??? ?? ??(CRL)?? ??
?? ??
? N. Virginia, Ohio, Oregon, Singapore, Sydney, Tokyo, Canada, Frankfurt, Ireland
10. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
TLS? ? ???? ?? C S2N
? ?? ?? ??? ?? ??? ?? AWS? ??? TLS ?????
? SSL v3 / TLS 1.0 / TLS 1.1 / TLS 1.2
? ?? ???? ?? TLS ??? ??(extension) ??? ??; ~6,000 ??
??? ??
? ??? AWS?????? ?????, ?? ??? ??
https://github.com/awslabs/s2n
11. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
Virtual Private Networking
AWS ??? VPN
??? VPC? ?? ??? ???? IPsec ?? VPN?? ??.
AWS VPN CloudHub
??? VPC? ???? ??? ???? IPsec ???? ???? ?? VPN ??.
??? ?? ????? ?? VPN
EC2??? VPN S/W? ???? ??? ???? ??.
12. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
?? ? ??? ???
13. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
??? ??? ??? ??
??
???
???? /
?????
????
???
?????
??? ??
????
??? ?
??? ?
(???)
??? ???? ?
(???)
? ?? ??
? ????
?
?? ???(Envelop Encryption)
15. ? 2018, Amazon Web Services, Inc. or Its Affiliates. All rights reserved.
????? ? ???(Client-Side Encryption)
A W S E n c r y p t i o n S D K , S 3 / E M R F S / D y n a m o D B c l i e n t s , c u s t o m e r - s u p p l i e d
?? IDC?
??
??????
EC2?? ??
??? ???
??? ?? ?????
??? ??? ??? EC2?? ??
??????
AWS??? ?? ???? ???
AWS
KMS
AWS
CloudHSM