With the rise of the cloud, every aspect of IT has been shaken to its core. The fundamentals for building systems are changing, and although many of the principles that underpin security still ring true, their implementation has become unrecognizable. This practical book provides recipes for AWS, Azure, and GCP to help you enhance the security of your own cloud native systems.
Based on his hard-earned experience working with some of the world's biggest enterprises and rapidly iterating startups, consultant Josh Armitage covers the trade-offs that security professionals, developers, and infrastructure gurus need to make when working with different cloud providers. Each recipe discusses these inherent compromises, as well as where clouds have similarities and where they're fundamentally different.
Learn how the cloud provides security superior to what was achievable in an on-premises world
Understand the principles and mental models that enable you to make optimal trade-offs as part of your solution
Learn how to implement existing solutions that are robust and secure, and devise design solutions to new and interesting problems
Deal with security challenges and solutions both horizontally and vertically within your business
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A recipe-driven field guide for engineers who must secure real cloud estates across AWS, Azure, and GCP, translating enduring security principles into concrete, infrastructure-as-code implementations. Best for security professionals, platform engineers, and developers who already know one cloud and need portable, trade-off-aware patterns.
【Book Arc】
- **Opening (~0%–10%)**: Frames the shift from on-premises to cloud-native security, introduces mental models (defense in depth, security as job zero, quality built in) and team topologies that shape how security work is organized.
- **Early (~10%–30%)**: Account and identity foundations — organization/folder/project structures, per-workload project separation, region locking, user and service-account provisioning, and standing up security visibility (SIEM/SOC, audit trails, log centralization).
- **Middle (~30%–55%)**: Data protection and encryption at rest across all three providers, including key management (KMS, customer-managed keys), service-account-to-key binding, and the operational cost of managing your own keys.
- **Late (~55%–85%)**: Networking, workload-level controls, and authentication mechanisms, building layered defenses that iteratively reduce blast radius rather than relying on a single perimeter.
- **Ending (~85%–100%)**: Enablement strategies, organizational adoption, and how to extend recipes horizontally (across teams) and vertically (through the stack) within a business.
【Key Takeaways】
- **Security is job zero, not a bolt-on** (Opening): The book argues that retrofitting security after functionality undermines agility and efficacy; culture is the foundation you cannot out-engineer. This reframes security as a prerequisite, not a gate.
- **Layered defense reduces blast radius** (Opening): VPN access, identity, firewall rules, and routing each add a layer so a single compromise doesn't cascade — a recurring design principle across every recipe.
- **Per-workload account/project separation is the core isolation primitive** (Early): Production, preproduction, development, and shared environments get distinct projects with different access rules, making change flow through IaC and CI/CD by default.
- **Visibility must be centralized and tamper-resistant** (Early): Organizational trails and centralized logging prevent teams from disabling audit capture, giving both proactive and retrospective breach response a full history.
- **Encryption at rest requires deliberate key strategy** (Middle): Provider-managed keys give defaults, but customer-managed keys enable explicit control and audit — at the cost of rotation and access burden that should only be shouldered when required.
- **Recipes are provider-parallel, not provider-neutral** (Throughout): Each solution shows where AWS, Azure, and GCP converge and where they are fundamentally different, so you learn trade-offs rather than memorizing one vendor's API.
- **Infrastructure as code is the delivery mechanism** (Throughout): Terraform is used consistently, with the book's companion repository providing runnable examples — the recipes assume you'll adapt, not copy verbatim.
- **Security scales through enablement, not gatekeeping** (Late): Making everyone security-literate is framed as the security team's most critical function, connecting technical controls to organizational design.
【Reading Tips】
- **Skim the principle chapters, deep-read the recipes**: The opening mental models are short and reusable; the value is in the per-provider implementations, so budget time for the Terraform you actually need.
- **Read one provider first, then compare**: Pick your primary cloud, work its recipes end-to-end, then revisit the other two to internalize the trade-offs the book emphasizes.
- **Treat code as scaffolding**: Run `terraform plan` and review resources before applying; the examples are starting points, and several recipes note where Terraform support is incomplete (e.g., needing `gcloud` via `null_resource`).
- **Watch the cost and operational footnotes**: Warnings about duplicate trails, log volume costs, and key-management burden are easy to skip but are where real deployments go wrong.
- **Use the companion repo alongside the text**: The GitHub examples are the practical companion; the prose explains intent, the repo gives you something to run.
【Coverage Limits】
This guide is synthesized from stratified excerpts covering roughly the first half of the book (principles, accounts/identity, visibility, and encryption), so later networking, authentication, and enablement chapters are described at a higher level than the excerpts directly support.
Page 10
unless you’re reproducing a significant portion of the code. For example, writing a program that uses several chunks of code from this book does not require...
es fail, then user access will be required to recover them. 24 | Chapter 2: Setting Up Accounts and Users The Individual Business Owners OU This houses resou...
e a full history of what has hap‐ pened across your estate. By configuring an organizational trail, you don’t allow teams to disable that trail in their acco...
e bucket, there is a Terraform data provider that gives you the details of the project-specific Service Account you need to use. To know what service account...
igured in Recipe 3.2. They are also automatically loaded on Amazon EventBridge, which allows you to create and trigger bespoke workflows upon certain finding...
nt, as long as the 15-minute exe‐ cution time is sufficient. Lambda functions, as used in this recipe, provide a lower total-cost-of-ownership approach to ex...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Cloud Native Security Cookbook Recipes for a Secure Cloud (Josh Armitage)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Cloud Native Security Cookbook Recipes for a Secure Cloud (Josh Armitage)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment