Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Josh Armitage

Rating No ratings yet

With the rise of the cloud, every aspect of IT has been shaken to its core. The fundamentals for building systems are changing, and although many of the principles that underpin security still ring true, their implementation has become unrecognizable. This practical book provides recipes for AWS, Azure, and GCP to help you enhance the security of your own cloud native systems. Based on his hard-earned experience working with some of the world's biggest enterprises and rapidly iterating startups, consultant Josh Armitage covers the trade-offs that security professionals, developers, and infrastructure gurus need to make when working with different cloud providers. Each recipe discusses these inherent compromises, as well as where clouds have similarities and where they're fundamentally different. Learn how the cloud provides security superior to what was achievable in an on-premises world Understand the principles and mental models that enable you to make optimal trade-offs as part of your solution Learn how to implement existing solutions that are robust and secure, and devise design solutions to new and interesting problems Deal with security challenges and solutions both horizontally and vertically within your business

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A recipe-driven field guide for engineers who must secure real cloud estates across AWS, Azure, and GCP, translating enduring security principles into concrete, infrastructure-as-code implementations. Best for security professionals, platform engineers, and developers who already know one cloud and need portable, trade-off-aware patterns. 【Book Arc】 - **Opening (~0%–10%)**: Frames the shift from on-premises to cloud-native security, introduces mental models (defense in depth, security as job zero, quality built in) and team topologies that shape how security work is organized. - **Early (~10%–30%)**: Account and identity foundations — organization/folder/project structures, per-workload project separation, region locking, user and service-account provisioning, and standing up security visibility (SIEM/SOC, audit trails, log centralization). - **Middle (~30%–55%)**: Data protection and encryption at rest across all three providers, including key management (KMS, customer-managed keys), service-account-to-key binding, and the operational cost of managing your own keys. - **Late (~55%–85%)**: Networking, workload-level controls, and authentication mechanisms, building layered defenses that iteratively reduce blast radius rather than relying on a single perimeter. - **Ending (~85%–100%)**: Enablement strategies, organizational adoption, and how to extend recipes horizontally (across teams) and vertically (through the stack) within a business. 【Key Takeaways】 - **Security is job zero, not a bolt-on** (Opening): The book argues that retrofitting security after functionality undermines agility and efficacy; culture is the foundation you cannot out-engineer. This reframes security as a prerequisite, not a gate. - **Layered defense reduces blast radius** (Opening): VPN access, identity, firewall rules, and routing each add a layer so a single compromise doesn't cascade — a recurring design principle across every recipe. - **Per-workload account/project separation is the core isolation primitive** (Early): Production, preproduction, development, and shared environments get distinct projects with different access rules, making change flow through IaC and CI/CD by default. - **Visibility must be centralized and tamper-resistant** (Early): Organizational trails and centralized logging prevent teams from disabling audit capture, giving both proactive and retrospective breach response a full history. - **Encryption at rest requires deliberate key strategy** (Middle): Provider-managed keys give defaults, but customer-managed keys enable explicit control and audit — at the cost of rotation and access burden that should only be shouldered when required. - **Recipes are provider-parallel, not provider-neutral** (Throughout): Each solution shows where AWS, Azure, and GCP converge and where they are fundamentally different, so you learn trade-offs rather than memorizing one vendor's API. - **Infrastructure as code is the delivery mechanism** (Throughout): Terraform is used consistently, with the book's companion repository providing runnable examples — the recipes assume you'll adapt, not copy verbatim. - **Security scales through enablement, not gatekeeping** (Late): Making everyone security-literate is framed as the security team's most critical function, connecting technical controls to organizational design. 【Reading Tips】 - **Skim the principle chapters, deep-read the recipes**: The opening mental models are short and reusable; the value is in the per-provider implementations, so budget time for the Terraform you actually need. - **Read one provider first, then compare**: Pick your primary cloud, work its recipes end-to-end, then revisit the other two to internalize the trade-offs the book emphasizes. - **Treat code as scaffolding**: Run `terraform plan` and review resources before applying; the examples are starting points, and several recipes note where Terraform support is incomplete (e.g., needing `gcloud` via `null_resource`). - **Watch the cost and operational footnotes**: Warnings about duplicate trails, log volume costs, and key-management burden are easy to skip but are where real deployments go wrong. - **Use the companion repo alongside the text**: The GitHub examples are the practical companion; the prose explains intent, the repo gives you something to run. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering roughly the first half of the book (principles, accounts/identity, visibility, and encryption), so later networking, authentication, and enablement chapters are described at a higher level than the excerpts directly support.
Page 10
unless you’re reproducing a significant portion of the code. For example, writing a program that uses several chunks of code from this book does not require...
View in text
Excerpt 2
es fail, then user access will be required to recover them. 24 | Chapter 2: Setting Up Accounts and Users The Individual Business Owners OU This houses resou...
View in text
Excerpt 3
e a full history of what has hap‐ pened across your estate. By configuring an organizational trail, you don’t allow teams to disable that trail in their acco...
View in text
Excerpt 4
e bucket, there is a Terraform data provider that gives you the details of the project-specific Service Account you need to use. To know what service account...
View in text
Excerpt 5
igured in Recipe 3.2. They are also automatically loaded on Amazon EventBridge, which allows you to create and trigger bespoke workflows upon certain finding...
View in text
Excerpt 6
rm_public_ip" "bastion" { name = "bastion" location = azurerm_resource_group.network.location resource_group_name = azurerm_resource_group.network.name alloc...
View in text
Excerpt 7
e" "network_public_egress" { type = "egress" from_port = 0 to_port = 0 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] security_group_id = aws_security_group.net...
View in text
Excerpt 8
nt, as long as the 15-minute exe‐ cution time is sufficient. Lambda functions, as used in this recipe, provide a lower total-cost-of-ownership approach to ex...
View in text
Tags
AI categories
Cloud NativeCybersecurityDevOps
ISBN: 109810630X
Publisher: O'Reilly Media
Publish Year: 2022
Language: English
Pages: 516
File Format: PDF
File Size: 6.1 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…