Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Heather Adkins, Betsy Beyer, Paul Blankinship, Ana Oprea, Piotr Lewandowski, Adam Stubblefield

Rating No ratings yet

Can a system be considered truly reliable if it isn't fundamentally secure? Or can it be considered secure if it's unreliable? Security is crucial to the design and operation of scalable systems in production, as it plays an important part in product quality, performance, and availability. In this book, experts from Google share best practices to help your organization design scalable and reliable systems that are fundamentally secure. Two previous O'Reilly books from Google (Site Reliability Engineering and The Site Reliability Workbook) demonstrated how and why a commitment to the entire service lifecycle enables organizations to successfully build, deploy, monitor, and maintain software systems. In this latest guide, the authors offer insights into system design, implementation, and maintenance from

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, Google-tested guide to treating security and reliability as one inseparable design problem, not two competing goals. Best for engineers, SREs, and technical leaders who build or operate production systems and need concrete patterns for designing, deploying, and maintaining them safely. 【Book Arc】 - **Opening (~0%–10%)**: Frames the core thesis—security and reliability are emergent properties of the whole lifecycle, and neither is meaningful without the other. Introduces the cultural prerequisites and explains how to navigate the book. - **Early (~10%–32%)**: Builds threat awareness and attacker literacy—motivations, profiles (hobbyists, researchers, governments, activists, criminals, insiders), methods like kill chains and TTPs—then moves into design with the Safe Proxies case study and the Tool Proxy pattern. - **Middle (~32%–50%)**: Centers on design tradeoffs and access control: balancing security, reliability, and features; narrow administrative APIs; authentication vs. authorization; least privilege; and the auditing culture that keeps breakglass use rare and meaningful. - **Late (beyond ~50%)**: Excerpts do not cover this range in detail, but the book's stated structure continues into implementation and maintenance—deployment safety, recovery, and operational practices. - **Ending (beyond ~50%)**: Excerpts do not cover the closing chapters; expect the book to return to culture and lifecycle themes, but specifics are not available here. 【Key Takeaways】 - **Security and reliability are inseparable** (Early): A system that is down or compromised fails either way; the book argues you must design for both simultaneously rather than trading one off against the other. - **Culture is a first-class engineering concern** (Opening): Technical best practices only stick if the organization supports them; the authors explicitly say culture change often requires up-front investment. - **Know your adversaries** (Early): Different attacker profiles—activists, criminals, insiders, governments—demand different defenses; hacktivists are vocal and hard to predict, while criminals range from sophisticated to click-to-attack. - **Design tradeoffs are unavoidable but manageable** (Middle): Security, reliability, and features often appear to conflict, yet careful planning can satisfy all three with modest up-front cost and lower total effort over the system's life. - **Narrow APIs and least privilege reduce risk** (Middle): Restricting administrative actions to the minimum needed limits blast radius and makes auditing feasible. - **Safe proxies add security without hurting UX** (Early): Transparent proxies that mirror target APIs can enforce policy, logging, and multi-party authorization while staying invisible to users. - **Auditing must be culturally reinforced** (Middle): Without genuine scrutiny, audit logs become rubber stamps and breakglass access becomes routine, eroding both security and reliability. - **Authentication and authorization are distinct steps** (Middle): Verify identity first, then evaluate whether that identity should be permitted; prefer reusing strong cryptographic mechanisms over ad hoc schemes. 【Reading Tips】 - Start with Chapters 1 and 2 as the authors recommend, then jump to chapters matching your role—design, implementation, or operations. - Use the boxed chapter prefaces: they state the problem, lifecycle stage, and security/reliability tradeoffs, so you can decide whether to deep-read or skim. - Treat the Safe Proxies and Tool Proxy material as a concrete pattern library; adapt the principles rather than copying solutions wholesale. - Pay attention to the alligator-icon deep dives only if the topic is directly relevant to your systems. - Read the culture sections carefully even if you're purely technical—the book insists they determine whether practices persist. 【Coverage Limits】 This guide is based on stratified excerpts covering roughly the first half of the book; implementation, maintenance, and closing chapters are not represented, so their specific practices and examples are not summarized here.
Page 10
18 Governments and Law Enforcement 19 Activists 21 Criminal Actors 22 Automation and Artificial Intelligence 24 Insiders 24 Attacker Methods 30 Threat Intell...
View in text
Excerpt 2
e security module (HSM) smart card. 3 ticking for some time. In any case, responders are operating under stress and time pressure, and (at least initially) w...
View in text
Excerpt 3
ion imposed by the proxy, we work closely with engineers to make sure they can access the systems through a breakglass mechanism during emergencies. We discu...
View in text
Excerpt 4
ents receive the scrutiny they deserve. Choosing an auditor Once you have collected a good audit log, you need to choose the right person to inspect the (hop...
View in text
Excerpt 5
d the corresponding TCBs necessary to uphold them in layers. For example, the security model of an operating system typically has a notion of “user identity,...
View in text
Excerpt 6
6). Rather than using a perimeter-based security model with untrusted external versus trusted internal traffic, microservices use a more Architecture Decisio...
View in text
Excerpt 7
s higher in an office location with heavy employee and vis‐ itor traffic, as opposed to a datacenter with tightly controlled physical access. With this in mi...
View in text
Excerpt 8
uires all parts of a system to coordinate around an integer value that represents a forward progression of “valid” versus “expired.” An epoch might be an int...
View in text
Tags
AI categories
CybersecurityDevOpsSoftware
ISBN: 1492083127
Publisher: O'Reilly Media
Publish Year: 2020
Language: English
Pages: 541
File Format: PDF
File Size: 8.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…