AWS Secure Landing Zone with Control Tower and AFT

所在平台: Udemy

课程主页: https://www.udemy.com/course/aws-secure-landing-zone-with-control-tower-and-aft/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**AWS Secure Landing Zone with Control Tower and AFT 课程总结** 本课程深入探讨了“Landing Zone”的概念及其在现代云环境中的重要性,特别是在应对大规模工作负载的挑战方面。课程将带领学员从理解当前云设置面临的问题入手,逐步探索 Landing Zone 的最佳实践,并在 AWS 云上进行实际部署。 **核心内容与流程:** * **云设置问题回顾:** 分析当前云部署模式存在的挑战。 * **Landing Zone 概念探索:** 详细介绍 Landing Zone 的定义、优势及其在多账户管理中的作用。 * **账户类型详解:** 深入剖析 Landing Zone 中各类账户(如管理账户、日志账户、安全账户等)的用途和配置。 * **主账户安全实践:** 学习如何在 AWS 管理账户中实施关键的安全措施。 * **AWS Control Tower 介绍:** 重点介绍 AWS Control Tower 服务,理解其如何简化 Landing Zone 的构建和管理。 * **使用 AWS Control Tower 进行 Landing Zone 部署:** 从零开始,通过 AWS Control Tower 实际部署一个安全的 Landing Zone。 * **AWS 服务配置组织安全:** 利用 AWS 提供的各种服务(如 IAM Access Analyzer, Security Hub, GuardDuty, Inspector 等)来配置和加强跨账户的安全。 * **AWS Control Tower Account Factory for Terraform (AFT) 详解:** 深入了解 AFT 的工作原理和功能,重点关注其如何实现基础设施即代码 (IaC) 的自动化。 * **使用 AFT 自动部署 Landing Zone:** 利用 AFT 实现 Landing Zone 的自动化部署和管理。 **课程涉及的主要服务与工具:** * **AWS 服务:** AWS Organizations, AWS Control Tower, AWS Service Catalog, AWS Config, AWS SNS, AWS Budgets, AWS KMS, AWS CloudTrail, AWS S3, AWS IAM Access Analyzer, AWS Security Hub, AWS GuardDuty, AWS Inspector, AWS CodePipeline. * **自动化工具:** AWS Control Tower Account Factory for Terraform (AFT). * **IaC 工具:** Terraform CLI. * **版本控制与命令行工具:** Git, GitHub, AWS CLI. **学习成果:** 完成本课程后,学员将能够: * 构建一个功能齐全且高度安全的 AWS Landing Zone。 * 利用 AWS Control Tower 和 AFT 实现 Landing Zone 的自动化部署和管理。 * 使用 Terraform 将账户结构脚本化,实现基础设施即代码。 * 根据 AWS 白皮书的最佳实践,为多账户基础设施构建高水平的安全架构。 本课程将帮助您系统化地管理和保护您的 AWS 多账户环境,为您的云之旅奠定坚实的安全基础。

课程评论(0条)

课程详情

Welcome!This course covers the topic of "Landing Zones". In today's dynamic cloud environment, the prominence of Landing Zones has grown significantly. This module explores why Landing Zones are increasingly favored in modern cloud setups and how they play a pivotal role in addressing challenges posed by large workloads.Here we will discover the Landing Zones' best practices, implement them in practice on the AWS cloud, using the AWS Control Tower service, and even automate it, using the "Infrastructure as code" feature AWS Control Tower Account Factory for Terraform [AFT].Workflow of the course:Review of the problem of current Cloud setupsLanding Zone concept explorationA detailed review of each type of the account in Landing ZoneImplementation of security practices on Master AWS accountDiscovery of AWS ControlTower serviceImplementation of the Landing Zone using the AWS Control Tower from the scratchConfiguring the organizational security using the AWS servicesDiscovery in details of AWS Control Tower Account Factory for Terraform Automation of Landing Zone using the AFT- - - - - - - - List of used services/tools:AWS OrganizationsAWS ControlTowerAWS Service CatalogAWS ConfigAWS SNSAWS BudgetsAWS KMSAWS CloudTrailAWS S3AWS IAM Access AnalyzerAWS Security HubAWS GuardDutyAWS InspectorAWS CodePipelineAWS Control Tower Account Factory for TerraformTerraform CLIAWS CLIGitGitHubAs a result of this course, you will receive a fully working and protected Landing Zone on the AWS cloud, which is also automated via AFT.This course will allow you to put the structure of your account on scripts (using the Terraform) and prepare the high level of security of your multi-account infrastructure followed by AWS whitepaper best practices.

课程标签

0人关注该课程

主题相关的课程