Containers & Kubernetes-Cilium N/W Policy+Spinnaker Delivery

所在平台: Udemy

课程主页: https://www.udemy.com/course/cilium-spinnaker/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:容器与Kubernetes-Cilium网络策略+Spinnaker交付 课程概述: 本课程专注于Cilium和Spinnaker两个重要的开源技术。Cilium利用BPF(Berkeley Packet Filter),为Linux容器框架(如Docker和Kubernetes)提供API感知的网络安全过滤,解决了现有Linux网络安全机制只在网络和传输层操作的问题。Cilium通过基于容器或Pod身份定义和实施网络层和应用层安全策略,让用户无需担心网络子网或容器IP地址,从而提高了网络安全性。 课程将探索Cilium的以下关键特性: - 身份基础安全:将安全策略与Kubernetes标签关联,简化安全管理和审计流程。 - 卓越性能:利用BPF提供高效的数据路径处理,确保网络安全的高性能。 - API协议可见性与安全:Cilium能够理解和过滤微服务之间的具体请求,例如HTTP、gRPC和Kafka。 同时,课程还涵盖了Spinnaker,一个多云的持续交付平台,旨在以高速度和高信心发布软件变更。由Netflix创建的Spinnaker经过广泛的实践验证,支持跨多云环境(如AWS、Google Cloud、Microsoft Azure等)的自动发布功能。课程将介绍Spinnaker的以下关键功能: - 自动化发布:创建运行集成和系统测试的部署管道。 - 内置部署最佳实践:创建和部署不可变镜像,简化回滚和配置问题。 - 活跃社区:与多家知名公司(如Netflix、Google等)合作,共同维护和改进Spinnaker。 通过本课程,学员将了解如何使用Cilium和Spinnaker实现跨云环境的持续交付,设计和自动化适合自身企业需求的交付流程,并掌握云资源管理及安全保证的最佳实践。

课程评论(0条)

课程详情

CILIUM:A microservices- based application is split into small independent services that communicate with each other via APIs using lightweight protocols like HTTP, gRPC, Kafka and more. However, existing Linux network security mechanisms (e.g., iptables) only operate at the network and transport layers (i.e., IP addresses and ports) and lack visibility into the microservices layer. Cilium brings API-aware network security filtering to Linux container frameworks like Docker &Kubernetes. Using a new Linux kernel technology called BPF, Cilium provides a simple and efficient way to define and enforce both network-layer and application-layer security policies based on container/pod identity. We believe in a future where Linux has deep network visibility and control for microservice at the API layer, making applications more secure than ever before. If this goal excites you too, we invite you to join us by contributing ideas, code, and documentation to Cilium. Identity Based Security:Cilium visibility and security policies are based on the container orchestrator identity (e.g., Kubernetes labels). Never again worry about network subnets or container IP addresses when writing security policies, auditing, or troubleshooting. Blazing Performance:BPF is the underlying Linux superpower to do the heavy lifting on the datapath by providing sandboxed programmability of the Linux kernel with incredible performance API-Protocol Visibility + Security:Traditional firewalls only see and filter packets based on network headers like IP address and ports. Cilium can do this as well, but also understands and filters the individual HTTP, gRPC, and Kafka requests that stitch microservices together. Designed for Scale:Cilium was designed for scale, with no node-to-node interactions required when new pods are deployed, and all coordination through a highly scalable key-value store. Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence. Created at Netflix, it has been battle-tested in production by hundreds of teams over millions of deployments. It combines a powerful and flexible pipeline management system with integrations to the major cloud providers. Multi-Cloud Deploy across multiple cloud providers including AWS EC2, Kubernetes, Google Compute Engine, Google Kubernetes Engine, Google App Engine, Microsoft Azure, and Openstack, with Oracle Bare Metal and DC/OS coming soon. Automated Releases Create deployment pipelines that run integration and system tests, spin up and down server groups, and monitor your rollouts. Trigger pipelines via git events, Jenkins, Travis CI, Docker, CRON, or other Spinnaker pipelines. Built-in Deployment Best Practices Create and deploy immutable images for faster rollouts, easier rollbacks, and the elimination of hard to debug configuration drift issues. Leverage an immutable infrastructure in the cloud with built-in deployment strategies such as red/black and canary deployments. Active Community Join a community that includes Netflix, Google, Microsoft, Veritas, Target, Kenzan, Schibsted, and many others, actively working to maintain and improve Spinnaker. Many companies are moving away from "big bang" software releases every six months or so to a continuous delivery (CD) model that enables IT to release updates frequently, even if that means several times a day. Using Netflix and its open source Spinnaker CD platform as examples, this practical ebook demonstrates how a new host of tools can help you deploy software changes to production quickly, safely, and automatically. A team of experts from Netflix and Google show you how to automate deployments with Spinnaker across multiple cloud accounts, regions, and even across multiple cloud platforms into continuous deployment pipelines. You'll learn how Spinnaker enables your company to design and automate a delivery process that not only fits your release cadence, but also the business criticality of your application. Learn about the organizational and technical practices that enable continuous deliveryUnderstand the fundamental considerations you need to solve before successfully deploying software to the cloudManage cloud resources for consistency across accounts, regions, and cloud providersUse Spinnaker's pipelines to structure deployments from customizable piecesUnderstand how CD pipelines to Kubernetes differ from pipelines to VM-based cloudsExamine how Spinnaker ensures safety across cluster deployments and pipeline executionsLearn how to integrate automated testing techniques such as chaos engineering or automated canary analysis into the delivery process

课程标签

0人关注该课程

主题相关的课程