

Hybrid Multi-cloud dynamic security management
source link: http://wei-meilin.blogspot.com/2021/08/hybrid-multi-cloud-dynamic-security.html?utm_campaign=Feed%3A+blogspot%2FhFXzh+%28Christina+%E7%9A%84+J%E8%80%81%E9%97%86%29
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Hybrid multi cloud can be a difficult, this is my study of a real customer use case on their journey using GitOps, multi cluster management system and securing dynamic infrastructure secrets.
Quick recap,
In my series of articles I went over the study I did among Red Hat customers that makes the jump towards deploying their workloads on hybrid and multi-cloud environments. These articles are abstractions of the common generic components summarized according to the actual implementations.
To overcome the common obstacles of going hybrid and multi-cloud, such as finding talents with multi-cloud knowledge. Secure and protect across low trust networks or just day to day operation across the board. I have identify some solutions from the study, where I will be covering in the serie of articles:
Briefing of the Hybrid Multi-cloud study.
Overview of making Hybrid Multi-cloud GitOps works
Hybrid Multi-cloud dynamic security management
Observability in Hybrid Multi-cloud environment
Dynamic Security Management,
Kubernetes offers it’s own secret management control, although it’s sufficient for running a single cluster, but when you are trying to manage multiple sets of credentials and secure configurations, especially with the introduction of automated process and continuous delivery practice. We need a better way to securely and centrally manage these data.
How it works,
Checkout my previous article on the setup of the hybrid and multi cloud environment, and if you are interested, another article on getting the GitOps works. But for now, we are going to assume we have a fleet of clusters deployed on top of multiple cloud vendors, and one in the local data center. All the infrastructure is set as code and stored in a source management system. Where our GitOps system constantly coverage the managed clusters with its desired state. In order to setup a secure way to manage credentials and configuration cross clusters, we need two components,
- External Secret management in OpenShift/Kubernetes
- Enable use of external secret management systems (like HashiCorp Vault in this case) to securely add secrets into the OpenShift platform.
- Hashicorp Vault
- Secure centralized store for dynamic infrastructure and application across clusters. For low trust networks between clouds and data centers.
This is how the two components work together to manage secret in dynamic infrastructure:
During setup, the token to securely access HashiCorp Vault is stored in Ansible Vault. It is encrypted to protect sensitive content.
Red Hat Advanced Cluster Management for Kubernetes (RHACM) allows us to have centralized control over the managing clusters. It acquires the token from Ansible Vault during install and distributes among the clusters.
To allow the cluster access to the external vault, we need to set up the external secret management. OpenShift Gitops is used to deploy the external secret object to a managed cluster.
External secret management fetches secrets from HashiCorp Vault using the token we created in step 2. And constantly watch for updates.
Secrets are created in each namespace, where applications can use.
This is how to manage dynamic infrastructure secret in a multi cluster and cloud environment.
Recommend
-
13
Analyzing the Wrong-Think about Hybrid and Multi-Cloud Every day, I see and hear about new data points that suggest we’re getting the whole hybrid- and multi-cloud story all wrong. It’s a given that stories about the cloud are all ab...
-
12
Does Identity Hinder Hybrid-Cloud and Multi-Cloud Adoption?Concerns about identity and access management in the cloud might slow enterprise migration as awareness of gaps in control are realized.IT decision makers may hesitate or at...
-
9
Finding the cloud computing approach that’s right for your business The rise of cloud computing has revolutionized business as we know it. The cloud has enabled businesses to focus their time and energy on building technology, rather...
-
11
Overview of making Hybrid Multi-cloud GitOps works Hybrid multi cloud can be a difficult, this is my study of a real customer use case on their journey using GitOps, multi cluster management system and securing...
-
11
Observability in Hybrid Multi-cloud environment
-
10
Hybrid Multi-cloud dynamic security management
-
6
What’s the Diff: Hybrid Cloud vs. Multi-cloud September 21, 2021 by Molly Clancy //
-
10
How Hybrid Multi-Cloud Can Mitigate Current Supply Chain WoesThe global supply chain shortage is massively impacting the entire technology industry, proving critical that CIOs find ways to leverage cloud resources efficie...
-
4
Multi Cloud vs Hybrid Cloud: Know the Difference Between Two Cloud Platforms Cloud Computing is one of the most critical aspects of the digital age. It has transformed the way we work and live. There are a few d...
-
7
Ranked #3 for todayAPI7 cloudAPI management platform for hybrid and multi-cloudFree OptionsDeploy, con...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK