1
00:00:06,480 --> 00:00:08,310
- In ten four, we're
gonna look specifically,

2
00:00:08,310 --> 00:00:11,310
at data center solution elements.

3
00:00:11,310 --> 00:00:13,050
If we're gonna be talking
about a data center,

4
00:00:13,050 --> 00:00:15,840
well, we definitely have
to talk about automation.

5
00:00:15,840 --> 00:00:17,583
Automation is the application,

6
00:00:18,499 --> 00:00:20,400
of technology programs, robotics,

7
00:00:20,400 --> 00:00:25,400
or processes to achieve outcomes
with minimal human input.

8
00:00:25,440 --> 00:00:29,520
Now, the goal of IT
automation is to improve QOS,

9
00:00:29,520 --> 00:00:32,400
that's quality of
service, increase agility,

10
00:00:32,400 --> 00:00:35,250
and reduce or eliminate
manual dependencies,

11
00:00:35,250 --> 00:00:36,750
and human error.

12
00:00:36,750 --> 00:00:38,880
Means we really wanna
make our data center,

13
00:00:38,880 --> 00:00:41,430
just work as perfectly and as effectively,

14
00:00:41,430 --> 00:00:44,280
and as efficiently and possible.

15
00:00:44,280 --> 00:00:47,760
Now, orchestration is the
integration of disparate tools,

16
00:00:47,760 --> 00:00:51,120
and platforms for an automated response.

17
00:00:51,120 --> 00:00:54,240
So in this lesson of data
center solution elements,

18
00:00:54,240 --> 00:00:55,830
the big solution we're gonna look at,

19
00:00:55,830 --> 00:00:58,953
is automation and orchestration.

20
00:01:01,620 --> 00:01:04,410
Now, demand generated resource allocation,

21
00:01:04,410 --> 00:01:07,828
is the automatic provisioning
and deprovisioning,

22
00:01:07,828 --> 00:01:09,750
of resources in our data center.

23
00:01:09,750 --> 00:01:12,180
And when we think about
demand generated resource

24
00:01:12,180 --> 00:01:14,970
allocation, we really
think about two components,

25
00:01:14,970 --> 00:01:18,060
scalability and elasticity.

26
00:01:18,060 --> 00:01:20,700
The scalability is the
ability of a system,

27
00:01:20,700 --> 00:01:23,400
to automatically accommodate larger loads,

28
00:01:23,400 --> 00:01:26,760
by adding more resources,
either making hardware stronger,

29
00:01:26,760 --> 00:01:28,740
and you'll hear the term scale up,

30
00:01:28,740 --> 00:01:32,373
or making additional nodes,
and that will be scale out.

31
00:01:33,390 --> 00:01:36,690
Elasticity is the
ability to fit resources,

32
00:01:36,690 --> 00:01:39,420
needed to cope with loads dynamically.

33
00:01:39,420 --> 00:01:42,990
So when the load increases, we
had more resources are added.

34
00:01:42,990 --> 00:01:46,290
And when the demand decreases,
resources are removed.

35
00:01:46,290 --> 00:01:48,540
And the way I always
remember between the two is,

36
00:01:48,540 --> 00:01:49,800
I think about a rubber band, right?

37
00:01:49,800 --> 00:01:50,700
An elastic band.

38
00:01:50,700 --> 00:01:51,930
And if you put it between your thumb,

39
00:01:51,930 --> 00:01:54,000
and your first finger
and you stretch it out,

40
00:01:54,000 --> 00:01:56,182
and then you bring your
fingers back together,

41
00:01:56,182 --> 00:01:57,390
it's gonna come back into its shape,

42
00:01:57,390 --> 00:01:59,340
stretch it out, bring it back.

43
00:01:59,340 --> 00:02:02,280
So it's that idea of dynamically,
we're stretching it out,

44
00:02:02,280 --> 00:02:05,280
adding more, coming back, taking it away.

45
00:02:05,280 --> 00:02:07,470
So scalability, scaling up and out,

46
00:02:07,470 --> 00:02:10,470
elasticity is dynamically
fitting the resources,

47
00:02:10,470 --> 00:02:13,143
needed to cope with loads dynamically.

48
00:02:15,720 --> 00:02:18,330
So what are some solution
elements that involves,

49
00:02:18,330 --> 00:02:21,810
some automation and allow
us to do scalability,

50
00:02:21,810 --> 00:02:23,670
and or elasticity.

51
00:02:23,670 --> 00:02:26,820
Infrastructure-as-code,
serverless computing,

52
00:02:26,820 --> 00:02:29,220
microservices, containerization,

53
00:02:29,220 --> 00:02:30,450
which we already touched on.

54
00:02:30,450 --> 00:02:34,110
And SDN, or software defined networking.

55
00:02:34,110 --> 00:02:36,660
Infrastructure-as-code is using code,

56
00:02:36,660 --> 00:02:40,383
to manage configurations and
to automate provisioning.

57
00:02:41,400 --> 00:02:44,280
Serverless computing just refers
to the dynamic allocation,

58
00:02:44,280 --> 00:02:47,793
of resources to execute
a specific piece of code.

59
00:02:48,690 --> 00:02:51,600
Microservices is breaking
down a larger application,

60
00:02:51,600 --> 00:02:54,930
into smaller, independently
deployable components,

61
00:02:54,930 --> 00:02:58,503
that will perform a specific
business function or task.

62
00:03:00,270 --> 00:03:03,330
Containerization, which we
talked about in the last lesson,

63
00:03:03,330 --> 00:03:06,420
is a technology that allows
applications to be packaged,

64
00:03:06,420 --> 00:03:09,933
and then run in isolated
environments called containers.

65
00:03:10,800 --> 00:03:12,660
And then we have software
defined networking,

66
00:03:12,660 --> 00:03:15,210
and that's using software to manage,

67
00:03:15,210 --> 00:03:18,000
and to configure the
network infrastructure.

68
00:03:18,000 --> 00:03:20,550
So let's look a little
deeper at each one of these.

69
00:03:21,960 --> 00:03:25,830
Infrastructure-as-code,
or IAC is used to define,

70
00:03:25,830 --> 00:03:28,890
and provisioning networking
components such as servers,

71
00:03:28,890 --> 00:03:32,340
networks, and storage that
can be version controlled,

72
00:03:32,340 --> 00:03:34,380
tested and automated.

73
00:03:34,380 --> 00:03:37,170
There's our automation,
through machine readable files,

74
00:03:37,170 --> 00:03:40,200
rather than physical
hardware configurations.

75
00:03:40,200 --> 00:03:41,580
So from a security perspective,

76
00:03:41,580 --> 00:03:43,110
what do I wanna think about?

77
00:03:43,110 --> 00:03:45,090
Well, first it's unauthorized access.

78
00:03:45,090 --> 00:03:49,013
If the attacker could
gain access to the IAC,

79
00:03:49,013 --> 00:03:51,090
the infrastructure's code
files or the configuration,

80
00:03:51,090 --> 00:03:53,700
they could potentially
modify the infrastructure,

81
00:03:53,700 --> 00:03:57,330
leading to unauthorized
access or data exfiltration.

82
00:03:57,330 --> 00:03:59,460
So we wanna have good security controls,

83
00:03:59,460 --> 00:04:01,533
over those configuration files.

84
00:04:02,670 --> 00:04:04,170
Could end up with insecure code.

85
00:04:04,170 --> 00:04:06,990
So flaws in a IAC code could,

86
00:04:06,990 --> 00:04:09,701
create vulnerabilities
in the infrastructure,

87
00:04:09,701 --> 00:04:12,121
such as open ports or weak
authentication methods.

88
00:04:12,121 --> 00:04:13,813
So we always wanna really test that code,

89
00:04:13,813 --> 00:04:15,600
and make sure that we
don't have any flaws.

90
00:04:15,600 --> 00:04:19,110
And then misconfiguration,
misconfiguration in IOC,

91
00:04:19,110 --> 00:04:21,450
could lead to unintended
consequences such as,

92
00:04:21,450 --> 00:04:24,510
exposing sensitive data or resources.

93
00:04:24,510 --> 00:04:27,240
But if we have good strong
configuration management,

94
00:04:27,240 --> 00:04:29,310
and we use our baseline configurations,

95
00:04:29,310 --> 00:04:31,170
and we test them all out,

96
00:04:31,170 --> 00:04:34,170
well then we can use those
same baselines, right,

97
00:04:34,170 --> 00:04:37,200
in setting up the the script
or the configuration files,

98
00:04:37,200 --> 00:04:39,003
for infrastructure-as-code.

99
00:04:41,490 --> 00:04:43,050
Next is serverless computing.

100
00:04:43,050 --> 00:04:45,330
Serverless computing
is an execution model,

101
00:04:45,330 --> 00:04:47,880
in which a cloud provider
dynamically allocates,

102
00:04:47,880 --> 00:04:50,490
only compute resources and storage,

103
00:04:50,490 --> 00:04:53,343
needed to execute a
particular piece of code.

104
00:04:54,213 --> 00:04:57,060
Now, serverless computing
is known as event driven,

105
00:04:57,060 --> 00:04:59,520
meaning the code is only gonna be invoked,

106
00:04:59,520 --> 00:05:02,160
when a request is triggered.

107
00:05:02,160 --> 00:05:05,760
So our security considerations,
well, injection attacks,

108
00:05:05,760 --> 00:05:07,980
that serverless functions
can be vulnerable,

109
00:05:07,980 --> 00:05:10,620
to an injection attack
where the attacker injects

110
00:05:10,620 --> 00:05:14,250
malicious code into the
function's input or output data.

111
00:05:14,250 --> 00:05:15,750
Hence why, input validation,

112
00:05:15,750 --> 00:05:17,700
and output validation are so important.

113
00:05:18,900 --> 00:05:21,060
Malware, that our serverless
functions can be used,

114
00:05:21,060 --> 00:05:24,000
to distribute malware such
as disguising malicious code,

115
00:05:24,000 --> 00:05:26,411
as a legitimate function.

116
00:05:26,411 --> 00:05:28,860
And data privacy sensitive
data can be exposed,

117
00:05:28,860 --> 00:05:30,630
if it's not properly secured,

118
00:05:30,630 --> 00:05:33,753
or if access controls are
not properly implemented.

119
00:05:36,690 --> 00:05:39,480
Microservices are a software
development approach,

120
00:05:39,480 --> 00:05:42,150
where a larger massive
application is broken down,

121
00:05:42,150 --> 00:05:44,490
into smaller independent services.

122
00:05:44,490 --> 00:05:48,420
Now, each microservice is
a self-contained component,

123
00:05:48,420 --> 00:05:52,200
that can be deployed, updated,
and scaled independently,

124
00:05:52,200 --> 00:05:55,440
without affecting the
rest of the application.

125
00:05:55,440 --> 00:05:57,030
So, sounds great, right?

126
00:05:57,030 --> 00:05:57,930
But as always,

127
00:05:57,930 --> 00:06:00,570
there's gonna be some security
configurations, right?

128
00:06:00,570 --> 00:06:02,730
There is an increased attack surface.

129
00:06:02,730 --> 00:06:05,430
Microservices architectures
have a large number,

130
00:06:05,430 --> 00:06:08,340
of interconnected components
which can increase

131
00:06:08,340 --> 00:06:10,590
the overall attack surface
and make it harder,

132
00:06:10,590 --> 00:06:13,770
to identify and mitigate vulnerabilities.

133
00:06:13,770 --> 00:06:16,020
And we have service to
service authentication,

134
00:06:16,020 --> 00:06:17,430
and authorization.

135
00:06:17,430 --> 00:06:18,990
In a microservices environment,

136
00:06:18,990 --> 00:06:22,110
services need to authenticate
and authorize to each other,

137
00:06:22,110 --> 00:06:25,293
which can be challenging
to manage and to secure.

138
00:06:26,640 --> 00:06:29,850
So microservices really
can be quite wonderful.

139
00:06:29,850 --> 00:06:30,960
But just like everything else,

140
00:06:30,960 --> 00:06:34,503
we really have to think about
these security considerations.

141
00:06:36,090 --> 00:06:38,790
Containerization, which we
have already chatted about,

142
00:06:38,790 --> 00:06:41,070
right, is a technology
that allows applications,

143
00:06:41,070 --> 00:06:44,190
to be packaged and run
in isolated environments.

144
00:06:44,190 --> 00:06:45,930
Now, containers do provide a way,

145
00:06:45,930 --> 00:06:49,410
to isolate the applications
and their dependencies,

146
00:06:49,410 --> 00:06:51,750
from whatever the underlying
infrastructure is,

147
00:06:51,750 --> 00:06:53,790
which does make it much
easier to deploy and manage,

148
00:06:53,790 --> 00:06:57,240
and scale applications across
different environments,

149
00:06:57,240 --> 00:07:01,320
which is why, you know,
Google uses containers.

150
00:07:01,320 --> 00:07:05,100
But our security considerations,
one is container breakouts.

151
00:07:05,100 --> 00:07:07,980
The containers share a host
operating systems kernel,

152
00:07:07,980 --> 00:07:10,110
and if a container is compromised,

153
00:07:10,110 --> 00:07:11,940
an attacker could potentially break out

154
00:07:11,940 --> 00:07:14,790
of the container and
access the host system.

155
00:07:14,790 --> 00:07:15,660
Now this can happen,

156
00:07:15,660 --> 00:07:18,210
if our container is not
properly configured,

157
00:07:18,210 --> 00:07:20,070
or if the attacker finds a vulnerability,

158
00:07:20,070 --> 00:07:21,483
in the container runtime.

159
00:07:22,800 --> 00:07:25,500
Then we have some container
orchestration vulnerabilities.

160
00:07:25,500 --> 00:07:27,030
Container orchestration tools,

161
00:07:27,030 --> 00:07:30,120
are used to manage and
scale our containers.

162
00:07:30,120 --> 00:07:31,680
Now these tools can be
vulnerable to exploits,

163
00:07:31,680 --> 00:07:35,793
especially, once again, if they
are not properly configured.

164
00:07:40,110 --> 00:07:43,560
Next up is SDN or
software-defined networking.

165
00:07:43,560 --> 00:07:47,070
SDN technology enables
network configuration,

166
00:07:47,070 --> 00:07:50,370
using a software application,
instead of changing

167
00:07:50,370 --> 00:07:52,920
the configuration of physical equipment.

168
00:07:52,920 --> 00:07:55,350
Now, SDN, interesting,
going all the way back,

169
00:07:55,350 --> 00:07:57,300
to what we talked about in our zero trust,

170
00:07:57,300 --> 00:08:00,180
or ZT environment, is made
possible by separating

171
00:08:00,180 --> 00:08:03,210
that control plane from
the data plane, right?

172
00:08:03,210 --> 00:08:05,910
The control plane is moved
to a centralized controller,

173
00:08:05,910 --> 00:08:09,300
that actually manages
those networking devices.

174
00:08:09,300 --> 00:08:11,130
So if you need a refresher
on the control plane,

175
00:08:11,130 --> 00:08:13,380
and data plane, go all the
way back to the lesson,

176
00:08:13,380 --> 00:08:14,853
about zero trust.

177
00:08:15,780 --> 00:08:19,620
Our security configurations,
centralized control, right?

178
00:08:19,620 --> 00:08:22,320
SDN does rely on a centralized controller,

179
00:08:22,320 --> 00:08:23,310
to manage the network,

180
00:08:23,310 --> 00:08:26,033
which makes it a single point of failure.

181
00:08:26,033 --> 00:08:26,866
So if the controller's compromised,

182
00:08:26,866 --> 00:08:29,490
the entire network could
potentially be compromised

183
00:08:29,490 --> 00:08:31,140
and controller vulnerabilities,

184
00:08:31,140 --> 00:08:33,390
the controller software can be vulnerable,

185
00:08:33,390 --> 00:08:37,890
to exploits such as buffer
overflows, injection attacks,

186
00:08:37,890 --> 00:08:40,830
which can be used to
gain unauthorized access,

187
00:08:40,830 --> 00:08:41,970
to the network.

188
00:08:41,970 --> 00:08:43,830
So these are all solution elements,

189
00:08:43,830 --> 00:08:48,090
that we've been talking about,
you know, in this lesson.

190
00:08:48,090 --> 00:08:50,644
I don't want you to
walk away thinking, wow,

191
00:08:50,644 --> 00:08:52,380
there's a lot of security
considerations on all of these.

192
00:08:52,380 --> 00:08:54,570
Well, there are, but that's not a reason,

193
00:08:54,570 --> 00:08:56,850
to just discard them or not use them.

194
00:08:56,850 --> 00:08:58,830
These are all some really
cool solution elements,

195
00:08:58,830 --> 00:09:02,040
that that definitely have
their benefits, but you know,

196
00:09:02,040 --> 00:09:04,290
like any other good thing,
and we always have to take it,

197
00:09:04,290 --> 00:09:06,540
with a grain of salt and
say, okay, this is good,

198
00:09:06,540 --> 00:09:08,430
but we need to look at
these certain things.

199
00:09:08,430 --> 00:09:11,490
And that's what those
security considerations are.

200
00:09:11,490 --> 00:09:13,080
All right, that's gonna bring us,

201
00:09:13,080 --> 00:09:14,430
to a three second challenge.

202
00:09:14,430 --> 00:09:15,263
You know what to do.

203
00:09:15,263 --> 00:09:17,583
Five questions, three
seconds each, here it goes.

204
00:09:18,780 --> 00:09:20,730
Using code to manage configurations,

205
00:09:20,730 --> 00:09:22,203
and automate provisioning.

206
00:09:23,130 --> 00:09:24,993
1, 2, 3.

207
00:09:26,250 --> 00:09:28,773
That's gonna be
infrastructure-as-code, or IAC.

208
00:09:30,150 --> 00:09:32,610
Number two, using software to manage,

209
00:09:32,610 --> 00:09:34,660
and configure the network infrastructure.

210
00:09:36,090 --> 00:09:38,490
1, 2, 3.

211
00:09:38,490 --> 00:09:41,253
That's SDN, software defined networking.

212
00:09:42,810 --> 00:09:44,310
Number three, dynamic allocation,

213
00:09:44,310 --> 00:09:47,343
of resources to execute
a specific piece of code.

214
00:09:48,330 --> 00:09:49,743
1, 2, 3.

215
00:09:50,640 --> 00:09:52,263
That's serverless computing.

216
00:09:53,610 --> 00:09:56,400
Number four, breaking
down a large application,

217
00:09:56,400 --> 00:10:00,240
into smaller independently
deployable components.

218
00:10:00,240 --> 00:10:02,223
1, 2, 3.

219
00:10:03,480 --> 00:10:05,043
That's microservices.

220
00:10:05,940 --> 00:10:09,300
And lastly, a technology
that allows applications,

221
00:10:09,300 --> 00:10:12,723
to be packaged and run
in isolated environments.

222
00:10:14,160 --> 00:10:16,410
1, 2, 3.

223
00:10:16,410 --> 00:10:19,203
That's gonna be containerization
or using containers.

224
00:10:20,490 --> 00:10:22,290
All right, let's do a security and action,

225
00:10:22,290 --> 00:10:25,110
on on-demand resource generation.

226
00:10:25,110 --> 00:10:27,750
Your organization is
evaluating cloud computing

227
00:10:27,750 --> 00:10:29,190
service providers.

228
00:10:29,190 --> 00:10:32,640
The proposals seem to
use the term elasticity,

229
00:10:32,640 --> 00:10:35,400
and scalability interchangeably.

230
00:10:35,400 --> 00:10:37,680
Then you wanna make sure
that the business unit

231
00:10:37,680 --> 00:10:41,040
decision makers really
understand the difference.

232
00:10:41,040 --> 00:10:45,720
So how are you gonna compare
elasticity and scalability?

233
00:10:45,720 --> 00:10:47,580
Go ahead and put me on
pause, write some notes,

234
00:10:47,580 --> 00:10:48,693
and then come on back.

235
00:10:51,120 --> 00:10:52,590
Well, both solutions are designed,

236
00:10:52,590 --> 00:10:54,363
to meet changing business needs.

237
00:10:55,680 --> 00:10:58,260
Scalability is the ability of a system,

238
00:10:58,260 --> 00:11:00,810
to automatically accommodate larger loads,

239
00:11:00,810 --> 00:11:04,290
by adding resources, either
making hardware stronger,

240
00:11:04,290 --> 00:11:08,460
which was scale up, or
adding nodes, scale out.

241
00:11:08,460 --> 00:11:10,950
Now in contrast to scalability,

242
00:11:10,950 --> 00:11:14,220
elasticity adapts to
both workload increase,

243
00:11:14,220 --> 00:11:17,190
as well as workload
decrease by provisioning,

244
00:11:17,190 --> 00:11:21,060
and de-provisioning resources
in an autonomic manner.

245
00:11:21,060 --> 00:11:24,150
So think of it as, a kinda
a pay-as-you-go model.

246
00:11:24,150 --> 00:11:26,787
So generally, this is how
we're gonna define scalability,

247
00:11:26,787 --> 00:11:30,330
and elasticity, but there's
a caveat or a caution.

248
00:11:30,330 --> 00:11:33,150
There are some providers
who may use these terms,

249
00:11:33,150 --> 00:11:33,990
a little bit differently.

250
00:11:33,990 --> 00:11:36,420
So you wanna be aware of
that out in the real world.

251
00:11:36,420 --> 00:11:39,420
But here's why I want you to
know these terms for your exam.

252
00:11:40,260 --> 00:11:43,200
Being able to understand
scalability and elasticity,

253
00:11:43,200 --> 00:11:45,750
and again, going to talk
to that business unit,

254
00:11:45,750 --> 00:11:48,720
decision maker to make sure
they understand the difference.

255
00:11:48,720 --> 00:11:51,630
Absolutely, absolutely,
critically important,

256
00:11:51,630 --> 00:11:52,770
to be able to do that.

257
00:11:52,770 --> 00:11:55,220
And you know what it is,
it's security in action.

258
00:11:56,190 --> 00:11:57,660
All right, there's your word cloud.

259
00:11:57,660 --> 00:12:00,544
Make sure you know all
of these things, right?

260
00:12:00,544 --> 00:12:02,580
All the terms, you know
what's going on with these,

261
00:12:02,580 --> 00:12:04,950
how we use them, why we care about them.

262
00:12:04,950 --> 00:12:06,810
You always wanna be able to speak to,

263
00:12:06,810 --> 00:12:09,840
any of these terms that
you see confidently.

264
00:12:09,840 --> 00:12:11,730
If you can't, go back
in through the lesson.

265
00:12:11,730 --> 00:12:14,040
There was a lot of detail in this lesson.

266
00:12:14,040 --> 00:12:16,440
And when you're ready, head
on over to the next lesson.

267
00:12:16,440 --> 00:12:18,240
I'll be waiting for you right there.
