Security and Secrets Management

Rohit Salecha · Apress eBooks · 2022

In this chapter, we’ll look into various different areas pertaining to the security of our application and infrastructure. We’ll discuss how to manage the database using AWS Secrets Manager and how it can directly be injected into the pods. Then we’ll look at a few small aspects of securing our ALB and restricting the network for the RDS. After that, we’ll look at how pods can authenticate to AWS and access different resources. Then we’ll look at how the disk of the EKS nodes can be encrypted using AWS KMS and how we can enforce Service Control Policies or SCPs on different OUs such that developers cannot spin up expensive EC2 resources. Finally, we’ll end by adding a tool called Checkov in the GitHub Actions pipeline, which will continuously spill out security issues on every PR.

Read the paper · More papers on PaperTik