BeyondProd 是指 Google 基础设施中协同工作以帮助保护工作负载的服务和控制。BeyondProd 有助于保护 Google 在其自己的环境中运行的应用服务,包括 Google 如何更改代码以及 Google 如何确保服务隔离。虽然 BeyondProd 论文指的是一种特定技术,供 Google 用来管理其不会向客户公开的基础设施,但 BeyondProd 的安全原则也可以应用于客户应用。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2024-12-13。"],[[["BeyondProd is a set of security principles and services in Google's infrastructure designed to protect workloads, which can also be applied to customer applications."],["Key security principles of BeyondProd include network edge protection, the absence of inherent mutual trust between services, and the use of trusted machines with known code provenance."],["Network edge protection is achieved through services like Cloud Load Balancing, Google Cloud Armor, Cloud CDN, and private GKE cluster configurations."],["Ensuring no inherent mutual trust between services involves enforcing authentication and authorization via Cloud Service Mesh, Workload Identity Federation, and firewall policies."],["Trusted machines and consistent policy enforcement are maintained with Binary Authorization, Policy Controller, and automated pipelines for standardized change rollouts, among others."]]],[]]