معسكر الأمن السحابي || Cloud Security BootCamp||CCSB
Open in Telegram
القناة العربية الأولى المتخصصة في الحوسبة السحابية والأمن السيبراني للحوسبة السحابية. All Cloud Security Resources in one place. #AWS , #Azure , #Google_Cloud , #GCP , #Oracle_Cloud
Show more6 132
Subscribers
No data24 hours
+87 days
+2630 days
Posts Archive
🔰سبيس لفت : Spacelift
سبيس لفت: Spacelift هي منصة متقدمة للتكامل المستمر والنشر المستمر (CI/CD) تم تصميمها خصيصًا لعمل تدفقات العمل المتعلقة بالبنية التحتية ككود (IaC). تدعم العديد من أدوات IaC مثل Terraform، OpenTofu، Terragrunt، Pulumi، AWS CloudFormation، AWS CDK، Kubernetes، Ansible وغيرها.
تم تطوير Spacelift من قبل ممارسي DevOps ذوي الخبرة الطويلة الذين عملوا على منصات كبيرة تضم العديد من الفرق، مئات المهندسين، وعشرات الآلاف من الموارد السحابية. هذه الخلفية ساهمت في تحويل Spacelift إلى منصة قوية تدير وتستدعي البنية التحتية بكفاءة.
تتكامل المنصة مع أدوات IaC الشهيرة، مما يتيح سير عمل مؤتمت لنشر وإدارة البنية التحتية طوال دورة حياتها. تكمن قوة Spacelift في قدرته على التعامل مع عمليات نشر IaC المعقدة والكبيرة، حيث تقدم دعمًا متقدمًا للفرق التي تحتاج إلى تكامل مستمر ونشر مستمر (CI/CD) للبنية التحتية.
توفر Spacelift أيضًا ميزات قوية مثل السياسات ككود لإدارة الامتثال للبنية التحتية، مما يتيح للفرق فرض معايير وممارسات محددة عبر عمليات النشر. كما أن تكاملها المرن يجعلها الخيار المثالي للمؤسسات التي تبحث عن منصة موحدة لإدارة عدة أدوات IaC وسير عملها في وقت واحد.
بدعمها لمجموعة متنوعة من أدوات IaC وتوفيرها لميزات أتمتة عالية المستوى، تعد Spacelift خيارًا ممتازًا للفرق التي ترغب في توسيع إدارة بنيتها التحتية مع الحفاظ على الحوكمة والكفاءة.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰 OpenTofu
OpenTofu is an open-source infrastructure as code (IaC) tool that enables users to define both cloud and on-premises resources using human-readable configuration files. These files can be versioned, reused, and shared, facilitating a consistent workflow for provisioning and managing infrastructure throughout its lifecycle. OpenTofu manages low-level components such as compute, storage, and networking resources, as well as high-level components like DNS entries and SaaS features.
OpenTofu's modular design allows for the organization of code into modules, enhancing reusability and maintainability, and simplifying the management of large and complex infrastructures. It also supports a registry that houses providers and modules compatible with OpenTofu, enabling users to search for documentation and download various versions of these components.
Additionally, OpenTofu offers a user interface that allows users to search for and view the documentation of providers and modules in the OpenTofu Registry, streamlining the process of finding suitable components for specific requirements.
Originally named OpenTF, OpenTofu is a fork of Terraform, created as an open-source, community-driven initiative managed by the Linux Foundation. This initiative was in response to HashiCorp's switch from an open-source license to the Business Source License (BSL), aiming to maintain an open-source alternative for infrastructure as code tools.
⏩ OpenTofu: A Community-Driven Fork of Terraform
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰أوبن توفو : OpenTofu
أوبن توفو : OpenTofu هي أداة مفتوحة المصدر لإدارة البنية التحتية ككود (IaC) تتيح لك تعريف الموارد السحابية والمحلية في ملفات تكوين قابلة للقراءة البشرية، والتي يمكن نسخها، إعادة استخدامها، ومشاركتها. باستخدام OpenTofu، يمكنك اتباع سير عمل موحد لإعداد وإدارة جميع البنية التحتية الخاصة بك طوال دورة حياتها. يمكن لـ OpenTofu إدارة المكونات منخفضة المستوى مثل الحوسبة، التخزين، والموارد الشبكية، بالإضافة إلى المكونات عالية المستوى مثل إدخالات DNS وميزات البرمجيات كخدمة (SaaS).
تتميز OpenTofu بتصميمها المعياري الذي يتيح تنظيم الكود كـ وحدات (Modules)، مما يعزز من إمكانية إعادة الاستخدام والصيانة، ويسهل إدارة البنية التحتية الكبيرة والمعقدة. كما تدعم OpenTofu السجل (Registry) الذي يحتوي على مزودين (Providers) ووحدات يمكن استخدامها مع OpenTofu، مما يتيح للمستخدمين البحث عن الوثائق وتنزيل الإصدارات المختلفة من هذه المكونات.
بالإضافة إلى ذلك، توفر OpenTofu واجهة مستخدم تتيح البحث وعرض الوثائق الخاصة بالمزودين والوحدات في السجل، مما يسهل على المستخدمين العثور على المكونات المناسبة لمتطلباتهم.
تسعى OpenTofu إلى تقديم بديل مفتوح المصدر لـ Terraform، مع التركيز على الحفاظ على توافقية عالية مع Terraform لضمان سهولة الانتقال للمستخدمين الحاليين. كما تهدف إلى توفير بيئة تطوير مدفوعة من المجتمع، مما يضمن استمرارية التحسين والتطوير المستمر للأداة.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰 Puppet
Puppet is an open-source configuration management tool that automates the deployment, configuration, and maintenance of servers. It operates on a client-server model, with the Puppet Server storing configurations and the Puppet Agent applying them on managed nodes. Puppet uses a declarative language to ensure systems stay in the desired state.
In contrast, Terraform focuses on infrastructure provisioning, creating cloud resources like virtual machines and networks. While both tools are declarative, Puppet manages configuration post-provisioning, whereas Terraform is used for resource creation. Puppet requires agents, while Terraform is agentless and interacts directly with cloud APIs. Both tools are often used together—Terraform for provisioning and Puppet for ongoing management.
⏩ Getting Started with Puppet
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰بوبيت : Puppet
بوبيت: هي أداة مفتوحة المصدر لإدارة تهيئة البنية التحتية تُستخدم لأتمتة نشر، تهيئة، وإدارة الخوادم والأنظمة.
تضمن Puppet أن تظل الأنظمة في حالة متسقة ومطلوبة عن طريق تعريف تكوينات البنية التحتية باستخدام لغة Puppet DSL (المبنية على Ruby). تعتمد Puppet على بنية عميل/خادم حيث يقوم خادم Puppet بتخزين وتوزيع التعريفات، بينما يقوم عميل Puppet على الأنظمة المستهدفة بالتواصل مع الخادم بشكل دوري لتحميل وتطبيق التكوينات.
تتميز Puppet باستخدام نموذج إعلاني حيث يتم تعريف الحالة المطلوبة وتقوم الأداة بضمان تطبيقها تلقائيًا.
يتم مقارنة Puppet بـ Terraform لأن كلاهما أدوات للبنية التحتية المبرمجة، ولكن الفرق أن Puppet تركز على إدارة التهيئة للأنظمة بعد توفيرها، بينما Terraform تركز على توفير البنية التحتية مثل إنشاء الموارد السحابية كالسيرفرات والشبكات والتخزين. أيضًا، بينما يستخدم Puppet نموذج عميل/خادم مع عملاء مثبتين على الأنظمة المستهدفة، فإن Terraform لا يحتاج إلى عملاء (أداة بلا وكيل) ويتفاعل مباشرة مع واجهات برمجة التطبيقات لمزودي الخدمات السحابية.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰Chef
Chef is an open-source Infrastructure as Code (IaC) tool designed for configuration management and automating the setup, maintenance, and deployment of servers and applications. It uses a procedural approach where the steps for configuring a system are explicitly defined using Ruby DSL (Domain-Specific Language). Chef ensures that servers remain in a desired state by continuously applying predefined configurations and making adjustments as needed.
Chef operates on a client-server architecture. The Chef Server acts as the central repository where configuration policies (known as Cookbooks and Recipes) are stored and managed. These policies define how servers should be configured, including tasks like installing software, managing files, setting permissions, and configuring services. On the other hand, the Chef Client runs on the target servers, periodically fetching policies from the Chef Server and applying them to ensure the system stays compliant with the desired state. Additionally, Chef Workstation is used by developers and system administrators to write and test these configuration policies before pushing them to the server.
Chef is particularly useful in large-scale environments where maintaining consistent server configurations is critical. It excels in ongoing system maintenance, such as patching, updating packages, and enforcing security policies, making it ideal for ensuring compliance and minimizing configuration drift.
⏩ Chef Introduction
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰تشيف : Chef
تشيف : Chef هي أداة مفتوحة المصدر لإدارة البنية التحتية ككود (IaC) تركز على تهيئة الخوادم (Configuration Management) وأتمتة عمليات الإعداد والتشغيل داخل الأنظمة. تستخدم لغة Ruby DSL لتحديد خطوات التهيئة وتثبيت البرمجيات وضبط الإعدادات على الخوادم.
تعتمد تشيف على عميل/خادم (Client/Server)، حيث يقوم Chef Server بتخزين التعليمات البرمجية (Cookbooks) وإدارتها، بينما يقوم Chef Client المثبت على الخوادم المستهدفة بتنفيذ هذه التعليمات ومزامنة الحالة مع الخادم المركزي.
تُستخدم تشيف بشكل أساسي لضمان بقاء الخوادم مهيئة باستمرار وفقًا للمعايير المحددة، مما يجعلها مناسبةً للبيئات التي تحتاج إلى تحديثات وإصلاحات متكررة داخل الأنظمة مثل تثبيت الحزم البرمجية، تحديث الإعدادات، أو إدارة المستخدمين.
الفرق بين Chef وTerraform :
تشيف : Chef: يركز على تهيئة وإعداد الخوادم داخل البنية التحتية بعد إنشائها، ويستخدم نهجًا إجرائيًا يحدد خطوات التنفيذ خطوة بخطوة.
تيرافورم : Terraform: يركز على توفير البنية التحتية نفسها مثل إنشاء الموارد السحابية (خوادم، شبكات، تخزين) ويعتمد على نهج تصريحي يحدد الحالة النهائية المطلوبة دون تحديد خطوات التنفيذ.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰DevOps Toolkit
⏩ Terraform vs. Pulumi vs. Crossplane - Infrastructure as Code (IaC) Tools Comparison
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰Crossplane
Crossplane is an open-source Infrastructure as Code (IaC) tool built on Kubernetes, enabling the management of both infrastructure and applications through a unified Kubernetes interface using familiar tools like kubectl.
It extends Kubernetes' API capabilities through Custom Resource Definitions (CRDs) and Controllers, allowing the creation of infrastructure components such as databases, networks, storage, and cloud servers using standard YAML files.
Crossplane offers a centralized management approach, reducing the need for separate tools while supporting a declarative model where the desired state of resources is defined and automatically enforced. Its deep integration with Kubernetes makes it ideal for cloud-native environments like EKS and GKE. Additionally, it supports multiple cloud providers, including AWS, Azure, and GCP, with extensibility through the Open Application Model (OAM) standard.
Crossplane is often compared to Terraform since both are used for infrastructure automation and management. However, Terraform relies on declarative configurations using HCL (HashiCorp Configuration Language), while Crossplane natively integrates with Kubernetes, making it a better fit for Kubernetes-centric environments.
⏩ Crossplane on Kubernetes Explained
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰كروسبلان : Crossplane
كروسبلان : Crossplane هي أداة مفتوحة المصدر لإدارة البنية التحتية ككود (IaC) تعتمد على Kubernetes، مما يسمح بإدارة كل من البنية التحتية والتطبيقات من خلال واجهة Kubernetes الموحدة باستخدام نفس أدوات التحكم مثل kubectl.
تعمل Crossplane عبر تمديد واجهة برمجة التطبيقات (APIs) الخاصة بـ Kubernetes باستخدام Custom Resource Definitions (CRDs) وControllers، مما يتيح إنشاء موارد مثل قواعد البيانات، الشبكات، التخزين، والخوادم السحابية عبر ملفات YAML.
تتميز Crossplane بالإدارة الموحدة التي تقلل الحاجة لاستخدام أدوات منفصلة، ودعمها لنهج تصريحي (Declarative) حيث يتم تعريف الحالة المطلوبة تلقائيًا، بالإضافة إلى تكاملها العميق مع Kubernetes مما يجعلها مناسبتًا للبيئات السحابية مثل EKS وGKE.
كما تدعم العديد من مزودي الخدمات السحابية مثل AWS وAzure وGCP مع إمكانية التوسعة عبر معايير Open Application Model (OAM).
تُقارن مع Terraform لأن كلاهما تُستخدمان لأتمتة وإدارة البنية التحتية، ولكن الفرق الأساسي أن Terraform تعتمد على ملفات تعريفية (Declarative) باستخدام لغة HCL، بينما Crossplane تتكامل بعمق مع Kubernetes، مما تجعلها الأداة الأنسب للبيئات المعتمدة على Kubernetes بشكل أساسي.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰Pulumi
Pulumi is a modern infrastructure as code and secrets management platform that allows you to use familiar programming languages and tools to automate, secure and manage everything you run in the cloud.
Pulumi IaC is free, open source, and optionally pairs with the Pulumi Cloud to make managing infrastructure secure, reliable, and hassle-free.
it's is an open source infrastructure as code platform that helps teams tame the cloud’s complexity using the world’s most popular programming languages (TypeScript, Go, .NET, Python, and Java) and markup languages (YAML, CUE).
⏩ Pulumi in Three Minutes
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰بولومي : Pulumi
بولومي : Pulumi هي أداة حديثة للبنية التحتية ككود (IaC) - البنية التحتية المُبرمجة - تسمح للمطورين بإدارة وأتمتة البنية التحتية السحابية باستخدام لغات برمجية مألوفة مثل Python، TypeScript، Go، وC#. تتيح بولومي كتابة التعليمات البرمجية بأسلوب برمجي كامل مع دعم البرمجة الكائنية (OOP) مما يوفر مرونة عالية في إدارة الموارد السحابية.
تيرافورم : Terraform، من ناحية أخرى، هي أداة شائعة ومفتوحة المصدر للبنية التحتية ككود طورتها HashiCorp، وتعتمد على لغة HCL (HashiCorp Configuration Language)، وهي لغة وصفية تسهل إدارة البنية التحتية بشكل أبسط. تيرافورم ممتازة في إدارة الموارد عبر ملفات تعريفية ثابتة (Declarative) لكنها أقل مرونة من حيث البرمجة مقارنة بـ Pulumi.
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰التحضير لشهادة فنّي البنية التحتية المبرمجة تيرافورم - باللغة العربية
⏪ اضغط-هنا
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰تحويل البنية التحتية والسيرفرات لكود باستخدام تيرافورم - باللغة العربية
⏪ اضغط-هنا
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰شرح البنية التحتية المُبرمجة - تيرافورم - للمهندس ابراهيم سليمان - باللغة العربية
⏪ اضغط-هنا
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
🔰شرح لعمل مشروع متكامل باستخدام تيرافورم - باللغة العربية
⏪ اضغط-هنا
Cloud Security BootCamp🇸🇦
☁️ @CCSB_0 🛡
