Set up Anthos Service Mesh for multiple GKE clusters using Terraform

Anthos Service Mesh is a managed service mesh for Google Kubernetes Engine (GKE) clusters. Anthos Service Mesh allows GKE clusters to use a single logical service mesh, so that pods can communicate across clusters securely and services can share a single Virtual Private Cloud (VPC). Using Anthos Service Mesh requires GKE clusters and firewall rules. As well, access to the GKE GKE control plane needs to be granted, if private clusters are used. Infrastructure-as-code (IaC) makes bootstrapping Anthos Service Mesh significantly easier. In this blog post, we explain the new features of Anthos Service Mesh, and how to implement it across two private GKE clusters using Terraform. We also provide automation scripts, giving a guided tour for setting up a cloud environment.For those who want to get started immediately, there is a Git repo with complete source code and README instructions. There are also bonus sections at the end, for mesh traffic security scanning and external databases respectively.Supported versionThe supported versions are Anthos Service Mesh 1.7 and 1.8. For more information on Anthos Service Mesh versions, please check the Anthos Service Mesh release notes.Fig 3.1 – Anthos Service Mesh version release notesShared VPCsAnthos Service Mesh 1.8 can be used for a single shared VPC, even across multiple projects. Please consult the documentation on Anthos Service Mesh 1.8 multi-cluster support for complete details:Fig 3.2 – Anthos Service Mesh multi-cluster supportSSL/TLS terminationTLS termination for external requests is supported with Anthos Service Mesh 1.8. Doing so requires modifying the Anthos Service Mesh setup files.You can set up Anthos Service Mesh using the install_asm script. A custom istio-operator.yaml file can be used by running install_asm with the –custom_overlay option.In order for Istio (i.e., Anthos Service Mesh) to allow access to external services, change the egress policy to REGISTRY_ONLY. Please see the blocking-by-default Istio documentation for more details.For TLS termination of requests to Prisma Cloud (Twistlock), please the below section on Prisma Cloud.SecurityAnthos Service Mesh has inherent security features (and limitations), as described in the security overview documentation. Additionally, please follow the GKE best practices for security.NOTE: Anthos Service Mesh inherently implements Istio security best practices, such as namespaces and limited service accounts. Workload identity is an optional GKE-specific service account, limited to a namespace.The Istio ingress gateway needs to be secured manually. Please see the Secure Gateways Istio documentation for more details.For security scanning of GKE cluster ingress, please see the below section on Prisma Cloud.Container workload securityGKE cluster network policies allow you to define workload access across pods and namespaces. This is built on top of the Kubernetes NetworkPolicy API. There is also a helpful tutorial on configuring GKE network policies for applications.There are detailed steps for securing container workloads in GKE. This involves a layered approach to node security, pod/container security contexts and pod security policies. As well, Google Cloud’s Container-Optimized OS (both cos and cos_containerd) apply the default Docker AppArmor security policies to all containers started by Kubernetes.Container runtime (Containerd)We recommend using the cos_containerd runtime for GKE clusters using Anthos Service Mesh. The current Docker container runtime is being sunsetted from GKE. Adopting cos_containerd now will avoid having to migrate in the future.Using Containerd as the container runtime still allows developers to use Docker to build containers. Here are some potential conflicts, when migrating from Docker to Containerd:running privileged Pods executing Docker commandsrunning scripts on nodes outside of Kubernetes infrastructure (for example, using ssh to troubleshoot issues)using third-party tools that perform such similarly privileged operationsusing tooling that was configured to react to Docker-specific log messages in your monitoring systemTo avoid such conflicts, we recommend a canary deployment of your clusters with cos_containerd. You can find Instructions for canary deployments in the above-linked migration documentation.Security scanning with Prisma Cloud (formerly Twistlock)To do a security scan of the pod traffic on Anthos Service Mesh, you can use Palo Alto Networks’ Prisma Cloud (formerly Twistlock), a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides multi-cloud visibility and threat detection. Please consult the Prisma Cloud admin guide (latest as of January 7, 2021) for more details.Prisma Cloud setupFor setup instructions, please see the Twistlock folder README file in the anthos-service-mesh-multicluster source code repository. The table below contains links to the official Prisma Cloud setup documentation.Table 4.1 – Prisma VersionsTLS terminationPrisma Cloud TLS requests are terminated at the Prisma Cloud console. When a request comes from Prisma Cloud SaaS to a Twistlock container, the API call is also terminated with a TLS certificate.External databases with Google Cloud SQL for PostgreSQLMany organizations wish to establish external database connectivity to their Anthos Service Mesh environment. One common example uses Google Cloud SQL for PostgreSQL (Cloud SQL).Cloud SQL is external to GKE, thus requiring GKE to do SSL termination for external services. With Anthos Service Mesh, you can use an Istio ingress gateway, which allows SSL passthrough, so that the server certificates can reside in a container. However, this approach is problematic for many PostgreSQL databases.PostgreSQL uses application-level protocol negotiation for SSL connections. The Istio proxy currently uses TCP-level protocol negotiation. This causes the Istio proxy sidecar to error out during the SSL handshake, when it tries to auto-encrypt the connection with PostgreSQL. Fortunately Cloud SQL can itself host a sidecar for TLS termination.For setup instructions, please see the postgres folder README file in the anthos-service-mesh-multicluster source code repository.Towards federated clustersAnthos Service Mesh 1.7 and 1.8 can now federate multiple GKE clusters. Taken as “managed Istio” in a single VPC, this container orchestration model takes GKE to its full potential, and can be configured using tools like Terraform and shell scripts that are available in the anthos-service-mesh-multicluster Git repo.If you have not already tried out the sample code, please navigate to the Git repo and do so. This is a good next step as the README files are detailed and instructive. Learning-by-doing is an effective way to understand Anthos Service Mesh. As well, the Terraform code uses the latest Google Cloud modules, giving you valuable tools for your toolbox.We encourage you to make contributions to the Git repo, using Google Cloud Professional Services’ contributing instructions.NOTE: As of November 12, 2020, Anthos Service Mesh, Mesh CA and the Anthos Service Mesh dashboards in Google Cloud Console are available for any GKE customer and do not require the purchase of Anthos. See pricing for details.[1] Prisma Cloud SaaS Version Administrator’s Guide[2] Twistlock Reference ArchitectureRelated ArticleGKE best practices: Exposing GKE applications through Ingress and ServicesWe’ll walk through the different factors you should consider when exposing applications on GKE, explain how they impact application expos…Read Article
Quelle: Google Cloud Platform

The Dunant subsea cable, connecting the US and mainland Europe, is ready for service

We’re thrilled to say bonjour to the Dunant submarine cable system, which has been deployed and tested and is now ready for service. Crossing the Atlantic Ocean between Virginia Beach in the U.S. and Saint-Hilaire-de-Riez on the French Atlantic coast, the system expands Google’s global network to add dedicated capacity, diversity, and resilience, while enabling interconnection to other network infrastructure in the region. It’s named in honor of Swiss businessman and social activist Henry Dunant, the founder of the Red Cross and first recipient of the Nobel Peace Prize. The historic landing was made possible in partnership with SubCom, a global partner for undersea data transport, which engineered, manufactured and installed the Dunant system on schedule despite the ongoing global pandemic.Delivering record-breaking capacity of 250 terabits per second (Tbps) across the AtlanticAs we shared when we originally announced the Dunant cable, Dunant is the first long-haul subsea cable to feature a 12 fiber pair space-division multiplexing (SDM) design, and will deliver record-breaking capacity of 250 terabits per second (Tbps) across the ocean—enough to transmit the entire digitized Library of Congress three times every second. Increased cable capacity is delivered in a cost-effective manner with additional fiber pairs (twelve, rather than six or eight in past generations of subsea cables) and power-optimized repeater designs. While previous subsea cable technologies relied on a dedicated set of pump lasers to amplify each fiber pair, the SDM technology used in Dunant allows pump lasers and associated optical components to be shared among multiple fiber pairs. This ‘pump sharing’ technology enables more fibers within the cable while also providing higher system availability. Transforming businesses in the cloud worldwideThe power and capacity of our infrastructure plays an important role in Google’s mission to make the world’s information more accessible and useful, and in Google Cloud’s role in transforming businesses in the cloud worldwide.This means organizations can:Run their apps where they need them with open, hybrid, and multi-cloud solutions so their developers can build and innovate faster, in any environment, without being forced into a single vendor solution.Get smarter and make better decisions with the leading data platform with machine learning and advanced analytics capabilities that helps them maximize the insights they derive from their data.Run on the cleanest cloud in the industry, on tools and technologies that will foster a carbon-free future for everyone and enable them to reduce their carbon footprint. Operate confidently with advanced security tools that protect their data, applications, and infrastructure—as well as that of their customers—from fraudulent activity, spam, and abuse. Transform how their people connect and collaborate, with all the digital tools they need to do their best work, whether at home, at work, or in the classroom.Save money, increase efficiency, and optimize spend—from reducing time spent on platform management with Anthos to saving up to 32% migrating your applications to Google versus running them on-prem.Get customized industry solutions that tackle their toughest challenges—retail, CPG, financial services, manufacturing, media, entertainment and telco, gaming, public sector, and healthcare and life sciences, you name it.Looking aheadThis work is part of our ongoing efforts to build a superior cloud network for our customers, with well-provisioned direct paths between our cloud and our customers. The Google Cloud network consists of fiber optic links and subsea cables—which will soon include the Grace Hopper subsea cable—between 100+ points of presence, thousands of edge node locations, 100+ Cloud CDN  locations, 91 dedicated interconnect locations and 24 GCP regions, with additional regions announced in places like Chile, Spain, Italy France and Poland. All of this means better reliability, speed and security performance as compared with the nondeterministic performance of the public internet, or other cloud networks. And while we haven’t hastened the speed of light, we’re still very much hard at work at bringing you a better and faster cloud.Learn more about our infrastructure and data centers.Related ArticleA quick hop across the pond: Supercharging the Dunant subsea cable with SDM technologyIn 1858, Queen Victoria sent the first transatlantic telegram to U.S. President James Buchanan, sending a message in Morse Code at a rate…Read Article
Quelle: Google Cloud Platform

Amazon Transcribe Medical bietet jetzt eine automatische Identifizierung geschützter Gesundheitsdaten (Protected Health Information, PHI)

Amazon Transcribe Medical ist ein HIPAA-kompatibler automatischer Spracherkennungsservice (ASR), der es Entwicklern erleichtert, Anwendungen für das Gesundheitswesen und die Biowissenschaften um Sprach-zu-Text-Funktionen zu erweitern. Wir freuen uns, dass wir ab heute die automatische Erkennung von geschützten Gesundheitsdaten (PHI) in Ihren medizinischen Transkriptionen unterstützen können. Mit der automatischen PHI-Identifizierung können Kunden die Kosten, die Zeit und den Aufwand reduzieren, die für die Identifizierung von PHI-Inhalten durch manuelle Prozesse anfallen. PHI-Entitäten werden mit jedem Ausgabetranskript eindeutig gekennzeichnet, sodass eine zusätzliche nachgelagerte Verarbeitung für eine Vielzahl von Zwecken, wie z. B. die Schwärzung vor der Textanalyse, problemlos möglich ist.
Quelle: aws.amazon.com