Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Aptible Update Webinar - January 2018

Aptible
January 30, 2018

Aptible Update Webinar - January 2018

The Aptible Update Webinar Series is a quarterly presentation that covers recent features and changes to the Enclave container orchestration platform and Gridiron security management tool. We hosted our Q1 Update Webinar on January 25, 2018. In it, we covered:

- An overview of Meltdown and Spectre. We discussed Enclave's security architecture, and our team's response to the the vulnerabilities.
- Metric Drains: We launched this feature, which had been requested often by customers. Metric drains let you route your Enclave container metrics to the destination of your choice, and allows you to do more with your metrics.
- Other Enclave feature updates.

Aptible

January 30, 2018
Tweet

More Decks by Aptible

Other Decks in Programming

Transcript

  1. Panel Discussion Meltdown & Spectre • Why Enclave is designed

    to protect you against this class of vulnerabilities • How we responded to this particular release
  2. Remediation: Timeline Date Actions January 3, 2018 Early notification on

    our status page about upcoming maintenance January 4, 2018 Shared-Tenancy • Patched all app and database instances Dedicated-Tenancy: • Patched all app instances • Scheduled maintenance windows for database instances, notified customers January 9, 2018 All patching complete
  3. • Identify abstract threats ◦ Where are you vulnerable? ◦

    Architecturally, what can you do to mitigate? • Respond to concrete vulnerabilities ◦ Prepare an incident response program ahead of time ◦ Execute on it • Assess and improve your security posture on an ongoing basis ◦ Enclave wasn’t built like this from day 1: re-architect as you identify new threats ◦ Continuously refine your incident response strategies and methods Meltdown & Spectre: Key Takeaways
  4. Metric Drains: Overview • Container Metrics captured every 30 seconds

    • Routed every 15 seconds to the destination of your choice ◦ InfluxDB (self-hosted on Enclave) ◦ InfluxDB (anywhere, e.g. hosted InfluxData) ◦ Datadog ◦ More third-party providers to come… feedback welcome!
  5. Metric Drains: What is captured? • Metrics: ◦ Running status

    ◦ CPU Usage ◦ Memory Usage (RSS / Total) & Limit ◦ Disk I/O ◦ Disk Usage & Limit (DB Only) • Each destination has its own metric format, review the documentation: ◦ go.aptible.com/metrics-influxdb ◦ go.aptible.com/metrics-datadog • Documentation also covers what these metrics mean
  6. Metric Drains: Tips • InfluxDB is now a supported Database

    on Enclave ◦ InfluxDB is a great choice to use as a Metric Drain ◦ It’s what we use ourselves for Dashboard metrics • InfluxDB pairs very well with Grafana ◦ Grafana provides visualization & alerting ◦ Grafana is trivial to deploy on Enclave with Direct Docker Image Deploy ◦ go.aptible.com/grafana
  7. Feature Review • Managed HIDS: Now generally available • VPC

    Peers & VPN Tunnels in Dashboard • Smarter CLI ◦ JSON Output ◦ Versions for aptible db:create • Smarter Databases ◦ MongoDB Replica Set Re-configuration on backup:restore ◦ Databases Auto Optimization • InfluxDB support
  8. Managed HIDS • Fully managed: enable it, we take care

    of everything else • All major compliance frameworks give credit for HIDS • Free for shared tenancy stacks. $0.02 / GB / hour for dedicated tenancy stacks. Try it out! Download reports through the Dashboard
  9. VPC Peers & VPN Tunnels: Setup • Setup is through

    support: contact.aptible.com • Once setup, connection details are visible in the Dashboard
  10. MongoDB Replica Set Re-configuration • Restored instances no longer attempt

    to join the existing replica set ◦ Required manual re-configuration before (potentially risky) ◦ Now fully automated
  11. Database Auto Optimization • Databases now configure according to their

    container size ◦ Get the most out of the resources you choose ◦ Easier to experiment with new footprints
  12. Thanks! Register for the next Aptible Product Update Webinar April

    25, 2018 2 p.m. ET / 11 a.m. PT http://go.aptible.com/product-webinar-apr-2018