
Cloud Identity & Secrets
IRSA (AWS), Workload Identity (GCP), Managed Identity (Azure), External Secrets Operator, รูปแบบ Vault
1ข้อดีหลักของการใช้ IRSA (IAM Roles for Service Accounts) ใน EKS cluster แทนการใช้ access key AWS แบบ static คืออะไร?
ข้อดีหลักของการใช้ IRSA (IAM Roles for Service Accounts) ใน EKS cluster แทนการใช้ access key AWS แบบ static คืออะไร?
คำตอบ
IRSA ช่วยให้ pod Kubernetes สามารถสวมบทบาท IAM role ชั่วคราวผ่าน OIDC ได้ ขจัดความจำเป็นในการเก็บ credential แบบ static ใน Secret สิทธิ์ถูกจำกัดตาม ServiceAccount ซึ่งเป็นไปตามหลักการ least privilege Credential จะถูกหมุนเวียนโดยอัตโนมัติโดย AWS STS (Security Token Service) ลดพื้นที่การโจมตีหาก pod ถูกบุกรุก
2ใน GCP Workload Identity Federation อนุญาตให้ pod GKE เข้าถึงทรัพยากร Google Cloud ได้อย่างไร?
ใน GCP Workload Identity Federation อนุญาตให้ pod GKE เข้าถึงทรัพยากร Google Cloud ได้อย่างไร?
คำตอบ
Workload Identity ผูก Kubernetes ServiceAccount เข้ากับ Google Service Account ผ่าน annotation Pod จะได้รับ OIDC token จาก Kubernetes API server ซึ่งจะถูกแลกเปลี่ยนเป็น GCP token ผ่าน metadata server วิธีนี้หลีกเลี่ยงการเก็บ JSON key ของ service account แบบ static ใน cluster ตามโมเดล zero-trust และช่วยให้สามารถหมุนเวียน credential อัตโนมัติได้
3ความแตกต่างหลักระหว่าง Azure Managed Identity และ service principal แบบดั้งเดิมคืออะไร?
ความแตกต่างหลักระหว่าง Azure Managed Identity และ service principal แบบดั้งเดิมคืออะไร?
คำตอบ
Managed Identity ขจัดความจำเป็นในการจัดการ credential ด้วยตนเอง (client secret, certificate) Azure จัดการวงจรชีวิตของ credential รวมถึงการหมุนเวียนโดยอัตโนมัติ Managed Identity สามารถเป็น system-assigned (ผูกกับวงจรชีวิตของทรัพยากร) หรือ user-assigned (เป็นอิสระ) ลดความเสี่ยงในการรั่วไหลของ secret เมื่อเทียบกับ service principal ที่ต้องเก็บและหมุนเวียน secret ด้วยตนเอง
External Secrets Operator ซิงโครไนซ์ secret จาก provider ภายนอก (AWS Secrets Manager, Vault) ไปยัง Kubernetes อย่างไร?
บทบาทของ mutating admission webhook controller ในการ inject secret อัตโนมัติผ่าน Vault Agent Injector คืออะไร?
+19 คำถามสัมภาษณ์
หัวข้อสัมภาษณ์ DevOps อื่นๆ
การควบคุมเวอร์ชัน & Git
พื้นฐาน Linux
Shell Scripting & Bash
พื้นฐาน Networking
พื้นฐาน Docker
พื้นฐาน CI/CD
GitHub Actions
GitLab CI/CD
Jenkins
พื้นฐาน Kubernetes
Networking ของ Kubernetes
Kubernetes ขั้นสูง
Ingress & API Gateway
พื้นฐาน Terraform
Terraform ขั้นสูง
Ansible & Configuration Management
พื้นฐาน AWS
พื้นฐาน Azure
พื้นฐาน GCP
การมอนิเตอร์และ Prometheus
Logging & ELK Stack
Alerting & Incident Response
ความปลอดภัยของ CI/CD Pipeline
Helm & Kubernetes
ความปลอดภัย Runtime และ Cluster
Container Supply Chain Security
Service Mesh & Istio
GitOps & ArgoCD
Progressive Delivery
Observability แบบกระจาย
Disaster Recovery & Backup
การปรับแต่งประสิทธิภาพ
การเพิ่มประสิทธิภาพต้นทุน Cloud
หลักการ SRE
Chaos Engineering
Platform Engineering
เชี่ยวชาญ DevOps สำหรับการสัมภาษณ์ครั้งถัดไป
เข้าถึงคำถามทั้งหมด flashcards แบบทดสอบเทคนิค แบบฝึกหัด code review และตัวจำลองสัมภาษณ์
เริ่มใช้ฟรี