0% found this document useful (0 votes)
10 views23 pages

Module 1

The document provides an overview of AWS Cloud Foundations and IAM, detailing the benefits of cloud computing, types of virtualization, and cloud deployment and service models. It explains AWS's global infrastructure, the shared responsibility model for security, and the features of AWS Identity and Access Management (IAM). Additionally, it highlights AWS's history, advantages, and the importance of IAM in managing user access to AWS resources.

Uploaded by

gokulleo1030
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views23 pages

Module 1

The document provides an overview of AWS Cloud Foundations and IAM, detailing the benefits of cloud computing, types of virtualization, and cloud deployment and service models. It explains AWS's global infrastructure, the shared responsibility model for security, and the features of AWS Identity and Access Management (IAM). Additionally, it highlights AWS's history, advantages, and the importance of IAM in managing user access to AWS resources.

Uploaded by

gokulleo1030
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module -1

AWS Cloud Foundations & IAM

Introduction to Cloud Computing

Cloud computing is a model to access IT resources (servers,


storage, databases, networking, set of application services, etc.) as a
service through internet. It allows applications and services to run on a
distributed network using virtualization technology.
Today almost everyone uses cloud computing such as startups,
organizations, IT professionals, analysts, and individual users. For
example, some well known software and applications such
as Netflix, Instagram, Office 365, LinkedIn, etc. are running on cloud.

Benefits of Cloud Computing

▪ Cost Savings: -You don’t need to buy physical hardware and setup
infra Infrastructure to build a software solution. You can get ready
for Infrastructure in a few minutes on a pay-as-you-go basis. It helps
you to save a lot on capital costs.
▪ Deployment Speed: As cloud computing can provide Infrastructure
in a few minutes, now it’s easy to deploy your services in a few clicks
and with less effort. The time consumed in deployment depends on
what technology is used in your application. A study says that
companies who have deployed their applications on the cloud are
gaining a competitive advantage because of rapid development and
early in the market.
▪ Data back-up and restore: It is easy to take back up and restore data
from cloud. You can also configure more (data replication policy) to
make sure data availability even after a disaster.
▪ Disaster Recovery: One of the most important factors to the success
of business. Unfortunate things such as downtime of
servers/services, disaster on one of your hosted regions, etc. can
happen at any time even if your organization planned everything very
well. The best way to manage disaster is a speed up your recovery.
cloud based services allow to recover your business quickly from
natural disasters, server downtime, power outages etc.
▪ Storage capacity: You can store a lot of data (almost limitless) on
cloud with cost applied by cloud providers. Cost of storage depends
on some parameters like how frequently you want to access it, where
you want to store it etc.
▪ Reliability: Reliability and availability in cloud computing is one of
the great advantages of cloud computing. Cloud providers maintain
their infrastructure for running workloads that require high
availability.
▪ Mobility: Cloud computing allows mobile access to corporate data
using internet from anywhere. This is a great way to offer
conveniently accessible information for remotely working co-
workers.

Including above some more benefits of cloud computing are


Automatic Software Updates, On-Demand Self-service, Multi-
tenancy, Sustainability, Scalability, etc.

Understanding Virtualization in Cloud Computing


Virtualization is a technique to transform physical infrastructure such as
operating system, storage devices, network, etc. into virtual infrastructure.
It allows multiple users to run multiple software and application on the
same server at the same time. .

Virtualization is one of the core components of cloud computing. For


example, If you want to create a private cloud you will need virtualization
software in order to create a virtual infrastructure like networks, servers,
storage, etc. Virtualization enables to share same resource with multiple
users, shared resources help to make cloud computing costs efficient,
maximize utilization of servers, and better accessibility, and scalability.
Different Types of virtualization are used in cloud computing such as
Network virtualization, Operating System Virtualization, Hardware
Virtualization, Server Virtualization, Storage Virtualization, etc.

Types Of Cloud Computing


Cloud computing can be separated into two types: Deployment Model and
Service Model.

Cloud Deployment Model


Cloud deployment models are a configuration of environment to declare
how the cloud services are available to users. The deployment model can
be separated by some parameters such as ownership, size of
infrastructure, who can control the infrastructure, and where infrastructure
exists.
There are four most common cloud deployment models are public cloud,
private cloud, hybrid, and community cloud.

1. Public Cloud: Public clouds are available for all users who want to
use infrastructures such as computing resources (Amazon Ec2),
Storage, database services, etc. on a pay-per-use or subscription
basis. User or organization do not need to buy and maintain
hardware instead cloud providers maintain the infrastructure.
Mostly public cloud deployment model is used for businesses where
privacy is not a major concern or non-mission critical tasks. Public
cloud uses the multi-tenancy model, which also allows users to scale
resources when required.
2. Private Cloud: Private cloud is more expensive than public cloud, but
it allows better control on security and privacy of organizations.
Private cloud provides the same benefits of public cloud, the
difference is that allocated cloud infrastructure is dedicated to only
one tenant/organization. Infrastructure resource is not shared with
other organizations. Private cloud can be managed on on-premise by
organization itself or it can be managed by a cloud service provider.
3. Hybrid Cloud: It is a combination of public and private cloud. For
example, An organization can manage its mission-critical workloads
on a secure private cloud and deploy less sensitive/secure ones to
public cloud. This scenario provides a very good balance between
security, scalability, Cost.
4. Community Cloud: A community deployment model is almost same
as a private cloud but the difference is sharing data between
organizations. In community cloud organizations who belong to
same backgrounds share the infrastructure, resources, and data. For
example, the government of a country can have multiple
organizations internally, but they need to share some common data.

Cloud Service Model


Cloud service model is mainly divided into three types: Infrastructure as a
Service (IAAS), Platform as a Service (PAAS), and Software as a Service
(SAAS). Selection of right service model depends on your requirement.
1. Infrastructure-as-a-Service (IaaS): Infrastructure as a Service
model: Cloud service provider allows virtual provision of your
infrastructure components (such as networking hardware, server,
storage, etc.). They also provide maintenance and support for the
provisioned hardware infrastructure while your business needs to
maintain the operating systems, system and security updates,
storage, and deployed applications. The IaaS model provides a lot of
flexibility to control, manage and customize your infrastructure as
per the requirement.
2. Platform-as-a-Service (PaaS): Cloud service providers deliver a set
of resources such as hardware, servers, storage, networking, etc.
which are required for application development. As hardware and
software are hosted by the service provider, they are managing the
hardware and software updates. Users only need to access the
platform to start their work. PAAS is based on subscription, which
means pricing/billing is depending on a per-user or monthly basis.
3. Software-as-a-Service (SaaS): Software as a Service model: SAAS
model allows quick access to your business using internet with zero
installation, User only needs a web browser to access cloud-based
web applications. This type of application runs on vendor’s cloud
also they control the entire computing platform. Some Well-known
SAAS examples are Netflix, Instagram, Microsoft Office
365, LinkedIn, etc.

What is AWS?
AWS (Amazon Web Services) is the world’s biggest and most secure cloud
platform.
AWS offers many services such as computing power, virtual private
network, database storage, content delivery, etc. to millions of customers
including individual user, startups, organizations, and government
agencies across the globe.

AWS History
▪ In 2002 Amazon Web Services was launched as a subsidiary of
Amazon.
▪ In 2004, first AWS service Simple Queue Service (SQS) was
launched.
▪ In 2006, AWS re-launched the three initial service S3 cloud storage,
SQS, and EC2.
▪ In 2009, AWS launched a new service virtual private cloud (VPC)
which enables customers to create their own isolated network within
the AWS cloud.
▪ Now, AWS offers around 175 fully featured services from data
centers globally.

Advantages of AWS
▪ AWS is a comprehensive cloud platform with almost 73 Availability
Zones within 23 geographic regions around the world. They already
support millions of active clients.
▪ AWS offers to all customers(an individual, start-up, or organizations)
simple billing with dynamic options such as per hour billing, term-
based pricing, and region-based pricing, you can select any option as
per your requirement.
▪ Security is one of the major concerns when using a cloud platform.
They have well defined security compliance and protocol to protect
your important business information from leaks and the risk. Some
well-known organizations like Netflix, NASDAQ, Dow Jones, US Govt.
applications use AWS platform.
▪ Almost every service available on AWS cloud platform can be
required for your organization. Also, Amazon continuously working
on cost optimization for services like machine learning, analytics,
blockchain, SAAS (Software as a Service) etc.
▪ Gartner report names AWS a 2021 Magic Quadrant Leader.

AWS Global Cloud Infrastructure


AWS Global Cloud Infrastructure is built around multiple geographical
locations (Regions) and Availability Zones (AZs). Availability Zones can
have one or more psychically separated data centers.
AWS Global infrastructure components

Region

Region is a collection of availability zones (AZs) and each region contains


at least two Availability Zone. Each region is geographically/physically
isolated from the others. AWS has deployed regions worldwide to provide
low latency connections, redundant networks, and high throughput to their
customers.

Availability zones(AZs)

Availability zones (AZs) are the logical data centers of AWS. Each
availability zone is isolated from another AZ within the same region. Each
Availability zone has separated infrastructure resources such as power,
network, compute server, database resources, storage, etc. with low
latency connections. An Availability zone can have one or more physical
data centers.
These AZs allow users to configure, design and run applications and
databases with high availability, scalability, and fault tolerance. For
example, when AWS resources are configured with ‘Multi-AZ’ deployments,
AWS automatically replicates same data based on its primary and
secondary AZs configurations.

Edge locations

In order to reduce latency, AWS provides content delivery network (CDN)


endpoints called Edge location. Edge locations are not used to deploy your
AWS resources, instead use (by end users) to cache data to reduce latency.

Regional Edge Caches

CloudFront points of presence (POPs) (edge locations) help to serve your


popular content quickly to your viewers. AWS announced a new type of
Edge Location (Regional Edge Caches) where a larger cache-width is
available to store content like video, photos, artwork, etc. Data can be
served from Regional Edge Cache even after expires/invalidate from the
cache at the Edge Locations.

AWS Global and Regional Services


▪ Global Services
▪ IAM (Users, Groups, Roles, Accounts)
▪ Route 53
▪ WAF
▪ CloudFront
▪ S3 – Global but data is Regional
▪ Regional Service – Check Complete list
here: [Link]
infrastructure/regional-product-services

To explore AWS products and services you can create 12 month free trial
account.

AWS shared responsibility model?


The Shared Responsibility Model is a structure for cloud security that
describes the responsibilities of cloud service providers and consumers.
Cloud provider offers to consumers a range of cloud services such as
computing, virtual private network, database storage, content delivery, etc.
Cloud provider offers the service and consumers makes advantage of it.
According to AWS Shared Responsibility Model, “AWS is responsible for
the Security of the Cloud and the customer is responsible for the Security
in the Cloud”. Cloud providers and consumers both share some
responsibilities, the cloud provider is responsible for the service provided,
and the consumers are responsible for the service usage.

Organizations’ primary issue is an unclear understanding of their roles,


which can compromise security. According to several studies, incorrectly
shared security responsibilities were to blame for several security
incidents. This uncertainty allows hackers a blind spot to attack. As a
result, Amazon Web Service (AWS) created the AWS Shared Responsibility
Model to define roles.

AWS responsibilities vs Customer responsibilities

AWS shared responsibility model

AWS Responsibilities (Securities of the cloud)

AWS is in charge of securing the infrastructure that runs all of the services
provided by the AWS Cloud. AWS Infrastructure-level security includes-
Data centers, Hardware, software, Virtualization, and Networking.

Customer Responsibility (Securities in the cloud)

Customers are responsible to manage the guest operating system,


including security patches and application software. Also, they need to
configure the AWS-provided security controls like security groups, network
access control, and IAM (Identity and Access Management). Or the
customer manages AWS services, software, and access to the data.
AWS - IAM (Identity and Access Management)
Identity and Access Management (IAM) is a security service offered by
AWS which allows you to manage user level access to AWS services and
resources securely. You can create and manage AWS IAM users and
groups to allow and deny access to AWS resources.

For example, a user allows to access EC2 service (Application server


service) but deny to access S3 Service(Application data storage).

IAM: Components
▪ Users: An AWS IAM user is a unique identity with security credentials
like a password or access & secret key. User is associated with
permissions to control use of AWS resources. IAM User can be an
individual person or application who needs access to another AWS
Service.
▪ Groups: A group of collection of AWS IAM users. You can grant
permissions to group using access control policies, Assigned
permissions apply to all users belongs to that group. A user can be
associated with multiple groups but a group can not be part of
another group. Groups are helpful to categorize multiple
responsibilities in an organization for example Admin Group,
Developer Group, Support Group etc.
▪ Roles: AWS IAM role is a set of permissions to access AWS services.
An IAM role is same as an IAM user that defines what is allowed and
denied by an entity (User, application, or AWS service).AWS IAM roles
are not associated with a group or specific user, Instead, it works
based on temporary credentials/assume roles. Assuming a role
means getting Security Token Service (STS) to provide you with a set
of temporary credentials which are associated with the role and not
with the entity that assumed the role.
▪ Policies: AWS IAM policies are associated with the AWS users,
groups, and roles. It is a set of permissions and control access to
AWS resources. Users, groups, and roles have no permissions by
default. A policy is a JSON document with information about
permissions such as:
▪ Who can access AWS resource
▪ Which AWS resources are allowed to access
▪ What actions are allowed and denied
▪ When AWS resources can be accessed.
AWS IAM: Features
▪ Centralize Control: AWS IAM Service allows you to manage
centralized control of your AWS account. It means you can manage
your AWS users, users’ security credentials, and their permission to
access AWS resources.
▪ Shared Access: You can create a new user (with username and
password) or modify existing user permission to delegate the
responsibility of your role (i.e. Admin) without sharing your
credentials.
▪ Granular Control: You can apply restrictions to different users for
different AWS resource access. For example, you might allow users
related to IT department can manage only EC2 service (i.e. your
application servers) and users related to Database Team can
manage only RDS services (i.e. your application database).
▪ Multi-factor authentication (MFA): You can use two-factor
authentication for extra security checks. Two-factor authentication
is a method of authentication where users must provide their
credentials to work with account and also require a code from a
configured device.
▪ Identity Federation: In case user is already registered and
authenticated, such as in your corporate network or Facebook or
Google or with any other internet Identity Provider- You can allow
user to get access to AWS account using trust authentication
method. This way helps user to maintain just one password to
manage both accounts.
▪ Password Policy: AWS IAM allows you setup your own password
policy using some configuration. For example, you can set password
rules/patterns, expiry date, rotation policy, and no. of attempts allow
before blocking the account.
▪ IAM Cost: It is free to use. There is no additional charge for creating
Users, Groups, roles, and policies. Charges will be applied only to use
of other AWS services by users.
▪ PCI DSS (Payment Card Industry Data Security Standard )
compliance: IAM complies/meet specified security standard for
payment related industry requirements like processing, storage, and
transmission of credit card data by a merchant or service provider.
▪ IAM can provide temporary access for User/Devices or services to
use other AWS resources in your account.

IAM: How It works


▪ IAM Request: To access AWS (AWS Console, CLI, API) an IAM
request sends to AWS by principal/user. Request context contains
information:
▪ Actions or operations – The actions or operations that the
principal wants to perform.
▪ Resources – The AWS resource object upon which the actions
or operations are performed.
▪ Principal – Principal and their the policies that are associated
with the entity that the principal used to sign in.
▪ Environment data – Information about the IP address, user
agent, SSL enabled status or the time of day.
▪ Resource data – Data related to the resource like S3 bucket,
file name, etc.

Identity and Access Management (IAM) is a security service that helps to


manage access for AWS resources. Authentication and authorization are
important for the security of any system. This tutorial will help you to
understand the AWS IAM entities and how to control permissions on AWS
services/resources.

IAM Entities
Users: AWS/IAM user is a unique identity with security credentials like a
password or access & secret key. User is associated with permissions to
control the use of AWS resources.

Groups: A user group can contain many users. You can grant permissions
to group using access control policies, Assigned permissions applicable
to all users belongs to that group.

Roles: An IAM role is similar to an IAM user, Roles are used to delegating
access to AWS resources and AWS Users temporarily instead of sharing
credentials. A role is intended to be assumable by anyone who needs it.

When you create a role in an AWS account, you need to define two policies
for granting permissions to someone to allow access to AWS resources
that you control:-

▪ Trust Policy: To define who is allowed to assume the role (Principle:


It includes users, roles, AWS accounts, and services)
▪ Permission policy: To define what actions and resources are allowed
by the role.

Policies: A policy is a JSON document with information about permissions.


IAM policies are associated with the AWS users, groups, and roles.
IAM Policy and Permissions
IAM policy let you define permissions such as:

▪ Who can access AWS resources.


▪ Which AWS resources are allowed to access.
▪ What actions are allowed and denied.
▪ When AWS resources can be accessed.

Identity-based and Resource-based permissions

By default IAM entities (users, groups, and roles) start with no permissions.
You need to follow the Least privilege principle as a security best
practices. Make sure you set permissions with IAM policies, and grant only
the required permissions to complete a task. AWS permissions are
managed by IAM Policies.
Types of IAM policies
▪ Identity-based policies: Identity-based policies are attached to AWS
identities like user, group, or role. For example, you can attach the
policy to an IAM user called “Bob” to list items from an Amazon
S3 bucket named “my-example-bucket-123”. Identity-based policies
can be further categorized :
▪ Managed Policies: Managed policies are standalone identity-
based policies that can be attached to multiple principal
entities (users, groups, and roles).
▪ AWS Managed – These policies are created, updated,
and managed by AWS. By default, there are many pre-
defined AWS managed policies available in your AWS
Account that are aligned with job functions in the IT
industry.
▪ Customer Managed – These policies are created,
updated, and managed by customers. AWS Customers
can create their own policy for customized environment.
▪ Inline Policies: Inline policies maintain the strict one-to-one
relationship. It means inline policies directly embedded in a
single principal entity (user, group, or role). Inline policies get
deleted when you delete the entity that contains the policy.
▪ Resource-based policies: Resource-based policies are attached to
the AWS resources like Amazon S3 buckets, VPC endpoints,
Amazon SQS queues, AWS KMS, and Other services.
IAM Policy elements
A JSON policy document contains following elements :

Version – The version of the policy language (2012-10-17). As a best


practice, use the latest version.

Statement – Main policy element as a container. You can add multiple


statement in a policy.

Sid – It is an optional identifier for the policy to differentiate between your


statements.

Effect – Grant permission (allow or deny)

Principal – Who can access it. In case of resource-based policy, you need
to add a principal (account, user, role, or federated) to define allow or deny
access. If you are creating an IAM permissions policy to attach to a user
or role, you cannot include this element.
Action – List of actions that the policy allows or denies.

Resource – If you create an IAM permissions policy, you need to specify


the list of resources to which the actions apply. In case of resource-based
policy, this element is optional.

Condition – It is an optional element. You can specify the condition under


which the policy grants permission.

IAM Policy Examples


Example-1: An identity-based policy to allow user to access EC2 service
within a specific Region (Mumbai – ap-south-1)

{
"Version": "2012-10-17",
"Statement": [
{
"Action": "ec2:*",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ec2:Region": "ap-south-1"
}
}
}
]
}
Example-2: A resource-based policy that allows Amazon S3 to invoke a
lambda function named store-url-function for a bucket named my-
example-bucket-123 in account 100006009000.

{
"Version": "2012-10-17",
"Id": "default",
"Statement": [
{
"Sid": "invoke-lambda-by-s3",
"Effect": "Allow",
"Principal": {
"Service": "[Link]"
},
"Action": "lambda:InvokeFunction",
"Resource": "arn:aws:lambda:ap-south-1:100006009000:function:store-
url-function",
"Condition": {
"StringEquals": {
"AWS:SourceAccount": "100006009000"
},
"ArnLike": {
"AWS:SourceArn": "arn:aws:s3:::my-example-bucket-123"
}
}
}
]
}

IAM Policy evaluation


When principal/user sends a request to access AWS resource from AWS
Console, CLI, or API, AWS first authenticates and authorizes the principal
that makes the request. Once the user’s request has been authenticated
and authorized, AWS check for the requested actions/operations in your
request and approves them if they are valid.

AWS evaluates policies depending on the types of policies that apply to the
request context. Summary of AWS evaluation logic for policies within a
single account:

▪ All requests are implicitly denied by default, except AWS account


root user which has full access.
▪ An explicit allow in the policy overrides this default.
▪ If a permissions boundary, Organizations SCP, or session policy is
present, it might override the allow with an implicit deny.
▪ An explicit denial in any policy overrides any allows.

Flow chart provides details about how the decision is made: –


IAM: Best practices
▪ Do not use your root user credentials for your daily work. Also,
remove access key and secret key of root user. Create an individual
IAM User for yourself as an Administrator to manage your work.
▪ Assign permissions at IAM group or role level instead of the
individual IAM user level.
▪ Make a practice to regularly review your organization’s AWS IAM
policies and grant least permissions to users.
▪ Try to use AWS managed Policies to assign permissions If possible.
▪ To manage your own custom policies use customer managed policy
option instead of inline policy. It helps to manage your own custom
policy in one place.
▪ Define a strong password policy for your users with some expiry
date. Force user to change password after a certain time to make
more secure your AWS environment.
▪ Use IAM roles for applications/resources that need to access other
AWS resources.
▪ Monitor user, and last activity and removed unused user and
credentials.
▪ Enable MFA ( multi-factor authentication)
▪ Do not share your credentials (password, access key, and secret
access key).

You might also like