Cloud Custodian - Policies? Resource Management? Something Else?

Cloud Custodian - Policies? Resource Management? Something Else?

Source: YouTube · DevOps & AI Toolkit · published Feb 13, 2023 · 31:09

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Cloud Custodian is a powerful tool for finding non-compliant cloud resources and enforcing policies as a "second line of defense" across multiple providers 1:33-1:55. It's particularly valuable for organizations that need to audit and remediate resources regardless of how they were created 30:20-30:57.

Key Takeaways:
• Cloud Custodian can identify non-compliant resources and take automated actions like tagging, stopping, or terminating them 5:01-5:47
• It works across multiple cloud providers (AWS, Azure, GCP) and Kubernetes environments 3:54-4:12
• Multiple policies can work together in sequences to enforce compliance over time 7:05-9:51
• It works regardless of how resources were created (direct console, Terraform, Pulumi, etc.) 13:04-13:52

Cloud Custodian is best suited for organizations that need to audit and enforce policies as a secondary measure, rather than as a primary prevention tool 30:20-30:57.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

policy tools are a must for any serious company and became a long long way since the days of wild west where anyone can do anything they want or the other extreme of no one being able to do anything because the sheriff says so today we can relatively easily create policies that can burn us when we do something wrong and Foster good practices I intentionally say good not the best practices because that's a really bad term it assumes that something is Everlasting forever and it's not anyways we can enforce policies on the client side like from a terminal or a cicd pipeline or on the server side from inside the server or a kubernetes cluster we can use those that are general purpose like Opa with gatekeeper caverno or that tree by the way I already explored those in the previous videos so che…