← Writing
Development & Cloud

รีวิว DevSecOps Transformation & Technologies — Skooldio (Part 2/3)

พัฒนา Software อย่างมีประสิทธิภาพ ด้วย DevSecOps

16 Dec 202414 min readAI AgentDashboard

รีวิว DevSecOps Transformation & Technologies — Skooldio (Part 2/3)

พัฒนา Software อย่างมีประสิทธิภาพ ด้วย DevSecOps

Connect with me and follow our journey: Linkedin, Facebook


ใน Part 1 เราได้เรียนรู้เกี่ยวกับ ภาพรวมของ DevSecOps, VCS, CI/CD และ Artifacts ซึ่งเป็นส่วนที่เน้นไปที่ฝั่ง Developer หากยังไม่ได้อ่านแนะนำให้กลับไปอ่านก่อนนะครับ:

ใน Part 2 นี้ เราจะโฟกัสที่ Infrastructure (Cloud, Containers, Docker, Kubernetes), Monitoring และ Automation Security ซึ่งเป็นส่วนที่เกี่ยวข้องกับ Operation และ Security

Figure: สรุปภาพรวมเนื้อหาในส่วนที่ 2 (Image by Author)

3. Infrastructure

Figure: Infrastructure: Cloud, Container, Docker, Kubernetes (Image by Author)

Modern Infrastructure

ปัจจุบัน Infrastructure ถูกออกแบบให้รองรับการพัฒนาซอฟต์แวร์ที่มีการ Scale อย่างรวดเร็วและ Dynamic ซึ่งทีม Dev และ Ops ควรรู้จักแนวคิดเหล่านี้:

  • Cloud Computing: รองรับการ Scale ระบบแบบ Dynamic
  • Container & Docker: ช่วยสร้าง Environment ที่คงที่และแชร์ได้
  • Kubernetes: ระบบจัดการและ Orchestrate Containers สำหรับระบบขนาดใหญ่

ประเภทของ Cloud: Private, Public, Hybrid และ Multi-Cloud

  • Private Cloud: องค์กรสร้างและดูแลโครงสร้างพื้นฐานเองทั้งหมด (Hardware & Software) ตัวอย่าง: VMWare, Nutanix, OpenStack
  • Public Cloud: ผู้ให้บริการ Cloud จัดเตรียม Infrastructure พร้อมใช้งานตัวอย่าง: AWS, Azure, Google Cloud, Alibaba Cloud
  • Hybrid Cloud: ผสานระหว่าง Private Cloud และ Public Cloud ตัวอย่าง: AWS Outposts, Google Anthos, Azure Stack
  • Multi-Cloud: ใช้ Cloud หลายเจ้าเพื่อเพิ่มความยืดหยุ่นและลดความเสี่ยง
  1. Hybrid Cloud และ Multi-Cloud เป็นที่นิยมในองค์กรขนาดใหญ่
  2. Cloud มีคุณสมบัติที่สอดคล้องกับ DevSecOps Core Values ได้แก่:
    - On-demand Self-service: Dev สามารถสร้างหรือปรับเปลี่ยน Environment ได้เองภายใต้ข้อจำกัดที่กำหนด
    - Rapid Elasticity and Scalability: รองรับการขยายระบบอย่างรวดเร็ว

Cloud Service Models

  • Private Cloud: ลูกค้าต้องดูแลโครงสร้างพื้นฐานเองทั้งหมด เช่น จัดการเซิร์ฟเวอร์, การเดินสาย, การจัดการ OS
  • Infrastructure as a Service (IaaS): ผู้ให้บริการดูแล Physical Infrastructure (Networking, Storage, Servers) ลูกค้าจัดการเฉพาะ OS และ Application เช่น AWS EC2, Google Compute Engine
  • Platform as a Service (PaaS): o ผู้ให้บริการดูแล OS และ Infrastructure ให้ทั้งหมด ลูกค้าเพียงจัดการโค้ดและการ Deploy เช่น Kubernetes, Google App Engine
  • Software as a Service (SaaS): ลูกค้าใช้งาน Software โดยไม่ต้องดูแลอะไรเลย เช่น Office 365, Gmail, Zoom

PaaS, Serverless และ BaaS

  • PaaS (Platform as a Service): ให้บริการ Platform สำหรับ Deploy โค้ด เช่น Kubernetes, Google App Engine ข้อเสีย: คิดค่าใช้จ่ายตลอดเวลา แม้ไม่มีผู้ใช้งาน
  • Serverless: พัฒนาแนวคิด PaaS โดยคิดค่าใช้จ่ายเฉพาะเมื่อมีการใช้งาน เช่น AWS Lambda, Cloud Run, Google Cloud Function ข้อเสีย: มีปัญหา Cold Start (เริ่มทำงานช้าในช่วงไม่มีการใช้งานนาน)
  • BaaS (Backend as a Service): ให้บริการ Backend สำเร็จรูป เช่น Database, Authentication เช่น Firebase

Containers, Docker และ Kubernetes

  • Virtual Machine (VM) vs Docker Container
    - VM: ระบบเสมือนที่จำลองทั้ง OS และฮาร์ดแวร์ ทำงานแยกจากกัน
    - Docker Container: ระบบเสมือนน้ำหนักเบาที่รันเฉพาะแอปพลิเคชันและไลบรารีที่จำเป็น บน OS หลักเดียวกัน
    - ทั้ง VM และ Container จะต้องใช้ด้วยกัน ไม่มีใครมาทดแทนใคร เพราะ Container ยังจัดการ Resource ไม่ดีในเครื่องขนาดใหญ่

- ทั้ง VM และ Container ควรถูกใช้ร่วมกัน เพราะแต่ละเครื่องมือมีจุดแข็งที่ต่างกัน
- อย่าใช้ Container สำหรับ Production Database ให้จัดการใน VM จะดีกว่า

Figure: VM vs Container from https://www.netsolutions.com/insights/containerization-vs-virtualization/

  • Container:
    Container เป็นการแยกทรัพยากรสำหรับรันแอปพลิเคชันอย่างมีประสิทธิภาพ ลดปัญหา “มันรันบนเครื่องฉันได้ แต่บน Production ไม่รัน”
  • Docker: Build → Ship → Run
    Docker คือซอฟต์แวร์ที่ทำให้การใช้งาน Container ง่ายขึ้น มี Workflow หลัก:
    - Build: สร้าง Docker Image ผ่าน Dockerfile (ชุดคำสั่งในการสร้าง Docker Image)
    - Ship: ส่ง Docker Image ไปยัง Docker Registry เช่น Docker Hub
    - Run: รัน Docker Image เป็น Container บนทุก Environment (Build once Run any where)

- ในตอนนี้แนะนำให้ Run Dover บน Linux OS
- Concept: “Build Once, Run Anywhere” คล้ายกับ CI/CD Pipeline:
CI = Build | Artifact Server = Ship | CD = Run

  • Docker Layer/Docker Components
    - Docker Image: ไฟล์ต้นแบบสำหรับสร้าง Container
    - Docker Container: Instance ของ Docker Image ที่รันอยู่
  • Kubernetes: Container Orchestration
    Kubernetes เป็นระบบจัดการ Containers หลายตัวแบบอัตโนมัติ เหมาะสำหรับระบบที่ต้องการการ Scale, Reliability, และการบริหารจัดการที่ซับซ้อน
  • Kubernetes Distribution: มีการพัฒนา Kubernetes แบ่งออกเป็น 3 กลุ่ม:
    - Installation Tools: Minikube, Kubespray, Kops, K3S, MicroK8s
    - Commercial: OpenShift (Red Hat), VMware Tanzu, Rancher
    - Public Cloud: Azure Kubernetes Service (AKS), Amazon Elastic Kubernetes Service (EKS), Google Kubernetes Engine (GKE), etc.

หากใช้ Cloud เจ้าไหน ควรเลือก Kubernetes เจ้านั้นเพื่อการ Integrate ที่ง่ายขึ้น

Figure: Automation and Infrastructure as Code (Image by Author)

Infrastructure Automation

Infrastructure Automation เป็นแนวคิดที่ช่วยให้การจัดการระบบ IT มีความง่ายและรวดเร็วมากขึ้น โดยใช้หลักการ Infrastructure as Code (IaC) เพื่อทำให้การกำหนดค่าโครงสร้างพื้นฐานเป็นแบบอัตโนมัติ และสามารถทำซ้ำได้อย่างแม่นยำ

  • Infrastructure as Code (IaC)
    IaC หมายถึง การกำหนดโครงสร้างของ Infrastructure ผ่าน Code โดยไม่ต้องใช้การตั้งค่าด้วยมือ (No Click Ops) ช่วยลดข้อผิดพลาดและเพิ่มความสามารถในการทำซ้ำ (Reproducibility) เครื่องมือยอดนิยมใน IaC ได้แก่:
    - Ansible: สำหรับ Orchestration และ Automation ใช้ภาษา YAML ที่เข้าใจง่าย
    - Terraform: สำหรับ Provision และจัดการ Infrastructure

ใช้ Terraform สร้าง Infrastructure และใช้ Ansible ในการ Orchestration

Figure: Monitoring (Image by Author)

4. Monitoring

Monitoring เป็นกระบวนการตรวจสอบและเก็บข้อมูลจากระบบเพื่อวิเคราะห์ประสิทธิภาพ, ตรวจจับปัญหา, และทำ Feedback Loop ในทุกขั้นตอน

ประเภทของ Monitoring Data

  1. Check (Alert/Status Monitoring): ใช้ตรวจสอบสถานะว่า ระบบทำงานปกติหรือไม่ เช่น 0 = ปกติ, 1 = Error, 2 = ไม่มี Data ส่งมา (บางที่มี)
  2. Metric (Time-Series Data): ค่าตัวเลขที่เปลี่ยนแปลงตามเวลา เช่น CPU Usage, Memory Usage
  3. Log (Textual Information): ข้อความที่แสดงข้อมูลการทำงาน เช่น Error Logs
  4. Tracing (Application Performance Monitoring — APM): แสดงเส้นทางการทำงานของ Application อย่างละเอียด

Monitoring Stack (6 Layers)

  1. Network: Bandwidth, Latency, Throughput
  2. Physical Devices: อุณหภูมิ CPU, สถานะพัดลม
  3. Operating System (OS): CPU Usage, Memory Usage
  4. Software & Database: จำนวน Requests, Query Latency
  5. Development Application: Latency ของ API, Error Rate
  6. Business Layer: รายได้, จำนวนผู้ใช้งาน

Monitoring Tools และ Components

  1. Collector Sensor: ทำหน้าที่เก็บข้อมูล เช่น StatSD, Fluentd
  2. Database: จัดเก็บข้อมูล Monitoring เช่น Prometheus, InfluxDB
  3. Visualization: แสดงข้อมูลใน Dashboard เช่น Grafana, Kibana
  4. Analysis Alert: วิเคราะห์และแจ้งเตือน เช่น Sensu, Flapjack

Performance Load Testing

  1. Load Testing: จำลองการเพิ่ม load จาก 0 จนถึงระดับที่กำหนด
  2. Stress Testing: เพิ่ม load ไปเรื่อย ๆ จนกว่าระบบจะล่ม เพื่อหาจุด breaking point ที่ระบบรองรับได้
  3. Spike Testing: ทดสอบการรับ load ที่เพิ่มขึ้นแบบฉับพลัน
  4. Soak Testing: ทดสอบระบบภายใต้ load ที่คงที่เป็นระยะยาว
  5. Capacity Testing: ประเมินความสามารถของระบบในการรองรับผู้ใช้งาน

Figure: Automation Security (Image by Author)

5. Automation Security

Automation Security ช่วยเร่งความเร็วและเพิ่มความแม่นยำในการตรวจสอบความปลอดภัย โดยใช้แนวคิด Shift Left (เน้นความปลอดภัยตั้งแต่ต้นกระบวนการ)

Step 1: Precommit Stage

ในขั้นตอนนี้ เน้นไปที่ Source Code Security เพื่อป้องกันปัญหาด้านความปลอดภัยตั้งแต่ต้นทาง โดยแนวปฏิบัติที่สำคัญคือ Secure Coding ซึ่งถึงแม้จะไม่ได้เกี่ยวข้องกับ DevSecOps โดยตรง แต่เป็นพื้นฐานสำคัญที่ Developer ทุกคนควรรู้

  • Best Practices in Secure Coding (ตาม OWASP):
    - Input Validation: ตรวจสอบข้อมูลที่เข้ามาว่าเป็นไปตามรูปแบบที่คาดไว้
    - Authentication & Password Management: หลีกเลี่ยงการเก็บ Password แบบ Plain Text
    - Access Control: กำหนดสิทธิ์การเข้าถึงข้อมูล
    - Cryptographic Practices: ใช้การเข้ารหัสที่แข็งแรง หลีกเลี่ยงการใช้วิธีล้าสมัย
  • Static Application Security Testing (SAST):
    สแกนโค้ดแบบ Static เพื่อค้นหาช่องโหว่ก่อน Compile หรือ Deploy
    ตัวอย่าง Tools: SonarQube, GitLab
  • Software Composition Analysis (SCA):
    วิเคราะห์ 3rd Party Libraries และ Framework เพื่อหาช่องโหว่และความเสี่ยง
    ตัวอย่าง Tools: OWASP Dependency Check, GitLab

Step 2: Acceptance Stage

Acceptance Stage มุ่งเน้นการ Security Testing เพื่อให้มั่นใจว่า Application พร้อมใช้งานอย่างปลอดภัยก่อนขึ้น Production
- Penetration Testing (Pen Test):จำลองการโจมตีจาก Hacker เพื่อหาช่องโหว่ (มักเป็น Manual Testing)
- Vulnerability Assessment (VA Scan): ใช้ฐานข้อมูล Vulnerabilities สแกน API หรือ Web-based UI (สามารถทำ Automation ได้ง่าย)
- Fuzz Testing: ใช้ข้อมูลแบบสุ่ม (Brute-force) ใส่ใน Form หรือ Input Fields (Automate ได้ 100%)

  • Dynamic Application Security Testing (DAST):
    ตรวจสอบ Application ที่รันอยู่ (Dynamic) โดยไม่ต้องเห็น Source Code (เรียกอีกชื่อว่า Black-box Testing)
    ตัวอย่าง Tools: GitLab, ZAP (Zed Attack Proxy), Checkmarx
  • Interactive Application Security Testing (IAST):
    ใช้ Agent หรือ Sensor ติดตั้งใน Application (Sidecar) รันไปพร้อมกัน
    ตัวอย่าง Tools: Acunetix, Hdiv
  • Infrastructure as Code (IaC) Security:
    สแกน IaC เช่น Ansible, Terraform, Kubernetes เพื่อหา Misconfigurations หรือ ช่องโหว่
  • Container Image Security:
    สแกน Container Image เพื่อค้นหา Vulnerabilities
    ตัวอย่าง Tools: Clair, Trend Micro, Anchore
  • Signed Container Image:
    ยืนยันความถูกต้องของ Container Image ว่าไม่มีการแก้ไขโดยไม่ได้รับอนุญาต
  • Privileged Access Management (PAM):
  • จัดการ Secrets เช่น Credentials, API Tokens
    ตัวอย่าง Tools: HashiCorp Vault, CyberArk Conjur

Step 3: Production Stage

Production Stage มุ่งเน้นการ Monitor Security และสร้าง Automation เพื่อปกป้องระบบใน Production อย่างต่อเนื่อง

  • Automation Security Baseline:
    ตรวจสอบว่าระบบทำงานตามมาตรฐานขั้นต่ำ เช่น CIS, NIST, OpenSCAP
  • Cloud Security Automation:
    ตั้งค่าความปลอดภัยและตรวจสอบระบบ Cloud อย่างต่อเนื่อง
  • Run-Time Application Security Protection (RASP):
    ตรวจจับและบล็อกภัยคุกคามระหว่างที่ Application กำลังทำงาน
    ตัวอย่าง Tools: Falco, Trend Micro, Palo Alto Networks
  • Web Application Firewall (WAF):
    Firewall ที่ทำงานอยู่หน้า Application เพื่อดักจับ Pattern ที่น่าสงสัย เช่น SQL Injection, XSS
  • Security Monitoring:
    - Security Event Monitoring (SEM): ตรวจจับ Pattern ที่ผิดปกติ
    - Security Operation Center (SOC): ทีมที่ตอบสนองต่อเหตุการณ์ความปลอดภัย
    - Security Orchestration Automation Response (SOAR): ใช้ Automation เพื่อตอบสนองต่อเหตุการณ์ได้อย่างรวดเร็ว
    - ตัวอย่าง Tools: Splunk, LogRhythm, Datadog

ใน Part 2/3 เราได้เรียนรู้เกี่ยวกับ Infrastructure, Monitoring และ Automation Security ซึ่งเป็นหัวใจสำคัญในการรักษาความปลอดภัยระบบใน DevSecOps ใน Part 3 เราจะเจาะลึกเกี่ยวกับ How to Start DevSecOps ฝากติดตามต่อด้วยนะครับ!


Data Science Explore the world of data science with Donato_Story

Dashboard Discover the power of data visualization with Donato_Story

Donato_Journey Join me on my journey (Thai version)

Course_Review Discover the training courses with Donato_Story (Thai version)

Let’s Connect!

Your feedback is invaluable. Feel free to share your thoughts or questions in the comments below. You can also connect with me on:

Originally published on Medium

Related