Skip to Content
Google系统架构解密: 构建安全可靠的系统
book

Google系统架构解密: 构建安全可靠的系统

by Heather Adkins, Betsy Beyer, Paul Blankinship, Piotr Lewandowski, Ana Oprea, Adam Stubblefield
September 2021
Beginner to intermediate
392 pages
12h 13m
Chinese
Posts & Telecom Press
Content preview from Google系统架构解密: 构建安全可靠的系统
面向恢复性的设计
149
9.4
 预期外的收益
本章中描述的设计原则建立在弹性设计原则的基础上,可以提高系统的可恢复性。除可靠
性和安全性外,这样做还能带来一系列预期外的收益,有助于推动这些实践在组织内的落
地。假设有一台服务器用于为固件更新身份认证、回滚、锁定和提供认证机制。使用这些
原语,在检测到机器被入侵后,可以有条不紊地开展恢复工作。现在假设要在“裸机”云
托管服务环境下使用这台机器,供应商希望自动化地清理并转售它。面向易恢复性设计的
机器已经有了安全和自动化的解决方案。
在供应链安全方面,这些好处会更加深远。当机器是由许多不同的部件组装而成时,由于
这些组件的完整性是以自动化的方式恢复的,这样就不需要对供应链安全有过多的关注
了,只需要执行一次恢复过程即可。还有一个额外的好处是,由于会对恢复过程做重新调
整,可以定期演练关键恢复能力。在事件发生后员工就可以立即开展行动。
设计用于恢复的系统是一个很深奥的话题,其业务价值只有在系统偏离预期状态时才能被
验证。但考虑到我们建议操作系统使用错误预算来最大限度地提高成本效率
28
,可以预期的
是,这类系统会不时地发生错误。建议团队尽早在开发过程中逐步投入速率限制或回滚机
制的建设。有关如何影响组织的更多信息,请参阅第
21
章。
9.5
 小结
本章探讨了设计易恢复性系统的方方面面,解释了为什么系统在部署变更的速率方面应具
有灵活性:这种灵活性允许在可能的情况下缓慢地展开变更并避免带来一系列故障。同
时,这样做也有助于在必须接受更多风险以实现安全目标时快速且从容地发布变更。对于 ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

管理Kubernetes

管理Kubernetes

Brendan Burns, Craig Tracey
Python机器学习基础教程

Python机器学习基础教程

Andreas C. Müller, Sarah Guido
解密金融数据

解密金融数据

Justin Pauley

Publisher Resources

ISBN: 9787115569257