Skip to Content
Security and Microservice Architecture on AWS
book

Security and Microservice Architecture on AWS

by Gaurav Raje
September 2021
Intermediate to advanced
394 pages
10h 40m
English
O'Reilly Media, Inc.
Content preview from Security and Microservice Architecture on AWS

Chapter 6. Public-Facing Services

In Chapter 5, I discussed the need to divide the network architecture and all your backend services into cleanly segregated pieces through the process of microsegmentation. Microsegmentation is great at having a clean and simple backend process that can be secured thoroughly. Although this process of domain segregation may work well for backend services, the end user–facing systems have to be designed with the requirements and security of the user in mind. These public-facing services are also called edge servers because they happen to live at the edge of your application.

Having a clean and separate edge infrastructure helps in decoupling the domain design of your backend services from the ever-evolving requirements of the end user. Figure 6-1 shows an example of a typical application where the edge is cleanly separated from the rest of the backend microservices.

Figure 6-1. This chapter focuses on the “public-facing edge server” area, which acts as the first point of contact with your application for anyone trying to access your services from the internet.

Let me begin this chapter by saying that the services on the public-facing edge servers are inherently less secure than the backend services. For any system, potential threats can be classified into three categories: possible, plausible, and probable. A lot of attacks are possible in theory. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Deploy Containers on AWS: With EC2, ECS, and EKS

Deploy Containers on AWS: With EC2, ECS, and EKS

Shimon Ifrah
Microservices Security in Action

Microservices Security in Action

Prabath Siriwardena, Wajjakkara Kankanamge Anthony Nuwan Dias
Serverless Architectures on AWS, Second Edition

Serverless Architectures on AWS, Second Edition

Yan Cui, Ajay Nair, Peter Sbarski

Publisher Resources

ISBN: 9781098101459Errata Page