Encryption architecture
Hãy tách data at rest, data in transit, principal, key ownership và recovery. KMS key policy/IAM quyết định ai dùng key; rotation/deletion/audit là lifecycle. Encryption bật nhưng application không có quyền decrypt vẫn là một failure mode cần dự đoán.
Bài tập
Thiết kế encryption cho S3, EBS và RDS; ghi key type, principal, rotation, cross-account và disable/delete behavior. Không đưa key material hoặc secret vào notes.
Bài giảng chuyên sâu
Encryption là lifecycle của key và dữ liệu
Tách data at rest, data in transit, principal, key ownership và recovery. KMS key policy/IAM quyết định ai dùng key; cross-account cần tính cả resource policy. Bật encryption mà app không có quyền decrypt là failure có thể dự đoán.
Thiết kế phải nói key type, rotation, alias, grant, audit, disable/delete window và backup/restore behavior. Secret và key material không đưa vào image, repository hay log. Encryption không thay access control hay network security.
Bài tập: vẽ flow app role → service → KMS key → encrypted data cho S3, EBS và RDS. Failure drill: key disabled, policy thiếu principal, cross-account decrypt và restore encrypted snapshot.