SlideShare a Scribd company logo
Elevating Privacy and Security
with Apache CloudStack
by Boris Stoyanov
Cloudstack Collaboration Conference – Paris 2023
About
me
• Been braking software since I was 18
• With CloudStack since 2016
• Father, husband
Agenda
• Cloud security overview
• CloudStack
• QA
Disclaimer / Tech in
focus
• CloudStack native components
• NFS shared/local
• SDS storage (PowerFlex)
Platform
Cloud
operator
Users
Identity & RBAC,
Public traffic and
Resource limits
Physical security
Compliance
Moderation
Internal traffic
Data protection
Insights/monitoring
Security is shared responsibility
Secure Direct Download
and checksum verification
Data Encryption
Secure Agent
Communication
Identity
SAML
LDAP
2FA
AEAD DB
Encryption
Role-based
Access
Control
Secure VM
and Volume
migration
Data retention
policy
Logical
Isolation of
customer data
CA Framework SSVM
over
HTTPS/TLS
CPVM
over
HTTPS/TLS
Monitoring
Zabbix/
Prometheus
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue

More Related Content

Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue

  • 1. Elevating Privacy and Security with Apache CloudStack by Boris Stoyanov Cloudstack Collaboration Conference – Paris 2023
  • 2. About me • Been braking software since I was 18 • With CloudStack since 2016 • Father, husband
  • 3. Agenda • Cloud security overview • CloudStack • QA
  • 4. Disclaimer / Tech in focus • CloudStack native components • NFS shared/local • SDS storage (PowerFlex)
  • 5. Platform Cloud operator Users Identity & RBAC, Public traffic and Resource limits Physical security Compliance Moderation Internal traffic Data protection Insights/monitoring Security is shared responsibility
  • 6. Secure Direct Download and checksum verification Data Encryption Secure Agent Communication Identity SAML LDAP 2FA AEAD DB Encryption Role-based Access Control Secure VM and Volume migration Data retention policy Logical Isolation of customer data CA Framework SSVM over HTTPS/TLS CPVM over HTTPS/TLS Monitoring Zabbix/ Prometheus