New trends in application operations, driven primarily by containerization and the elimination of traditional servers, are fundamentally changing the way applications are designed, interconnected, and secured. Network policies can no longer be managed only at the classic network element level. Existing tools, such as WAF (Web Application Firewall), cannot sufficiently protect against vulnerabilities in application communications and their APIs.
The course provides an introduction to the management, analysis, and operation of globally distributed applications and their APIs, focusing on new approaches to application and API security in multi-tenant environments.cloud and service mesh. Participants, whether they DevOps, NetOps or architects, will explore current trends and work in live SaaS Volterra environments, with access to a dedicated tenant for hands-on exercises.
- NetOps
- DevOps
- IT systems designers
- Networking for distributed and multi-applicationscloud
- Service discovery and ADN (Application Delivery Network) concepts
- HTTP and TCP load balancing, service mesh in multi-cloud
- Observability and troubleshooting in microservice environments
- Key security principles for applications and APIs
- The concept of Web Application Firewall and advanced service policies
- Anomaly detection and protection against application-level DDoS attacks
- General knowledge of networks, firewalls, microservices, and application APIs
- Operating system compatible with kubectl
- SSH client
Module 1: Introduction to distributed application networking
- Trends in Cloud Native: moving from static monolithic applications to dynamic distributed microservices
- Service discovery and multi-networkingcloud (connectivity between AWS and on-premise)
- The DNA (Application Delivery Network) concept and the implementation of microservices in multiple locations
- Load balancing HTTP (Anycast L7) and TCP
- Service Mesh in multi-environmentscloud
- Observability and troubleshooting: analyzing metrics and logs in environments microservices
Module 2: Application Security
- Key principles for securing applications and APIs
- The concept of Web Application Firewall: filtering, monitoring and blocking HTTP traffic
- Using service policies to define intents instead of standard IP/port rules
- Application communication discovery and automatic security policy generation
- Protecting web applications with Captcha or Javascript Challenge
- Identifying PII data in API communications
- Anomaly detection and machine learning in service mesh
- Defining rate-limiting for protection against L7 DDoS attacks
There are no recommendations at this time.

