Knowledge Base

Blogs & Articles

Deep dives into Google Cloud Security, Secure Cloud development and more.

Filter by topic:
Top 5 Organization Policy Constraints for Google Cloud
Cloud SecurityGoogle Cloud
•6 min read

Top 5 Organization Policy Constraints for Google Cloud

Apply the right guardrails to keep your Cloud Workload secure The Google Cloud is a cloud service that enables users to create and manage virtual machines and Containers, Kubernetes clusters, store data, and run applications. When using Google Cloud, it’s important to implement technical boundaries that enforce your company’s security and privacy policies. Just as office buildings are secured with locks and limiting access to certain areas, your cloud environment needs safeguards to maintain security and compliance. To help users implement safeguards (guardrails), Google Cloud created Organization Policy Services, which offer ways to maintain programmatic control over cloud resources. Knowing where to begin is difficult with many available services, so we compiled our top five recommendations to help you get started! Organisational Policy Services and other Cloud-native solutions can help you take the security of your Google Cloud to the next level. First Things First: How to Structure Your Google Cloud Environment Before diving into our recommendations, let’s start with the basics–how to set up your Google Cloud. It’s important to structure your cloud environment in a way that lets you get the most out of the Organization Policy Services. Organizations are the highest structural level in Google Cloud, demonstrated by the ‘Company’ in blue at the top of the chart. The organization defines the domains in which all other resources reside. Each resource belongs to a specific project. A project is an isolated part of the organization that has its own resources, (IAM) permissions, virtual machines (VMs), and so on. Sorting projects into folders facilitates administration. Policies are set at the organization level and inherited by nodes, or projects/folders, lower in the hierarchy. However, if desired, you can exclude inheritance for certain nodes, enabling you to tailor permissions to each project’s needs. Hierarchy of resources in Google Cloud For every recommended Organisational Policy Constraints. I added Terraform examples to deploy the constraints with IaaC. 1. Resource Location Restriction This constraint policy enables companies to limit the physical location in which new cloud resources may be deployed. For example, a company can limit resources to only be deployed in the United States or Europe. These restrictions may be necessary for compliance reasons, such as the General Data Protection Regulations (GDPR) within the EU. By restricting resource locations to regions that are geographically closer to the end users, companies can reduce network latency, which may lead to better performance and improved user experience. Considering where data is stored and where employees work is a helpful step to ensure optimal performance when setting up a cloud environment. These location choices can also support a company’s green initiatives. Some regions have stricter CO2 emission regulations than others. Choosing a data center in a region that requires lower emissions is a simple step companies can take to be more environmentally conscious. Terraform example for gcp.resourceLocations 2. Define Allowed External IP Addresses for VM Instances Defining allowed external IP addresses enables companies to control which users, devices, or networks can access their VM instances. This constraint is especially important when working with remote teams or contractors because it allows companies to grant access only to specific, trusted entities. Restricting external IP addresses for VM instances also helps prevent unauthorized access to the company’s resources and reduces the change and impact of data breaches. Additionally, this policy makes identifying unusual or suspicious activity easier because traffic from unexpected IP addresses can be flagged and investigated. Terraform example for compute.vmExternalIpAccess 3. Domain Restricted Sharing This feature allows organizations to control how their users share content with people outside the company. It provides an extra layer of security to stored data and ensures that only authorized users can access sensitive information. Having this safeguard in place is particularly important for offboarding employees. If an employee uses their personal account to access company data, that person will still have access after leaving the company. Similarly, if outside collaborators are granted access, they may maintain it long after their work is complete if no security measures are in place. Terraform example for iam.allowedPolicyMemberDomains 4. Define Trusted Image Projects This policy enables companies to control which cloud storage buckets or projects are trusted sources for their Compute Engine instance images. Doing so helps ensure consistency across the company’s virtual machine instances, helping to prevent vulnerabilities caused by untested images. Companies can also define which operating system images can be used and assigned to a VM. In this way, a company can control costs by placing limits on the number and type of images that can be run, for example. This safeguard also helps to prevent malicious software from running on your virtual machines. Terraform example for compute.trustedImageProjects** 5. Enforce Public Access Prevention This restriction prevents data from being publicly accessible, reducing the risk of data breaches and other security incidents. Employees are also restricted from inviting all users, ensuring data is only accessible by trusted sources. This policy is a simple step with huge benefits. Get started today with Policy Organisational Constraints! My top five recommendations will help ensure your company’s resources and data are safe as you create and build in your Google Cloud. Ultimately, what additional services a company uses will depend on its specific needs. Don’t forget to evaluate (dry-run) and test the Policy Org Constrain of your choice before applying it to production workloads. Curious looking into more Org Policies, take a look at: https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints Follow me for more tips on how to take your Google Cloud to the next level.

Read article
Google Cloud User Group April Edition 2023
Cloud SecurityGoogle Cloud
•2 min read

Google Cloud User Group April Edition 2023

Announcement of the April Edition Meetup Get ready for the next Google Cloud User Group the April Edition at Flow Traders Amsterdam** On April 13th, we will host the next edition of the Google Cloud ⛅️ User Group meetup! You'll have the opportunity to hear from experts in the field of Cloud Engineer, DevOps, API Management and Security, ask questions, and connect with other like-minded people. We'll have delicious food and awesome goodies for all attendees. You can also win some great Google gadgets during our Quiz. Don't miss out on this exciting opportunity - RSVP https://www.meetup.com/google-cloud-user-group-benelux/events/292276300/ now, and we'll see you there! The following great speakers will join this edition and share their knowledge and experience: Speaker 1: Santhosh Chami (Cloud engineer) A presentation about their Cloud self-service platform at Flow! DevOps + faster time to market + scalability = 🔥 Speaker 2: Sander Alberink (Cloud architect) Manage your APIs with Apigee incl. demo! The event takes place at the awesome Flow Traders office in Amsterdam. Thanks Frank Hart for having us over 🙏 The Google Cloud User Group Benelux is a great collaboration between our friends at Google Cloud (Fahd Ekadioin), Xebia (Annemieke Stigter Simon Karman and Walter van der Scheer) and CTS Patty Vinagre de Freitas! See you the 13rd of April 2023!

Read article
Google Cloud CFT Scorecard
Cloud SecurityGoogle Cloud
•4 min read

Google Cloud CFT Scorecard

Scan your Cloud with Cloud Foundation Toolkit (CFT) Check your current Google Cloud setup against Google Cloud Foundation Toolkit (CFT), with the CFT Scorecard. We will export data, IAM, Org Policy and Access Policy data from Cloud Asset Inventory (CAI). The CAI exports can be done on a organization, folder or project level. could also use --project --folder or --organization The CFT Scorecard is integrated into the CFT CLI and provides an easy integration with Forseti Config Validator. It can be used to print a scorecard of your GCP environment, for resources and IAM policies in Cloud Asset Inventory (CAI) exports. The policies tested are based on constraints and constraint templates from the Config Validator policy library. You'll need to use CAI to generate the resource and IAM policy information for the project. https://github.com/GoogleCloudPlatform/cloud-foundation-toolkit/blob/master/cli/docs/scorecard.md What? Why? How? https://github.com/GoogleCloudPlatform/cloud-foundation-toolkit/blob/master/cli/docs/scorecard.md https://cloud.google.com/asset-inventory/docs/access-control#required_permissions Scorecard has two dependencies: Cloud Asset Inventory (CAI) Policy Library For downloading CAI data from GCS For exporting CAI data to GCS Create Service Account Grant Storage admin role to the Cloud Asset Service account Create Google Cloud Storage Buckets Export resource data Check export status Export CAI data Export resource data Export IAM data Export org policy data Export access policy data OS X Linux Make cft executable Run CFT scorecard application Clone the Policy Library: git clone https://github.com/forseti-security/policy-library.git Copied! You realize Policy Library enforces policies that are located in the policy-library/policies/constraints folder, in which case you can copy a sample policy from the samples directory into the constraints directory. cp policy-library/samples/storage_denylist_public.yaml policy-library/policies/constraints/ Add more constraints to CFT scorecard Add the following constraint to ensure you are entirely aware who has the IAM roles/owner role aside from your allowlisted user: Rerun CFT scorecard: ./cft scorecard --policy-path=policy-library/ --bucket=$CAI_BUCKET_NAME

Read article
Google Cloud User Group February Edition 2023
Google CloudCommunity & Events
•2 min read

Google Cloud User Group February Edition 2023

Aftermovie of the February Edition Meetup Google Cloud User Group February Edition 2023 Last week we hosted the last Google Cloud ⛅ User Group meetup of 2022! The event was all about Data 🗂 & Analytics 🔎 . Big thanks to our guests and presenters for making this a great evening 👏 Vito Minheere and Constantijn Visinescu The speakers presented about the topics: Small scale Data Mesh and Analysing streaming data. Small scale Data Mesh by Vito Minheere He will introduce the Data Mesh Concepts, how they can be understood and applied. Entire architecture strategies can be thought out covering thousands of microservices but what does a Data Mesh look like on a small scale? How could it be made more comprehensible? And most importantly, where would you start? Analysing streaming data on Google Cloud by Constantijn Visinescu** Streaming systems are great for monitoring and acting on data in real-time, but at some point you're also going to want to run analysis on all that streaming data. We will show you how to manage it with using the new BigQuery subscription for pubsub. Expect a hands on live demo by Constantijn. The 2022 Google Cloud User Group sessions were impossible to organise without the help of the awesome Google Fahd Ekadioin, the Xebia heroes Annemieke Stigter Simon Karman and Walter van der Scheer! Stay tuned for new Google Cloud meetups in 2023, and enjoy the after-movie! Happy Holidays 🎄 🎅

Read article
1 year at Xebia and in the Google Cloud
Cloud SecurityGoogle Cloud
•1 min read

1 year at Xebia and in the Google Cloud

. TEXT? Last week I celebrated working one year at Xebia. Time flies when you're having fun 😀 What better excuse to share some nice cake with other Xebians 🍰 Every day working with my favorite Cloud almost doesn’t feel like work 😉 Thank you all at Xebia Google Cloud Mollie and ASML for making this first year awesome with great collaborations and cool Google Cloud Security projects 🎉 Looking forward to what the future will bring! See you in the Cloud ⛅️

Read article
Happy New Car - Volvo XC40
Cloud Security
•2 min read

Happy New Car - Volvo XC40

Safety ≠ Security Happy New Car** [PHOTO Volvo XC40 Recharge] Diagram // Overlap Volvo XC40 Recharge has arrived! Fully electric and had twin engine. The power is amazing and is able to bring the ????KG car in 4,9 seconds to the 100KM/sec. Design, comfort, power and safety So people who know me know that I love the Swedish car brand. This is my 6th Volvo (For the Volvo fans; V40 D2, V40 D4, V60 D6 Twin Engine, XC40 T4, V60 T8 Recharge) Why Volvo? Safety ≠ Security Autonomous driving What’s the difference between safety and security? Safety stands for accident avoidance, and security for crime prevention. The best way to explain it is to use an example: If you think of an emergency exit, on the one hand you have the safety aspect. In safety terms you need to be able to get out of the building at any time, and the door should preferably always be open. As far as security – with a focus on building protection – is concerned, this door would ideally not be there at all, so that no-one can get in. The goals and values of safety and security are in some places contradictory, which is what makes the subject so intriguing. In the field of classic safety, functions are enabled in potentially dangerous machinery to protect people and the environment. When it comes to security, however, you’re no longer protecting people from machines – in fact it’s quite the reverse: You have to protect the machine to ensure that people can’t bring it to a juddering halt or switch off relevant safety functions.

Read article
Certified Google Cloud Professional Cloud Security Engineer
Cloud SecurityGoogle Cloud
•1 min read

Certified Google Cloud Professional Cloud Security Engineer

. What a better way to end the year 2022, by passing the exam and becoming a certified Google Cloud Professional Cloud Security Engineer 🎉💥 Looking forward the great events 2023 will bring! I'll be planning to get traing and certified for Google Cloud Professional Cloud Architect, Network Engineer and Cloud DevOps. Feel free to contact me if you want to more about getting certified for Google Cloud or other Google Cloud related challenges.

Read article
Getting inspiration for your smart home
Tech & Engineering
•3 min read

Getting inspiration for your smart home

Here you need to start when you want to make your home smart It's almost the Christmas holidays! The best time of the year to get some new inspiration for making your home smart. Do you already have a smart home? Or looking for some inspiration to make it more convenient and smarter? Then make sure to check out the video. At the beginning of December, the crew of Bright TV visited my home for an interview and tour of the smart home solutions I've implemented. Creating a smart home already started 10 years ago with a starter kit from Philips Hue. Being able to remotely control your lights with an app and using a single physical switch to control the lights in multiple rooms was mindblowing for that time. When is a home Smart? \ It might be a good idea to describe what defines a "smart home" for me. A Smart home is centred around the home itself, being able to think and act on the sensor input it reads. For example, you are close to your home and the weather outside is 10 degrees, based on these inputs your home starts executing smart flows to turn on the lights, the vacuum robot goes back to its station, heat up the living room and starts playing your favourite music. My Smart home Journey \ I kicked off my smart home journey by using different home automation gateways like Domoticz, and Home Automation. Currently, I am using the Homey Pro gateway from Athom. I choose the Homey Pro gateway because it has stable software, supports many communication protocols (Z-Wave Plus, Zigbee, Bluetooth and infrared) and it has a lot of apps that create integration with other vendors. Prevent vendor lock-in** \ I aim to create a smart home where I can combine the best available solution in the market that fit my use cases and prevent any vendor lock-in. I am a big fan of Apple hardware and love the Google Nest Hub for its great Voice Assistant, the Homey Pro gateway makes these and other vendors work together to create a smart home. For that reason, I am not using any Google Nest (Nest Protect, Nest Doorbell, Nest Camera) hardware besides the Google Nest Hub for the Google Voice Assistant. The options to integrate Nest hardware with smart home gateways like Homey Pro are limited. In the future, I will post more about my smart home journey and setup.

Read article
Google Cloud User Group Christmas Edition 2022
Google CloudCommunity & Events
•2 min read

Google Cloud User Group Christmas Edition 2022

Recap of the GCUP 2022 Meetups Google Cloud User Group Christmas Edition 2022 Last week we hosted the last Google Cloud ⛅ User Group meetup of 2022! The event was all about Data 🗂 & Analytics 🔎 . Big thanks to our guests and presenters for making this a great evening 👏 Vito Minheere and Constantijn Visinescu The speakers presented about the topics: Small scale Data Mesh and Analysing streaming data. Small scale Data Mesh by Vito Minheere He will introduce the Data Mesh Concepts, how they can be understood and applied. Entire architecture strategies can be thought out covering thousands of microservices but what does a Data Mesh look like on a small scale? How could it be made more comprehensible? And most importantly, where would you start? Analysing streaming data on Google Cloud by Constantijn Visinescu** Streaming systems are great for monitoring and acting on data in real-time, but at some point you're also going to want to run analysis on all that streaming data. We will show you how to manage it with using the new BigQuery subscription for pubsub. Expect a hands on live demo by Constantijn. The 2022 Google Cloud User Group sessions were impossible to organise without the help of the awesome Google Fahd Ekadioin, the Xebia heroes Annemieke Stigter Simon Karman and Walter van der Scheer! Stay tuned for new Google Cloud meetups in 2023, and enjoy the after-movie! Happy Holidays 🎄 🎅

Read article
Future workplace in Google Cloud with Chromebook
Google Cloud
•1 min read

Future workplace in Google Cloud with Chromebook

Creating a future workplace in Google Cloud with Chromebook Here comes some great content about how to create a future workplace in Google Cloud with HP Chromebook, Cameyo (VAD) and Google Cloud. Target audience? Google Workspace HP Chromebook Google Cloud Compute Engine Confidential Compute CMKS (Customer Managed Keys)

Read article
Secure Google Cloud with Organizational Policy Services
Cloud SecurityGoogle Cloud
•2 min read

Secure Google Cloud with Organizational Policy Services

Protect your Google Cloud resources and workloads with Here comes some great content about how to use Organizational Policy Services (Org. Policies) in Google Cloud to secure your Cloud resources and workloads. Org structure What is it? Constraints Protect Limit Be in control How to use it? My favorite Organizational Policy to apply 1. Name + What it does? + 2. 3. 4. 5. Google Cloud gives you the ability to restrict the usage of resources and services when utilising Organisation Policy Services. The restrictions are named constraints. Example of Organization Policies Service Constraints are: Limit the regions where services can be deployed or whitelist the Disk Images that can be used by developers. Organisation Policy Services will help you to increase the level of control and increase the overall security in a Cloud native service and centralised way within your organisation. Be aware that Organisation Policies will only apply on newly created resources and not on existing resources. We seen a lot of customer who don't utilise the power of Organisation Policy Services in their Cloud. Our recommendation is to apply additional Organisation Policy Services (constraints) on the organisation and/or folder level. We recommend looking into and applying the following core Organisation Policy Services constraints. The list is curacted based on our experience as Xebia Cloud and Google Cloud best practices. Organisation Policy Services Core Constraints Domain-restricted sharing (iam.allowedPolicyMemberDomains) Resource Location Restriction (gcp.resourceLocations) Define trusted image projects (compute.trustedImageProjects) Skip default network creation (compute.skipDefaultNetworkCreation) Prevent removal of Shared VPC Project (compute.restrictXpnProjectLienRemoval) Disable VM serial port access (compute.disableGlobalSerialPortAccess) Require OS Login (compute.requireOsLogin) Define allowed external IPs for VM instances (compute.vmExternalIpAccess) Restrict Public IP access on Cloud SQL instances (sql.restrictPublicIp) Disable service account key creation (iam.disableServiceAccountKeyCreation) Disable Guest Attributes Access (compute.disableGuestAttributesAccess) Prevent auto grant permissions to default App Engine and Compute Engine Service Account (iam.automaticIamGrantsForDefaultServiceAccounts) Enforce Public Access Prevention (storage.publicAccessPrevention) Enforce uniform bucket-level access (storage.uniformBucketLevelAccess) Additional Policy Controls In addition to the Organisation Policy Services Core Constraints, you can also apply the additional Policy Controls to extend and further increase the security of your Google Cloud.. 1. Limit session and GCloud timeouts 2. Disable Cloud Shell 3. Use phishing resistant security keys 4. Enable access transparency 5. Enable access approval More details about Organization Policy Constraints can be found here: https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints

Read article
Recognized as a 2022 Google Cloud Partners All-star
Cloud SecurityGoogle Cloud
•3 min read

Recognized as a 2022 Google Cloud Partners All-star

Jorge Liauw Calo recognized as a 2022 Google Cloud Partners All-star in Solutions Engineering and delivery. This week I was recognized by Google Cloud as a 2022 Google Cloud Partners All-star in Solutions Engineering and Delivery! I am really excited and absolutely honoured that I am recognized for the awesome Google Cloud Security initatives and projects I worked on! Why I got awared?* \ Jorge, on behalf of the Google Cloud Benelux team we want to say we think you're a true Google Cloud champion! Especially in the way you have made a difference with highly strategic customers such as Mollie, by explaining how Google Cloud makes a difference in security. Lastly, Googlers would like to recognize you for driving new product adoption on GCP! What Googlers say about Jorge* \ "Jorge Liauw Calo has proven himself a true hero when it comes to his Google solution skills, especially around #security! Thank you on behalf of many Googlers for making such an impact; not only on stage but also at valued customers like Mollie!" What makes a Google Cloud Partner All-star? \ To be eligible, individuals must be a Google Cloud champion within their organization, and are leading in excellence across the following qualities by category: SOLUTIONS ENGINEERING & DELIVERY Delivers superior customer experiences by keeping professional skills up to date, earning at least one Google technical certification Embraces customer challenges head-on, taking responsibility for end-to-end solutioning Works with purpose, providing deliverables in a timely manner while never compromising quality Works effectively across joint product areas, leveraging technology in new and innovative ways to address customer needs At Google Cloud, we know that individuals like you are behind every great partner organization. In order to be named an All-star in Solutions Engineering & Delivery, you must embrace customer challenges head-on, work effectively across joint product areas, and consistently provide high-quality deliverables in a timely manner. You’ve come through in every one of these areas. About the Google Cloud Partners All-star program\ Google Cloud Partner All-stars is a new annual program that recognizes and celebrates remarkable people within our partner organizations. From December 5 - 9 of this year, we’re honoring individuals in marketing, solutions engineering & delivery, and sales for their exceptional achievements. Individuals have been nominated and selected by Google Cloud partner leadership and local partner account teams. I would really like to thank all the Googlers, Xebia and Mollie for the great time working together and creating awesome secure solution in Google Cloud. Thank you for the recognition and partnership Google Cloud! Looking forward to everything that's coming in 2023 and beyond 🌤

Read article
From freelance to getting back working for a boss
Cloud SecurityGoogle Cloud
•5 min read

From freelance to getting back working for a boss

Finding the Spark that Drives You. Freelance Getting back to work for a boss (Xebia) Finding the Spark that Drives You Jorge Liauw Calo joined Xebia as a Google Cloud Security Engineer in February after freelancing for himself for four years. Here’s his take on the big changes becoming an Xebian brought to his life and what motivated him to make the leap. Making Connections \ Like everyone else in the world, I was ready to be around people again after spending two years at home during the pandemic. Although things were going well as a freelancer, my gut told me it was time for a change. But, what was next? A recruiter from Binx contacted me and her approach was totally different from other recruiters that have reached out in the past. She talked to me about what I was working on, what challenges I was facing, and shared relevant things her team was working on. Most of the time recruiters just say things like, “I have the best job - join us! This company is awesome!” When I ask what the job entails and why they think I’m the best fit, things get blurry. Of course, every company says it’s awesome when it’s trying to recruit you. You really need to see it for yourself and I could early on. The recruitment process was casual, in a good way. I came in to have coffee with the CEO and talk to some of the other engineers. Our conversations were friendly and relaxed. “People first” is the company value that really resonates with me. I could see it was a genuine part of the company culture. That’s when I first started feeling a spark. Being around cool, knowledgeable colleagues was the most important thing to me and I could sense I would be at this company. The first thing I want to know about my colleagues is: Who are you? What do you love to do? I like to really get to know them as a person, rather than just as what they do for the company. One small way I have started doing that is through a morning ritual with my colleague, Laurens. We get coffee and sit in the two chairs by the front entrance so we can greet and chat with people as they arrive. It’s really been a great way to start building relationships. The Big Picture \ People often ask what’s the biggest difference between being a freelancer and an employee. Honestly, it’s the money. That is not the full story though, because working here is about more than my paycheck. At Xebia, I’m surrounded by colleagues that have a different knowledge base, experiences, and skills than mine. Working with them helps me improve my own skills. Collaborating with them forces me to push my edges, which is really motivating. Professional growth doesn’t just happen informally. Employees receive an annual training budget, which is not an unusual benefit for this type of company to give. What caught my attention is that we are also given six days off to attend trainings or pursue other learning opportunities. Otherwise, as a full-time employee the training budget is nice but we would have to use our own time — nights or weekends — to actually take advantage of it. The knowledge exchanges (XKEs) are one of the most fun parts of working here. They are on Tuesday afternoons and Xebia actually tells clients that the team needs to be off then. That’s how serious the company is about these sessions. All XKEs are led by Xebia employees so you get to learn from your colleagues. Some sessions are technical and some are about our personal interests. For example, I love pasta so I decided to do a session on making pasta carbonara. And that’s really what I love about these events — they give you a platform and the freedom to share your experience pursuing your passions. Value Driven* \ Being here gives me the opportunity to work on more complex projects and with new clients. As a consultant, it can be easy to spend all your time with the clients. I don’t want to do that, though, because then I could just work for the client. Also adding value here, at Xebia, is really important to me. I enjoy talking to my colleagues about what we can create together — bouncing ideas around until something sticks. The Xebia Cloud Control proposition is a new venture I’ll be working on. Getting involved in that is another time I felt a spark — I like the proposition, building a new business which will enable me to collaborate with my colleagues at Xebia and help our clients even more. Work is such a big part of life it is important to make it count. When I’m 70, I want to look back on my life and feel good about my choices. Staying the course is easy. As we learn and grow, our wants and needs change. I like to check-in with myself along the way — Does this still make me happy? Is there something else I could be doing to deliver the most value? You’ve got to find and do the things in life that you love. Joining Xebia was a decision I made because it aligned with my personal values. I took a big pay cut to be here and wanted certain things in return: more challenging projects, cool colleagues, professional development opportunities, and a fun work environment. All those things are sparks that drive me and I found them at Xebia making it all worth it. This story was published in the December 2022 edition of Xebia Vibes Magazine.

Read article
Presenting about Cloud Security at Cloud Next 2022
Cloud SecurityGoogle Cloud
•1 min read

Presenting about Cloud Security at Cloud Next 2022

Howto stay ahead Security Challenges in the Cloud On the 11th of November 2022 I was honourd to present onstage at Google Cloud Next 2022 Recap in Antwerpen, Belgium together with our friends from Google Cloud and Travix. During my presentation I talked about why Security is important in the Cloud. The security in the cloud and how to mitage or at least lower the risk around these security risks. I discussed the following Security challenges from a process and technical perspective: Gain Full Observability Continuous Compliance Scaling Security Capabilities Store infra and app passwords securely Defining use cases for Security Feel free to contact me if you want to more about security challenges in the cloud and the solutions to solve them.

Read article
Google Cloud Security Webinar 2nd of November 2022
Cloud SecurityGoogle Cloud
•2 min read

Google Cloud Security Webinar 2nd of November 2022

Cloud Security threats and modern defense mechanism Laurens Baardman & Jorge Liauw Calo in the Xebia Club Cloud Studio On the 2nd of November 2022, we did a webinar at Xebia about Cloud Security on Google Cloud with Laurens Baardman and our fantastic host Walter van der Scheer. During this webinar event, seasoned security experts Laurens Baardman and I shared our best practices to effectively gain insight into security risks and demonstrate how Google Cloud can help you minimize these risks. Watch the video on YouTube** https://youtu.be/0LtxtIHelZU During the webinar, we discussed how Google Cloud blocked the largest Layer 7 DDoS attack at 46 million requests per second (RPS) and how you, as a Google Cloud customer, can leverage Google's DDoS protection and Web Application Firewall (WAF) capabilities Cloud Armor. Defending against the largest DDoS attack How this all began? Cyber threats and attacks as we know them today. We discussed the history of hacking and attacks like DDoS and Ransomware. Maersk attacked by NotPetya Ransomware Although cyberattacks have become more complex and frequent, you can do many things to minimize the attack surface and reduce the impact of an attack. Concepts like DevSecOps will help you transition to shift left approach, meaning that you apply security activities and continuous monitoring and guardrails in the earliest possible stage of your software development cycle. DevSecOps Shit-left Contact about the topics you would like us to cover. Stay tuned for new Google Cloud webinars!

Read article
Export Google Cloud Compute Engine disk to VMware Disk
Google Cloud
•3 min read

Export Google Cloud Compute Engine disk to VMware Disk

Convert your GCE disk and to run it on a local VMware ESX Server This post will describe how to export and convert your Google Cloud Compute Engine (GCE) disks to a Vmware Disk (vmdk). Think about if you want run some Cloud workloads in a on-premise environment to lower the costs of your test (DTAP) environment. Export Compute Engine Disk and convert to VMware (vmdk) 0. Create a Cloud Storage bucket Name: export-gce-disks gs://export-gce-disks https://storage.cloud.google.com/export-gce-disks/ 1. Storage Disk Action: Create Image 2. Create an Image Go to Virtual Machine -> Storage -> Disks -> Click on Action -> Create Image Name: image-chatsupport-disk-image Source: disk Source disk: boot (Disk you want to migrate to convert to image) Loction: Regional Encryption: Google-managed encryption key CLI 3. Export Image to Storage Bucket Keep in mind that Destination URI should include filename project = should be the projectID Argument: --export-format vmdk Export failed on: step "export-disk" run error: step "run-export-disk" run error: googleapi: Error 400: Invalid value for field 'resource.networkInterfaces[0]': '{ "network": "projects/blastcsc-vms/global/networks/default", "accessConfig": [{ "type": "ONE_T...'. Subnetwork should be specified for custom subnetmode network, invalid Fix: Create new VPC network Select: Subnet creation mode set to Automatic Assign VPC network Compute Image Instance Repeat from step 2 --subnet=default \ --zone=europe-west4-b \ Attempt 2: Add subnet + Zone where the subnet is deployed in. Fixes the problem. Reference: https://cloud.google.com/compute/docs/images/export-image#exporting_an_image

Read article
Meet Traefik Cloud Native Application Proxy
Tech & Engineering
•2 min read

Meet Traefik Cloud Native Application Proxy

Get Traefik proxy and expose services securly Here comes some great content about what Traefik is and how you can use it to securely expose your services running in Docker to the web. Traefik is a Cloud Native Application Proxy just like NGINX. You might already know or work with NIGNX as a standalone webserver, although it's also used a lot as a reverse proxy. They reason I switched to Traefik is because it does the heavy lifting when it comes to load balancing, routing and generating HTTPS certificates. So how does the Traefik architecture looks like? Traefik reverse proxy architecture I run the Traefik proxy in a Docker container and created it with the help of Docker Compose. The way Treafik will work is that it will sit between the outside world and your Docker containers. Communication to the outside world can only be down through Traefik. Traefik reverse proxy interacting with Docker This is a working Docker Compose file to deploy and run Traefik as a reserve proxy. All the services that run within Docker and use the correct labels in the Docker Compose of the service(s) are able communicate of HTTPS with auto generated letsencrypt certificates and all the HTTP traffic is redirected to HTTPS. Docker Compose file for running Traefik Proxy Container Example of a Docker Compose file to deploy a test services behind Traefik. Don't forget to change the hostname to the correct subdomain you want to use. Make sure that the name of the service (Example is whoami) is also correct defined within the labels "traefik.http.routers.nameoftheservice" Want to read more about Traefik? Check out their website: https://doc.traefik.io/traefik/

Read article
Google Cloud Storage bucket lock
Cloud SecurityGoogle Cloud
•1 min read

Google Cloud Storage bucket lock

Protect your Cloud Storage backups against ransomware Here comes some great content about how to protect your backups stored in Google Cloud Storage (buckets) against ransomware attacks or accidental deletion. Retetion policy and bucket lock Reference: https://cloud.google.com/storage/docs/bucket-lock

Read article
Meet Cloud Custodian
Cloud SecurityCloud Custodian
•1 min read

Meet Cloud Custodian

Learn and meet Cloud Custodian. Here comes some great content about what is Cloud Custodian and how to use it to control and maintain Cloud resources that meet your security policies.

Read article
Cloud Custodian Policy as Code
Cloud SecurityGoogle Cloud
•1 min read

Cloud Custodian Policy as Code

Succesfull pass those failed build steps Here comes some great content about how to process multiple policy files with Cloud Custodian (c7n-org). Cloud Custodion is a great tool to scan your Cloud enviroments (Google Cloud, AWS and Azure) and check them against defined policies. It's essentially a stateless rules engine for policies and it supports metrics. The policies are created in YAML What is Policy-As-Code? ...

Read article
GCP Run Hugo on AppEngine
Google Cloud
•1 min read

GCP Run Hugo on AppEngine

Lets deploy and run Hugo on Google App Engine Here comes some great content about running Hugo on Google Cloud App Engine.

Read article
Cloud Build Allow failure
Google Cloud
•1 min read

Cloud Build Allow failure

Succesfull pass those failed build steps Here comes some great content about Cloud Build on Google Cloud and how to succesful continu build (steps) when errors have occurred.

Read article