Visão Geral
Este curso aborda os princípios e padrões para projetar arquiteturas de mensageria seguras, resilientes e alinhadas a ambientes corporativos, Cloud Native e distribuídos. O participante aprenderá a incorporar segurança desde a concepção da arquitetura, protegendo message brokers, APIs, producers, consumers, topics, queues e fluxos de eventos. O conteúdo explora Zero Trust, identidade, autenticação, autorização, criptografia, gestão de secrets, segmentação de redes, segurança de APIs, auditoria, observabilidade e resposta a incidentes. Também são analisadas estratégias de segurança para plataformas como Apache Kafka, RabbitMQ, Apache Pulsar e ambientes Kubernetes.
Conteúdo Programatico
Module 1: Secure Messaging Architecture Fundamentals
- Messaging security architecture
- Security principles for distributed systems
- Messaging attack surfaces
- Threat modeling for messaging platforms
- Defense-in-depth
- Secure-by-design principles
Module 2: Identity and Authentication Architecture
- Service identity
- Authentication models
- Certificate-based authentication
- Mutual TLS
- SASL authentication
- OAuth 2.0 and token-based authentication
- Identity lifecycle management
Module 3: Authorization and Access Control
- Authorization architecture
- Role-Based Access Control
- Access Control Lists
- Topic and queue permissions
- Producer and Consumer authorization
- Administrative access control
- Least privilege architecture
Module 4: Encryption and Key Management
- Encryption in transit
- Encryption at rest
- TLS architecture
- Certificate lifecycle management
- Key management
- Key rotation
- Hardware and cloud-based key management concepts
Module 5: Network Security for Messaging
- Network segmentation
- Security zones
- Firewall architecture
- Private endpoints
- Secure broker exposure
- Kubernetes Network Policies
- Zero Trust network architecture
Module 6: Secure Messaging Platforms
- Apache Kafka security architecture
- RabbitMQ security architecture
- Apache Pulsar security architecture
- Broker hardening
- Secure topic and queue design
- Secure administrative interfaces
- Platform-specific security considerations
Module 7: Cloud Native and Kubernetes Security
- Messaging workloads on Kubernetes
- Pod and service security
- Kubernetes Secrets
- External secrets management
- Service Accounts
- Workload identity
- Container security
- Secure Cloud messaging architectures
Module 8: Governance, Observability and Incident Response
- Security logging
- Audit architecture
- Security monitoring
- Event and message traceability
- Anomaly detection
- Incident response
- Security governance
- Secure Messaging Architecture Workshop