Application Identity Manager in Ansible with CyberArk Enhancing Secrets ...

+

Enhancing Secrets Management in Ansible with CyberArk

Application Identity Manager

1

TODAY'S PRESENTERS:

Chris Smith

Moderator

DevOps Product Marketing, CyberArk

Naama Schwartzblat

Application Identity Manager Senior Product Manager CyberArk

Kyle Benson

Global Alliance Architect, Red Hat

TODAY'S IT ARCHITECTURES

are continually changing and must be infinitely flexible.

3 CONFIDENTIAL

IT OPERATIONS BEARS THE BURDEN

CEO

LINE OF

BUSINESS

DEVELOPERS

IT OPERATIONS

4 CONFIDENTIAL

EFFECTIVE MANAGEMENT & AUTOMATION MUST SPAN CLOUD, CONTAINERS AND TRADITIONAL I.T.

Traditional code development & deployment tooling

CI/CD Pipelines & Code Repositories

Databases

VMs

Kubernetes Container Orchestration Platforms

Middleware SaaS/PaaS

Bare metal

Container packaging platforms

OS Network and storage infrastructure

X-cloud Portability & Integrations

Private Clouds

AWS

Azure

Google

IT Automation

Service catalogs & governance Full stack monitoring Root cause Analytics Capacity Optimization Cloud Financial Mgt Security & Compliance Config & Provision Patch & Remediate Hosts ITSM & CMDB Integration

WHAT IS ANSIBLE AUTOMATION?

---

The Ansible project is an open source community[use-r@nhaomsten:amien:s$t]alalnsiabnlde-sptlaayrbtooakp-aichienventory playbook.yml

sponsored by Red Hat. It's also a simple

hosts: all PLAY [vianrstsa:ll and start apache] ***********************************

automation language that perfectly describes IT

http_port: 80

application environments in Ansible Playbooks. TASK [Gamthaexr_icnlgiFeancttss:] *2*0*0*****************************************

ok: [webserver.local]

remote_user: root

Ansible

Engine

is

a

supported

product

built

fromTASK [install httpd] **********************************************

changetda:s[kwse:bserver.local]

the Ansible community project.

- name: install httpd

TASK [wryituem:thpekagp=ahcthtepcdonsftiagtfei=llea]test

********************************

Ansible Tower is an enterprise framework for changed: [webserver.local]

- name: write the apache config file

controlling,

securing,

managing

and

extending

your TASK

[sttaretmphltattpde]:

src=/srv/httpd.j2

dest=/etc/httpd.conf

Ansible automation (community or engine) with a*************************************************

UI and RESTful API.

change-d:n[awmeeb:sesrvtearr.tlochatlt]pd service: name=httpd state=started

PLAY RECAP

*********************************************************

webserver.local failed=0

: ok=4 changed=3 unreachable=0

6 CONFIDENTIAL

WHY ANSIBLE?

SIMPLE

Human readable automation No special coding skills needed Tasks executed in order Usable by every team Get productive quickly

POWERFUL

App deployment Configuration management Workflow orchestration Network automation Orchestrate the app lifecycle

7 CONFIDENTIAL

AGENTLESS

Agentless architecture Uses OpenSSH & WinRM No agents to exploit or update Get started immediately More efficient & more secure

8

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download