Module 5 Intermediate Network Isolation, Zero-Trust & Data Security

Networking & Security Foundation

VPC Topology, Subnet Isolation, Least Privilege IAM & KMS Encryption

Estimated Time 6 Hours
Primary Services
Amazon VPCAWS IAMAWS Key Management Service (KMS)AWS Secrets ManagerAWS WAFAWS PrivateLink
Module 5 သင်ရိုးမာတိကာ Network Isolation, Micro-Segmentation & Threat Surface Reduction

Enterprise VPC Networking & Zero-Trust Security

3-Tier Subnet Topology, VPC Endpoints, Transit Gateway, WAF နှင့် IAM Boundaries

အဆင့်မြင့် လုပ်ငန်းသုံး ကွန်ရက်လုံခြုံရေး ဒီဇိုင်းများ- 3-Tier Isolated Subnets (Public, Private, Isolated Database), NAT Gateways, VPC Endpoints (PrivateLink), AWS WAF Layer-7 ကာကွယ်မှုနှင့် IAM Least-Privilege Role Architecture။

ရရှိမည့် အဓိက ဗိသုကာဆိုင်ရာ ကျွမ်းကျင်မှုများ (Learning Outcomes)

1

Production-grade 3-Tier VPC Architecture (Public ALB, Private App, Isolated Data Subnets) ရေးဆွဲနိုင်ခြင်း။

2

AWS PrivateLink / VPC Interface Endpoints ဖြင့် Traffic များကို Public Internet သို့ မထွက်စေဘဲ AWS Network အတွင်း၌သာ ပို့ဆောင်နိုင်ခြင်း။

3

Security Groups (Stateful) နှင့် Network ACLs (Stateless) များ၏ အလုပ်လုပ်ပုံကို ရှင်းလင်းစွာ ခွဲခြားအသုံးပြုနိုင်ခြင်း။

4

AWS WAF (Web Application Firewall) ဖြင့် SQL Injection, Cross-Site Scripting (XSS) နှင့် DDoS တိုက်ခိုက်မှုများကို ကာကွယ်နိုင်ခြင်း။

အခြေခံ သဘောတရားနှင့် စဉ်းစားပုံ Mental Models

လုံခြုံရေးဆိုသည်မှာ ပတ်လည်တံတိုင်းတစ်ခုတည်း ကာရံထားခြင်း မဟုတ်ဘဲ အဆင့်တိုင်းတွင် စစ်ဆေးကာကွယ်သော Defense-in-Depth ပုံစံ ဖြစ်ရပါမည်။

Zero-Trust မူဝါဒအရ VPC အတွင်းရှိ Server အချင်းချင်းပင်လျှင် IAM Authentication နှင့် Security Group Port Level ခွင့်ပြုချက်မရှိဘဲ ဆက်သွယ်ခွင့် မပြုရပါ။

အဓိက ဗိသုကာ သဘောတရားများနှင့် မဏ္ဍိုင်များ (Key Architecture Concepts)

Isolated Database Subnet

Internet Gateway သို့မဟုတ် NAT Gateway လမ်းကြောင်း လုံးဝမရှိသော သီးသန့်လုံခြုံသည့် Subnet။

VPC Gateway & Interface Endpoints

S3, DynamoDB နှင့် SSM တို့ကို Public IP မလိုဘဲ Private IP ဖြင့်သာ ဆက်သွယ်စေသည့် နည်းပညာ။

IAM Permission Boundaries

Developer များအား IAM Role ဖန်တီးခွင့်ပေးသော်လည်း Privilege Escalation မလုပ်နိုင်အောင် ကန့်သတ်သည့် မူဝါဒ။

Production စနစ်များတွင် မဖြစ်မနေ လိုက်နာရမည့် Golden Rules

  • Database Subnets များတွင် 0.0.0.0/0 Route (Internet Route) ကို လုံးဝ မထည့်ပါနှင့်။
  • S3 Bucket Access အတွက် NAT Gateway Data Transfer အစား အခမဲ့ဖြစ်သော VPC Gateway Endpoint (S3) ကို သုံးပါ။

Hands-On Case Studies

လက်တွေ့ လေ့လာနိုင်သော Case Studies များ

2 Case Studies
Advanced Banking & FinTech
8 min read

Zero-Trust Financial Backend: Eliminating NAT Gateway Data Fees

Securing private banking APIs and saving $3,000/month by replacing NAT Gateway S3/DynamoDB traffic with VPC Interface Endpoints and PrivateLink.

NAT Egress Costs: -94%
Data Path Security: 100% Private