MindMap Gallery Alibaba Cloud Operation and Maintenance Security Center (Bastion Host)
This article introduces in detail a unified, efficient, and secure operation and maintenance channel on the cloud, which is used to centrally manage asset permissions, monitor operating behaviors throughout the process, and restore operation and maintenance scenarios in real time to ensure that cloud operation and maintenance identities can be identified, permissions can be controlled, and risks can be blocked. Operations can be audited to help ensure compliance.
Edited at 2024-01-16 09:15:24This is a mind map about bacteria, and its main contents include: overview, morphology, types, structure, reproduction, distribution, application, and expansion. The summary is comprehensive and meticulous, suitable as review materials.
This is a mind map about plant asexual reproduction, and its main contents include: concept, spore reproduction, vegetative reproduction, tissue culture, and buds. The summary is comprehensive and meticulous, suitable as review materials.
This is a mind map about the reproductive development of animals, and its main contents include: insects, frogs, birds, sexual reproduction, and asexual reproduction. The summary is comprehensive and meticulous, suitable as review materials.
This is a mind map about bacteria, and its main contents include: overview, morphology, types, structure, reproduction, distribution, application, and expansion. The summary is comprehensive and meticulous, suitable as review materials.
This is a mind map about plant asexual reproduction, and its main contents include: concept, spore reproduction, vegetative reproduction, tissue culture, and buds. The summary is comprehensive and meticulous, suitable as review materials.
This is a mind map about the reproductive development of animals, and its main contents include: insects, frogs, birds, sexual reproduction, and asexual reproduction. The summary is comprehensive and meticulous, suitable as review materials.
Alibaba Cloud Operation and Maintenance Security Center (Bastion Host)
Product introduction
The Operation and Maintenance Security Center (bastion machine) is an operation and maintenance and security audit management and control platform provided by Alibaba Cloud. It can centrally manage operation and maintenance permissions, control operation behaviors throughout the process, restore operation and maintenance scenarios in real time, and ensure that the identities of operation and maintenance behaviors can be identified and permissions can be controlled. , operations can be audited, solving problems such as difficult asset management, unclear operation and maintenance responsibilities and authorities, and difficult traceability of operation and maintenance events, helping enterprises meet the requirements for grade guarantee compliance.
type
Version describe Bastion machine (basic version, enterprise dual-engine version) Unified operation and maintenance management and control of Alibaba Cloud, heterogeneous cloud and offline hybrid assets, providing one-stop operation and maintenance services, including the management of multiple types of assets such as Linux, Windows and databases. It also supports multiple operation and maintenance access methods such as C/S and B/S, and adopts dual-engine deployment to ensure high stability. Bastion machine (developer version, lightweight version) Provides convenient cloud operation and maintenance experience for Alibaba Cloud ECS assets, lightweight deployment, one-click operation and maintenance of multiple VPCs, deep integration of cloud assets, automatic synchronization of assets and credentials, and intelligent identification of privileged accounts.
Product advantages
Basic Edition, Enterprise Dual Engine Edition
Stable cloud architecture
The bastion host adopts cloud architecture, that is,
Cloud server ECS SLS OSS cloud database RDS are stored separately and run independently. On the one hand, the stable cloud architecture avoids the interruption of operation and maintenance services caused by single points of failure. On the other hand, Alibaba Cloud SLS, OSS, and RDS are highly stable and mature, and can more safely protect system resources. Therefore, bastion machines based on cloud architecture are more stable, flexible and secure.
Safe and reliable operation and maintenance capabilities
The bastion function can be operated and maintained efficiently and stably on Windows and Linux systems. It can be operated and maintained on Windows systems without lag or missed review. It also realizes unified management of server assets in hybrid cloud scenarios such as multi-cloud, offline IDC, and cross-VPC. Centralized operation and maintenance. In addition, the code of the bastion machine has been commercially sealed and packaged, making it less vulnerable to attacks, making operation and maintenance more stable and secure.
Global deployment
The bastion machine supports global deployment, covering Asia-Pacific, America, Europe, the Middle East and India, and has good adaptability. It provides a pure English interface and supports two-factor operation and maintenance authentication of mobile phone numbers in multiple overseas countries, ensuring the safe operation and maintenance of assets worldwide.
Dual engine architecture
The dual-node deployment of the engine ensures the stability of the bastion machine. Under normal business conditions, it can balance business pressure and improve operation and maintenance efficiency. When the connection is abnormal, it automatically enables HA mode to ensure the continuity of business and monitoring.
Convenient, practical and considerate service
The bastion machine is simple, easy to use and efficient. It can be activated immediately upon purchase and can be flexibly configured according to needs. Supports one-click activation and also supports
One-click synchronization of cloud server ECS and cloud database dedicated cluster hosts, as well as one-click import of RAM users, AD users, and LDAP users. We provide considerate 7*24-hour expert services to respond to your needs at any time.
Developer version, lightweight version
Unified asset operation and maintenance management
We provide secure custody of cloud assets and privileged accounts. Through a cross-regional unified operation and maintenance management perspective, we improve the visibility of cloud assets and help administrators efficiently manage resources and credentials.
Privileged access behavior control
The authorization configuration of assets and credentials is very flexible, allowing fine-grained control of access behavior, thereby reducing the exposure risk of core cloud assets on the operation and maintenance side, and effectively reducing losses caused by operation and maintenance risks.
Intelligent operation and maintenance risk control and audit
By comprehensively recording privileged access trajectories and intelligently analyzing operation and maintenance risks and abnormal operating behaviors, we build a safe and trustworthy operation and maintenance platform on the cloud to meet operation and maintenance compliance requirements.
Features
Applicable scene
Version Scenes Bastion machine (basic version, enterprise dual-engine version) Basic version Suitable for the more professional operation and maintenance experience needs of small and medium-sized enterprise users (50~500 mixed assets), providing more fine-grained operation and maintenance management and control capabilities, such as client operation and maintenance, fine-grained operation and maintenance user access and behavior authorization, risk command automation Interception, high-risk command operation and maintenance approval, real-time operation and maintenance monitoring and blocking, users support RAM, AD or LDAP self-created user management and control, etc., which can meet the basic operation and maintenance security management and control needs of small and medium-sized enterprises. Enterprise Dual Engine Edition It is suitable for enterprises with high security requirements for operation and maintenance business or large business scale, such as government enterprises, finance, games, online education, information technology, etc. In addition to the basic operation and maintenance security capabilities, more sufficient performance and basic configuration of the basic version, the Enterprise Dual Engine Edition can also meet higher business operation and maintenance security requirements. The advantages are as follows: Database operation and maintenance scenarios: Supports operation and maintenance authorization management and control of RDS, self-built databases, and third-party databases, including MySQL, SQL Server, PostgreSQL, and Oracle. Hybrid operation and maintenance scenario: Unified operation and maintenance management and control of assets under offline IDC, other clouds and cross-accounts are realized through the network domain proxy model. High business stability guarantee: It adopts dual-engine architecture, active-active operation, and SLA can reach 99.95%. Other value-added capabilities: In terms of operation and maintenance, it provides Web operation and maintenance portal operation and maintenance, and in terms of asset management, it provides the ability to automatically change passwords of Linux assets, effectively improving password security. Bastion machine (developer version, lightweight version) Developer version It is suitable for individual developers or pure cloud customers of small enterprises (5 to 20 ECS or K8s assets). It has basic administrator unified operation and maintenance, operation and maintenance user access authorization management and control, operation and maintenance audit full recording and other capabilities, and provides Deeper cloud experience, lightweight deployment and activation, multi-VPC intranet access on the cloud, automatic identification of asset accounts, etc. Light version It is suitable for small pure cloud enterprise customers (5~20 ECS or K8s assets). In addition to the basic operation and maintenance requirements of the developer version, it also adds more common operation and management and control capabilities for enterprises, such as file transfer and audit capabilities. Administrators can control command operations for operation and maintenance users, automatically block high-risk commands to ensure operation and maintenance security, and have higher configuration specifications and performance such as 365-day log storage.
Function comparison
Function describe Free version Developer version Light version Basic version Enterprise Dual Engine Edition Architecture Adopt stable architecture deployment to ensure stable operation of business and monitoring. SaaS SaaS SaaS Cloud architecture Cloud dual-engine architecture Cross-domain operation and maintenance Manage assets of multiple VPCs in multiple regions through unified console operation and maintenance. Support intranet one-click access Support intranet one-click access Support self-built network mode Support self-built network mode and network domain proxy mode Privilege management Divide privileged and ordinary permission system accounts, and support quick authorization and management by category. Flexible expansion Supports asset number, storage and other specifications, and can be flexibly expanded according to demand. deploy Adaptable to international scenarios and can be deployed overseas. It supports real-time switching between Simplified Chinese, Traditional Chinese and English scenes, and is adapted to two-factor authentication of overseas mobile phone numbers. User and asset management Supports multi-role division of users. Users support RAM, AD, LDAP, Azure AD synchronization and batch file import. Supports Windows system and Linux system operation and maintenance; supports common operation and maintenance protocols: SSH, RDP. Supports operation, maintenance, control and auditing of MySQL, SQL Server, PostgreSQL, Oracle type RDS and self-built databases. Supports batch import of third-party assets. Supports one-click import of Alibaba Cloud assets. Supports Alibaba Cloud database dedicated clusters, cloud servers, IDC computer room offline servers and other application scenarios. Supports multi-regional SMS dynamic passwords and email two-factor authentication mechanisms. Supports mobile App dynamic password authentication to log in to the bastion host. Supports manual and regular encryption tasks for Linux servers. Operation and maintenance control Support client tools such as Mstsc, Xshell, SecureCRT, Putty, etc. to log into the bastion machine to access graphics or character devices and restore the consistency of the view interface. Use local WinSCP, Xftp, SecureFX and other SFTP client tools to log in to the bastion host for operation and maintenance. Operation and maintenance users can operate and maintain authorized assets on the Web through the operation and maintenance portal, and local users can also log in through OTP token authentication through the operation and maintenance portal. Supports direct operation and maintenance of the server via the Web. Supports real-time monitoring of operation and maintenance sessions and can block sessions. Support real-time monitoring Support real-time monitoring Supports the control of uploading or downloading of RDP pasteboard, disk mapping and other operations. Supports policy blocking and approval of key commands. Support command blocking Supports the control of file upload, download, deletion, renaming, folder creation, deletion and other operations during the operation and maintenance process. Operational audit Supports the recording of operation logs, and supports full audit recording and playback. Supports auditing of file transfers. Supports generating operation and maintenance reports. Reports support export in three formats: PDF, HTML, and WORD. interface Support OpenAPI interface call.