Cloud Practices

Practices

Best practices for cloud services in NUP projects

Cloud practices ensure secure, cost-effective, and resilient use of cloud services. This practice covers security, architecture, and operational best practices for cloud deployments.

Cloud Security Best Practices

Cloud Security Layers
Cloud Security Layers

Identity and Access Management

IAM Best Practices

PracticeDescriptionImplementation
Least PrivilegeGrant minimum required permissionsRegular access reviews
MFA EverywhereRequire MFA for all human usersEnforce via IAM policy
Service AccountsDedicated accounts for applicationsNo shared credentials
Temporary CredentialsUse short-lived tokensIAM roles, not keys
Regular RotationRotate credentials regularlyAutomated rotation

IAM Policy Example (AWS)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowS3ReadOnly",
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:ListBucket"
      ],
      "Resource": [
        "arn:aws:s3:::my-bucket",
        "arn:aws:s3:::my-bucket/*"
      ],
      "Condition": {
        "StringEquals": {
          "aws:PrincipalTag/Environment": "production"
        }
      }
    }
  ]
}

Service Account Security

# Kubernetes service account with workload identity
apiVersion: v1
kind: ServiceAccount
metadata:
  name: my-app
  annotations:
    # AWS IRSA
    eks.amazonaws.com/role-arn: arn:aws:iam::123456789:role/my-app-role
    # GCP Workload Identity
    iam.gke.io/gcp-service-account: my-app@project.iam.gserviceaccount.com

Network Security

VPC Architecture

VPC Architecture
VPC Architecture

Security Group Rules

# Terraform security group
resource "aws_security_group" "app" {
  name        = "app-sg"
  description = "Security group for application servers"
  vpc_id      = aws_vpc.main.id

  # Allow HTTP from ALB only
  ingress {
    from_port       = 8080
    to_port         = 8080
    protocol        = "tcp"
    security_groups = [aws_security_group.alb.id]
  }

  # Allow all outbound
  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  tags = {
    Name = "app-sg"
  }
}

Data Protection

Encryption at Rest

ServiceEncryption MethodKey Management
S3SSE-S3, SSE-KMS, SSE-CAWS KMS
RDSAES-256AWS KMS
EBSAES-256AWS KMS
DynamoDBAWS-owned, customer-managedAWS KMS

KMS Key Policy

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Enable IAM policies",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789:root"
      },
      "Action": "kms:*",
      "Resource": "*"
    },
    {
      "Sid": "Allow use of the key",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789:role/app-role"
      },
      "Action": [
        "kms:Encrypt",
        "kms:Decrypt",
        "kms:GenerateDataKey"
      ],
      "Resource": "*"
    }
  ]
}

Secrets Management

# Using External Secrets Operator with AWS Secrets Manager
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
  name: my-app-secrets
spec:
  refreshInterval: 1h
  secretStoreRef:
    kind: ClusterSecretStore
    name: aws-secrets-manager

  target:
    name: my-app-secrets
    creationPolicy: Owner

  data:
    - secretKey: database-url
      remoteRef:
        key: prod/my-app/database
        property: url

    - secretKey: api-key
      remoteRef:
        key: prod/my-app/api
        property: key

High Availability and Disaster Recovery

Multi-AZ Architecture

Multi-AZ Deployment
Multi-AZ Deployment

Backup Strategy

ResourceBackup MethodFrequencyRetention
DatabaseAutomated snapshotsDaily30 days
S3Cross-region replicationReal-timeIndefinite
EBSSnapshotsDaily7 days
ConfigurationGit + IaCOn changeIndefinite

Cost Optimization

Cost Management Practices

PracticeDescriptionTools
Right-sizingMatch resources to workloadAWS Compute Optimizer
Reserved capacityCommit for discountsSavings Plans, Reserved Instances
Spot instancesUse spare capacitySpot Fleet, Spot Instances
Auto-scalingScale with demandAuto Scaling Groups
CleanupRemove unused resourcesAWS Cost Explorer, Trusted Advisor

Cost Monitoring

# AWS Budget configuration
Resources:
  MonthlyBudget:
    Type: AWS::Budgets::Budget
    Properties:
      Budget:
        BudgetName: Monthly-Budget
        BudgetLimit:
          Amount: 1000
          Unit: USD
        TimeUnit: MONTHLY
        BudgetType: COST
      NotificationsWithSubscribers:
        - Notification:
            NotificationType: ACTUAL
            ComparisonOperator: GREATER_THAN
            Threshold: 80
          Subscribers:
            - SubscriptionType: EMAIL
              Address: team@example.com

Compliance and Governance

Compliance Frameworks by Cloud

FrameworkAWSAzureGCP
SOC 2AWS ArtifactAzure ComplianceGCP Compliance Reports
HIPAABAA availableBAA availableBAA available
FedRAMPGovCloudAzure GovernmentAssured Workloads
ISO 27001CertifiedCertifiedCertified

Cloud Security Posture Management

# Checkov policy-as-code example
# .checkov.yaml
framework:
  - terraform
  - kubernetes

skip-check:
  - CKV_AWS_18  # Known exception

hard-fail-on:
  - CKV_AWS_19  # S3 encryption required
  - CKV_AWS_21  # S3 versioning required
  - CKV_AWS_145 # KMS encryption required

Compliance

This section fulfills ISO 13485 requirements for infrastructure management (6.3) and service provision control (7.5.1), and ISO 27001 requirements for cloud security (A.5.23), network security (A.8.20), data protection (A.8.24), and access control (A.5.15).

View full compliance matrix

Sign in or sign up

Enter your work email to receive a temporary sign-in link.

By continuing, you agree to our Terms of Service and Privacy Policy.