《使用 AWS Lambda 为 SaaS 平台提供安全的用户代码执行保障.pdf》由会员分享,可在线阅读,更多相关《使用 AWS Lambda 为 SaaS 平台提供安全的用户代码执行保障.pdf(34页珍藏版)》请在三个皮匠报告上搜索。
1、 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.C N S 3 7 0Secure user code execution with AWS Lambda for SaaS platformsAnubhav SharmaPrincipal Solutions Architect,ISVAWSJoe LosinskiSenior Solutions Architect,ISVA
2、WS 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.SaaS isolation modelsTenant-specific code customizationsLambda native security primitivesCustom code customizations with Lambda FunctionsAgenda 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.SaaS deployment mod
3、elsOrderCatalogProductPooled modelTenant 2Tenant 1Tenant 1Tenant 2Hybrid modelAnalyticsAnalyticsTenant 3OrderCatalogProductFull stack silo modelAnalyticsOrderProduct 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Problem statement on customizationDeveloperStandard TierFeature 1Fe
4、ature 2Feature 3ONOffOffAdvanced TierFeature 1Feature 2Feature 3OffONONTenant-aware deploymentFull stack silo modelPooled modelHybrid modelPremium TierFeature 1Feature 2Feature 3OffONOffCustom Code 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Customizing application flowStep 1S
5、tep 2Step 4A flow in your SaaS applicationTenants3?Tenant 1 codeTenant 2 codeTenant 3 code 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Customizing application flow:Silo ModelStep 1Step 2Step 4A flow in your SaaS application3?Per-tenant Lambda functionTenants 2025,Amazon Web Se
6、rvices,Inc.or its affiliates.All rights reserved.Customizing application flow:Silo ModelExecution environmentTenantsPer-tenant Lambda functionExecution environmentExecution environmentFully isolated 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Lambda Security:FirecrackerWorker