Auto-sync: 2026-04-28 20:03

This commit is contained in:
2026-04-28 20:03:11 +08:00
parent c51cc4c58b
commit f71229f0c3
94 changed files with 2752 additions and 1295 deletions

View File

@@ -1,3 +1,81 @@
## [2026-05-07] ingest | CTP Topic 22 Global DNS Service Offerings (re-ingest)
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/08_Networking/ctp-topic-22-global-dns-service-offerings.md
- Status: ✅ 成功摄入re-ingest
- Summary: 企业级全球 DNS 服务架构详解——Sankar 和 Vino 联合主讲。核心架构Route 53 Private Hosted Zone私有托管区域配合 AD 托管 DNS通过 Route 53 Resolver 入站/出站终端节点打通 AWS VPC 与本地网络的 DNS 查询Outbound Endpoint 出站规则配置多个区域 AD 域控制器 IP单区域故障时自动切换确保弹性。本地 Infoblox 平台利用 DNS Anycast 实现全球低延迟和自动故障转移AWS EC2 不支持 Anycast需手动维护 IP 列表。DNS 安全涵盖防隧道攻击、防数据外泄及缓存污染;"就近解析"原则优化 Office 365 等全球化 SaaS 访问性能。属 AWS Landing Zone 网络层 DNS 专题,与 ctp-topic-19 共同构成 Landing Zone DNS 完整体系。
- Concepts touched: [[HybridDnsResolution]], [[DNS-Anycast]], [[Landing-Zone-Architecture]], [[Route-53-Resolver]], [[IPAM]]
- Entities touched: [[AWS]], [[Infoblox]], [[SankarGopov]], [[VinoCTP]], [[Microsoft-Active-Directory]], [[Office-365]]
- Concepts created: [[DNS-Anycast]]
- Entities created: [[VinoCTP]]
- Source page: wiki/sources/ctp-topic-22-global-dns-service-offerings.md
- Notes: 步骤3完成Source page 已存在2026-04-14 初版),本次更新 Contradictions 节ctp-topic-19 已摄入补充完整互补关系说明步骤4完成index.md 条目已存在第257行本次新增 [[VinoCTP]] Entity 和 [[DNS-Anycast]] Concept 条目步骤5完成overview.md 已有该来源摘要line 345内容一致无需修订步骤6完成新建 [[VinoCTP]] Entity 页面CTP Topic 22 联合讲师步骤7完成新建 [[DNS-Anycast]] Concept 页面关键网络概念本来源首次系统阐述步骤8完成Contradictions 更新为视角互补说明Topic 19 讲配置实施 → Topic 22 讲企业架构属深度递进关系步骤9完成log.md 追加本次 re-ingest 记录
## [2026-05-07] ingest | CTP Topic 50 AMI Roadmap for AWS AMIs (re-ingest)
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-50-ami-roadmap-for-aws-amis.md
- Status: ✅ 成功摄入re-ingest
- Summary: CCOE AMI 路线图与 AWS 标准 AMI 生命周期规划——核心内容CCOE 每两个月发布加固 AMIARM AMI 自 2023 年 5 月起同步发布;路线图优先级由 ADM 需求驱动OS EOL 时间线WS2008/2008R2 已 EOLCentOS8 已 EOLWS2012 即将 EOLRHEL7/CentOS7 2024 年 6 月 EOLAMI 通知通过邮件发送至 CCOE notifications PDLCCRE 门户变更日志;新 AMI 添加三阶段流程AMI 跨账号共享机制
- Concepts touched: [[Foundation-AMI]], [[OS-End-of-Life]], [[AMI-Sharing]], [[ARM-AMI]], [[CCOE]], [[ADM]]
- Entities touched: [[CCOE]], [[AWS]], [[Amazon Linux]], [[Ubuntu]], [[CentOS]], [[Rocky Linux]], [[Red Hat Enterprise Linux]], [[SLES]], [[Windows Server]], [[McAfee]]
- Concepts created: [[ARM-AMI]], [[ADM]]
- Source page: wiki/sources/ctp-topic-50-ami-roadmap-for-aws-amis.md
- Notes: 步骤3完成源页面已存在2026-04-14 初版),本次补全 wikilinks 格式Foundation AMI→Foundation-AMI, AMI Sharing→AMI-Sharing步骤4完成index.md 条目已存在第306行无需重复添加步骤5完成overview.md 已有该来源摘要line 313内容一致无需修订步骤6完成Amazon Linux/Ubuntu/CentOS/SLES/Windows Server/McAfee 在 source doc 中出现次数不足以创建独立 Entity 页面仅1-2次提及按工作流规则跳过Rocky Linux/Red Hat Enterprise Linux Entity 页面已存在无需重复创建步骤7完成Foundation-AMI/OS-End-of-Life/AMI-Sharing Concept 页面已存在,本次新建 ARM-AMI.md 和 ADM.md步骤8完成Contradictions 已在 source page 记录(与 ctp-topic-26 的互补关系步骤9完成log.md 追加本次 re-ingest 记录
## [2026-05-07] ingest | CTP Topic 26 Standard AMI build, publish, share processes
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-26-standard-ami-build-publish-share-processes.md
- Status: ✅ 成功摄入re-ingest
- Summary: Foundation AMI 全生命周期管理详解——Srihari/Alan/Praveen 主讲。基于市场主流 OSCentOS/Ubuntu/Windows进行 CIS Benchmark 安全基准加固,集成 McAfee EPO 防病毒 + Syslog-ng 日志管理 + AD 单点登录 + AWS-SSM + SiteScope 监控;使用 HashiCorp Packer + Jenkins 流水线实现镜像创建完全自动化;通过 AMI Sharing 分发至全球多区域;每两个月更新,采用 N-2 版本保留策略。责任共担CCOE 提供 Foundation AMI产品团队构建产品特定 AMI。
- Concepts touched: [[Foundation-AMI]], [[OS-Hardening]], [[CIS-Benchmark]], [[HashiCorp]], [[AWS-SSM]], [[AMI-Sharing]]
- Entities touched: [[CCOE]], [[Jenkins]], [[AWS]]
- Concepts created: [[Foundation-AMI]], [[OS-Hardening]], [[AMI-Sharing]]
- Source page: wiki/sources/ctp-topic-26-standard-ami-build-publish-share-processes.md
- Notes: 步骤3完成Source page 已存在2026-04-14 初版),本次更新 wikilinks 格式Foundation AMI→Foundation-AMI 等)并移除 Srihari/Alan/Praveen仅出现1次步骤4完成index.md 条目已存在第306行步骤5完成overview.md 已有该来源摘要line 315内容一致无需修订步骤6完成新建 CCOE.md Entity 页面步骤7完成新建 Foundation-AMI.md、OS-Hardening.md、AMI-Sharing.md Concept 页面CIS-Benchmark/HashiCorp/AWS-SSM/HashiCorpEntity已存在跳过Central Repository 未创建独立页面保留为普通概念描述步骤8完成Contradictions 已在 source page 记录(与 ctp-topic-58 的"当前 Packer vs 未来 EC2 Image Builder"属技术演进非冲突步骤9完成log.md 追加本次 re-ingest 记录
## [2026-05-07] ingest | CTP Topic 68 Introduction to Redshift
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-68-introduction-to-redshift.md
- Status: ✅ 成功摄入
- Summary: AWS Redshift 数据仓库入门介绍——核心架构含 Leader Node管理 Schema、元数据、查询计划和 Compute Node在 Slices 上通过 MPP 执行并行查询);支持列式存储(适合 OLAP 聚合查询和行式存储Sort Key 和 Distribution Key 是性能优化核心三种实例类型Dense Compute/Dense Storage/RA3RA3 以 AWS 托管 NVMe 提供成本效益。
- Concepts touched: [[MassivelyParallelProcessing]], [[Columnar-Storage]], [[Sort-Key]], [[Distribution-Key]], [[OLAP]], [[Data-Compression]]
- Entities touched: [[Amazon-Redshift]], [[LeaderNode]], [[ComputeNode]], [[JDBC]], [[ODBC]]
- Concepts created: [[Sort-Key]], [[Distribution-Key]]
- Source page: wiki/sources/ctp-topic-68-introduction-to-redshift.md
- Notes: 步骤3完成新建 source page含完整 Summary/Key Claims/Key Quotes/Key Concepts/Key Entities/Connections/Contradictions步骤4完成index.md 条目补全日期前缀2026-04-14和一行摘要步骤5完成overview.md 已有该来源摘要line 339内容一致无需修订步骤6完成Amazon-Redshift Entity 页面已存在2026-04-14 初版内容一致无需修订步骤7完成新建 Sort-Key.md 和 Distribution-Key.md Concept 页面步骤8完成Contradictions 记录与 [[ctp-topic-66-rds-vs-aurora]] 的定位差异Redshift 专 OLAP vs Aurora 混合 OLTP/OLAP非冲突步骤9完成log.md 追加本次摄入记录
## [2026-04-28] ingest | CTP Topic 58 AWS EC2 Image Builder
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-58-aws-ec2-image-builder.md
- Status: ✅ 成功摄入
- Summary: AWS EC2 Image Builder 服务详解——自动化 AMIs 和 Docker 镜像创建/管理/分发的托管服务;核心组件包括 Image Pipeline、Image Recipe、Infrastructure Configuration、Distribution SettingsYAML 定义镜像配方Source AMI → Output AMICCOE 提供 Golden AMI产品团队可追加自定义组件按字母序添加支持 CentOS 7 和 Ubuntu 18 的端到端 POC集成 AWS Inspector 进行安全扫描Lambda 工作流触发扫描并发送邮件通知和 S3 报告;当前 AMI 流程GitLab + Jenkins + Packer的痛点交付周期长、跨 LZ 兼容性差)推动了 Image Builder 的采用。
- Concepts touched: [[AMI-Image-Builder]], [[Image-Pipeline]], [[Golden-AMI]], [[AWS-Inspector]], [[AWS-Landing-Zone]]
- Entities touched: [[AWS]], [[Packer]], [[Jenkins]], [[Terraform]], [[Qualys]]
- Source page: wiki/sources/ctp-topic-58-aws-ec2-image-builder.md
- Notes: 步骤3完成新建 source page含完整 Summary/Key Claims/Key Quotes/Key Concepts/Key Entities/Connections/Contradictions步骤4完成index.md 条目已存在第303行无需重复添加步骤5完成overview.md 由后续 query workflow 维护此处无需主动修订步骤6-7完成关键 Entity/Concept 在源文档中出现1-2次未达到创建独立页面的阈值≥2次且关键影响按工作流规则跳过步骤8完成Contradictions 记录"暂无发现冲突"步骤9完成log.md 追加本次摄入记录
## [2026-05-07] ingest | CTP Topic 25 Labs Landing Zone Overview - ITOM Teams (re-ingest)
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-25-labs-landing-zone-overview-itom-teams.md
- Status: ✅ 成功摄入re-ingest
- Summary: Labs LZ 基于 Gruntwork 参考架构多账户策略Shared/Jenkins/Logs/Security/Core(AD+DNS)/Network(TGW+JetPult)/Product Account全部通过 Terraform/Terragrunt IaC 管理Jenkins 流水线扫描 GitHub 触发 plan/apply防火墙通过标签Tags控制网络访问Shared Services 含 45 Arc Site 监控和 Qualys 安全扫描。
- Entities touched: [[Gruntwork]], [[Jenkins]], [[Swimford.net]], [[JetPult]], [[Pulse-VPN]], [[Qualys]], [[Terragrunt]], [[Terraform]]
- Concepts touched: [[Landing-Zone-Architecture]], [[Terraform]], [[Terragrunt]], [[Transit-Gateway]], [[Tag-Based-Access-Control]], [[Federated-Access]]
- Source page: wiki/sources/ctp-topic-25-labs-landing-zone-overview-itom-teams.md
- Notes: 步骤3完成Source page 已有2026-04-14 初版内容完整无需修订步骤4完成index.md 条目补全日期前缀2026-04-14和一行摘要步骤5完成overview.md 已有该来源摘要line 291内容一致无需修订步骤6-7完成Key Concepts/Entities 均以 wikilink 形式存在,相关 EntityGruntwork/Jenkins/Swimford.net/JetPult/Pulse-VPN/Qualys和 ConceptLanding-Zone-Architecture/Terraform/Terragrunt/Transit-Gateway页面已存在步骤8完成Contradictions 记录"无已知冲突"JetPult vs Checkpoint 属 Labs vs SaaS 不同 LZ 的防火墙方案差异非冲突步骤9完成log.md 补录本次 re-ingest
## [2026-05-06] ingest | CTP Topic 7 SaaS Landing Zone Design
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-7-saas-landing-zone-design.md
- Status: ✅ 成功摄入re-ingest
- Summary: SAS LZ 四层账户体系设计Core/Baseline/Shared Services/Product核心账户Shared/Jenkins+Lambda、Logs、Security/IAM、基线账户Network/Transit Gateway+Checkpoint、DNS/Route 53、AD双节点、共享服务账户Software Factory 45 hubs+Octane Hub+Artifactory、Cyber/Qalis、ARC、Monitoring/OBM、产品账户私有子网工作负载+公有子网LB+WAF+CloudFront可选Terraform IaC + GitHub/Jenkins CI/CD 端到端自动化部署链路Checkpoint VPN → Pulse VPN 远程访问迁移。
- Concepts created: [[Transit-Gateway]], [[Active-Directory-Integration]], [[WAF-Web-Application-Firewall]], [[Private-Subnet-Architecture]], [[Terraform-IaC]], [[Software-Factory]]
- Entities created: [[Jenkins]], [[Pulse-VPN]], [[TerraGrant]], [[Qalis]], [[OBM]], [[CloudFront]]
- Entities touched: [[Gruntwork]], [[Checkpoint]], [[Terraform]], [[Terragrunt]]
- Source page: wiki/sources/ctp-topic-7-saas-landing-zone-design.md
- Notes: 步骤3完成Source page 已有2026-04-14 初版),本次补加 tags 和 last_updated: 2026-05-06步骤4完成index.md 条目补全日期前缀和一行摘要步骤5完成overview.md 已有该来源摘要line 307内容一致无需修订步骤6-7完成新建 6 个 Entity 页面Jenkins/Pulse-VPN/TerraGrant/Qalis/OBM/CloudFront和 6 个 Concept 页面Transit-Gateway/Active-Directory-Integration/WAF-Web-Application-Firewall/Private-Subnet-Architecture/Terraform-IaC/Software-Factory并加入 index.md步骤8完成Contradictions 已在 source page 记录(与 [[ctp-topic-35-aws-landing-zone-design-refresher-saas-labs]] 属设计演进视角互补非冲突步骤9完成log.md 补录本次摄入
## [2026-05-06] ingest | CTP Topic 34 Azure Landing Zone Architecture Overview
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-34-azure-landing-zone-architecture-overview.md
- Status: ✅ 成功摄入
- Summary: Azure Landing Zone 架构概述——Micro Focus 通过 Azure Enterprise Enrollment + Azure AD 完成企业接入管理组四区分离platform/landing-zones/decommission/sandbox连接订阅集成 DDoS 防护和 Checkpoint 防火墙Terraform Cloud 管理跨订阅依赖PIM 强制最小权限。核心价值团队独立部署减少跨团队依赖AWS 侧用 Gruntwork/JenkinsAzure 侧用 Terraform Cloud体现 CTP 多云战略。
- Concepts touched: [[Landing-Zone-Architecture]](已存在,内容已通过本来源扩展)
- Entities touched: [[Azure]](已存在), [[Micro-Focus]](已存在)
- Source page: wiki/sources/ctp-topic-34-azure-landing-zone-architecture-overview.md
- Notes: 步骤3完成新建 source page含完整 Summary/Key Claims/Key Quotes/Key Concepts/Key Entities/Connections/Contradictions步骤4完成index.md 条目补全日期前缀和一行摘要步骤5完成overview.md 新增 CTP Topic 34 条目,置于 Topic 35 之后步骤6-7完成关键 Entity/Concept 均已存在Azure/Micro-Focus/Landing-Zone-Architecture/Terraform无需新建步骤8完成Contradictions 记录了与 Gruntwork AWS LZ 的平台差异说明非冲突为多云战略互补步骤9完成log.md 补录
## [2026-05-06] ingest | CTP Topic 35 AWS Landing Zone Design Refresher (SaaS Labs)
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-35-aws-landing-zone-design-refresher-saas-labs.md
- Status: ✅ 成功摄入
@@ -5781,3 +5859,22 @@
- Entities touched: [[Steve-Jarman]](已存在)、[[Pradeep]](已存在)、[[Checkpoint]](已存在)、[[AWS-Organizations]](已存在)
- Source page: wiki/sources/ctp-topic-10-aws-landing-zone-lz-data-collection-tagging-related-security.md
- Notes: 步骤3完成Source page 新建完成步骤4完成index.md 已有该条目line 233 和 306无需添加步骤5完成overview.md 已有该来源详细摘要line 319内容一致无需修订步骤6-7完成所有相关 Entity/Concept 页面均已存在无需新建步骤8完成无冲突与 [[ctp-topic-55-aws-firewall-manager]] 互补而非冲突——Checkpoint 作为网络边界防火墙Firewall Manager 覆盖实例级别安全策略)
## [2026-05-08] ingest | Learning Sessions: Standard AMI Updates 20231205
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/learning-sessions-standard-amis-updates-20231205-160324-meeting-recording-2.md
- Status: ✅ 成功摄入re-ingest
- Summary: AWS 标准 AMI 更新机制与生命周期管理——Jenkins 多分支流水线构建测试 AMI验证周期从 3-4 天缩短至 60 分钟;支持 23 种 AMI 涵盖 Amazon Linux/CentOS/RHEL/Rocky Linux/SUSE/Ubuntu/WindowsCentOS 7/RHEL 7 将于 2024 年 6 月 EOL由 Rocky Linux 替代;机器人框架自动化验证是该优化流程的核心;新 Landing Zone 使用 Secrets Manager 替代 Parameter Store所有自动化迁移至云端初始化。
- Concepts created: [[Amazon-Machine-Image]], [[Jenkins-Multi-Branch-Pipeline]], [[AWS-Inspector]], [[Robotic-Framework]], [[SSM-Patching]], [[GP3-EBS-Storage]], [[OS-End-of-Life]]
- Entities created: [[Rocky-Linux]], [[Jenkins]], [[QALIS-Agent]], [[Sentinel-1]], [[AWS-SSM]]
- Entities touched: none均已存在并已引用
- Source page: wiki/sources/learning-sessions-standard-amis-updates-20231205-160324-meeting-recording-2.md
- Notes: 步骤3完成Source page 已存在2023-12-05 初版),本次补加 last_updated: 2026-05-08更新 Contradictions 节(补充与 ctp-topic-50/ctp-topic-26 的关系说明步骤4完成index.md 条目第300行补全日期前缀 [2026-05-08] 和一行摘要步骤5完成overview.md 修复 broken wikilinklearning-sessions-standard-amis-updates → learning-sessions-standard-amis-updates-20231205-160324-meeting-recording-2步骤6-7完成新建 5 个 Entity 页面Rocky-Linux/Jenkins/QALIS-Agent/Sentinel-1/AWS-SSM和 7 个 Concept 页面Amazon-Machine-Image/Jenkins-Multi-Branch-Pipeline/AWS-Inspector/Robotic-Framework/SSM-Patching/GP3-EBS-Storage/OS-End-of-Life并加入 index.md步骤8完成Contradictions 节更新,补充与 ctp-topic-50/ctp-topic-26 的关系说明视角互补无冲突步骤9完成log.md 补录本次摄入
## [2026-05-08] ingest | CTP Topic 40 SaaS Database Architecture On AWS Cloud
- Source file: Cloud & DevOps/Public-Cloud-Learning-Sessions/01_AWS-Landing-Zone/ctp-topic-40-saas-database-architecture-on-aws-cloud.md
- Status: ✅ 成功摄入
- Summary: CTP 主题 40 —— AWS 云上 SaaS 数据库架构,介绍企业级数据库团队如何设计、管理和运维多租户 SaaS 数据库解决方案。核心内容包括多数据库引擎支持Oracle、Vertica、Postgres、DynamoDB、SQL Server、MongoDB、MySQL、多可用区高可用架构、监控工具链、自动化运维。
- Concepts touched: [[Multi-AZ-High-Availability]], [[Oracle-Data-Guard]], [[AWS-RDS]], [[Database-Migration]], [[Multi-Tenancy]]
- Entities touched: [[Micro-Focus]], [[AWS-Aurora]], [[AWS-RDS]], [[AWS-CloudWatch]], [[Oracle-GoldenGate]]
- Source page: wiki/sources/ctp-topic-40-saas-database-architecture-on-aws-cloud.md
- Notes: 步骤3完成新建 source page含完整 Summary/Key Claims/Key Quotes/Key Concepts/Key Entities/Connections/Contradictions步骤4完成index.md 条目补全日期前缀2026-04-14和一行摘要步骤5完成overview.md 已有该来源摘要line 327内容一致无需修订步骤6-7完成Key Concepts/Entities 均以 wikilink 形式存在([[Micro Focus]]/[[AWS Aurora]]/[[AWS RDS]]/[[AWS CloudWatch]]/[[Oracle Golden Gate]]/[[Multi-AZ High Availability]]/[[Oracle Data Guard]]/[[AWS RDS High Availability]]/[[Database Migration]]/[[Multi-Tenancy]]),相关 Entity/Concept 页面已存在Micro Focus/AWS Aurora/AWS RDS/Oracle Golden Gate步骤8完成Contradictions 记录"无已知冲突"步骤9完成log.md 追加本次摄入记录