{"id":18794175,"url":"https://github.com/yandex-cloud-examples/yc-security-solutions-library","last_synced_at":"2025-12-29T15:30:13.973Z","repository":{"id":227544912,"uuid":"771742388","full_name":"yandex-cloud-examples/yc-security-solutions-library","owner":"yandex-cloud-examples","description":"Yandex Cloud Security Solutions Library. Useful links.","archived":false,"fork":false,"pushed_at":"2025-02-16T06:35:28.000Z","size":13,"stargazers_count":26,"open_issues_count":1,"forks_count":3,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-02-16T07:24:25.225Z","etag":null,"topics":["security-solutions","solutions","yandex-cloud","yandexcloud"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yandex-cloud-examples.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2024-03-13T21:38:11.000Z","updated_at":"2025-02-14T20:12:45.000Z","dependencies_parsed_at":"2024-03-13T22:44:05.794Z","dependency_job_id":"851882b4-f0a6-4afc-ad8e-207efb3bf530","html_url":"https://github.com/yandex-cloud-examples/yc-security-solutions-library","commit_stats":null,"previous_names":["yandex-cloud-examples/yc-security-solutions-library"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yandex-cloud-examples%2Fyc-security-solutions-library","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yandex-cloud-examples%2Fyc-security-solutions-library/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yandex-cloud-examples%2Fyc-security-solutions-library/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yandex-cloud-examples%2Fyc-security-solutions-library/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yandex-cloud-examples","download_url":"https://codeload.github.com/yandex-cloud-examples/yc-security-solutions-library/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239718377,"owners_count":19685726,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["security-solutions","solutions","yandex-cloud","yandexcloud"],"created_at":"2024-11-07T21:28:31.473Z","updated_at":"2025-12-29T15:30:13.905Z","avatar_url":"https://github.com/yandex-cloud-examples.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🔐 Yandex Cloud Security Solution Library\n**Yandex Cloud Security Solution Library** — это набор примеров и рекомендаций, собранных в публичных репозиториях на GitHub. Они помогут компаниям, которые хотят построить безопасную инфруструктуру в Yandex Cloud и соответствовать требованиям различных регуляторов и стандартов.\nКоманда Yandex Cloud проработала самые распространённые задачи, которые возникают при построении безопасности в облаке, протестировала и подробно описала необходимые сценарии.\n\n#### Вводный вебинар \n[![image](https://user-images.githubusercontent.com/85429798/146542425-b250c494-9a3c-4744-897d-5f65849355d5.png)](https://www.youtube.com/watch?v=WZOB9ow0WrA)\n\n\n#### ☑️ Стандарт по защите облачной инфраструктуры Yandex Cloud 1.1\nЧеклист по безопасности в облачной инфраструкутре Yandex Cloud:\n\n[https://cloud.yandex.ru/docs/security/standard/all](https://cloud.yandex.ru/docs/security/standard/all)\n\n# Список решений\n- 🕸 Сетевая безопасность\n  - [Пример организации site-to-site VPN соединений к Yandex Cloud на основе IPsec с помощью решения StrongSwan ](https://github.com/yandex-cloud-examples/yc-site-to-site-vpn-with-ipsec-strongswan)\n  - [Пример создания remote-acess VPN соединений к Yandex Cloud на основе Wireguard с помощью решения Firezone](https://github.com/yandex-cloud-examples/yc-remote-acess-vpn-with-wireguard-firezone)\n- 🔑 Аутентификация и управление доступом\n  - [Развёртывание федерации удостоверений в Yandex Cloud на базе решения Keycloak](https://github.com/yandex-cloud-examples/yc-iam-federation-with-keycloak-vm)\n- 🦠 Защита от вредоносного кода\n  - [Развертывание Kaspersky Antivirus в Yandex Cloud (Compute Instance, COI)](https://github.com/yandex-cloud-examples/yc-kasperksy-antivirus-deploy)\n- 🐞 Управление уязвимостями\n  - [Отказоустойчивая эксплуатация PT Application Firewall в Yandex Cloud](https://github.com/yandex-cloud-examples/yc-webinar-pt-application-firewall-ha-operations)\n  - [Тестирование AntiDDos системы с помощью Yandex Load Testing](https://github.com/yandex-cloud-examples/yc-load-testing-for-dos-simulation)\n- 🔏 Шифрование данных и управление ключами/секретами\n  - [Шифрование секретов средствами KMS при передачи их в контейнер ВМ на базе Container Optimized Image (COI) в Yandex Cloud](https://github.com/yandex-cloud-examples/yc-encrypt-coi-secrets)\n  - [Шифрование диска ВМ в Облаке с помощью YC KMS](https://github.com/yandex-cloud-examples/yc-encrypt-vm-disk-with-kms)\n  - [Vault-to-Lockbox Migrator](https://github.com/yandex-cloud-examples/yc-lockbox-migration-from-hashicorp-vault)\n  - [Lockbox Безопасная передача паролей в Windows](https://github.com/yandex-cloud-examples/yc-secure-bypass-password-to-cloudinit)\n  - [Использование Lockbox для получения паролей в VM](https://github.com/yandex-cloud-examples/yc-lockbox-for-keycloak-vm)\n- 🔎 Сбор, мониторинг и анализ аудит логов\n  - [Сбор, мониторинг и анализ аудит логов Yandex Cloud в Yandex Managed Opensearch](https://github.com/yandex-cloud-examples/yc-export-auditlogs-to-opensearch)\n  - [Сбор, мониторинг и анализ аудит логов в Yandex Managed Service for Elasticsearch (ELK)](https://github.com/yandex-cloud-examples/yc-export-auditlogs-to-elk)\n  - [Сбор, мониторинг и анализ аудит логов во внешний SIEM ArcSight](https://github.com/yandex-cloud-examples/yc-export-auditlogs-to-arcsight)\n  - [Сбор, мониторинг и анализ аудит логов во внешний Splunk](https://github.com/yandex-cloud-examples/yc-export-auditlogs-to-splunk)\n  - [Сбор, мониторинг и анализ аудит логов во внешний Wazuh](https://github.com/yandex-cloud-examples/yc-export-auditlogs-to-wazuh)\n  - [Trails-function-detector: Оповещения и реагирование на события ИБ Audit trails с помощью Cloud Logging/Cloud Functions + Telegram](https://github.com/yandex-cloud-examples/yc-audit-trails-automatic-response)\n  - [Мониторинг Audit Trails и событий в Yandex Cloud Monitoring](https://github.com/yandex-cloud-examples/yc-audit-trails-monitoring)\n\n- 👮 Безопасная конфигурация\n  - [Пример безопасной конфигурации Yandex Cloud Object Storage: Terraform](https://github.com/yandex-cloud-examples/yc-s3-secure-bucket)\n  - (Скоро) запрет доступа к метадате\n\n\u003cp align=\"left\"\u003e\n    \u003cimg src=\"https://github.com/kubernetes/kubernetes/blob/master/logo/logo.svg\" alt=\"Kubernetes logo\" width=\"50\"/\u003e\n\u003c/p\u003e\n\n- Безопасность Kubernetes\n  - Аутентификация и управление доступом Managed Kubernetes:\n    - [Пример настройки ролевых моделей и политик в Managed Service for Kubernetes](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/kubernetes-security/auth_and_access/role-model-example/README_RU.md)\n  - Сбор, мониторинг и анализ аудит логов:\n    - [Анализ логов безопасности k8s в ELK: аудит-логи, policy engine, falco](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/auditlogs/export-auditlogs-to-ELK_k8s)\n    - [Экспорт Cilium Flow Logs в Object Storage(s3)](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/auditlogs/cilium-s3)\n    - [Экспорт k8s аудит логов в s3/object storage](https://github.com/yandex-cloud/yc-solution-library-for-security/blob/master/auditlogs/export-k8s-to-s3/README.md)\n    - [Экспорт k8s аудит логов в Yandex Data Streams/Kinesis Data Streams](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/auditlogs/export-k8s-to-yds)\n  - Шифрование данных и управление ключами/секретами Managed Kubernetes\n    - [Управление секретами c SecretManager(Lockbox,Vault)](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/kubernetes-security/encrypt_and_keys/secret-management/README_RU.md)\n  - Безопасная конфигурация Managed Kubernetes:\n    - [osquery и kubequery в k8s: osquery (защита k8s nodes), kubequery (анализ конфиг. всего k8s) ](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/kubernetes-security/osquery-kubequery/README_RU.md)\n  - [Интеграция Starboard с Yandex Cloud Container Registry с целью сканирования запущенных образов](https://github.com/yandex-cloud/yc-solution-library-for-security/tree/master/kubernetes-security/starboard_and_yc-cr/README_RU.md)\n\n\u003cp align=\"left\"\u003e\n    \u003cimg src=\"https://logowik.com/content/uploads/images/gitlab8368.jpg\" alt=\"Gitlab logo\" height=\"50\" width=\"50\"/\u003e\n\u003c/p\u003e\n\n- CI/CD Security\n  - Secure CI/CD на базе Managed GitLab:\n    - [Вебинар+материалы:Обнаружение Log4shell и др. уязвимостей в CI/CD на базе Managed GitLab](https://github.com/yandex-cloud-examples/yc-webinar-secure-cicd-with-gitlab):\n      - [Обнаружение уязвимостей в CI/CD (Ultimate лицензия)](https://github.com/yandex-cloud-examples/yc-webinar-secure-cicd-with-gitlab)\n      - [Обнаружение уязвимостей в CI/CD (Free лицензия)](https://github.com/yandex-cloud-examples/yc-webinar-secure-cicd-with-gitlab)\n      - [Security in Gtilab instance check-list](https://github.com/yandex-cloud-examples/yc-webinar-secure-cicd-with-gitlab/tree/main/gitlab_instance_sec_checklist)\n  - [Выступление про комплаенс и devsecops](https://github.com/yandex-cloud-examples/yc-webinar-devsecops-compliance-2022)\n  - [Вебинар+материалы:Как выстроить процесс безопасной разработки в Yandex Cloud](https://github.com/yandex-cloud-examples/yc-webinar-security-pipeline-2023)\n\n\u003cp align=\"left\"\u003e\n    \u003cimg src=\"https://upload.wikimedia.org/wikipedia/commons/thumb/8/83/Telegram_2019_Logo.svg/1200px-Telegram_2019_Logo.svg.png\" alt=\"Telegram logo\" width=\"50\"/\u003e\n\u003c/p\u003e\n\n# Обратная связь и пожелания\n- Доработки, ошибки, contribute - с помощью инструментов Github - [Issues](https://docs.github.com/en/issues/tracking-your-work-with-issues/about-issues) и [Pull Requests (PR)](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request)\n- Вопросы, пожелания, консультации: Пишите нам в телеграм https://t.me/YandexCloudSecurity\n\n#### Референсная архитектура\n![Refer_arc](https://user-images.githubusercontent.com/85429798/132501079-0bd89876-2cc9-405b-aac3-ea65ac1fb6d2.png)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyandex-cloud-examples%2Fyc-security-solutions-library","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyandex-cloud-examples%2Fyc-security-solutions-library","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyandex-cloud-examples%2Fyc-security-solutions-library/lists"}