Security
Coming from another cloud?
▸AWS·Security Pillar
This Quake AI feature maps to AWS’s Security Pillar.
▸DigitalOcean·Security
This Quake AI feature maps to DigitalOcean’s Security.
Security
Quake AI follows a shared responsibility model: the platform secures the underlying infrastructure, and you configure and protect your workloads, data, and access within your projects.
Shared responsibility at a glance#
| Area | Platform responsibility | Your responsibility |
|---|---|---|
| Physical infrastructure | Datacenter security, hardware, power, cooling | N/A |
| Hypervisor and host OS | Isolation between tenants, patching | N/A |
| Network backbone | Backbone integrity, DDoS mitigation | Security groups, firewall rules, and TLS on public endpoints |
| API authentication | Keystone identity, token issuance | Credential rotation, app credential scope, MFA |
| Compute instances | VM placement, host security | OS patching, SSH key management, user data scripts |
| Block storage | Volume encryption at rest (infrastructure layer) | Access control, snapshot policies, backup strategy |
| Object storage | Storage infrastructure availability | Bucket policies, SSE-C/SSE-OMK encryption, access control |
| Kubernetes | Control plane provisioning (via Magnum) | RBAC, network policies, image scanning, secrets |
| Service availability | API uptime, regional redundancy | Workload redundancy, health checks, auto-scaling |
For the full breakdown, see Shared responsibility model.
Get started#
Start with the Security hardening checklist for an actionable walkthrough of the most important security configurations for a new project.
Security guides#
Network security#
- Security groups: concepts
- Create a security group
- Create security group rules
- Security groups CLI reference
- Issue and auto-renew a TLS certificate
- Put a CDN in front of a workload
- Put a WAF in front of a workload
Object storage security#
- Server-side encryption (SSE-C and SSE-OMK)
- Grant access control
- Example IP whitelist policy
- Example public read policy
- Example read-only policy
- Example restricted public read policy
- Example reversible read-only policy
Related services#
Security configurations exist in each service. Compute instances use SSH key pairs and security groups. Network provides firewall rules and public addressing. Application servers, reverse proxies, CDNs, and WAFs terminate TLS. Storage offers encryption at rest and bucket policies. Kubernetes adds RBAC and network policies at the workload level.