NGINX
How will NGINX continue to innovate and power your modern apps?
updated
Speakers:
Melissa McKay, Developer Advocate, JFrog
jfrog.com/blog-author/melissa-mckay
Damian Curry, Technical Director Community and Alliances, NGINX
nginx.com/people/damian-curry
We encourage you to share any lessons you may have learned in your application development journey in the comments!
You'll also learn how to connect NGINX App Protect to the Security Monitoring module on NGINX Management Suite to visualize and monitor for potential threats.
This simple architecture defends GraphQL APIs from some of the most common API vulnerabilities, including missing authentication and authorization, injection attacks, unrestricted resource consumption, and more.
PREREQUISITES:
• 30-day free trial of the API Connectivity Stack from NGINX: bit.ly/44yztPs
• Apollo GraphQL Server: bit.ly/3Kb4G2X
• Linux/Unix or another compatible environment
• Basic familiarity with the Linux command line
• A tex editor (Vi or Vim)
• Curl
Read the companion blog "Deliver and Secure GraphQL APIs with F5 NGINX":
⬢ bit.ly/3K2bM9N
Check out the official GitHub repo:
⬢ bit.ly/3O3XqXW
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Blog: Managing NGINX Configuration at Scale with Instance Manager
⬡ nginx.com/blog/managing-nginx-configuration-at-scale-with-instance-manager
Interested in trying NGINX Management Suite Instance Manager?
⬡ nginx.com/pricing
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Blog: Managing NGINX Configuration at Scale with Instance Manager
⬡ nginx.com/blog/managing-nginx-configuration-at-scale-with-instance-manager
Interested in trying NGINX Management Suite Instance Manager?
⬡ nginx.com/pricing
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Blog: Managing NGINX Configuration at Scale with Instance Manager
⬡ nginx.com/blog/managing-nginx-configuration-at-scale-with-instance-manager
Interested in trying NGINX Management Suite Instance Manager?
⬡ nginx.com/pricing
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Blog: Managing NGINX Configuration at Scale with Instance Manager
⬡ nginx.com/blog/managing-nginx-configuration-at-scale-with-instance-manager
Interested in trying NGINX Management Suite Instance Manager?
⬡ nginx.com/pricing
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Blog: Managing NGINX Configuration at Scale with Instance Manager
⬡ nginx.com/blog/managing-nginx-configuration-at-scale-with-instance-manager
Interested in trying NGINX Management Suite Instance Manager?
⬡ nginx.com/pricing
Links shared in the Zoom chat:
Developer survey
forms.office.com/r/Ma4WBiaxz8
Project Tetsuo
https://tetsuo.dev/
Open Source Summit, Europe
events.linuxfoundation.org/open-source-summit-europe
Docker Official Image
hub.docker.com/_/unit
Roadmap
github.com/orgs/nginx/projects/1
Chapters:
0:00 - Intros
3:36 - Community News
6:28 - Developer Survey Results
11:46 - New Features Roundup
16:51 - Demo
40:05 - Roadmap
50:08 - Q&A / Discussion
Read the companion blog "How to Scan Your Environment for NGINX Instances"
⬡ nginx.com/blog/how-to-scan-your-environment-for-nginx-instances
Additional Resources:
Webpage: NGINX Management Suite Instance Manager
⬡ nginx.com/products/nginx-management-suite/instance-manager
Datasheet: NGINX Management Suite Instance Manager
⬡ nginx.com/resources/datasheets/f5-nginx-management-suite-instance-manager
Free Trial: Test Drive NGINX Management Suite Instance Manager
⬡ nginx.com/pricing
⬢ What is F5 NGINXaaS for Azure?
NGINXaaS for Azure is an Infrastructure-as-a-Service (IaaS) version of NGINX Plus that enables application developers to deliver consistent, secure, and high-performance apps in the cloud – deployed straight from the Azure Marketplace with just a few clicks on the console.
Tightly integrated with the Microsoft Azure public cloud and its ecosystem, this integration makes applications fast, efficient, and reliable with full lifecycle management of advanced NGINX traffic services. NGINXaaS for Azure integrates with core Azure services – including Azure Active Directory (AD), Azure Key Vault, Azure Monitor, and Azure DevOps – meaning admins can easily leverage the Azure Portal, Azure Console, Azure API/SDK, Azure CLI, and Terraform for configuration and management.
⬢ Learn more: bit.ly/3VbXnfV
NGINX App Protect WAF secures gRPC APIs by enforcing your schema, setting size limits, blocking unknown files, and preventing resource-exhaustion types of DoS attacks. You can import your Interface Definition Language (IDL) file to NGINX App Protect WAF so that it can enforce the structure and schema of your gRPC messages and scan for attacks in the right places. This enables accurate detection of attempts to exploit your application through gRPC and avoids false positives that can occur when scanning for security in the wrong places without context. Learn how NGINX App Protect WAF can defend your gRPC bidirectional streaming APIs from attacks in this demo.
docs.nginx.com
Additional Resources:
Blog: Secure Your API Gateway with NGINX App Protect WAF
nginx.com/blog/secure-your-api-gateway-with-nginx-app-protect-waf
Blog: Securing gRPC APIs with NGINX App Protect WAF
nginx.com/blog/securing-grpc-apis-with-nginx-app-protect
Webpage: NGINX App Protect WAF
nginx.com/products/nginx-app-protect/web-application-firewall
Datasheet: NGINX App Protect WAF
nginx.com/resources/datasheets/nginx-app-protect-web-application-firewall
eBook: Modern App and API Security
nginx.com/resources/library/modern-app-api-security
eBook: Mastering API Architecture from O’Reilly
nginx.com/resources/library/mastering-api-architecture
Test drive NGINX App Protect WAF today with a 30-day free trial.
nginx.com/free-trial-request
Attack signatures packages are sets of installable profiles that define unwanted behaviors against applications and defend against evolving vulnerabilities and emerging threats. Threat campaigns are high confidence, low false positive packages that are designed to defend against the latest and most severe advanced persistent threats (APTs).
In this demo, we show you how to manually install the most up to date packages for signatures and threat campaigns on NGINX App Protect WAF from the NGINX security updates repository, as well as how to automate these updates for your VMs or containers. For notifications on the signatures and threat campaigns package updates, we show you where to register on myf5.com, to sign-up for security alerts for consistent app protection from the latest threats.
docs.nginx.com/nginx-app-protect-waf
Additional Resources:
Webpage: NGINX App Protect WAF
⬢ bit.ly/41IEYtc
Datasheet: NGINX App Protect WAF
⬢ bit.ly/40sebzX
Blog: Automate Security with NGINX App Protect WAF to Reduce the Cost of Breaches
⬢ nginx.com/blog/automate-security-f5-nginx-app-protect-f5-nginx-plus-to-reduce-cost-of-breaches
Free Trial: Test Drive NGINX App Protect WAF for 30 Days
⬢ bit.ly/3Ad9WOk
This demo will showcase the OWASP Juice Shop modern app that has vulnerabilities associated with it and needs protection. It is hosted on a container and NGINX Plus with NGINX App Protect WAF is installed on it with the default policy to provide the needed app protection. We will use a third-party logging and monitoring dashboard tool, an ELK stack, to review the log output from NGINX App Protect WAF and help monitor the application.
We will look at an alert, the violation associated with it, and drill down into the event details and show how to apply policy tuning. NGINX App Protect WAF is lightweight and can be integrated easily into your CI/CD workflows to enable app security policies to be tested in lower environments prior to reaching production.
docs.nginx.com/nginx-app-protect-waf
Additional Resources:
Webpage: NGINX App Protect WAF
⬢ bit.ly/41IEYtc
Datasheet: NGINX App Protect WAF
⬢ bit.ly/40sebzX
Blog: Automate Security with NGINX App Protect WAF to Reduce the Cost of Breaches
⬢ nginx.com/blog/automate-security-f5-nginx-app-protect-f5-nginx-plus-to-reduce-cost-of-breaches
Free Trial: Test Drive NGINX App Protect WAF for 30 Days
⬢ bit.ly/3Ad9WOk
In this demo, we review the out of the box default policy provided by NGINX App Protect WAF as the starting point for your application security. We discuss the supported security features and provide guidance on what to consider prior to tuning your policy.
NGINX App Protect WAF’s policy is a JSON file that allows you to attach a JSON schema file or OpenAPI file that describes your apps or APIs to the JSON policy to help you easily and quickly create a detailed policy without having to build out all the individual positive security rules. Additionally, it works well with security automation tools providing consistency in functionality and assurance of security efficacy once your application goes into production.
docs.nginx.com/nginx-app-protect-waf
Additional Resources:
Webpage: NGINX App Protect WAF
⬢ bit.ly/41IEYtc
Datasheet: NGINX App Protect WAF
⬢ bit.ly/40sebzX
Blog: Automate Security with NGINX App Protect WAF to Reduce the Cost of Breaches
⬢ nginx.com/blog/automate-security-f5-nginx-app-protect-f5-nginx-plus-to-reduce-cost-of-breaches
Free Trial: Test Drive NGINX App Protect WAF for 30 Days
⬢ bit.ly/3Ad9WOk
Visibility into introspection queries enables NGINX App Protect WAF to block them, as well as block detected patterns in responses. This method helps to detect attacks and run signatures in the appropriate segments of a payload, and by doing so, helps to reduce false positives. Watch this demo to learn how NGINX App Protect WAF provides protection for GraphQL APIs.
Learn more at docs.nginx.com
Additional Resources:
Blog: Secure Your API Gateway with NGINX App Protect WAF
⬢ bit.ly/41rSKjZ
Webpage: NGINX App Protect WAF
⬢ bit.ly/41IEYtc
Datasheet: NGINX App Protect WAF
⬢ bit.ly/40sebzX
eBook: Modern App and API Security
⬢ bit.ly/3UMu2s5
eBook: Mastering API Architecture from O’Reilly
⬢ bit.ly/3KPHYx0
Free Trial: Test Drive NGINX App Protect WAF for 30 Days
⬢ bit.ly/3Ad9WOk
Chapters:
00:00:00 Introduction
00:05:30 What is the Engine Room?
00:07:07 How do your pronounce NGINX?
00:12:30 The appeal of NGINX and NGINX Swag
00:16:50 The history of NGINX
00:34:30 Join the NGINX Community Slack
00:37:43 What are some NGINX enterprise use cases?
00:52:41 What are the NGINX Developer Tools?
01:24:04 XKCD A webcomic of Romance, Sarcasm, Math and Language
01:28:07 How to Install NGINX
02:02:44 Let's talk about future episodes of the Engine Room
Challenge 1: Hard code secrets in your app
Challenge 2: Pass secrets as environment variables
Challenge 3: Use local secrets
Challenge 4: Use a secrets manager
Although this tutorial uses a JWT as a sample secret, the techniques apply to anything for containers that you need be kept secret, such as database credentials, SSL private keys, and other API keys.
Watch the second webinar Microservices Secrets Management 101
youtu.be/CiW61FXgIpM
Join this session to learn:
• About the three classes of observability data
• The importance of infrastructure and app alignment
• Ways to start getting deep data from your apps
Read the blog How to Use OpenTelemetry Tracing to Understand Your Microservices
bit.ly/4102voL
Watch the demo How to Use GitHub Actions to Automate Microservices Canary Deployments
youtu.be/lj5T9lO5KBs
Join this session to learn:
• The principles of secret management
• How to store secrets securely
• How to distribute secrets into container runtimes
• Why it's important to rotate secrets
Read the blog How to Securely Manage Secrets in Containers
bit.ly/3ldae3W
Watch the demo How to Securely Manage Secrets in Containers
youtu.be/5NUAsTw_wSA
• Set up basic OTel instrumentation
• Set up OTel instrumentation and trace visualization for all services
• Learn to read OTel traces
• Optimize instrumentation based on trace readings
Learn more at Microservices March 2023
bit.ly/3YVHnzn
⬢ Understand three types of microservices configuration
⬢ Create deployment scripts for a service
⬢ Expose a service to the outside world
⬢ Migrate a database using a service as a “job runner”
The demo uses four technologies:
⬢ Messenger – A simple chat API with message storage capabilities, created for this lab
⬢ NGINX Open Source – An entry point to the messenger service and the wider system at large
⬢ Consul – A dynamic service registry and key-value store
⬢ RabbitMQ – A popular open source message broker that provides a way for services to communicate asynchronously
Learn more at Microservices March 2023
bit.ly/3YVHnzn
Join this session to learn:
• How to use GitHub Actions to streamline your processes
• About managing security
• Why automation simplifies quick recovery from failures
Read the blog How to Use GitHub Actions to Automate Microservices Canary Deployments
bit.ly/40KNJTu
Watch the demo How to Use GitHub Actions to Automate Microservices Canary Deployments
youtu.be/lj5T9lO5KBs
Challenge 1: Deploy the initial container app
Challenge 2: Create an Azure Managed Identity
Challenge 3: Create GitHub Actions
Challenge 4: Test successful and unsuccessful deployments
This lab uses GitHub and Microsoft Azure, but the principles of automating and testing deployments based on changes in source control can be applied to many different scenarios.
Learn more at Microservices March 2023
bit.ly/3YVHnzn
Join this session to learn:
• Which of the Twelve Factors need extra attention in microservices
• How the confluence of team organization and microservices affects your decision making
• How GitOps has changed how we think about configuration
Read the blog How to Deploy and Configure Microservices
bit.ly/3Yswjc8
Watch the demo How to Deploy and Configure Microservices
youtu.be/S3FBQYOsAbw
Read the blog Best Practices for Configuring Microservices Apps
bit.ly/3JrlLWq
This API security solution provides Platform Ops teams with global visibility and control for securing your API platform and empowers developer teams to publish and manage their APIs with the agility and autonomy they need. Learn how NGINX Management Suite API Connectivity Manager allows you to deliver APIs using a NGINX Plus API gateway in a Kubernetes environment combined with F5 NGINX App Protect WAF and DoS to secure REST APIs.
Secure API Connectivity Solution Brief
bit.ly/3zq9P1a
F5 NGINX Management Suite API Connectivity Manager Product Datasheet
bit.ly/42Rg9MS
F5 NGINX Plus API Gateway
bit.ly/4174oAr
F5 NGINX Management Suite API Connectivity Manager
bit.ly/3FHoO9L
Manage and Scale Billions of API Calls
bit.ly/40RBfJl
NGINX Management Suite API Connectivity Manager documentation
bit.ly/3Xu9wNp
Test Drive the NGINX Management Suite API Connectivity Manager today with a 30-day FREE Trial
bit.ly/3Kkxvuh
Platform Ops, Development and IT Security teams can learn how to implement this Zero Trust solution by using the NGINX API gateway to deliver authentication and authorization, NGINX Service Mesh and policies for traffic steering, the NGINX Management Suite API Connectivity Manager to configure the NGINX API gateway on Kubernetes and the use of an ELK stack for security visibility of NGINX App Protect WAF.
Zero Trust Security for Kubernetes Apps Solution Brief
bit.ly/3LJzXvn
Zero Trust Security for Kubernetes Applications
bit.ly/3yZPzne
Zero Trust Architectures in Kubernetes O'Reilly eBook
bit.ly/3Z9reFS
Secure Kubernetes Connectivity
bit.ly/407CxzR
· How NGINXaaS for Azure works
· The steps to get load balancing up-and-running on Azure and how to monitor your traffic
· The time-saving convenience and significant power that NGINXaaS for Azure offers to application developers
Tightly integrated with the Microsoft Azure public cloud and its ecosystem, NGINXaaS for Azure is a fully-managed service that makes applications fast, efficient, and reliable with full lifecycle management of advanced NGINX traffic services.
If you want to give NGINXaaS for Azure a try, visit the Azure Marketplace
bit.ly/3YVALB3
NGINXaaS for Azure
bit.ly/3YZgFGd
NGINXaaS for Azure
bit.ly/3XY3LqD
With platform-agnostic NGINX App Protect WAF, you can easily shift left and automate security into the CI/CD pipeline.
Watch the Full Webinar: Easily View, Manage, and Scale Your App Security with F5 NGINX
⬡ http://bit.ly/3yP7NYu
Free Trial: NGINX App Protect WAF
⬡ http://bit.ly/3Tr8Ffg
bit.ly/3YVHnzn
Don't miss Microservices March 2023! Join us as we explore the time-tested 12 Factor app guidance and its relevance in modern microservice architectures. Register now to learn about flexible configuration, increased ownership for delivery teams and more!
Microservices March 2023 is a free educational program that addresses some of the key fundamentals of delivering microservices. The entire curriculum is eight hours of activities spread out over four weeks. Do it all or pick just the parts that interest you.
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
Unit 2: Microservices Secrets Management 101
Unit 3: Accelerate Microservices Deployments with Automation
Unit 4: Manage Microservices Chaos and Complexity with Observability
Get an Official Badge!
Show your network (and manager) what you learned! For the first time, we’re offering a badge when you complete the webinars and labs.
Badge requirements:
- Attend four webinars (live or on-demand), Complete four hands-on labs
Extras to support your education:
- Blog tutorials to take your skills to the next level Access to NGINX experts via our Slack community
Download the whitepaper today:
bit.ly/3EKCLV3
bit.ly/3YVHnzn
Microservices architectures can create some really cool apps, but they also create complexity challenges with loosely coupled communications. Cloud environments, add even more chaos to this elastic and ephemeral behavior. Problems may not be exactly repeatable. Monitoring for monolithic apps may not work as we need to track our requests through our system. Fortunately, observability with its classes of data such as metrics, traces and logs, are here to help us out. In fact, that tracking of request through our applications and our systems is crucial to help us understand the happiness of our users as well as the well-being of our systems. During Microservices this march, we'll take a look into the details of observability data, how we could start using it, and what you might need to know in order to find out what you are looking for.
Microservices March 2023 is a free educational program that addresses some of the key fundamentals of delivering microservices. The entire curriculum is eight hours of activities spread out over four weeks. Do it all or pick just the parts that interest you.
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
Unit 2: Microservices Secrets Management 101
Unit 3: Accelerate Microservices Deployments with Automation
Unit 4: Manage Microservices Chaos and Complexity with Observability
Get an Official Badge!
Show your network (and manager) what you learned! For the first time, we’re offering a badge when you complete the webinars and labs.
Badge requirements:
- Attend four webinars (live or on-demand), Complete four hands-on labs
Extras to support your education:
- Blog tutorials to take your skills to the next level Access to NGINX experts via our Slack community
You can find the topics we covered the last series here:
bit.ly/3RPSvuU
Register today:
bit.ly/3YTGNlM
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
Unit 2: Microservices Secrets Management 101
Unit 3: Accelerate Microservices Deployments with Automation
Unit 4: Manage Microservices Chaos and Complexity with Observability
Get an Official Badge!
Show your network (and manager) what you learned! For the first time, we’re offering a badge when you complete the webinars and labs.
Badge requirements:
- Attend four webinars (live or on-demand), Complete four hands-on labs
Extras to support your education:
- Blog tutorials to take your skills to the next level Access to NGINX experts via our Slack community
Resources:
NGINX Unit
unit.nginx.org
What is NGINX Unit?
bit.ly/3wInuPM
Real World Use Cases and Success Stories Using NGINX Unit
youtu.be/0dPEuvX6mbY
What's New with NGINX Unit?
youtu.be/VRHcok0mf4U
We've developed a whole course covering all of the ins and outs of NGINX Unit, how to install it, exploring the configuration api, writing your first hello world, web-server configuration, intro into unit languages modules and so much more.
Chapters:
0:00 - How to Install NGINX Unit on Windows Subsystem for Linux
0:26 - Step-by-Step Installation Demo
2:40 - Use Repo Installation Script
5:53 - Check Binary with "unitd" and Grep for Unit
7:17 - Start Unit in Unprivileged Mode
9:38 - Curl Unit API to See if Up and Running
10:46 - Future Chapters in NGINX Unit Video Series
Resources:
NGINX Unit
unit.nginx.org
What is NGINX Unit?
bit.ly/3wInuPM
Real World Use Cases and Success Stories Using NGINX Unit
youtu.be/0dPEuvX6mbY
What's New with NGINX Unit?
youtu.be/VRHcok0mf4U
NGINX Unit is a universal web app server – intended as a building block for any web architecture regardless of its complexity, from enterprise-scale deployments to your pet's home page. It is equally suited to simplifying modern microservices environments as it is to modernizing legacy and monolithic applications.
We've developed a whole course covering all of the ins and outs of NGINX Unit, how to install it, exploring the configuration api, writing your first hello world, web-server configuration, intro into unit languages modules and so much more.
Chapters:
0:00 - How to Install NGINX Unit using Homebrew on MacOS
0:40 - What is Homebrew?
1:27 - Homebrew on MacOS Step-by-Step Demo
5:11 - Check Installation
6:31 - Start "unitd" and Additional Steps
8:48 - Check that Unit Instance is Successful
9:38 - Operating System Comparisons
10:30 - Future Topics in NGINX Unit Video Series
Official NGINX Documentation:
bit.ly/3Xu9wNp
Start a 30-day free trial of F5 NGINX Management Suite API Connectivity Manager:
bit.ly/3HjFMNM
Official NGINX Documentation:
bit.ly/3Xu9wNp
Start a 30-day free trial of F5 NGINX Management Suite API Connectivity Manager:
bit.ly/3HjFMNM


