Lộ trình đang học Current learning path

AI Security & Adoption AI Security & Adoption

Quản trị Shadow AI, bảo vệ data và ship AI app có kiểm soát. Govern Shadow AI, protect data, and ship controlled AI applications.

Về trang lộ trình Track home

AI Security & Adoption AI Security & Adoption

Adopt AI an toàn từ user đến ứng dụng Adopt AI safely from users to applications

Lộ trình riêng cho AI adoption kết hợp SASE controls (CASB, SWG, RBI, DLP) với AI Gateway, WAF và agent/RAG security. A dedicated AI-adoption path combining SASE controls (CASB, SWG, RBI, DLP) with AI Gateway, WAF, and agent/RAG security.

Ai nên học lộ trình này? Who is this for?

Security, IT, platform và application teams cùng triển khai AI. Security, IT, platform, and application teams rolling out AI together.

Mô hình tư duy Mental model

User/device → Zero Trust policy → sanctioned AI → AI Gateway/app controls → model/tool/data. User/device → Zero Trust policy → sanctioned AI → AI Gateway/app controls → model/tool/data.

Sơ đồ kiến trúc tham chiếu Reference architecture diagrams

Multi-vendor AI architecture

Multi-vendor AI observability and control Multi-vendor AI observability and control

By shifting features such as rate limiting, caching, and error handling to the proxy layer, organizations can apply unified configurations across services and inference service providers. By shifting features such as rate limiting, caching, and error handling to the proxy layer, organizations can apply unified configurations across services and inference service providers.

Sơ đồ chính thức ↗ Official diagram ↗ · AI Artificial Intelligence (AI)

Figure 1: Only traffic that has passed the Cloudflare network and relevant policies is authorized to access the SaaS application.

Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE)

Figure 1: Knowledge seeding

Retrieval Augmented Generation (RAG) Retrieval Augmented Generation (RAG)

RAG kết hợp retrieval (Vectorize/KV) với Workers AI để chatbot trả lời chính xác hơn — seeding knowledge và query path tách biệt. RAG combines retrieval with generative models for better text. It uses external knowledge to create factual, relevant responses, improving coherence and accuracy in NLP tasks like chatbots.

Thuật ngữ: Concepts: RAG · Vectorize · Workers AI · Knowledge seeding · Embeddings

Sơ đồ chính thức ↗ Official diagram ↗ · AI Artificial Intelligence (AI)

Sau lộ trình bạn sẽ What you will achieve

  • Inventory Shadow AI và policy theo risk Inventory Shadow AI and policy by risk
  • Áp SWG/RBI/CASB/DLP cho AI SaaS Apply SWG/RBI/CASB/DLP to AI SaaS
  • Bảo vệ AI app với Gateway, WAF và bot controls Protect AI apps with Gateway, WAF, and bot controls
  • Thiết kế RAG/agent có authorization rõ ràng Design RAG/agents with clear authorization

Khái niệm cần nắm Key concepts

  • Shadow AI
  • CASB
  • SWG
  • RBI
  • DLP
  • AI Gateway
  • Firewall for AI
  • RAG
  • Agents

Nội dung từng phần Module-by-module content

2 bài 2 lessons

Phần 1: Quản trị AI doanh nghiệp Part 1: Enterprise AI governance

Visibility, policy và SaaS controls. Visibility, policy, and SaaS controls.

  1. 1

    CASB: Shadow AI và posture CASB: Shadow AI and posture

    Inventory AI SaaS, review token/user findings và remediation theo data sensitivity. Inventory AI SaaS, review token/user findings, and remediate by data sensitivity.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    SWG và RBI cho web AI SWG and RBI for web AI

    Discover, allow/block/steer AI destinations; isolate browsing/upload risk cao. Discover, allow/block/steer AI destinations; isolate high-risk browsing/uploads.

    Hướng dẫn chi tiết → Detailed guide →
2 bài 2 lessons

Phần 2: AI application controls Part 2: AI application controls

Gateway, WAF và security baseline. Gateway, WAF, and the security baseline.

  1. 1

    AI Gateway: routing và audit AI Gateway: routing and audit

    Route provider, observe usage và apply guardrails mà không đưa credential ra client. Route providers, observe usage, and apply guardrails without exposing credentials to clients.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    WAF, bots và prompt protection WAF, bots, and prompt protection

    Treat model output as untrusted; validate tools, rate limit endpoint và apply Firewall for AI policies. Treat model output as untrusted; validate tools, rate-limit endpoints, and apply Firewall for AI policies.

    Hướng dẫn chi tiết → Detailed guide →
2 bài 2 lessons

Phần 3: Build AI có trách nhiệm Part 3: Build AI responsibly

RAG và agent với data/tool boundaries. RAG and agents with data/tool boundaries.

  1. 1

    RAG với Vectorize và access scope RAG with Vectorize and access scope

    Authorize trước retrieval; metadata ACL và source citation không phải optional. Authorize before retrieval; ACL metadata and source citation are not optional.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    Agents, tools và least privilege Agents, tools, and least privilege

    Tool nhỏ, typed, auditable; model không được tự cấp quyền hay secret. Tools should be small, typed, and auditable; a model must not grant itself access or secrets.

    Hướng dẫn chi tiết → Detailed guide →

Trình tự học gợi ý Suggested learning order

  1. Inventory Shadow AI Inventory Shadow AI
  2. Pilot Access/SWG Pilot Access/SWG
  3. Add CASB/DLP Add CASB/DLP
  4. Govern app-owned AI with Gateway/WAF Govern app-owned AI with Gateway/WAF
  5. Build RAG/agents with scoped tools Build RAG/agents with scoped tools

Tình huống trong lộ trình Use cases for this path

Ví dụ triển khai (trong lộ trình này) Deployment examples (this path only)

Tutorial và guide từ Cloudflare Resources — chỉ hiển thị nội dung phù hợp lộ trình AI Security & Adoption. Mỗi bài học gợi ý 4 ví dụ riêng. Tutorials and guides from Cloudflare Resources — only content matched to the AI Security & Adoption path. Each lesson suggests four examples.

0 / 244

Không có kết quả — thử bộ lọc khác.No results — try different filters.

Tài liệu mở rộng (tùy chọn) Optional extended reading Mở Expand GitHub, Reference Architecture, CloudSecOp, demo script — không bắt buộc để hoàn thành lộ trình. GitHub, Reference Architecture, CloudSecOp, demo scripts — not required to complete this path.

Tài nguyên chính thức (Resource Hub) Official resources (Resource Hub)

Liên kết từ Cloudflare Resource Hub — docs, community, case studies phù hợp track này. Links from the Cloudflare Resource Hub — docs, community, and case studies for this track.

Học & tài liệu Learn & docs Gợi ý Recommended

Developer Documentation Developer Documentation

Tài liệu sản phẩm, tutorial và ví dụ cho mọi dịch vụ Cloudflare. Product docs, tutorials, and examples for every Cloudflare service.

Mở trên Cloudflare Open on Cloudflare
Học & tài liệu Learn & docs Trong hub In this hub Gợi ý Recommended

Reference Architectures Reference Architectures

Pattern kiến trúc và best practices — SASE, CDN, Workers, Zero Trust. Architecture patterns and best practices — SASE, CDN, Workers, Zero Trust.

Xem trong hub View in hub
Cộng đồng & cập nhật Community & updates Trong hub In this hub Gợi ý Recommended

Developer Changelog Developer Changelog

Cập nhật sản phẩm theo ngày — Agents, Workers, Cloudflare One, R2, security. Hub có bản tóm tắt chọn lọc. Daily product updates — Agents, Workers, Cloudflare One, R2, security. This hub includes a curated summary.

Xem trong hub View in hub
Cộng đồng & cập nhật Community & updates

Cloudflare Blog Cloudflare Blog

Cập nhật sản phẩm, launch và bài kỹ thuật sâu. Product updates, launches, and technical deep dives.

Mở trên Cloudflare Open on Cloudflare

Đọc thêm — kinh nghiệm thực tế (CloudSecOp) Further reading — field notes (CloudSecOp)

Bài viết từ cloudsecop.net — bổ sung lộ trình hub với context triển khai production, không thay tài liệu chính thức Cloudflare. Posts from cloudsecop.net — complement this track with production deployment context; not a replacement for official Cloudflare docs.

7 phút đọc 7 min read

lol-html: streaming HTML rewriter trên Workers — 3 production patterns lol-html streaming HTML rewriter on Workers

CSP nonce per request, rewrite analytics URL, A/B inject tại edge. Per-request CSP nonce, analytics URL rewrite, A/B inject at the edge.

  • Workers
  • HTML
Đọc trên CloudSecOp Read on CloudSecOp
9 phút đọc 9 min read

Pingora vs AWS ALB/NLB Pingora vs AWS ALB/NLB

Khi nào self-host reverse proxy bằng pingora-core thắng ALB managed. When self-hosted pingora-core beats managed ALB.

  • Pingora
Đọc trên CloudSecOp Read on CloudSecOp
Phần 18 Part 18 8 phút đọc 8 min read

Security cho Worker: secrets, CSP, Bot Management, Turnstile Worker security: secrets, CSP, Bot Management, Turnstile

Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-pattern. Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-patterns.

  • security
  • Turnstile
Đọc trên CloudSecOp Read on CloudSecOp
Phần 17 Part 17 9 phút đọc 9 min read

Observability cho Worker: Logs, Tail Workers, Analytics Worker observability: Logs, Tail Workers, Analytics

4 tầng: Workers Logs, Tail, Logpush, Analytics Engine — debug production. Four layers: Workers Logs, Tail, Logpush, Analytics Engine — production debugging.

  • observability
Đọc trên CloudSecOp Read on CloudSecOp

Bước tiếp theo Next step

Áp dụng ngay qua tình huống thực tế và checklist. Apply what you learned via a use case and checklist.

Học xong hoặc muốn đổi hướng? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths