Lộ trình đang học Current learning path Current learning path

AI Security & Adoption AI Security & Adoption AI Security & Adoption

Quản trị Shadow AI, bảo vệ data và ship AI app có kiểm soát. Govern Shadow AI, protect data, and ship controlled AI applications. Govern Shadow AI, protect data, and ship controlled AI applications.

Về trang lộ trình Track home Track home

AI Security & Adoption AI Security & Adoption AI Security & Adoption

Adopt AI an toàn từ user đến ứng dụng Adopt AI safely from users to applications Adopt AI safely from users to applications

Lộ trình riêng cho AI adoption kết hợp SASE controls (CASB, SWG, RBI, DLP) với AI Gateway, WAF và agent/RAG security. A dedicated AI-adoption path combining SASE controls (CASB, SWG, RBI, DLP) with AI Gateway, WAF, and agent/RAG security. A dedicated AI-adoption path combining SASE controls (CASB, SWG, RBI, DLP) with AI Gateway, WAF, and agent/RAG security.

Ai nên học lộ trình này? Who is this for? Who is this for?

Security, IT, platform và application teams cùng triển khai AI. Security, IT, platform, and application teams rolling out AI together. Security, IT, platform, and application teams rolling out AI together.

Mô hình tư duy Mental model Mental model

User/device → Zero Trust policy → sanctioned AI → AI Gateway/app controls → model/tool/data. User/device → Zero Trust policy → sanctioned AI → AI Gateway/app controls → model/tool/data. User/device → Zero Trust policy → sanctioned AI → AI Gateway/app controls → model/tool/data.

Sơ đồ kiến trúc tham chiếu Reference architecture diagrams Reference architecture diagrams

Kiến trúc AI đa nhà cung cấp

Quan sát và kiểm soát AI đa nhà cung cấp Multi-vendor AI observability and control Multi-vendor AI observability and control

Đưa rate limiting, cache và xử lý lỗi lên lớp proxy để áp cấu hình thống nhất cho nhiều dịch vụ và nhà cung cấp inference. By shifting features such as rate limiting, caching, and error handling to the proxy layer, organizations can apply unified configurations across services and inference service providers. By shifting features such as rate limiting, caching, and error handling to the proxy layer, organizations can apply unified configurations across services and inference service providers.

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · AI Artificial Intelligence (AI) Artificial Intelligence (AI)

Hình 1: Chỉ traffic đã qua mạng Cloudflare và policy liên quan mới được phép vào ứng dụng SaaS.

Truy cập SaaS an toàn với SASE Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Hình 1: Nạp tri thức (knowledge seeding)

Retrieval Augmented Generation (RAG) Retrieval Augmented Generation (RAG) Retrieval Augmented Generation (RAG)

RAG kết hợp retrieval (Vectorize/KV) với Workers AI để chatbot trả lời chính xác hơn — seeding knowledge và query path tách biệt. RAG combines retrieval with generative models for better text. It uses external knowledge to create factual, relevant responses, improving coherence and accuracy in NLP tasks like chatbots. RAG combines retrieval with generative models for better text. It uses external knowledge to create factual, relevant responses, improving coherence and accuracy in NLP tasks like chatbots.

Thuật ngữ: Concepts: Concepts: RAG · Vectorize · Workers AI · Knowledge seeding · Embeddings

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · AI Artificial Intelligence (AI) Artificial Intelligence (AI)

Sau lộ trình bạn sẽ What you will achieve អ្វីដែលអ្នកនឹងសម្រេច

  • Inventory Shadow AI và policy theo risk Inventory Shadow AI and policy by risk Inventory Shadow AI and policy by risk
  • Áp SWG/RBI/CASB/DLP cho AI SaaS Apply SWG/RBI/CASB/DLP to AI SaaS Apply SWG/RBI/CASB/DLP to AI SaaS
  • Bảo vệ AI app với Gateway, WAF và bot controls Protect AI apps with Gateway, WAF, and bot controls Protect AI apps with Gateway, WAF, and bot controls
  • Thiết kế RAG/agent có authorization rõ ràng Design RAG/agents with clear authorization Design RAG/agents with clear authorization

Khái niệm cần nắm Key concepts គោលគំនិតសំខាន់

  • Shadow AI
  • CASB
  • SWG
  • RBI
  • DLP
  • AI Gateway
  • Firewall for AI
  • RAG
  • Agents

Nội dung từng phần Module-by-module content ខ្លឹមសារតាមផ្នែក

2 bài 2 lessons 2 មេរៀន

Phần 1: Quản trị AI doanh nghiệp Part 1: Enterprise AI governance Part 1: Enterprise AI governance

Visibility, policy và SaaS controls. Visibility, policy, and SaaS controls. Visibility, policy, and SaaS controls.

  1. 1

    CASB: Shadow AI và posture CASB: Shadow AI and posture CASB: Shadow AI and posture

    Inventory AI SaaS, review token/user findings và remediation theo data sensitivity. Inventory AI SaaS, review token/user findings, and remediate by data sensitivity. Inventory AI SaaS, review token/user findings, and remediate by data sensitivity.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →
  2. 2

    SWG và RBI cho web AI SWG and RBI for web AI SWG and RBI for web AI

    Discover, allow/block/steer AI destinations; isolate browsing/upload risk cao. Discover, allow/block/steer AI destinations; isolate high-risk browsing/uploads. Discover, allow/block/steer AI destinations; isolate high-risk browsing/uploads.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →
2 bài 2 lessons 2 មេរៀន

Phần 2: AI application controls Part 2: AI application controls Part 2: AI application controls

Gateway, WAF và security baseline. Gateway, WAF, and the security baseline. Gateway, WAF, and the security baseline.

  1. 1

    AI Gateway: routing và audit AI Gateway: routing and audit AI Gateway: routing and audit

    Route provider, observe usage và apply guardrails mà không đưa credential ra client. Route providers, observe usage, and apply guardrails without exposing credentials to clients. Route providers, observe usage, and apply guardrails without exposing credentials to clients.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →
  2. 2

    WAF, bots và prompt protection WAF, bots, and prompt protection WAF, bots, and prompt protection

    Treat model output as untrusted; validate tools, rate limit endpoint và apply Firewall for AI policies. Treat model output as untrusted; validate tools, rate-limit endpoints, and apply Firewall for AI policies. Treat model output as untrusted; validate tools, rate-limit endpoints, and apply Firewall for AI policies.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →
2 bài 2 lessons 2 មេរៀន

Phần 3: Build AI có trách nhiệm Part 3: Build AI responsibly Part 3: Build AI responsibly

RAG và agent với data/tool boundaries. RAG and agents with data/tool boundaries. RAG and agents with data/tool boundaries.

  1. 1

    RAG với Vectorize và access scope RAG with Vectorize and access scope RAG with Vectorize and access scope

    Authorize trước retrieval; metadata ACL và source citation không phải optional. Authorize before retrieval; ACL metadata and source citation are not optional. Authorize before retrieval; ACL metadata and source citation are not optional.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →
  2. 2

    Agents, tools và least privilege Agents, tools, and least privilege Agents, tools, and least privilege

    Tool nhỏ, typed, auditable; model không được tự cấp quyền hay secret. Tools should be small, typed, and auditable; a model must not grant itself access or secrets. Tools should be small, typed, and auditable; a model must not grant itself access or secrets.

    Hướng dẫn chi tiết → Detailed guide → មគ្គុទេសក៍លម្អិត →

Trình tự học gợi ý Suggested learning order លំដាប់សិក្សាណែនាំ

  1. Inventory Shadow AI Inventory Shadow AI Inventory Shadow AI
  2. Pilot Access/SWG Pilot Access/SWG Pilot Access/SWG
  3. Add CASB/DLP Add CASB/DLP Add CASB/DLP
  4. Govern app-owned AI with Gateway/WAF Govern app-owned AI with Gateway/WAF Govern app-owned AI with Gateway/WAF
  5. Build RAG/agents with scoped tools Build RAG/agents with scoped tools Build RAG/agents with scoped tools

Tình huống trong lộ trình Use cases for this path ករណីប្រើប្រាស់សម្រាប់ផ្លូវនេះ

Ví dụ triển khai (trong lộ trình này) Deployment examples (this path only) Deployment examples (this path only)

Tutorial và guide từ Cloudflare Resources — chỉ hiển thị nội dung phù hợp lộ trình AI Security & Adoption. Mỗi bài học gợi ý 4 ví dụ riêng. Tutorials and guides from Cloudflare Resources — only content matched to the AI Security & Adoption path. Each lesson suggests four examples. Tutorials and guides from Cloudflare Resources — only content matched to the AI Security & Adoption path. Each lesson suggests four examples.

0 / 244

Không có kết quả — thử bộ lọc khác.No results — try different filters.No results — try different filters.

Tài liệu mở rộng (tùy chọn) Optional extended reading Optional extended reading Mở Expand Expand GitHub, Reference Architecture, CloudSecOp, demo script — không bắt buộc. Lab guided nằm phía trên (Developer Labs). GitHub, Reference Architecture, CloudSecOp, demo scripts — not required. Guided labs sit above (Developer Labs). GitHub, Reference Architecture, CloudSecOp, demo scripts — not required. Guided labs sit above (Developer Labs).

Tài nguyên chính thức (Resource Hub) Official resources (Resource Hub) Official resources (Resource Hub)

Liên kết từ Cloudflare Resource Hub — docs, community, case studies phù hợp track này. Links from the Cloudflare Resource Hub — docs, community, and case studies for this track. Links from the Cloudflare Resource Hub — docs, community, and case studies for this track.

Học & tài liệu Learn & docs Learn & docs Gợi ý Recommended Recommended

Developer Documentation Developer Documentation Developer Documentation

Tài liệu sản phẩm, tutorial và ví dụ cho mọi dịch vụ Cloudflare. Product docs, tutorials, and examples for every Cloudflare service. Product docs, tutorials, and examples for every Cloudflare service.

Mở trên Cloudflare Open on Cloudflare Open on Cloudflare
Học & tài liệu Learn & docs Learn & docs Trong hub In this hub In this hub Gợi ý Recommended Recommended

Reference Architectures Reference Architectures Reference Architectures

Pattern kiến trúc và best practices — SASE, CDN, Workers, Zero Trust. Architecture patterns and best practices — SASE, CDN, Workers, Zero Trust. Architecture patterns and best practices — SASE, CDN, Workers, Zero Trust.

Xem trong hub View in hub View in hub
Cộng đồng & cập nhật Community & updates Community & updates Trong hub In this hub In this hub Gợi ý Recommended Recommended

Developer Changelog Developer Changelog Developer Changelog

Cập nhật sản phẩm theo ngày — Agents, Workers, Cloudflare One, R2, security. Hub có bản tóm tắt chọn lọc. Daily product updates — Agents, Workers, Cloudflare One, R2, security. This hub includes a curated summary. Daily product updates — Agents, Workers, Cloudflare One, R2, security. This hub includes a curated summary.

Xem trong hub View in hub View in hub
Cộng đồng & cập nhật Community & updates Community & updates

Cloudflare Blog Cloudflare Blog Cloudflare Blog

Cập nhật sản phẩm, launch và bài kỹ thuật sâu. Product updates, launches, and technical deep dives. Product updates, launches, and technical deep dives.

Mở trên Cloudflare Open on Cloudflare Open on Cloudflare

Đọc thêm — kinh nghiệm thực tế (CloudSecOp) Further reading — field notes (CloudSecOp) Further reading — field notes (CloudSecOp)

Bài viết từ cloudsecop.net — bổ sung lộ trình hub với context triển khai production, không thay tài liệu chính thức Cloudflare. Posts from cloudsecop.net — complement this track with production deployment context; not a replacement for official Cloudflare docs. Posts from cloudsecop.net — complement this track with production deployment context; not a replacement for official Cloudflare docs.

7 phút đọc 7 min read 7 min read

lol-html: streaming HTML rewriter trên Workers — 3 production patterns lol-html streaming HTML rewriter on Workers lol-html streaming HTML rewriter on Workers

CSP nonce per request, rewrite analytics URL, A/B inject tại edge. Per-request CSP nonce, analytics URL rewrite, A/B inject at the edge. Per-request CSP nonce, analytics URL rewrite, A/B inject at the edge.

  • Workers
  • HTML
Đọc trên CloudSecOp Read on CloudSecOp Read on CloudSecOp
9 phút đọc 9 min read 9 min read

Pingora vs AWS ALB/NLB Pingora vs AWS ALB/NLB Pingora vs AWS ALB/NLB

Khi nào self-host reverse proxy bằng pingora-core thắng ALB managed. When self-hosted pingora-core beats managed ALB. When self-hosted pingora-core beats managed ALB.

  • Pingora
Đọc trên CloudSecOp Read on CloudSecOp Read on CloudSecOp
Phần 18 Part 18 Part 18 8 phút đọc 8 min read 8 min read

Security cho Worker: secrets, CSP, Bot Management, Turnstile Worker security: secrets, CSP, Bot Management, Turnstile Worker security: secrets, CSP, Bot Management, Turnstile

Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-pattern. Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-patterns. Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-patterns.

  • security
  • Turnstile
Đọc trên CloudSecOp Read on CloudSecOp Read on CloudSecOp
Phần 17 Part 17 Part 17 9 phút đọc 9 min read 9 min read

Observability cho Worker: Logs, Tail Workers, Analytics Worker observability: Logs, Tail Workers, Analytics Worker observability: Logs, Tail Workers, Analytics

4 tầng: Workers Logs, Tail, Logpush, Analytics Engine — debug production. Four layers: Workers Logs, Tail, Logpush, Analytics Engine — production debugging. Four layers: Workers Logs, Tail, Logpush, Analytics Engine — production debugging.

  • observability
Đọc trên CloudSecOp Read on CloudSecOp Read on CloudSecOp

Bước tiếp theo Next step Next step

Áp dụng ngay qua tình huống thực tế và checklist. Apply what you learned via a use case and checklist. Apply what you learned via a use case and checklist.

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Application Services Application Services Application Services

Follow-along: DNS → proxy → SSL → WAF → cache — rồi mới rẽ API Shield hoặc Load Balancing Follow-along: DNS → proxy → SSL → WAF → cache — then branch to API Shield or Load Balancing Follow-along: DNS → proxy → SSL → WAF → cache — បន្ទាប់មកទើបបែកផ្លូវទៅ API Shield ឬ Load Balancing

Vào lộ trình này → Enter this path → Enter this path →

Developer Platform Developer Platform Developer Platform

Follow-along Worker-first: C3 + Wrangler, rồi storage, Pages (compat), operate và AI Follow-along Worker-first: C3 + Wrangler, then storage, Pages (compat), operate, and AI Follow-along Worker-first: C3 + Wrangler បន្ទាប់មក storage, Pages (compat), operate និង AI

Vào lộ trình này → Enter this path → Enter this path →

Cloudflare One Cloudflare One Cloudflare One

Triển khai Zero Trust theo từng mô-đun: identity, thiết bị, ZTNA, Gateway, DLP, AI và Cloudflare WAN Deploy Zero Trust module by module: identity, devices, ZTNA, Gateway, DLP, AI, and Cloudflare WAN Deploy Zero Trust module by module: identity, devices, ZTNA, Gateway, DLP, AI, and Cloudflare WAN

Vào lộ trình này → Enter this path → Enter this path →

Operational Excellence Operational Excellence Operational Excellence

Vận hành Cloudflare an toàn, ổn định và hiệu quả Operate Cloudflare safely, reliably, and efficiently Operate Cloudflare safely, reliably, and efficiently

Vào lộ trình này → Enter this path → Enter this path →

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths