Lộ trình đang học Current learning path

Operational Excellence Operational Excellence

Biến signals thành quyết định: observe, respond, release, recover và improve. Turn signals into decisions: observe, respond, release, recover, and improve.

Về trang lộ trình Track home

Operational Excellence Operational Excellence

Vận hành Cloudflare an toàn, ổn định và hiệu quả Operate Cloudflare safely, reliably, and efficiently

Lộ trình cross-product cho DevOps, SRE, IT và platform teams: observability, incident response, release safety, resilience, performance và cost. A cross-product path for DevOps, SRE, IT, and platform teams: observability, incident response, release safety, resilience, performance, and cost.

Ai nên học lộ trình này? Who is this for?

DevOps/SRE, IT admin, platform engineer hoặc technical lead đã có workload trên Cloudflare. DevOps/SRE, IT admins, platform engineers, or technical leads with workloads on Cloudflare.

Mô hình tư duy Mental model

Signals → triage → runbook → safe change → verify → learn. Dùng dashboard, logs và status để giảm thời gian phát hiện/phục hồi, không chỉ “xem metric”. Signals → triage → runbook → safe change → verify → learn. Use dashboards, logs, and status to reduce detection/recovery time, not merely to “view metrics”.

Sơ đồ kiến trúc tham chiếu Reference architecture diagrams

Figure 1: Data flow overview

Designing a distributed web performance architecture Designing a distributed web performance architecture

Pattern L7: data flow, cache tiers, deployment models — giảm latency và cải thiện Core Web Vitals. A prescriptive pattern for building a Cloudflare-based L7 performance architecture that reduces latency, raises cache efficiency, and improves Core Web Vitals.

Thuật ngữ: Concepts: CDN · Cache · Core Web Vitals · Smart Shield · Argo

Sơ đồ chính thức ↗ Official diagram ↗ · Content delivery Content Delivery

Figure 1: How Cloudflare identifies, scores and processes traffic from bots.

Bot management Bot management

Luồng phát hiện, chấm điểm và xử lý bot traffic trên edge — nền tảng cho WAF, rate limit và Bot Management. Cloudflare has bot management capabilities to help identify and mitigate automated traffic to protect domains from bad bots.

Thuật ngữ: Concepts: Bot score · Super Bot Fight Mode · WAF · Rate limiting

Sơ đồ chính thức ↗ Official diagram ↗ · Bots Bots

Figure 1:  Traditional single-region architecture

Serverless global APIs Serverless global APIs

An example architecture of a serverless API on Cloudflare and aims to illustrate how different compute and data products could interact with each other. An example architecture of a serverless API on Cloudflare and aims to illustrate how different compute and data products could interact with each other.

Thuật ngữ: Concepts: Workers · D1 · R2 · Global API · Edge compute

Sơ đồ chính thức ↗ Official diagram ↗ · Serverless Serverless

Sau lộ trình bạn sẽ What you will achieve

  • Thiết kế signals và logs hữu ích cho zone, Worker, Zero Trust và AI Design useful signals and logs for zones, Workers, Zero Trust, and AI
  • Triage incident với status, Security Events và runbook Triage incidents with status, Security Events, and runbooks
  • Release có preview, rollback, purge/cache plan và secret hygiene Release with preview, rollback, purge/cache plans, and secret hygiene
  • Lập kế hoạch resilience, performance và cost review định kỳ Plan resilience, performance, and recurring cost reviews

Khái niệm cần nắm Key concepts

  • Observability
  • Logpush
  • Runbooks
  • Rollback
  • Health checks
  • Core Web Vitals
  • SLOs
  • Cost

Nội dung từng phần Module-by-module content

~60 phút ~60 min 4 bài 4 lessons

Phần 1: Observability & logging Part 1: Observability & logging

Signals từ traffic, application, security và AI. Signals from traffic, applications, security, and AI.

  1. 1

    Zone và traffic analytics Zone and traffic analytics

    Chọn baseline cho traffic, cache hit/miss, 4xx/5xx và latency trước khi đặt alert. Establish baselines for traffic, cache hit/miss, 4xx/5xx, and latency before creating alerts.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    Workers/Pages logs và traces Workers/Pages logs and traces

    Dùng structured logs, request ID và traces để nối lỗi user-facing với code path. Use structured logs, request IDs, and traces to connect user-facing errors to code paths.

    Hướng dẫn chi tiết → Detailed guide →
  3. 3

    Security Events và Logpush Security Events and Logpush

    Triage WAF, DDoS và bot events; export log khi cần retention hoặc correlation bên ngoài. Triage WAF, DDoS, and bot events; export logs when you need retention or external correlation.

    Hướng dẫn chi tiết → Detailed guide →
  4. 4

    AI Gateway usage signals AI Gateway usage signals

    Theo dõi model, latency, error và cost signal mà không log prompt nhạy cảm không cần thiết. Track model, latency, error, and cost signals without unnecessarily logging sensitive prompts.

    Hướng dẫn chi tiết → Detailed guide →
~50 phút ~50 min 3 bài 3 lessons

Phần 2: Incident response Part 2: Incident response

Triage có bằng chứng và giao tiếp rõ ràng. Evidence-based triage and clear communication.

  1. 1

    Status và correlation Status and correlation

    Khi error spike, kiểm tra Cloudflare Status cùng metric và deployment timeline trước khi kết luận root cause. When errors spike, check Cloudflare Status alongside metrics and deployment timelines before concluding root cause.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    Triage security incident Triage a security incident

    Phân biệt attack, false positive và app regression; preserve evidence trước khi thay policy. Separate attacks, false positives, and app regressions; preserve evidence before changing policy.

    Hướng dẫn chi tiết → Detailed guide →
  3. 3

    Runbook và stakeholder communication Runbooks and stakeholder communication

    Define owner, severity, update cadence, rollback criteria và post-incident actions trước incident tiếp theo. Define owners, severity, update cadence, rollback criteria, and post-incident actions before the next incident.

    Hướng dẫn chi tiết → Detailed guide →
~45 phút ~45 min 3 bài 3 lessons

Phần 3: Release & deployment safety Part 3: Release & deployment safety

Ship nhanh nhưng reversible. Ship quickly while staying reversible.

  1. 1

    Preview → production → rollback Preview → production → rollback

    Test preview URL, define production checks và giữ rollback path rõ ràng trước release. Test preview URLs, define production checks, and keep a clear rollback path before release.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    Environment, secrets và change control Environments, secrets, and change control

    Tách config theo environment; secret không nằm trong source; log ai thay đổi gì và khi nào. Separate configuration by environment; never place secrets in source; record who changed what and when.

    Hướng dẫn chi tiết → Detailed guide →
  3. 3

    Cache purge và coordinated release Cache purge and coordinated release

    Version asset, purge đúng scope và kiểm tra cache behavior sau frontend/API release. Version assets, purge the right scope, and verify cache behavior after frontend/API releases.

    Hướng dẫn chi tiết → Detailed guide →
~45 phút ~45 min 3 bài 3 lessons

Phần 4: Resilience & availability Part 4: Resilience & availability

Giảm blast radius và phục hồi nhanh. Reduce blast radius and recover quickly.

  1. 1

    Health checks và load balancing Health checks and load balancing

    Định nghĩa health signal có ý nghĩa cho user và test failover trước khi cần dùng. Define health signals meaningful to users and test failover before you need it.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    DDoS và availability patterns DDoS and availability patterns

    Kết hợp proxy, DDoS protection, WAF/rate limit và origin hardening để giữ service available. Combine proxying, DDoS protection, WAF/rate limiting, and origin hardening to keep services available.

    Hướng dẫn chi tiết → Detailed guide →
  3. 3

    Rollout theo wave Wave-based rollout

    Mở rộng policy hoặc Zero Trust deployment theo nhóm nhỏ, feedback loop và rollback plan. Expand policy or Zero Trust deployments through small groups, feedback loops, and rollback plans.

    Hướng dẫn chi tiết → Detailed guide →
~40 phút ~40 min 3 bài 3 lessons

Phần 5: Performance & cost Part 5: Performance & cost

Review liên tục thay vì tối ưu một lần. Continuously review instead of optimizing once.

  1. 1

    Core Web Vitals và cache metrics Core Web Vitals and cache metrics

    Đo LCP/FCP/CLS, hit ratio và origin request để ưu tiên công việc performance. Measure LCP/FCP/CLS, hit ratio, and origin requests to prioritize performance work.

    Hướng dẫn chi tiết → Detailed guide →
  2. 2

    Plan sizing và cost drivers Plan sizing and cost drivers

    Review usage, product limits và cost driver trước khi scale workload hoặc bật add-on. Review usage, product limits, and cost drivers before scaling workloads or enabling add-ons.

    Hướng dẫn chi tiết → Detailed guide →
  3. 3

    Operational review cadence Operational review cadence

    Lập monthly review cho changelog, incidents, policy exceptions, SLO và backlog reliability. Create a monthly review for changelog, incidents, policy exceptions, SLOs, and reliability backlog.

    Hướng dẫn chi tiết → Detailed guide →

Trình tự học gợi ý Suggested learning order

  1. Thiết lập baseline signals Establish baseline signals
  2. Viết runbook cho incident phổ biến Write runbooks for common incidents
  3. Chuẩn hóa preview/release/rollback Standardize preview/release/rollback
  4. Test health/failover Test health/failover
  5. Review performance và cost định kỳ Review performance and cost regularly

Ví dụ triển khai (trong lộ trình này) Deployment examples (this path only)

Tutorial và guide từ Cloudflare Resources — chỉ hiển thị nội dung phù hợp lộ trình Operational Excellence. Mỗi bài học gợi ý 4 ví dụ riêng. Tutorials and guides from Cloudflare Resources — only content matched to the Operational Excellence path. Each lesson suggests four examples.

0 / 244

Không có kết quả — thử bộ lọc khác.No results — try different filters.

Tài liệu mở rộng (tùy chọn) Optional extended reading Mở Expand GitHub, Reference Architecture, CloudSecOp, demo script — không bắt buộc để hoàn thành lộ trình. GitHub, Reference Architecture, CloudSecOp, demo scripts — not required to complete this path.

Tài nguyên chính thức (Resource Hub) Official resources (Resource Hub)

Liên kết từ Cloudflare Resource Hub — docs, community, case studies phù hợp track này. Links from the Cloudflare Resource Hub — docs, community, and case studies for this track.

Học & tài liệu Learn & docs Gợi ý Recommended

Developer Documentation Developer Documentation

Tài liệu sản phẩm, tutorial và ví dụ cho mọi dịch vụ Cloudflare. Product docs, tutorials, and examples for every Cloudflare service.

Mở trên Cloudflare Open on Cloudflare
Học & tài liệu Learn & docs Trong hub In this hub Gợi ý Recommended

Reference Architectures Reference Architectures

Pattern kiến trúc và best practices — SASE, CDN, Workers, Zero Trust. Architecture patterns and best practices — SASE, CDN, Workers, Zero Trust.

Xem trong hub View in hub
Cộng đồng & cập nhật Community & updates Trong hub In this hub Gợi ý Recommended

Developer Changelog Developer Changelog

Cập nhật sản phẩm theo ngày — Agents, Workers, Cloudflare One, R2, security. Hub có bản tóm tắt chọn lọc. Daily product updates — Agents, Workers, Cloudflare One, R2, security. This hub includes a curated summary.

Xem trong hub View in hub
Cộng đồng & cập nhật Community & updates

Cloudflare Blog Cloudflare Blog

Cập nhật sản phẩm, launch và bài kỹ thuật sâu. Product updates, launches, and technical deep dives.

Mở trên Cloudflare Open on Cloudflare

Đọc thêm — kinh nghiệm thực tế (CloudSecOp) Further reading — field notes (CloudSecOp)

Bài viết từ cloudsecop.net — bổ sung lộ trình hub với context triển khai production, không thay tài liệu chính thức Cloudflare. Posts from cloudsecop.net — complement this track with production deployment context; not a replacement for official Cloudflare docs.

7 phút đọc 7 min read

lol-html: streaming HTML rewriter trên Workers — 3 production patterns lol-html streaming HTML rewriter on Workers

CSP nonce per request, rewrite analytics URL, A/B inject tại edge. Per-request CSP nonce, analytics URL rewrite, A/B inject at the edge.

  • Workers
  • HTML
Đọc trên CloudSecOp Read on CloudSecOp
9 phút đọc 9 min read

Pingora vs AWS ALB/NLB Pingora vs AWS ALB/NLB

Khi nào self-host reverse proxy bằng pingora-core thắng ALB managed. When self-hosted pingora-core beats managed ALB.

  • Pingora
Đọc trên CloudSecOp Read on CloudSecOp
Phần 18 Part 18 8 phút đọc 8 min read

Security cho Worker: secrets, CSP, Bot Management, Turnstile Worker security: secrets, CSP, Bot Management, Turnstile

Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-pattern. Defense-in-depth: WAF, Turnstile, Access JWT, Zod validation, anti-patterns.

  • security
  • Turnstile
Đọc trên CloudSecOp Read on CloudSecOp
Phần 17 Part 17 9 phút đọc 9 min read

Observability cho Worker: Logs, Tail Workers, Analytics Worker observability: Logs, Tail Workers, Analytics

4 tầng: Workers Logs, Tail, Logpush, Analytics Engine — debug production. Four layers: Workers Logs, Tail, Logpush, Analytics Engine — production debugging.

  • observability
Đọc trên CloudSecOp Read on CloudSecOp

Bước tiếp theo Next step

Áp dụng ngay qua tình huống thực tế và checklist. Apply what you learned via a use case and checklist.

Học xong hoặc muốn đổi hướng? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths