filmov
tv
Fortifying Microservice Security with SPIRE and OPA - Ash Nakar

Показать описание
Fortifying Microservice Security with SPIRE and OPA - Ash Nakar
Microservice architecture although beneficial brings with it unique security challenges around authentication and authorization which become more acute due to the diverse nature of microservice environments.
How do we reliably authenticate and authorize interactions between 10s, 100s, or even 1000s of services at scale while handling 1000 API calls per second?
SPIRE solves authentication by creating an identity plane across varied infrastructure over which cryptographically verifiable identities such as JWTs are delivered securely to workloads. OPA provides a policy engine that can be used to enforce fine-grained authorization policies across the stack.
We will show how SPIRE issued JWT SVID claims created using SPIRE’s OIDC Federation can be used by OPA to enforce service-to-service and end-user access control in microservice environments without compromising on speed and availability.
Microservice architecture although beneficial brings with it unique security challenges around authentication and authorization which become more acute due to the diverse nature of microservice environments.
How do we reliably authenticate and authorize interactions between 10s, 100s, or even 1000s of services at scale while handling 1000 API calls per second?
SPIRE solves authentication by creating an identity plane across varied infrastructure over which cryptographically verifiable identities such as JWTs are delivered securely to workloads. OPA provides a policy engine that can be used to enforce fine-grained authorization policies across the stack.
We will show how SPIRE issued JWT SVID claims created using SPIRE’s OIDC Federation can be used by OPA to enforce service-to-service and end-user access control in microservice environments without compromising on speed and availability.
Fortifying Microservice Security with SPIRE and OPA - Ash Nakar
Fortifying gRPC Microservices: Beyond JWT with mTLS and SPIFFE | Mehrdad Afshari, Signeen
Service Authentication for Zero Trust Model with SPIRE
Creating a Zero Trust Model for Microservices Architectures with SPIRE and Envoy
Five Things You Didn’t Know You Could Do with SPIFFE and SPIRE - Andrew Jessup & Andrés Vega
Fortifying gRPC Microservices: Beyond JWT with mTLS and SPIFFE - Mehrdad Afshari, Signeen
Zero Trust Service Mesh with Calico, SPIRE, and Envoy - Shaun Crampton & Evan Gilman
Operationalizing SPIRE at Square
Demo: Decoupled Authentication & Authorization for the Cloud Native Enterprise with OPA and SPIR...
Uber x Security: Why and How We Built Our Workload Identity Platform - Tyler Julian & Daniel Fel...
Securing Application Telemetry & Tracing with SPIFFE and Envoy - Sabree Blackmon, Docker
Cryptographic service identity in Kubernetes with SPIFFE and SPIRE
Securing Communication Between Meshes and Beyond with SPIFFE Federation - Evan Gilman & Oliver L...
Intro: SPIFFE - Emiliano Bernbaum & Scott Emmons, Scytale
Keynote: Introduction to SPIFFE by Kelsey Hightower
Running SPIRE In Large Scale, Enterprise-Grade Environments - Andrew Harding, HPE
The Production Identity Control Plane: Recommended Practices for SPIFFE/SPIRE at Scale - Andres Vega
Securing Kubernetes with Istio - Erlend Oftedal
SPIFFE at GitHub - Eric Lee
OPA everywhere! Exploring new opportunities in policy evaluation - Anders Eknert - NDC Security 2023
SPIFFE Meetup Feb 2021 - AWS AppMesh and SPIRE Integration
Istio New Workload Identity Provision Pipeline Based on Envoy SDS - Quanjie Lin & Diem Vu, Googl...
Welcome - Andrés Vega, Umair Khan
Overview of SPIRE
Комментарии