Главная
Study mode:
on
1
Intro
2
Credits: Solving the Bottom Turtle Booksprint
3
Agenda
4
Solving for the Bottom Turtle
5
PKI/Auth Pain points in Modern Applicatio
6
Reasons to use SPIFFE and SPIRE
7
SPIFFE in a turtleshell
8
Trust domains
9
SPIRE Server
10
SPIRE Agent
11
SPIRE Plugin Architecture
12
Node attestation
13
Workload Attestation
14
Security Boundaries: Workload Agent
15
Security Boundaries: Agent Server
16
Security Boundaries: Server Server
17
Single Trust Domain Deployment
18
Single Trust Domain High Availability
19
Nested SPIRE Deployment
20
Federated SPIRE
21
Enabling software thru SPIFFE-Aware Prom
22
Automated Registration Entries
23
Independent Islands vs Bridged Islands
24
Other Considerations for Scale
Description:
Explore recommended practices for implementing SPIFFE/SPIRE at scale in this 25-minute conference talk from KubeCon + CloudNativeCon Europe 2021. Dive into the concept of a "production identity control plane" and learn how to establish trusted bi-directional communication in distributed systems. Discover solutions for common identity challenges, including credential rotation, federation with other systems, and policy implementation. Gain insights on leveraging the identity control plane for service-to-service communication in complex, heterogeneous environments. Examine topics such as PKI/Auth pain points, SPIFFE and SPIRE components, trust domains, security boundaries, deployment strategies, and considerations for scaling your identity infrastructure.

The Production Identity Control Plane - Recommended Practices for SPIFFE-SPIRE at Scale

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00