Главная
Study mode:
on
1
Intro
2
Three types of callers
3
Crawl Walk Run
4
The Bad Old Days
5
The Crawl Phase
6
SAML Flow
7
Request Driven
8
Walk
9
Walk Stage
10
Run Stage
11
Run Phase
12
External Authorization
13
Open Policy Agent
14
Bundle API
15
What we did
16
Moving from Nginx to Envoy
17
Authentication
18
Stateless Authorization
19
Fine Grain Authorization
20
New UI
21
All services have auth
22
Transparent TLS between services
23
Join us
24
Questions
Description:
Explore the evolution of authentication and authorization practices at Cruise in this conference talk. Delve into the journey from basic implementations to advanced zero trust security models within Kubernetes clusters. Learn about the challenges faced, unique solutions developed, and the three-phase approach of Crawl, Walk, Run. Discover how Cruise transitioned from traditional methods to implementing SAML flows, request-driven processes, and external authorization using Open Policy Agent. Gain insights into the company's move from Nginx to Envoy, the implementation of stateless authorization, and the introduction of fine-grained access controls. Understand the importance of transparent TLS between services and the development of new user interfaces to support these security enhancements. This presentation offers valuable lessons for organizations looking to improve their AuthN and AuthZ strategies at scale.

AuthN and AuthZ at Cruise - Crawl, Walk, Run

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00