Cloud Native
Security Talks
RSS

KubeCon Europe 2024

OAuth2 Token Exchange for Microservice API Security

Ahmet Soormally & Letz Yaara, Tyk

Abstract

APIs need a way to authenticate, authorize and propagate identity between services. Load Balancers, API Gateways, ingress and chained microservice calls make propagating identity and authorization in a secure manner significantly more complex. In this session, we will dive into typical OAuth2.0 flows with practical examples using Keycloak. We will then illustrate some of the challenges you will face applying OAuth2 in a microservice environment, alongside the typical workarounds or hacks that are seen in the wild. We will discuss advantages and drawbacks of each approach, and most importantly highlight potential vulnerabilities. Finally, we will present a relatively new standard known as the OAuth2 Token Exchange RFC8693 as a recommended approach to authorization and propagating identity using Keycloak to demonstrate. Key Points:- OAuth 2.0 Essentials- Live Demo: with shortcomings applying OAuth2 in a microservice environment- Token Exchange RFC8693 ImportancePR we used for our demo: https://github.com/TykTechnologies/tyk/pull/6069Link to the API Gateway we used in the demo: tyk.io

More from KubeCon Europe 2024

Open in the index →
  1. Securing the Supply Chain with Sigstore Artifacts Signatures at ScaleDmitry Savintsev & Yonghe Zhao, Yahoo 2024-03-20
  2. Safety or Usability: Why Not Both? Towards Referential Auth in K8sRob Scott, Google & Mo Khan, Microsoft 2024-03-20
  3. SLSA and FRSCA: Beyond Snacks and Soda!Christopher Hanson, RX-M, llc. 2024-03-20
  4. Playing Defense: The Reactive Cloud Native Security BattleAyse Kaya, Slim.AI 2024-03-20
  5. I'll Let Myself In: Kubernetes Privilege Escalation TacticsAndrew Martin & Iain Smart, ControlPlane 2024-03-20
  6. Why Barricade the Door if the Window Is Open? Making Sense of Kubernetes Initial Access VectorsShay Berkovich, Wiz 2024-03-21
  7. VEXinating Your Container Images: The European WayDina Truxius, Federal Office for Information Security (BSI) & Jose Antonio Carmona Fombella, VMware 2024-03-21
  8. Stop Leaking Kubernetes Service Information via DNS!John Belamaric, Google & Yong Tang, Ivanti 2024-03-21
  9. Navigating the Software Supply Chain Defense LandscapeMarina Moore & Aditya Sirish A Yelgundhalli, New York University 2024-03-21
  10. Misconfigurations in Helm Charts: How Far Are We from Automated Detection and Mitigation?Francesco Minna, Vrije Universiteit Amsterdam & Agathe Blaise, Thales SIX 2024-03-21
  11. Memory Armor for SPIRE: Fortifying SPIRE with Confidential Containers (CoCo)Matthew Bates, Stealth Security Startup & Suraj Deshmukh, Microsoft 2024-03-21
  12. Keep Hackers Out of Your Cluster with These 5 Simple TricksChristophe Tafani-Dereeper & Frederic Baguelin, Datadog 2024-03-21
  13. Federated IAM for Kubernetes with OpenFGAJonathan Whitaker, Okta 2024-03-21
  14. Confidential Containers for GPU Compute: Incorporating LLMs in a Lift-and-Shift Strategy for AIZvonko Kaiser, NVIDIA 2024-03-21
  15. Cloud Native Security: Cell-Based Architecture & K8sRostyslav Myronenko & Shweta Vohra, Booking.com 2024-03-21
  16. Bringing SPIFFE to Linkerd for Mesh ExpansionZahari Dichev, Buoyant 2024-03-21
  17. Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native EcosystemConstanze Roedig, Technische Universität Wien & James Callaghan, ControlPlane 2024-03-21
  18. You Shall Not Pass! Unless You Are GUAC Verified….Parth Patel, Kusari & Dejan Bosanac, Red Hat 2024-03-22
  19. Living off the Land Techniques in Managed Kubernetes ClustersRonen Shustin & Shay Berkovich, Wiz 2024-03-22
  20. Leveraging OCI 1.1 for Enhanced SBOM Integration and Vulnerability Scanning in HarborAnais Urlichs, Aqua Security & Shengwen Yu, VMware 2024-03-22
  21. Lessons Learned from Generating 100M SBOMs: Google’s Approach to SBOM ComplianceBrandon Lum & Isaac Hepworth, Google 2024-03-22
  22. Kubernetes Security Blind Spot: Misconfigured System PodsShaul Ben Hai, Palo Alto Networks 2024-03-22
  23. Kubernetes MLSec: Securing AI in SpaceFrancesco Beltramini & James Callaghan, ControlPlane 2024-03-22
  24. Keeping Kubernetes Safe: The Lowdown on Locked NamespacesMarco De Benedictis, ControlPlane 2024-03-22
  25. It's Not Just About SBOMs: Perspectives on Cloud Native Supply Chain SecurityMichael Lieberman, Kusari; Dana Wang, OpenSSF - The Linux Foundation; Marina Moore, New York University; John Kjell, TestifySec; Arnaud Le Hors, IBM 2024-03-22
  26. IAM Confused: Analyzing 8 Identity Breach IncidentsMaya Levine, Sysdig 2024-03-22