Cloud Native
Security Talks
RSS

KubeCon Europe 2026

Signed, Sealed, Delivered: Why Reverse Proxies Outperform VPNs

Peter ONeill, Teleport & Boris Kurktchiev, Independent

Abstract

To use an analogy, traditional VPNs are like picking up a package from a shared storage room. Once you are inside, you can see and touch far more than the package meant for you. This model worked when networks were smaller and trust was implicit, but in cloud-native environments it creates excessive privilege, blind spots, and unnecessary risk.Reverse proxies in contrast act like signature on delivery. Access is granted only to the intended recipient, only for the right resource, and every handoff is logged. This session will explain how reverse proxies work, the evolution from forward proxies, and why they are a better fit than VPNs for securing modern systems.To make this concrete, we will walk through a demo using Envoy, Keycloak, and two sample applications. Attendees will see how a reverse proxy validates identity, enforces per-route authorization, and logs every action.

More from KubeCon Europe 2026

Open in the index →
  1. When Multitenancy Goes Wrong: A Deep Dive Into Kcp’s First CVEMarvin Beckers, ClickHouse 2026-03-24
  2. What LLMs Do, and Don't, Know About Securing KubernetesRory McCune, Datadog 2026-03-24
  3. Real-World Supply-Chain SecurityAlex Leong, Buoyant 2026-03-24
  4. Privacy as Infrastructure: Declarative Data Protection for AI on KubernetesJoaquin Rodriguez, Microsoft & Krishnendu Dasgupta, AXONVERTEX AI 2026-03-24
  5. Policy Engines for Kubernetes: Picking One Without Losing Your MindNabarun Pal, Broadcom 2026-03-24
  6. Why Security of Kubernetes Comes Down to Linux SecurityMarina Moore, Edera 2026-03-25
  7. Why Isn't the Fix in My Container? Tracking CVE Propagation Across 10,000 ProjectsMor Weinberger, Echo Security & Lior Kaplan, Kaplan Open Source 2026-03-25
  8. Kubernetes Third Party Audit ReviewIain Smart, AmberWolf; Amir Montazery, Open Source Technology Improvement Fund; Rey Lejano, Red Hat; Tabitha Sable, Datadog; Pietro Tirenna, Shielder 2026-03-25
  9. Kubernetes Security at Shopify Scale: Automating Security Across an Infrastructure MonorepoJie Wu & Pulkit Garg, Shopify 2026-03-25
  10. Invisible Guardrails: Enabling Developer Velocity With a Secure PlatformJames Elías Sigurðarson & Vignir Hafsteinsson, Asana 2026-03-25
  11. How To Break Multi-Tenancy Again and Again ...and What We Can Learn From ItLorin Lehawany & Sven Nobis, ERNW 2026-03-25
  12. Hacking GPU Observability: eBPF & Ephemeral Containers in Action on KubernetesBrandon Kang, Akamai Technologies 2026-03-25
  13. Hack Me If You Can: Learning Kubernetes Security Through a Role-Play BattleAoi Takahashi, Recruit Co., Ltd. & Keita Mochizuki, NTT DATA Japan Corporation 2026-03-25
  14. Exploring NRI for Automated CA Trust InjectionTsuzuki Tsuchiya & Kento Kubo, LY Corporation 2026-03-25
  15. Detect, Decide, Defend: Building Cloud Native Security That Fights BackMatthias Bertschy, ARMO 2026-03-25
  16. Bob and Alice Revisited: Understanding Encryption in KubernetesJackie Maertens & Mitch Connors, Microsoft 2026-03-25
  17. Automating and Scaling of Threat Modelling for Cloud Native ArchitectureHanna Papirna & Emma Yuan Fang, EPAM Systems 2026-03-25
  18. Automate Once, Run Anywhere: The Docker Moment for Security WorkflowsNancy Chauhan & Aseem Shrey, ShipSecAI 2026-03-25
  19. Audit-Ready Kubernetes: How Chase UK Leveraged Policy as Code for Continuous ComplianceJim Bugwadia, Nirmata & Nischay Goyal, JP Morgan Chase 2026-03-25
  20. The Shared Service Blueprint: A Guide to Multi-Tenancy, Illustrated With KEDAAya Igarashi, Preferred Networks, Inc. 2026-03-26
  21. Tailor Made: Dynamic Fine-Grained Authorization for API TrafficErica Hughberg, Tetrate & Andres Aguiar, Okta 2026-03-26
  22. SPIFFE Meets OAuth: Federated Identity for Cloud Native WorkloadsYoshiyuki Tabata, Hitachi, Ltd. 2026-03-26
  23. SB💣💣M: Making SBOMs Play TogetherJacopo Bufalino, CNAM & Agathe Blaise, Thales SIX GTS France 2026-03-26