Cloud Native
Security Talks
RSS

KubeCon North America 2019

Securing Communication Between Meshes and Beyond with SPIFFE Federation

Evan Gilman, Scytale & Oliver Liu, Google

Abstract

One of the hottest features that Istio brings to the table is transparent, mutually-authenticated TLS between all workloads running on it. Under the covers, it relies on SPIFFE to provide the cryptographic identity that is used to perform this mutual authentication.SPIFFE relies on an authority to issue identity. In an Istio mesh, Istio Citadel (CA) issues certificates to workloads by default… but, what happens when you have more than one Istio mesh, and hence more than one Citadel? Or Istio workloads talking to external services?Enter SPIFFE federation. It allows SPIFFE identity issuers to peer with each other, enabling workloads in disparate domains to securely authenticate and communicate with each other. In this talk, we will describe the challenges involved here and how SPIFFE addresses them, as well as demonstrate SPIFFE federation between Istio mesh and SPIRE.

More from KubeCon North America 2019

Open in the index →
  1. Walls Within Walls: What if Your Attacker Knows Parkour?Tim Allclair & Greg Castle, Google 2019-11-19
  2. The Devil in the Details: Kubernetes’ First Security AssessmentAaron Small, Google & Jay Beale, InGuardians 2019-11-19
  3. Panel: Control Plane vs Data Plane: Untangling the Tenets of MultitenancyTasha Drew, VMware; Sanjeev Rampal, Cisco; Ryan Bezdicek, Cray Inc.; Adrian Ludwin, Google; & Fei Guo, Alibaba 2019-11-19
  4. Enforcing Automatic mTLS with Linkerd and OPA GatekeeperIvan Sim, Buoyant & Rita Zhang, Microsoft 2019-11-19
  5. CAP_NET_RAW and ARP Spoofing in Your Cluster: It's Going Downhill From HereLiz Rice, Aqua Security 2019-11-19
  6. Redesigning Notary in a Multi-registry WorldJustin Cormack, Docker 2019-11-20
  7. Piloting Around the Rocks: Avoiding Threats in KubernetesRobert Tonic & Stefan Edwards, Trail of Bits 2019-11-20
  8. No video On the Security of Copying To and From Live ContainersAriel Zelivansky & Yuval Avrahami, Palo Alto Networks 2019-11-20
  9. Knative - The Security Platypus?Ariel Shuper, Aqua Security 2019-11-20
  10. Binary Authorization in KubernetesAysylu Greenberg, Google & Liron Levin, Palo Alto Networks 2019-11-20
  11. Prepare to Be Boarded! A Tale of Kubernetes, Plunder, and CryptobootyJames Condon, Lacework 2019-11-21
  12. Kubernetes Policy Enforcement Using OPA At Goldman SachsMiguel Uzcategui, Goldman Sachs & Tim Hinrichs, Styra 2019-11-21
  13. Identity Bootstrapping in Multi-tenant Multi-cluster KubernetesManish Mehta, Volterra & Derek Suzuki, The Voleon Group 2019-11-21
  14. How Yelp Moved Security From the App to the Mesh with Envoy and OPADaniel Popescu, Yelp & Ben Plotnick, Cruise 2019-11-21
  15. How Kubernetes Components Communicate Securely in Your ClusterMaya Kaczorowski, Google 2019-11-21