Cloud Native
Security Talks
RSS

KubeCon North America 2024

SPIFFE the Easy Way: Universal X509 and JWT Identities Using cert-manager

Tim Ramlot & Ashley Davis, Venafi

Abstract

SPIFFE is incredible. Each workload is assigned its own universal identity, simplifying the security and management of communications in distributed systems. While SPIRE (the reference SPIFFE implementation) is exceptionally powerful, it is also quite complex. Deploying SPIRE on Kubernetes requires StatefulSets, which can be challenging and frustrating. Many cloud vendors are starting to offer turnkey SPIFFE solutions, but that comes with risk of vendor lock-in. In this talk, we will demonstrate how to use the Cloud Native cert-manager solution to implement SPIFFE (x509 and JWT) with low operational overhead for all Kubernetes workloads. The session includes all you need to know to issue X.509 SVIDs, use them and validate them. Additionally, we will introduce an experimental solution to convert x509 SVIDs into JWT SVIDs. The demo will highlight how to authenticate to third-party APIs (such as AWS, GCP, Azure, and others) using these JWT SVIDs.

More from KubeCon North America 2024

Open in the index →
  1. Workload Identity Federation – Stop Using Long-Lived CredentialsBenjamin Dronen, Ford Motor Company & Anjali Telang, Red Hat 2024-11-13
  2. GitOops... I Did It Again! Protecting Your GitOps System from Being Used for Privilege EscalationOreen Livni & Elad Pticha, Cycode 2024-11-13
  3. From Observability to Enforcement: Lessons Learned Implementing eBPF Runtime SecurityAnna Kapuścińska & Kornilios Kourtis, Isovalent 2024-11-13
  4. Expanding the Capabilities of Kubernetes Access ControlJimmy Zelinskie, authzed & Lucas Käldström, Upbound 2024-11-13
  5. CEL-Ebrating Simplicity: Mastering Kubernetes Policy EnforcementKevin Conner, Getup Cloud & Anish Ramasekar, Microsoft 2024-11-13
  6. Bridging Clouds: TikTok’s Blueprint for Unified OIDC Access on Multi-Cloud KubernetesNaveen Mogulla, TikTok 2024-11-13
  7. Breaking Free from Vulnerability Scanning Noise: Automated VEX Aggregation for AccuracyTeppei Fukuda, Aqua Security Software Ltd. 2024-11-13
  8. AuthZEN: The “OpenID Connect” for AuthorizationOmri Gazitt, Aserto 2024-11-13
  9. What Agent to Trust with Your K8s: Falco, Tetragon or KubeArmor?Henrik Rexed, Dynatrace 2024-11-14
  10. Multi-Tier Security in WasmCloud: From Developer Constraints to Platform ExtensibilityBrooks Townsend, Cosmonic 2024-11-14
  11. Mish-Mesh: Abusing the Service Mesh to Compromise Kubernetes EnvironmentsHillai Ben-Sasson & Nir Ohfeld, Wiz 2024-11-14
  12. It's Dangerous to Build It Alone, Take This.Jeremy Rickard & Ashna Mehrotra, Microsoft 2024-11-14
  13. From Standards to Practice: The Journey to Container MaturityCarmen Chow & Thomas Robinson, Yelp 2024-11-14
  14. From Silicon to Service: Ensuring Confidentiality in Serverless GPU Cloud FunctionsZvonko Kaiser, NVIDIA 2024-11-14
  15. Why Perfect Compliance Is the Enemy of Good Kubernetes SecurityMichele Chubirka, Google 2024-11-15
  16. The Policy Engines ShowdownGabriel L. Manor, Permit.io; Andres Aguiar, Okta; Omri Gazitt, Aserto; Pauline Jamin, Agicap; Tyler Schade, Geico; Joy Scharmen, StrongDM 2024-11-15
  17. Seccomp and eBPF; What’s the Difference? Why Do I Need to Know?Natalia Reka Ivanko & Duffie Cooley, Isovalent @ Cisco 2024-11-15
  18. SPIFFE Deployments in Non-Kubernetes EnvironmentsNadin El-Yabroudi & Eli Nesterov, SPIRL 2024-11-15
  19. Rogue No More: Securing Kubernetes with Node-Specific RestrictionsAnish Ramasekar, Microsoft & James Munnelly, Apple 2024-11-15
  20. Practical Supply Chain Security: Implementing SLSA Compliance from Build to RuntimeEnguerrand Allamel, Ledger 2024-11-15
  21. Powering Automatic Authorization in Envoy Through Live Traffic InspectionDom Del Nano, Pixie core maintainer 2024-11-15