Modern cloud-native platforms have replaced static security boundaries with constantly changing identities, workloads, APIs, and trust relationships. Kubernetes clusters, microservices, service meshes, and distributed APIs require security architectures that can make reliable authorization decisions across continuously changing infrastructure.
This book examines how to design and operate identity and data-access security for these environments using OAuth 2.0, OpenID Connect, JWTs, workload identity, service meshes, policy enforcement, and Zero Trust principles.
Rather than treating OAuth as an isolated authentication technology, the book examines how identity and authorization operate across an entire distributed platform. It explores the relationship between API gateways, Kubernetes workloads, internal services, authorization policies, and data-access boundaries, with particular attention to the architectural decisions that determine whether a security design remains reliable under production conditions.
The book covers:
- Cloud-native identity architecture and distributed trust boundaries
- Threat modeling for Kubernetes and microservices environments
- OAuth 2.0 authorization flows and token-based trust models
- JWT validation, claims, audiences, issuers, expiration, and key rotation
- Identity propagation across distributed microservice architectures
- API gateway authorization and secure ingress patterns
- Kubernetes service accounts, RBAC, and workload identity
- Workload identity federation across cloud and hybrid environments
- SPIFFE and SPIRE for portable workload identity
- Service mesh security, mTLS, and identity-aware authorization
- Policy-as-code and centralized authorization enforcement
- Zero Trust security models for cloud-native platforms
- Fine-grained data access and multi-tenant isolation
- Security observability, audit events, and identity telemetry
- OAuth deployment failures, token lifecycle problems, and authorization misconfigurations
- End-to-end reference architectures for production cloud-native platforms
Particular attention is given to the problems that appear after deployment: expired and revoked tokens, signing-key rotation, clock skew, policy drift, excessive permissions, identity propagation failures, service-to-service trust, authorization outages, and security controls that behave differently across platform layers.
The result is an architecture-focused treatment of cloud-native identity and security for engineers who need to design systems that remain secure, observable, and operationally reliable as infrastructure and workloads scale.
Designed for experienced developers, platform engineers, DevOps teams, cloud architects, security engineers, and infrastructure practitioners working with distributed systems, APIs, Kubernetes, and modern cloud platforms.
Les informations fournies dans la section « Synopsis » peuvent faire référence à une autre édition de ce titre.
Vendeur : AHA-BUCH GmbH, Einbeck, Allemagne
Taschenbuch. Etat : Neu. Neuware. N° de réf. du vendeur 9784110814634
Quantité disponible : 2 disponible(s)