Running SPIRE in Large Scale, Enterprise-Grade Environments
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore the practical aspects of running SPIRE in large-scale, enterprise-grade environments in this 31-minute conference talk by Andrew Harding from HPE. Delve into key topics such as high availability, nested deployment for multiple availability zones, integration with upstream certificate authorities, observability, and monitoring. Gain valuable insights on trust domains, database management, failure scenarios, agent internals, and TLS implementation. Learn about SPIFFE bundles, multizone deployment strategies, upstream authorities, and the advantages they offer. Discover the intricacies of nested SPIRE setups, SPIRE federation, and trust domain management. Whether you're already using SPIRE at scale or considering its implementation as your infrastructure grows, this talk provides essential knowledge for navigating the complexities of SPIRE in enterprise environments.
Syllabus
Introduction
Agenda
Trust Domain
Database
Failure scenarios
Agent internals
TLS
Svids
Summary
Zones
SPiffy Bundle
Multizone Deployment
Upstream Authority
Bundles
Jot Signing Keys
Upstream Authority Advantages
Nested SPIRE
Upstream SPIRE
SPIRE Federation
SPIRE Bundle Endpoint
Trust Domains
Recap
Outro
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Introducción a SPIFFE y SPIRE - Autenticando servicios nativos de la nubeEkoparty Security Conference via YouTube Road to SLSA3 - Non-falsifiable Provenance in Tekton with SPIFFE/SPIRE
Linux Foundation via YouTube How SPIFFE Helps Istio in Service Mesh Federation
Linux Foundation via YouTube Trust No System: The Unsettling Reality of Zero Trust
CNCF [Cloud Native Computing Foundation] via YouTube Growing SPIFFE and SPIRE in 2023 and Beyond - Secure Identity Management Progress
CNCF [Cloud Native Computing Foundation] via YouTube