YoVDO

The Production Identity Control Plane - Recommended Practices for SPIFFE-SPIRE at Scale

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Conference Talks Courses Distributed Systems Courses Identity Management Courses SPIFFE Courses SPIRE Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore recommended practices for implementing SPIFFE/SPIRE at scale in this 25-minute conference talk from KubeCon + CloudNativeCon Europe 2021. Dive into the concept of a "production identity control plane" and learn how to establish trusted bi-directional communication in distributed systems. Discover solutions for common identity challenges, including credential rotation, federation with other systems, and policy implementation. Gain insights on leveraging the identity control plane for service-to-service communication in complex, heterogeneous environments. Examine topics such as PKI/Auth pain points, SPIFFE and SPIRE components, trust domains, security boundaries, deployment strategies, and considerations for scaling your identity infrastructure.

Syllabus

Intro
Credits: Solving the Bottom Turtle Booksprint
Agenda
Solving for the Bottom Turtle
PKI/Auth Pain points in Modern Applicatio
Reasons to use SPIFFE and SPIRE
SPIFFE in a turtleshell
Trust domains
SPIRE Server
SPIRE Agent
SPIRE Plugin Architecture
Node attestation
Workload Attestation
Security Boundaries: Workload Agent
Security Boundaries: Agent Server
Security Boundaries: Server Server
Single Trust Domain Deployment
Single Trust Domain High Availability
Nested SPIRE Deployment
Federated SPIRE
Enabling software thru SPIFFE-Aware Prom
Automated Registration Entries
Independent Islands vs Bridged Islands
Other Considerations for Scale


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Introducción a SPIFFE y SPIRE - Autenticando servicios nativos de la nube
Ekoparty Security Conference via YouTube
Road to SLSA3 - Non-falsifiable Provenance in Tekton with SPIFFE/SPIRE
Linux Foundation via YouTube
How SPIFFE Helps Istio in Service Mesh Federation
Linux Foundation via YouTube
Trust No System: The Unsettling Reality of Zero Trust
CNCF [Cloud Native Computing Foundation] via YouTube
Growing SPIFFE and SPIRE in 2023 and Beyond - Secure Identity Management Progress
CNCF [Cloud Native Computing Foundation] via YouTube