cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://tag-security.cncf.io
Other
2.09k stars 518 forks source link

[Presentation] Get to know heimdall - an identity aware proxy #1346

Open dadrus opened 3 months ago

dadrus commented 3 months ago

Title: Get to know heimdall - an identity aware proxy

Speakers: Dimitrij Drus (@dadrus)

Description: I would like to present a project, I'm maintaining - https://github.com/dadrus/heimdall, which is an identity aware proxy and can also turn any existing proxy supporting extrnal/forward auth capabilities into an API gateway (from security point of view). Heimdall helps addressing authentication and authorization challenges by orchestrating existing authn/authz systems, essentially closing the existing gap between the two. As such it can be used to implement edge level authentication and authorization architectures (EAA). I did that recently for TAG Network as well: https://www.youtube.com/watch?v=G8gWVNBD5IA

Time: Depending on the amount of interest roughly one hour

Availability: I live in the CET time zone. Everything, which is not mid of the night will work for me.

TO DO

dadrus commented 3 months ago

Contacting you and doing a presentation was a recommendation from the TAG Network group as answer to may CNCF Sandbox application: https://github.com/cncf/sandbox/issues/92

dadrus commented 3 months ago

Btw, the link to the presentation guide is broken. I assume, that one is meant.

Same issue exists with the link to the charter in the document I linked above.

I can open corresponding PRs if you like

mlieberman85 commented 3 months ago

Hi, we can get you on the schedule. Let me check what upcoming and then throw some dates in here.

mlieberman85 commented 2 months ago

I spoke to @dadrus and he said EMEA TAG Security meeting is most convenient to present for him.

@dadrus here are the open slots we have:

September 11th October 9th

It looks like we have nothing planned post Oct 9th as well and our EMEA meetings happen every other week. So

October 23rd Nov 6th

etc.

dadrus commented 2 months ago

September 11th won't work for me, unfortunately, but October 9th is perfectly fine.

As you're aware, I've already presented Heimdall to TAG Network, which led to the video I linked above. I'm curious if you're interested in exploring topics beyond that presentation for deeper insights and more details?

Thank you in advance!

mlieberman85 commented 2 months ago

Sure, so beyond the usual basics (use case, goals, current features) TAG Security tends to be interested in a few things:

eddie-knight commented 5 days ago

Hi all, is this still pending— or ready to close?

dadrus commented 5 days ago

I still need to share the presentation slides I showed. Unfortunately, the past few weeks have been incredibly busy, and I haven’t had time to update the slides to align with what I covered during the presentation.

Since my presentation mainly focused on the security aspects heimdall addresses rather than heimdall’s own security, I’m curious if there’s interest in that topic as well. I’d be happy to cover it in one of the future meetings as well if there is!

eddie-knight commented 5 days ago

What are you hoping to achieve with the presentation?

We welcome any community presentations, but it helps to understand the goals beforehand. Typically our presentations are connected to requests from the CNCF TOC, which gives us a clearer scope for discussion.

dadrus commented 3 days ago

Thanks for the question, Eddie! This presentation is part of my effort to align heimdall more closely with the CNCF security community, as suggested by the TOC. While I previously shared heimdall's focus on real-world challenges, this session is about fostering deeper engagement, exploring collaboration opportunities, and addressing the feedback around visibility and bus factor, criticized by the TOC. It's about building connections and finding ways heimdall can contribute to and grow within the CNCF ecosystem. Does it make sense?

eddie-knight commented 3 days ago

Yeah! Would you like to do a short presentation sometime? If we keep it to 15 minutes, you might even be able to just drop in and do a quick demo whenever you'd like. Or we can plan ahead and schedule you for a full presentation.