cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://tag-security.cncf.io
Other
2.04k stars 509 forks source link

CyberArk: Application Identity in Cloud Foundry and Kubernetes, from the Perspective of an External Service #6

Closed izgeri closed 6 years ago

izgeri commented 6 years ago

CyberArk Conjur recently built two new integrations with Pivotal Cloud Foundry / Cloud Foundry and OpenShift (RedHat's implementation of Kubernetes). Through that process, we learned a lot about how applications are uniquely identified in these two systems, and how external services might leverage the internal app identities to reliably privilege appropriate applications to utilize their services.

I am proposing to speak to the SAFE working group about the current state of each of these systems with respect to application identity, and some lessons learned about potential improvements that could be made.

duglin commented 6 years ago

I assume this is related to OSB API right ? Either way I’d be interested in hearing this.

-Doug

Sent from my iPhone

On Apr 6, 2018, at 10:31 AM, izgeri notifications@github.com wrote:

CyberArk Conjur recently built two new integrations with Pivotal Cloud Foundry / Cloud Foundry and OpenShift (RedHat's implementation of Kubernetes). Through that process, we learned a lot about how applications are uniquely identified in these two systems, and how external services might leverage the internal app identities to reliably privilege appropriate applications to utilize their services.

I am proposing to speak to the SAFE working group about the current state of each of these systems with respect to application identity, and some lessons learned about potential improvements that could be made.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub, or mute the thread.

izgeri commented 6 years ago

For one of these integrations we used the OSB API, but I wasn't actually thinking I'd talk much about that. I'm actually more interested in the emerging standards around certificate-based app identity, such as the SPIFFE standard and CF instance identity.

dshaw commented 6 years ago

@izgeri Scheduled for 2018-06-08

izgeri commented 6 years ago

Slides are available here

dshaw commented 5 years ago

Meeting notes: https://docs.google.com/document/d/10iJ3wA7uVI6JMyvIv9qXdxdLCyQeS-djYsTqL_JG3d0/edit

Meeting video recording: https://www.dropbox.com/s/rmr3231e26zue4j/zoom_0.mp4?dl=0