Learning outcomes
- Compare identity-aware proxies, API gateways, service meshes, load balancers, and VPNs by protected resource.
- Place enforcement near the facts and action it must control.
- Combine layers without duplicate, contradictory, or missing authorization.
- Test bypass, identity propagation, protocol, and failure boundaries.
Protection need
Start with the subject, resource, action, protocol, fact owner, and bypass paths. An identity-aware proxy protects named user-facing services. An API gateway applies API routing and controls. A service mesh mediates workload-to-workload communication. A load balancer distributes traffic and can terminate transport security. A VPN or network tunnel grants network reachability. An application enforces object and business-action permission.
No layer is the universal owner. The correct placement depends on what the control can identify and intercept.
Security objectives and requirements
Place broad exposure and identity checks at the external route. Place API contract and client controls at an API layer. Place workload identity and service communication policy at workload boundaries. Place object, tenant, and transaction authorization in the application.
For each layer, define the protected resource, authenticated principal, trusted inputs, failure result, decision age, protocol coverage, and evidence. Remove a layer that has no distinct security job.
Security invariants and evidence
- Every path to an action crosses one named enforcement owner.
- No layer treats another layer's coarse allow as its complete permission result.
- Identity changes form and trust explicitly at each termination point.
- Policy failures have one stated safe result.
- Evidence can correlate the external request, service calls, and final action.
Failure cases
- A VPN grants reachability and is treated as user authorization.
- A load balancer forwards spoofed identity fields.
- An API gateway authorizes a route but not an object.
- A mesh authenticates workloads but loses the human actor.
- External and internal policies drift or contradict each other.
- An origin, node port, or maintenance listener bypasses all intended layers.
Design tradeoffs and residual risk
More layers can reduce blast radius but increase policy drift, latency, and investigation cost. Central enforcement improves consistency but can lack local facts. Application enforcement has the richest facts but cannot close external exposure alone. Network controls reduce paths but use coarse identities and resources.
Assign one owner per decision. Use defense in depth for independent failure modes, not to repeat the same unclear rule.
Pomerium boundary
Pomerium provides identity-aware enforcement for configured routes and supported protocols. It can complement load balancers, API gateways, service meshes, and network controls. It does not replace workload identity, network segmentation, or application object authorization.
Exercise
For a web user calling an API that calls three workloads and writes a tenant record, assign every control to a layer. Remove duplicated rules. Add an alternate origin, compromised workload, wrong tenant, and policy-service outage.
Explain which layer denies each failure and which evidence proves it.
Evaluation checklist
- Does each layer protect a resource it can name and intercept?
- Is the principal at that layer authenticated and preserved correctly?
- Are route, API, workload, network, and object permissions distinct?
- Can any protocol or infrastructure path bypass all intended controls?
- Do failure behavior and evidence remain clear when one layer is unavailable?
Next learning unit
Gateway Bypass Path
Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.
