Skip to main content

Use east-west and north-south traffic as topology

Use traffic direction to describe topology, then make identity and resource decisions independently.

Learning outcomes

  • Define traffic direction relative to an explicit boundary.
  • Trace identity and policy across external and internal hops.
  • Avoid using direction or network location as a trust decision.
  • Test lateral, direct, service, and control-plane paths.

System and boundaries

North-south and east-west are relative topology labels. North-south usually crosses a selected external boundary. East-west usually stays among internal systems or peers. A request can be north-south at cloud ingress and east-west across services. Neither direction proves trust.

Request and decision flow

Trace a user request through external gateway, internal services, data stores, and control planes. At each hop, identify actor, subject, workload, credential, resource, action, policy, enforcement, and target. Repeat for a service-originated request.

Failure domains

Perimeter policy can protect entry and leave internal services implicitly trusted. Service identity can exist while application object permission is absent. An internal workload can reach a public endpoint and reenter. Control planes, metadata services, and recovery systems create high-impact internal paths.

Design tradeoffs and residual risk

Central north-south gateways simplify entry policy and concentrate load. Distributed east-west enforcement adds local identity and policy complexity. Internal encryption protects transport and does not authorize actions.

Residual risk includes unknown internal paths, shared workload identities, compromised nodes, direct service addresses, and application trust based on network source.

Pomerium boundary

Pomerium can protect named external or internal routes that pass through it. It does not automatically mediate all east-west traffic or internal application calls. Operators decide where Pomerium, a mesh, cloud policy, Kubernetes policy, and application authorization apply.

Exercise

Choose one user-to-service action and one service-to-service action. Mark every external and internal boundary, then remove direction labels. Verify the remaining identity, resource, action, policy, and enforcement model still explains security.

Evaluation checklist

  • Relative to which boundary is each direction label defined?
  • Which identity and credential exist at each hop?
  • Does any internal path use location as authorization?
  • Can a compromised workload move to another service or control plane?
  • Which enforcement and evidence cover every target action?

Next learning unit

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Sources and further reading

Keep learning

Zero TrustNetwork and Infrastructure

Implicit Trust Zone

An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo