Learning outcomes
- Define traffic direction relative to an explicit boundary.
- Trace identity and policy across external and internal hops.
- Avoid using direction or network location as a trust decision.
- Test lateral, direct, service, and control-plane paths.
System and boundaries
North-south and east-west are relative topology labels. North-south usually crosses a selected external boundary. East-west usually stays among internal systems or peers. A request can be north-south at cloud ingress and east-west across services. Neither direction proves trust.
Request and decision flow
Trace a user request through external gateway, internal services, data stores, and control planes. At each hop, identify actor, subject, workload, credential, resource, action, policy, enforcement, and target. Repeat for a service-originated request.
Failure domains
Perimeter policy can protect entry and leave internal services implicitly trusted. Service identity can exist while application object permission is absent. An internal workload can reach a public endpoint and reenter. Control planes, metadata services, and recovery systems create high-impact internal paths.
Design tradeoffs and residual risk
Central north-south gateways simplify entry policy and concentrate load. Distributed east-west enforcement adds local identity and policy complexity. Internal encryption protects transport and does not authorize actions.
Residual risk includes unknown internal paths, shared workload identities, compromised nodes, direct service addresses, and application trust based on network source.
Pomerium boundary
Pomerium can protect named external or internal routes that pass through it. It does not automatically mediate all east-west traffic or internal application calls. Operators decide where Pomerium, a mesh, cloud policy, Kubernetes policy, and application authorization apply.
Exercise
Choose one user-to-service action and one service-to-service action. Mark every external and internal boundary, then remove direction labels. Verify the remaining identity, resource, action, policy, and enforcement model still explains security.
Evaluation checklist
- Relative to which boundary is each direction label defined?
- Which identity and credential exist at each hop?
- Does any internal path use location as authorization?
- Can a compromised workload move to another service or control plane?
- Which enforcement and evidence cover every target action?
Next learning unit
East-West Traffic
East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.
