Learning outcomes
- Separate control-plane, data-plane, ingress, egress, east-west, and north-south paths.
- Combine network segmentation with user and workload identity policy.
- Limit Kubernetes and service-mesh authority at both route and object layers.
- Find direct, cross-cloud, node, metadata, credential, and recovery bypass paths.
Scenario
Applications span a data center, cloud virtual network, and Kubernetes cluster. Users need selected services, but no one needs a route to every subnet. Enforcement must reach each upstream without creating a bypass.
Ordered learning units
Trace network reachability for access systems
Trace addresses, prefixes, routes, ports, translation, names, and firewalls without confusing reachability with identity.
Load Balancer and Gateway
A load balancer selects a backend, while a gateway terminates or mediates a protocol boundary and can apply policy.
Control Plane and Data Plane
Separate the systems that define and distribute access policy from the request path that enforces it on live traffic.
Ingress and Egress
Place controls on traffic entering and leaving a workload boundary without treating direction or network location as identity.
Use east-west and north-south traffic as topology
Use traffic direction to describe topology, then make identity and resource decisions independently.
Firewall
A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.
Choose layer 4 or layer 7 access control
Place transport and application enforcement where the required identity, destination, protocol, resource, and action are visible.
Combine segmentation with identity policy
Use network segmentation to limit reachability and identity policy to decide access to named services, resources, and actions.
Workload Identity
Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.
Build SPIFFE workload identity
Trace SPIFFE IDs, SVIDs, trust domains, bundles, Workload API delivery, attestation, rotation, and federation.
Federate workload identity without static keys
Exchange attested platform identity for short-lived target credentials without copying long-lived cloud keys into workloads.
Kubernetes Service Account
Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.
Kubernetes RBAC
Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.
Trace Kubernetes control-plane access
Trace Kubernetes API transport, authentication, authorization, admission, persistence, and audit for human and workload requests.
Kubernetes NetworkPolicy
Kubernetes NetworkPolicy controls selected Pod ingress and egress reachability through a supporting network plugin.
Kubernetes Gateway API
Gateway API models infrastructure, listeners, routes, backends, and policy attachment through role-oriented resources.
Kubernetes Namespace and Tenancy
A namespace scopes names and policy objects, but tenant isolation depends on many cluster and workload controls.
Compare process, container, and VM isolation
Compare shared kernel, virtual machine, host, node, runtime, credential, and control-plane trust boundaries.
Place access control in a service mesh
Place identity, transport, route, and application policy across mesh gateways, sidecars, ambient proxies, and workloads.
Cloud Metadata Service Risk
Cloud metadata services can deliver workload credentials, so network and identity boundaries must stop unintended callers.
Threat-model a multi-cloud access path
Trace human and workload identity across clouds and find direct, federation, routing, control-plane, and recovery bypass paths.
Evaluation questions
- Where do user and workload traffic cross a trust boundary or change identity?
- Which control protects the route, service, namespace, object, action, and direct path?
- How do cloud, cluster, mesh, identity, and gateway policy interact during failure?
Completion conditions
- Draw one cross-cloud or cluster access path with every control and credential boundary.
- Prove another workload, namespace, audience, direct endpoint, and stale credential fail.
