Skip to main content

Design cloud-native access boundaries

Combine named application access, segmentation, workload identity, Kubernetes authorization, and multi-cloud trust.

Learning outcomes

  • Separate control-plane, data-plane, ingress, egress, east-west, and north-south paths.
  • Combine network segmentation with user and workload identity policy.
  • Limit Kubernetes and service-mesh authority at both route and object layers.
  • Find direct, cross-cloud, node, metadata, credential, and recovery bypass paths.

Scenario

Applications span a data center, cloud virtual network, and Kubernetes cluster. Users need selected services, but no one needs a route to every subnet. Enforcement must reach each upstream without creating a bypass.

Ordered learning units

  1. Concept

    Load Balancer and Gateway

    A load balancer selects a backend, while a gateway terminates or mediates a protocol boundary and can apply policy.

  2. Concept

    Control Plane and Data Plane

    Separate the systems that define and distribute access policy from the request path that enforces it on live traffic.

  3. Concept

    Ingress and Egress

    Place controls on traffic entering and leaving a workload boundary without treating direction or network location as identity.

  4. Concept

    Firewall

    A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

  5. Concept

    Workload Identity

    Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

  6. Concept

    Kubernetes Service Account

    Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.

  7. Concept

    Kubernetes RBAC

    Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.

  8. Concept

    Kubernetes NetworkPolicy

    Kubernetes NetworkPolicy controls selected Pod ingress and egress reachability through a supporting network plugin.

  9. Concept

    Kubernetes Gateway API

    Gateway API models infrastructure, listeners, routes, backends, and policy attachment through role-oriented resources.

  10. Concept

    Cloud Metadata Service Risk

    Cloud metadata services can deliver workload credentials, so network and identity boundaries must stop unintended callers.

Evaluation questions

  • Where do user and workload traffic cross a trust boundary or change identity?
  • Which control protects the route, service, namespace, object, action, and direct path?
  • How do cloud, cluster, mesh, identity, and gateway policy interact during failure?

Completion conditions

  • Draw one cross-cloud or cluster access path with every control and credential boundary.
  • Prove another workload, namespace, audience, direct endpoint, and stale credential fail.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo