±à¼ÍƼö: |
±¾ÎĽéÉÜÁËÁãÐÅÈΰ²È«¼Ü¹¹µÄÁãÐÅÈÎÀíÄî¡¢ÁãÐÅÈÎÓ봫ͳ°²È«²úÆ·/É豸µÄ¹ØÏµ¼°ÁãÐÅÈβο¼¼Ü¹¹¡£Ï£Íû¶ÔÄúµÄѧϰÓÐËù°ïÖú¡£
±¾ÎÄÀ´×ÔÓÚCSDN£¬ÓÉ»ðÁú¹ûÈí¼þLinda±à¼¡¢ÍƼö¡£ |
|
¼ò½é
ÁãÐÅÈΰ²È«×îÔçÓÉÖøÃûÑо¿»ú¹¹ Forrester µÄÊ×ϯ·ÖÎöʦԼº².½ðµÂά¸ñÔÚ 2010 ÄêÌá³ö¡£ÁãÐÅÈΰ²È«Õë¶Ô´«Í³±ß½ç°²È«¼Ü¹¹Ë¼Ïë½øÐÐÁËÖØÐÂÆÀ¹ÀºÍÉóÊÓ£¬²¢¶Ô°²È«¼Ü¹¹Ë¼Â·¸ø³öÁËеĽ¨Òé¡£
ÆäºËÐÄ˼ÏëÊÇ£¬Ä¬ÈÏÇé¿öϲ»Ó¦¸ÃÐÅÈÎÍøÂçÄÚ²¿ºÍÍⲿµÄÈκÎÈË/É豸/ϵͳ£¬ÐèÒª»ùÓÚÈÏÖ¤ºÍÊÚÈ¨ÖØ¹¹·ÃÎÊ¿ØÖƵÄÐÅÈλù´¡¡£ÖîÈç
IP µØÖ·¡¢Ö÷»ú¡¢µØÀíλÖá¢Ëù´¦ÍøÂçµÈ¾ù²»ÄÜ×÷Ϊ¿ÉÐŵį¾Ö¤¡£ÁãÐÅÈζԷÃÎÊ¿ØÖƽøÐÐÁË·¶Ê½Éϵĵ߸²£¬Òýµ¼°²È«Ìåϵ¼Ü¹¹´Ó¡°ÍøÂçÖÐÐÄ»¯¡±×ßÏò¡°Éí·ÝÖÐÐÄ»¯¡±£¬Æä±¾ÖÊËßÇóÊÇÒÔÉí·ÝΪÖÐÐĽøÐзÃÎÊ¿ØÖÆ¡£
ĿǰÂ䵨ÁãÐÅÈθÅÄî°üÀ¨ Google BeyondCorp¡¢Google ALTS¡¢Azure Zero
Trust Framework µÈ£¬ÔÆÉÏÁãÐÅÈÎÌåϵ£¬Ä¿Ç°»¹ÊÇÒ»¸öÐÂÐ˵ļ¼ÊõÇ÷ÊÆ·½Ïò£¬Í¬ÑùµÄÁãÐÅÈÎÄ£ÐÍҲͬÑùÊÊÓÃÓÚ
Kubernetes£¬±¾ÎÄÖØµã½²½âһϠKubernetes ÏÂÁãÐÅÈΰ²È«¼Ü¹¹µÄ¼¼Êõ·ÖÎö¡£
´«Í³ÁãÐÅÈθÅÄîºÍĿǰÂ䵨Çé¿ö
1. Microsoft Azure
Azure µÄÁãÐÅÈÎÏà¶ÔÀ´Ëµ»¹ÊDZȽÏÍêÉÆµÄ£¬´ÓÌåϵ½Ç¶ÈÀ´¿´º¸ÇÁ˶ˡ¢ÔÆ¡¢On-Permises¡¢SaaS
µÈÓ¦Óã¬ÏÂÃæÎÒÃÇ·ÖÎöÒ»ÏÂÏà¹ØµÄ×é¼þ£º
Óû§ Identity£ºÈ»ºóͨ¹ý Identity Provider£¨´´½¨¡¢Î¬»¤ºÍ¹ÜÀíÓû§Éí·ÝµÄ×é¼þ£©µÄÈÏÖ¤£¬ÔÙÈÏÖ¤µÄ¹ý³ÌÖпÉÒÔʹÓÃÕ˺ÅÃÜÂ룬Ҳ¿ÉÒÔʹÓÃ
MFA£¨Multi Factor Auth£©¶àÒòËØÈÏÖ¤µÄ·½Ê½£¬¶àÒòËØÈÏÖ¤°üÀ¨Èí¡¢Ó² Token¡¢SMS¡¢ÈËÌåÌØÕ÷µÈ£»
É豸 Identity£ºÉ豸°üº¬Á˹«Ë¾µÄÉ豸ÒÔ¼°Ã»ÓÐͳһ¹ÜÀíµÄÉ豸£¬ÕâЩÉ豸µÄÐÅÏ¢£¬°üº¬ IP µØÖ·¡¢MAC
µØÖ·¡¢°²×°µÄÈí¼þ¡¢²Ù×÷ϵͳ°æ±¾¡¢²¹¶¡×´Ì¬µÈ´æ´¢µ½ Device Inventory£»ÁíÍâÉ豸Ҳ»áÓÐÏàÓ¦µÄ
Identity À´Ö¤Ã÷É豸µÄÉí·Ý£»É豸»áÓжÔÓ¦µÄÉ豸״̬¡¢É豸µÄ·çÏÕ½øÐÐÅж¨£»
Security Policy Enforcement£ºÍ¨¹ýÊÕ¼¯µÄÓû§ Identity ÒÔ¼°×´Ì¬¡¢É豸µÄÐÅÏ¢£¬×´Ì¬ÒÔ¼°
Identity ºó£¬SPE ²ßÂÔ½øÐÐ×ۺϵÄÅж¨£¬Í¬Ê±¿ÉÒÔ½áºÏ Threat Intelligence
À´ÔöÇ¿ SPE µÄ²ßÂÔÅж¨µÄ·¶Î§ºÍ×¼±¸ÐÔ£»²ßÂÔµÄÀý×Ó°üÀ¨¿ÉÒÔ·ÃÎʺóÃæµÄ Data¡¢Apps¡¢Infrastructure¡¢Network£»
Data£ºÕë¶ÔÊý¾Ý£¨Emails¡¢Documents£©½øÐзÖÀà¡¢±êÇ©¡¢¼ÓÃܵIJßÂÔ£»
Apps£º¿ÉÒÔ×ÔÊÊÓ¦·ÃÎʶÔÓ¦µÄ SaaS Ó¦ÓÃºÍ On-Permises Ó¦Óã»
Infrastructure£º°üÀ¨ IaaS¡¢PaaS¡¢Container¡¢Serverless ÒÔ¼°
JIT£¨°´Ð迪Æô·ÃÎÊ£©ºÍ GIT °æ±¾¿ØÖÆÈí¼þ£»
Network£ºÕë¶ÔÍøÂç½»¸¶¹ý³ÌÒÔ¼°ÄÚ²¿µÄ΢¸ôÀë½øÐвßÂÔ´òͨ¡£

ÏÂÃæÕâÕÅ΢ÈíµÄͼ½øÐÐÁ˸ü¼Óϸ»¯µÄ½²½â£º
Óû§£¨Ô±¹¤¡¢ºÏ×÷»ï°é¡¢Óû§µÈ£©°üÀ¨ Azure AD¡¢ADFS¡¢MSA¡¢Google ID µÈ£»
É豸£¨¿ÉÐŵĺϹæÉ豸£©°üÀ¨ Android¡¢iOS¡¢MacOS¡¢Windows¡¢Windows Defender
ATP£»
¿Í»§¶Ë£¨¿Í»§¶Ë APP ÒÔ¼°ÈÏÖ¤·½Ê½£©°üÀ¨ä¯ÀÀÆ÷ÒÔ¼°¿Í»§¶ËÓ¦Óã¬Î»Öã¨ÎïÀíºÍÐéÄâµØÖ·£©°üÀ¨µØÖ·Î»ÖÃÐÅÏ¢¡¢¹«Ë¾ÍøÂçµÈ¡£
ÀûÓà Microsoft µÄ»úÆ÷ѧϰ ML¡¢ÊµÊ±ÆÀ¹ÀÒýÇæ¡¢²ßÂԵȽøÐÐÕë¶ÔÓû§¡¢¿Í»§¶Ë¡¢Î»ÖúÍÉ豸½øÐÐ×ÛºÏÅж¨£¬À´³ÖÐø×ÔÊÊÓ¦µÄ·ÃÎÊ
On-Permises¡¢Cloud SaaS Apps¡¢Microsoft Cloud£¬°üº¬µÄ²ßÂÔ°üÀ¨
Allow¡¢Deny£¬ÏÞÖÆ·ÃÎÊ¡¢¿ªÆô MFA¡¢Ç¿ÖÆÃÜÂëÖØÖá¢×èÖ¹ºÍËø¶¨·Ç·¨ÈÏÖ¤µÈ¡£
´ÓÏÂͼ¿ÉÒÔ¿´³ö Azure ÒѾ´òͨÁË On-Permises¡¢Cloud¡¢SaaS µÈ¸÷¸ö²ãÃæ£¬¹¹½¨ÁËÒ»¸ö´ó¶øÈ«µÄÁãÐÅÈÎÌåϵ¡£

2. Google BeyondCorp
Google BeyondCorp ÊÇΪÁËÓ¦¶ÔÐÂÐÍÍøÂçÍþвµÄÒ»ÖÖÍøÂ簲ȫ½â¾ö·½°¸£¬Æäʵ Google
BeyondCorp ±¾Éí²¢Ã»ÓÐÌ«¶àµÄ¼¼ÊõÉϵĸüл»´ú£¬¶øÊÇÀûÓÃÁ˳ÖÐøÑéÖ¤µÄÒ»ÖÖ˼·À´×öµÄ£¬È¥µôÁË
VPN ºÍ²»ÔÙ·ÖÄÚÍâÍø¡£
Google ÔÚ 2014 Äê֮ǰ¾ÍÔ¤²âµ½»¥ÁªÍøºÍÄÚÍøµÄ°²È«ÐÔÊÇÒ»ÑùΣÏյģ¬ÒòΪһµ©ÄÚÍø±ß½ç±»Í»ÆÆµÄ»°£¬¹¥»÷Õ߾ͺÜÈÝÒ׵ķÃÎÊÆóÒµµÄһЩÄÚ²¿Ó¦Óã¬ÓÉÓÚ°²È«ÒâʶµÄÎÊÌâµ¼ÖÂÆóÒµ»áÈÏΪÄÚ²¿ºÜ°²È«£¬¾Í¶ÔÄÚ²¿µÄÓ¦ÓýøÐеÍÓÅÏȼ¶±ðµÄ´¦Àí£¬µ¼Ö´óÁ¿ÄÚ²¿µÄ°²È«ÎÊÌâ´æÔÚ¡£
ÏÖÔ򵀮óÒµÔ½À´Ô½¶àµÄÓ¦ÓÃÒÆ¶¯ºÍÔÆ¼¼Êõ£¬µ¼Ö±߽籣»¤Ô½À´Ô½ÄÑ¡£ËùÒÔ Google ¸É´àÒ»ÊÓͬÈÊ£¬²»·ÖÄÚÍⲿ£¬ÓÃÒ»ÑùµÄ°²È«ÊÖ¶ÎÈ¥·ÀÓù¡£
´Ó¹¥·À½Ç¶ÈÀ´¿´Ò»Ï Google µÄ BeyondCorp Ä£ÐÍ£º
ÀýÈç·ÃÎÊ Google ÄÚ²¿Ó¦Óà http://blackberry.corp.google.com
£¬Ëü»áÌø×ªµ½ https://login.corp.google.com/ Ò²¾ÍÊÇ Google Moma
ϵͳ£¬Ê×ÏÈÐèÒªÊäÈëÕ˺ÅÃÜÂë²ÅÄܵǽ£¬Õâ¸öµÇ¼µÄ¹ý³ÌÖлáÕë¶ÔÉ豸ÐÅÏ¢¡¢Óû§ÐÅÏ¢½øÐÐ×ÛºÏÅж¨£¬Õ˺ÅÃÜÂëÕýÈ·ÒÔ¼°É豸ÐÅϢͨ¹ý¹æÔòÒýÇæÑéÖ¤Ö®ºó£¬»á¼ÌÐøÌø×ªµ½ÐèÒª
YubiKey µÇ¼½çÃæ£¬Ã¿¸ö Google µÄÔ±¹¤¶¼»áÓÐ Yubikey£¬Í¨¹ý Yubikey À´×ö¶þ´ÎÑéÖ¤¡£
Yubikey µÄ¼ÛÖµ£¬Google ÈÏΪÊÇ¿ÉÒÔÍêÈ«¶Å¾øµöÓã¹¥»÷µÄ¡£ÁíÍâÀàËÆµÄ¾ÍÊÇ Amazon µÄ
Midway-Auth ·½Ê½¡£

Kubernetes ÏÂÈÝÆ÷ÁãÐÅÈÎÄ£ÐÍ
1. ÈÝÆ÷ÏÂÍøÂçÁãÐÅÈÎ
Ê×ÏȽéÉÜÒ»ÏÂÈÝÆ÷ϵÄÍøÂçÁãÐÅÈÎ×é¼þ Calico£¬Calico ÊÇÕë¶ÔÈÝÆ÷£¬ÐéÄâ»úºÍ»ùÓÚÖ÷»úµÄ±¾»ú
Workload µÄ¿ªÔ´ÍøÂçºÍÍøÂ簲ȫ½â¾ö·½°¸²úÆ·¡£
Calico Ö§³Ö¹ã·ºµÄƽ̨£¬°üÀ¨ Kubernetes¡¢OpenShift¡¢Docker EE¡¢OpenStack
ºÍÂã½ðÊô·þÎñ¡£ÁãÐÅÈÎ×î´óµÄ¼ÛÖµ¾ÍÊǼ´Ê¹¹¥»÷Õßͨ¹ýÆäËû¸÷ÖÖÊÖ·¨ÆÆ»µÓ¦ÓóÌÐò»ò»ù´¡¼Ü¹¹£¬ÁãÐÅÈÎÍøÂçÒ²¾ßÓе¯ÐÔ¡£ÁãÐÅÈμܹ¹Ê¹µÃʹ¹¥»÷ÕßÄÑÒÔºáÏòÒÆ¶¯£¬Õë¶ÔÐԵIJȵã»î¶¯Ò²¸üÈÝÒ×·¢ÏÖ¡£
ÔÚÈÝÆ÷ÍøÂçÁãÐÅÈÎÌåϵÏ£¬Calico+Istio ĿǰÊDZȽÏÈȵÄÒ»Ì×½â¾ö·½°¸£»ÏÈÀ´¿´¿´Á½ÕßµÄһЩ²î±ð£¬´Ó²î±ðÉÏ¿ÉÒÔ¿´µ½
Istio ÊÇÕë¶Ô Pod ²ã Workload µÄ·ÃÎÊ¿ØÖÆ£¬ÒÔ¼° Calico Õë¶Ô Node ²ãµÄ·ÃÎÊ¿ØÖÆ£º

ÏÂÃæÖØµã½²½âһϠCalico ×é¼þºÍ Istio µÄһЩ¼¼Êõϸ½Ú£¬Calico ¹¹½¨ÁËÒ»¸ö 3 ²ã¿É·ÓÉÍøÂ磬ͨ¹ý
Calico µÄ Felix£¨ÊÇÔËÐÐÔÚ Node µÄÊØ»¤³ÌÐò£¬ËüÔÚÿ¸ö Node ×ÊÔ´ÉÏÔËÐС£
Felix ¸ºÔð±àÖÆÂ·ÓÉºÍ ACL ¹æÔòÒÔ¼°Ôڸà Node Ö÷»úÉÏËùÐèµÄÈÎºÎÆäËûÄÚÈÝ£¬ÒÔ±ãΪ¸ÃÖ÷»úÉϵÄ×ÊÔ´Õý³£ÔËÐÐÌṩËùÐèµÄÍøÂçÁ¬½Ó£©ÔËÐÐÔÚÿ¸ö
Node ÉÏ£¬Ö÷Òª×ö·ÓÉºÍ ACL µÄ²ßÂÔÒÔ¼°´î½¨ÍøÂ磻ͨ¹ýÔËÐÐÔÚ Node É쵀 Iptables
½øÐÐϸÁ£¶ÈµÄ·ÃÎÊ¿ØÖÆ¡£
¿ÉÒÔͨ¹ý Calico ÉèÖÃĬÈÏ Deny µÄ²ßÂÔ£¬È»ºóͨ¹ý×ÔÊÊÓ¦µÄ·ÃÎÊ¿ØÖÆÀ´½øÐÐ×îС»¯µÄ·ÃÎÊ¿ØÖƲßÂÔµÄÖ´ÐУ¬´Ó¶ø¹¹½¨ÈÝÆ÷ϵÄÁãÐÅÈÎÌåϵ£»Dikastes/Envoy£º¿ÉÑ¡µÄ
Kubernetes sidecars£¬¿ÉÒÔͨ¹ýÏ໥ TLS Éí·ÝÑéÖ¤±£»¤ Workload µ½ Workload
µÄͨÐÅ£¬²¢Ôö¼ÓÏà¹ØµÄ¿ØÖƲßÂÔ¡£

2. Istio
ÔÚ½²½â Istio ֮ǰÏȽ²Ò»ÏÂ΢·þÎñµÄһЩ°²È«ÐèÇóºÍ·çÏÕ·ÖÎö£º
΢·þÎñ±»Í»ÆÆÖ®ºóͨ¹ý Sniffer ¼à¿ØÁ÷Á¿£¬½ø¶ø½øÐÐÖмäÈ˹¥»÷£¬ÎªÁ˽â¾öÕâÖÖ·çÏÕÐèÒª¶ÔÁ÷Á¿½øÐмÓÃÜ£»
ΪÁËÕë¶Ô΢·þÎñºÍ΢·þÎñÖ®¼äµÄ·ÃÎÊ¿ØÖÆ£¬ÐèҪ˫Ïò TLS ºÍϸÁ£¶ÈµÄ·ÃÎʲßÂÔ£»
ÒªÉóºËËÔÚʲôʱºò×öÁËʲô£¬ÐèÒªÉ󼯹¤¾ß¡£
·ÖÎöÁ˶ÔÓ¦µÄ·çÏÕÖ®ºó£¬ÏÂÃæÀ´½âÊÍһϠIstio ÈçºÎʵÏÖµÄÁãÐÅÈμܹ¹¡£
Ê×ÏȺÜÃ÷ÏÔµÄÒ»¸öÌØµã¾ÍÊÇÈ«Á´Â·¶¼ÊÇË«Ïò mTLS ½øÐмÓÃܵģ¬µÚ¶þ¸öÌØµã¾ÍÊÇ΢·þÎñºÍ΢·þÎñÖ®¼äµÄ·ÃÎÊÒ²¿ÉÒÔ½øÐмøÈ¨£¬Í¨¹ýȨÏÞ·ÃÎÊÖ®ºó»¹ÐèÒª½øÐÐÉ󼯡£Istio
ÊÇÊý¾ÝÃæºÍ¿ØÖÆÃæ½øÐзÖÀëµÄ£¬¿ØÖÆÃæÊÇͨ¹ý Pilot ½«ÊÚȨ²ßÂԺͰ²È«ÃüÃûÐÅÏ¢·Ö·¢¸ø Envoy£¬È»ºóÊý¾ÝÃæÍ¨¹ý
Envoy À´½øÐÐ΢·þÎñµÄͨÐÅ¡£
ÔÚÿ¸ö΢·þÎñµÄ Workload É϶¼»á²¿Êð Envoy£¬Ã¿¸ö Envoy ´úÀí¶¼ÔËÐÐÒ»¸öÊÚȨÒýÇæ£¬¸ÃÒýÇæÔÚÔËÐÐʱÊÚȨÇëÇó¡£µ±ÇëÇóµ½´ï´úÀíʱ£¬ÊÚȨÒýÇæ¸ù¾Ýµ±Ç°ÊÚȨ²ßÂÔÆÀ¹ÀÇëÇóÉÏÏÂÎÄ£¬²¢·µ»ØÊÚȨ½á¹û
ALLOW »ò DENY¡£

3. ΢·þÎñÏ嵀 Zero Trust API °²È«
42Crunch ½« API °²È«´ÓÆóÒµ±ßÔµÀ©Õ¹µ½ÁËÿ¸öµ¥¶ÀµÄ΢·þÎñ£¬²¢Í¨¹ý¿É´ó¹æÄ£²¿ÊðµÄ³¬µÍÑÓ³Ù΢
API ·À»ðǽÀ´½øÐб£»¤¡£
42Crunch API ·À»ðǽµÄ²¿ÊðģʽÊÇÒÔ Kubernetes Pod ÖÐÒÔ Sidecar
´úÀíģʽ²¿Ê𣬺ÁÃë¼¶±ðµÄÐÔÄÜÏìÓ¦£¬ÕâʡȥÁ˱àдºÍά»¤µ¥¸ö API °²È«²ßÂÔ¹ý³Ì£¬²¢ÊµÊ©ÁËÁãÐÅÈΰ²È«Ìåϵ½á¹¹£¬ÌáÉýÁË΢·þÎñϵÄ
API °²È«ÐÔ¡£42Crunch µÄ API °²È«ÄÜÁ¦°üÀ¨£º
ÉóºË£ºÔËÐÐ 200 ¶à¸ö OpenAPI ¹æ·¶¶¨ÒåµÄ°²È«ÉóºË²âÊÔ£¬²¢½øÐÐÏêϸµÄ°²È«ÆÀ·Ö£¬ÒÔ°ïÖú¿ª·¢ÈËÔ±¶¨ÒåºÍ¼ÓÇ¿
API °²È«£»
ɨÃ裺ɨÃèʵʱ API ¶Ëµã£¬ÒÔ·¢ÏÖDZÔڵĩ¶´£»
±£»¤£º±£»¤ API ²¢ÔÚÓ¦ÓÃÉϲ¿ÊðÇáÁ¿¼¶£¬µÍÑÓ³Ù Micro API Firewall¡£
4. ÂìÒÏÁãÐÅÈμܹ¹ÌåϵÂ䵨×î¼Ñʵ¼ù
Ëæ×Å Service Mesh ¼Ü¹¹µÄÑݽø£¬ÂìÒÏÒѾ¿ªÊ¼ÔÚÄÚ²¿Â䵨 Workload ³¡¾°ÏµķþÎñ¼øÈ¨ÄÜÁ¦£¬ÈçºÎ½¨ÉèÒ»Ì×·ûºÏÂìÒϼܹ¹µÄ
Workload ¼äµÄ·þÎñ¼øÈ¨ÄÜÁ¦£¬ÎÒÃǽ«ÎÊÌâ·ÖΪһÏÂÈý¸ö×ÓÎÊÌ⣺
Workload µÄÉí·ÝÈçºÎ¶¨Ò壬ÈçºÎÄܹ»ÊµÏÖÒ»Ì×ͨÓõÄÉí·Ý±êʶµÄÌåϵ£»
Workload ¼ä·ÃÎʵÄÊÚȨģÐ͵ÄʵÏÖ£»
·ÃÎÊ¿ØÖÆÖ´ÐеãÈçºÎÑ¡Ôñ¡£
Workload Éí·Ý¶¨Òå & ÈÏÖ¤·½Ê½
ÂìÒÏÄÚ²¿Ê¹Óà SPIFFE ÏîÄ¿Öиø³öµÄ Identity ¸ñʽÀ´ÃèÊö Workload µÄÉí·Ý£¬¼´£º
spiffe://<domain>/cluster/<cluster>/ns/<namespace> |
²»¹ýÔÚ¹¤³ÌÂ䵨¹ý³ÌÖз¢ÏÖ£¬ÕâÖÖά¶ÈµÄÉí·Ý¸ñʽÁ£¶È²»¹»Ï¸£¬²¢ÇÒÓë Kubernetes ¶ÔÓÚ namespace
µÄ»®·Ö¹æÔòÓнÏÇ¿µÄñîºÏ¡£ÂìÒϵÄÌåÁ¿½Ï´ó£¬³¡¾°½Ï¶à£¬²»Í¬³¡¾°Ï namespace µÄ»®·Ö¹æÔò¶¼²»ÍêȫһÖ¡£Òò´ËÎÒÃǶԸñʽ½øÐÐÁ˵÷Õû£¬ÔÚÿһ³¡¾°ÏÂÊáÀí³öÄܹ»±êʶһ¸ö
Workload ʾÀýËùÐëÒªµÄÒ»×鱨±¸ÊôÐÔ£¨ÀýÈçÓ¦ÓÃÃû£¬»·¾³ÐÅÏ¢µÈ£©£¬²¢½«ÕâЩÊôÐÔЯ´øÔÚ Pod µÄ
Labels ÖС£µ÷ÕûºóµÄ¸ñʽÈçÏ£º
spiffe://<domain>/cluster/<cluster>
/<required_attr_1_name>/<required_attr_1_value> /<required_attr_2_name> /<required_attr_2_value> |
ÅäºÏÕâ¸öÉí·Ý¸ñʽ±ê×¼£¬ÎÒÃÇÔÚ Kubernetes API Server ÖÐÌí¼ÓÁË Validating
Webhook ×é¼þ£¬¶ÔÉÏÊö Labels ÖбØÐëЯ´øµÄÊôÐÔÐÅÏ¢½øÐÐУÑé¡£Èç¹ûȱÉÙÆäÖÐÒ»ÏîÊôÐÔÐÅÏ¢£¬ÔòʵÀý
Pod ½«ÎÞ·¨´´½¨¡£ÈçÏÂͼËùʾ£º

ÔÚ½â¾öÁË Workload Éí·Ý¶¨ÒåµÄÎÊÌâºó£¬Ê£ÏµľÍÊÇÈçºÎ½«Éí·Ýת»»³ÉijÖÖ¿ÉУÑéµÄ¸ñʽ£¬ÔÚ Workload
Ö®¼äµÄ·þÎñµ÷ÓÃÁ´Â·ÖÐ͸´«¡£ÎªÁËÖ§³Ö²»Í¬µÄʹÓó¡¾°£¬ÎÒÃÇÑ¡ÔñÁË X.509 Ö¤ÊéÓë JWT ÕâÁ½ÖÖ¸ñʽ¡£
¶ÔÓÚ Service Mesh ¼Ü¹¹µÄ³¡¾°£¬ÎÒÃǽ«Éí·ÝÐÅÏ¢´æ·ÅÔÚ X.509 Ö¤ÊéµÄ Subject
×Ö¶ÎÖУ¬ÒÔ´ËÀ´Ð¯´ø Workload µÄÉí·ÝÐÅÏ¢¡£ÈçÏÂͼËùʾ£º

¶ÔÓÚÆäËû³¡¾°£¬ÎÒÃǽ«Éí·ÝÐÅÏ¢´æ·ÅÔÚ JWT µÄ Claims ÖУ¬¶ø JWT µÄ°ä·¢ÓëУÑ飬²ÉÓÃÁË
Secure Sidecar Ìṩ·þÎñ¡£ÈçÏÂͼËùʾ£º

ÊÚȨģÐÍ
ÔÚÏîÄ¿Â䵨µÄ³õÆÚ£¬Ê¹Óà RBAC Ä£ÐÍÀ´ÃèÊö Workload ¼ä·þÎñµ÷ÓõÄÊÚȨ²ßÂÔ¡£¾ÙÀýÃèÊö£¬Ó¦ÓÃ
A µÄijһ¸ö·þÎñ£¬Ö»Äܱ»Ó¦Óà B µ÷Óá£ÕâÖÖÊÚȨ²ßÂÔÔÚ´ó¶àÊý³¡¾°Ï¶¼Ã»ÓÐÎÊÌ⣬²»¹ýÔÚÏîÄ¿ÍÆ½ø¹ý³ÌÖУ¬ÎÒÃÇ·¢ÏÖÕâÖÖÊÚȨ²ßÂÔ²»ÊÊÓÃÓÚ²¿·ÖÌØÊⳡ¾°¡£
ÎÒÃÇ¿¼ÂÇÕâÑùÒ»¸ö³¡¾°£¬Éú²úÍøÄÚ²¿ÓÐÒ»¸öÓ¦Óà A£¬Ö°ÔðÊǶÔÉú²úÍøÄÚ²¿µÄËùÓÐÓ¦ÓÃÔÚÔËÐÐʱËùÐèҪʹÓõÄһЩ¶¯Ì¬ÅäÖÃÌṩÖÐÐÄ»¯µÄ·þÎñ¡£Õâ¸ö·þÎñµÄ¶¨ÒåÈçÏ£º
A Ó¦Óà - »ñÈ¡¶¯Ì¬ÅäÖÃµÄ RPC ·þÎñ£º
message FetchResourceRequest
{// The appname of invokerstring appname = 1;//
The ID of resourcestring resource_id = 2;} message
FetchResourceResponse {string data = 1;} service
DynamicResourceService {rpc FetchResource (FetchResourceRequest)
returns (FetchResourceResponse) {}} |
Ôڴ˳¡¾°Ï£¬Èç¹ûÒÀȻʹÓà RBAC Ä£ÐÍ£¬Ó¦Óà A µÄ·ÃÎÊ¿ØÖƲßÂÔ½«ÎÞ·¨ÃèÊö£¬ÒòΪËùÓÐÓ¦Óö¼ÐèÒª·ÃÎÊ
A Ó¦ÓõķþÎñ¡£µ«ÊÇÕâÑù»áµ¼ÖÂÏÔ¶øÒ×¼ûµÄ°²È«ÎÊÌ⣬µ÷Ó÷½Ó¦Óà B ¿ÉÒÔͨ¹ý¸Ã·þÎñ»ñÈ¡µ½ÆäËüÓ¦ÓõÄ×ÊÔ´¡£
Òò´ËÎÒÃǽ« RBAC Ä£ÐÍÉý¼¶Îª ABAC Ä£ÐÍÀ´½â¾öÉÏÊöÎÊÌâ¡£ÎÒÃDzÉÓà DSL ÓïÑÔÀ´ÃèÊö ABAC
µÄÂß¼£¬²¢ÇÒ¼¯³ÉÔÚ Secure Sidecar ÖС£
·ÃÎÊ¿ØÖÆÖ´ÐеãµÄÑ¡Ôñ
ÔÚÖ´ÐеãÑ¡Ôñ·½Ã棬¿¼Âǵ½ Service Mesh ¼Ü¹¹ÍƽøÐèÒªÒ»¶¨µÄʱ¼ä£¬ÎÒÃÇÌṩÁËÁ½²»Í¬µÄ·½Ê½£¬¿ÉÒÔ¼æÈÝ
Service Mesh µÄ¼Ü¹¹£¬Ò²¿ÉÒÔ¼æÈݵ±Ç°³¡¾°¡£
ÔÚ Service Mesh ¼Ü¹¹³¡¾°Ï£¬RBAC Filter ºÍ ABAC Filter£¨Access
Control Filter£©¼¯³ÉÔÚ Mesh Sidecar ÖС£

ÔÚµ±Ç°³¡¾°Ï£¬ÎÒÃÇĿǰÌṩÁË JAVA SDK£¬Ó¦ÓÃÐèÒª¼¯³É SDK À´Íê³ÉËùÓÐÈÏÖ¤ºÍÊÚȨÏà¹ØµÄÂß¼¡£Óë
Service Mesh ¼Ü¹¹³¡¾°ÀàËÆ£¬ËùÓÐ Identity µÄ°ä·¢¡¢Ð£Ñ飬ÊÚȨÓë Secure
Sidecar ½»»¥£¬ÓÉ Secure Sidecar Íê³É¡£

½áÓï
ÁãÐÅÈεĺËÐÄÊÇ "Never Trust, Always Verify"£¬Î´À´»á¼ÌÐøÉÁãÐÅÈÎÔÚÕû¸ö°¢Àï°Í°ÍµÄʵ¼ù£¬¸³Ó費ͬµÄ½ÇÉ«²»Í¬µÄÉí·Ý£¬ÀýÈçÆóÒµÔ±¹¤¡¢Ó¦ÓᢻúÆ÷£¬²¢½«·ÃÎÊ¿ØÖƵãϳÁµ½ÔÆÔÉú»ù´¡ÉèÊ©µÄ¸÷¸öµã£¬ÊµÏÖÈ«¾ÖϸÁ£¶ÈµÄ¿ØÖÆ£¬´òÔ찲ȫ·À»¤µÄб߽硣
±¾ÎÄ´ÓÒµ½çµÄÁãÐÅÈÎÌåϵµÄÂ䵨×î¼Ñʵ¼ù£¬µ½»ùÓÚ Kubernetes µÄÁãÐÅÈÎÂ䵨·½Ê½½øÐÐÁ˼òµ¥µÄÃèÊö£¬±¾ÎÄÖ»ÊÇÅ×שÒýÓñ£¬Ï£ÍûÄÜÒý·¢¸ü¶à¹ØÓÚ
¡£
|