Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
Kubernetes ÏÂÁãÐÅÈΰ²È«¼Ü¹¹·ÖÎö
 
×÷ÕߣºÎµ1
  2199  次浏览      29
2021-8-6
 
±à¼­ÍƼö:
±¾ÎĽéÉÜÁËÁãÐÅÈΰ²È«¼Ü¹¹µÄÁãÐÅÈÎÀíÄî¡¢ÁãÐÅÈÎÓ봫ͳ°²È«²úÆ·/É豸µÄ¹ØÏµ¼°ÁãÐÅÈβο¼¼Ü¹¹¡£Ï£Íû¶ÔÄúµÄѧϰÓÐËù°ïÖú¡£
±¾ÎÄÀ´×ÔÓÚCSDN£¬ÓÉ»ðÁú¹ûÈí¼þLinda±à¼­¡¢ÍƼö¡£

¼ò½é

ÁãÐÅÈΰ²È«×îÔçÓÉÖøÃûÑо¿»ú¹¹ Forrester µÄÊ×ϯ·ÖÎöʦԼº².½ðµÂά¸ñÔÚ 2010 ÄêÌá³ö¡£ÁãÐÅÈΰ²È«Õë¶Ô´«Í³±ß½ç°²È«¼Ü¹¹Ë¼Ïë½øÐÐÁËÖØÐÂÆÀ¹ÀºÍÉóÊÓ£¬²¢¶Ô°²È«¼Ü¹¹Ë¼Â·¸ø³öÁËеĽ¨Òé¡£

ÆäºËÐÄ˼ÏëÊÇ£¬Ä¬ÈÏÇé¿öϲ»Ó¦¸ÃÐÅÈÎÍøÂçÄÚ²¿ºÍÍⲿµÄÈκÎÈË/É豸/ϵͳ£¬ÐèÒª»ùÓÚÈÏÖ¤ºÍÊÚÈ¨ÖØ¹¹·ÃÎÊ¿ØÖƵÄÐÅÈλù´¡¡£ÖîÈç IP µØÖ·¡¢Ö÷»ú¡¢µØÀíλÖá¢Ëù´¦ÍøÂçµÈ¾ù²»ÄÜ×÷Ϊ¿ÉÐŵį¾Ö¤¡£ÁãÐÅÈζԷÃÎÊ¿ØÖƽøÐÐÁË·¶Ê½Éϵĵ߸²£¬Òýµ¼°²È«Ìåϵ¼Ü¹¹´Ó¡°ÍøÂçÖÐÐÄ»¯¡±×ßÏò¡°Éí·ÝÖÐÐÄ»¯¡±£¬Æä±¾ÖÊËßÇóÊÇÒÔÉí·ÝΪÖÐÐĽøÐзÃÎÊ¿ØÖÆ¡£

ĿǰÂ䵨ÁãÐÅÈθÅÄî°üÀ¨ Google BeyondCorp¡¢Google ALTS¡¢Azure Zero Trust Framework µÈ£¬ÔÆÉÏÁãÐÅÈÎÌåϵ£¬Ä¿Ç°»¹ÊÇÒ»¸öÐÂÐ˵ļ¼ÊõÇ÷ÊÆ·½Ïò£¬Í¬ÑùµÄÁãÐÅÈÎÄ£ÐÍҲͬÑùÊÊÓÃÓÚ Kubernetes£¬±¾ÎÄÖØµã½²½âһϠKubernetes ÏÂÁãÐÅÈΰ²È«¼Ü¹¹µÄ¼¼Êõ·ÖÎö¡£

´«Í³ÁãÐÅÈθÅÄîºÍĿǰÂ䵨Çé¿ö

1. Microsoft Azure

Azure µÄÁãÐÅÈÎÏà¶ÔÀ´Ëµ»¹ÊDZȽÏÍêÉÆµÄ£¬´ÓÌåϵ½Ç¶ÈÀ´¿´º­¸ÇÁ˶ˡ¢ÔÆ¡¢On-Permises¡¢SaaS µÈÓ¦Óã¬ÏÂÃæÎÒÃÇ·ÖÎöÒ»ÏÂÏà¹ØµÄ×é¼þ£º

Óû§ Identity£ºÈ»ºóͨ¹ý Identity Provider£¨´´½¨¡¢Î¬»¤ºÍ¹ÜÀíÓû§Éí·ÝµÄ×é¼þ£©µÄÈÏÖ¤£¬ÔÙÈÏÖ¤µÄ¹ý³ÌÖпÉÒÔʹÓÃÕ˺ÅÃÜÂ룬Ҳ¿ÉÒÔʹÓà MFA£¨Multi Factor Auth£©¶àÒòËØÈÏÖ¤µÄ·½Ê½£¬¶àÒòËØÈÏÖ¤°üÀ¨Èí¡¢Ó² Token¡¢SMS¡¢ÈËÌåÌØÕ÷µÈ£»

É豸 Identity£ºÉ豸°üº¬Á˹«Ë¾µÄÉ豸ÒÔ¼°Ã»ÓÐͳһ¹ÜÀíµÄÉ豸£¬ÕâЩÉ豸µÄÐÅÏ¢£¬°üº¬ IP µØÖ·¡¢MAC µØÖ·¡¢°²×°µÄÈí¼þ¡¢²Ù×÷ϵͳ°æ±¾¡¢²¹¶¡×´Ì¬µÈ´æ´¢µ½ Device Inventory£»ÁíÍâÉ豸Ҳ»áÓÐÏàÓ¦µÄ Identity À´Ö¤Ã÷É豸µÄÉí·Ý£»É豸»áÓжÔÓ¦µÄÉ豸״̬¡¢É豸µÄ·çÏÕ½øÐÐÅж¨£»

Security Policy Enforcement£ºÍ¨¹ýÊÕ¼¯µÄÓû§ Identity ÒÔ¼°×´Ì¬¡¢É豸µÄÐÅÏ¢£¬×´Ì¬ÒÔ¼° Identity ºó£¬SPE ²ßÂÔ½øÐÐ×ۺϵÄÅж¨£¬Í¬Ê±¿ÉÒÔ½áºÏ Threat Intelligence À´ÔöÇ¿ SPE µÄ²ßÂÔÅж¨µÄ·¶Î§ºÍ×¼±¸ÐÔ£»²ßÂÔµÄÀý×Ó°üÀ¨¿ÉÒÔ·ÃÎʺóÃæµÄ Data¡¢Apps¡¢Infrastructure¡¢Network£»

Data£ºÕë¶ÔÊý¾Ý£¨Emails¡¢Documents£©½øÐзÖÀà¡¢±êÇ©¡¢¼ÓÃܵIJßÂÔ£»

Apps£º¿ÉÒÔ×ÔÊÊÓ¦·ÃÎʶÔÓ¦µÄ SaaS Ó¦ÓÃºÍ On-Permises Ó¦Óã»

Infrastructure£º°üÀ¨ IaaS¡¢PaaS¡¢Container¡¢Serverless ÒÔ¼° JIT£¨°´Ð迪Æô·ÃÎÊ£©ºÍ GIT °æ±¾¿ØÖÆÈí¼þ£»

Network£ºÕë¶ÔÍøÂç½»¸¶¹ý³ÌÒÔ¼°ÄÚ²¿µÄ΢¸ôÀë½øÐвßÂÔ´òͨ¡£

ÏÂÃæÕâÕÅ΢ÈíµÄͼ½øÐÐÁ˸ü¼Óϸ»¯µÄ½²½â£º

Óû§£¨Ô±¹¤¡¢ºÏ×÷»ï°é¡¢Óû§µÈ£©°üÀ¨ Azure AD¡¢ADFS¡¢MSA¡¢Google ID µÈ£»

É豸£¨¿ÉÐŵĺϹæÉ豸£©°üÀ¨ Android¡¢iOS¡¢MacOS¡¢Windows¡¢Windows Defender ATP£»

¿Í»§¶Ë£¨¿Í»§¶Ë APP ÒÔ¼°ÈÏÖ¤·½Ê½£©°üÀ¨ä¯ÀÀÆ÷ÒÔ¼°¿Í»§¶ËÓ¦Óã¬Î»Öã¨ÎïÀíºÍÐéÄâµØÖ·£©°üÀ¨µØÖ·Î»ÖÃÐÅÏ¢¡¢¹«Ë¾ÍøÂçµÈ¡£

ÀûÓà Microsoft µÄ»úÆ÷ѧϰ ML¡¢ÊµÊ±ÆÀ¹ÀÒýÇæ¡¢²ßÂԵȽøÐÐÕë¶ÔÓû§¡¢¿Í»§¶Ë¡¢Î»ÖúÍÉ豸½øÐÐ×ÛºÏÅж¨£¬À´³ÖÐø×ÔÊÊÓ¦µÄ·ÃÎÊ On-Permises¡¢Cloud SaaS Apps¡¢Microsoft Cloud£¬°üº¬µÄ²ßÂÔ°üÀ¨ Allow¡¢Deny£¬ÏÞÖÆ·ÃÎÊ¡¢¿ªÆô MFA¡¢Ç¿ÖÆÃÜÂëÖØÖá¢×èÖ¹ºÍËø¶¨·Ç·¨ÈÏÖ¤µÈ¡£

´ÓÏÂͼ¿ÉÒÔ¿´³ö Azure ÒѾ­´òͨÁË On-Permises¡¢Cloud¡¢SaaS µÈ¸÷¸ö²ãÃæ£¬¹¹½¨ÁËÒ»¸ö´ó¶øÈ«µÄÁãÐÅÈÎÌåϵ¡£

2. Google BeyondCorp

Google BeyondCorp ÊÇΪÁËÓ¦¶ÔÐÂÐÍÍøÂçÍþвµÄÒ»ÖÖÍøÂ簲ȫ½â¾ö·½°¸£¬Æäʵ Google BeyondCorp ±¾Éí²¢Ã»ÓÐÌ«¶àµÄ¼¼ÊõÉϵĸüл»´ú£¬¶øÊÇÀûÓÃÁ˳ÖÐøÑéÖ¤µÄÒ»ÖÖ˼·À´×öµÄ£¬È¥µôÁË VPN ºÍ²»ÔÙ·ÖÄÚÍâÍø¡£

Google ÔÚ 2014 Äê֮ǰ¾ÍÔ¤²âµ½»¥ÁªÍøºÍÄÚÍøµÄ°²È«ÐÔÊÇÒ»ÑùΣÏյģ¬ÒòΪһµ©ÄÚÍø±ß½ç±»Í»ÆÆµÄ»°£¬¹¥»÷Õ߾ͺÜÈÝÒ׵ķÃÎÊÆóÒµµÄһЩÄÚ²¿Ó¦Óã¬ÓÉÓÚ°²È«ÒâʶµÄÎÊÌâµ¼ÖÂÆóÒµ»áÈÏΪÄÚ²¿ºÜ°²È«£¬¾Í¶ÔÄÚ²¿µÄÓ¦ÓýøÐеÍÓÅÏȼ¶±ðµÄ´¦Àí£¬µ¼Ö´óÁ¿ÄÚ²¿µÄ°²È«ÎÊÌâ´æÔÚ¡£

ÏÖÔ򵀮óÒµÔ½À´Ô½¶àµÄÓ¦ÓÃÒÆ¶¯ºÍÔÆ¼¼Êõ£¬µ¼Ö±߽籣»¤Ô½À´Ô½ÄÑ¡£ËùÒÔ Google ¸É´àÒ»ÊÓͬÈÊ£¬²»·ÖÄÚÍⲿ£¬ÓÃÒ»ÑùµÄ°²È«ÊÖ¶ÎÈ¥·ÀÓù¡£

´Ó¹¥·À½Ç¶ÈÀ´¿´Ò»Ï Google µÄ BeyondCorp Ä£ÐÍ£º

ÀýÈç·ÃÎÊ Google ÄÚ²¿Ó¦Óà http://blackberry.corp.google.com £¬Ëü»áÌø×ªµ½ https://login.corp.google.com/ Ò²¾ÍÊÇ Google Moma ϵͳ£¬Ê×ÏÈÐèÒªÊäÈëÕ˺ÅÃÜÂë²ÅÄܵǽ£¬Õâ¸öµÇ¼µÄ¹ý³ÌÖлáÕë¶ÔÉ豸ÐÅÏ¢¡¢Óû§ÐÅÏ¢½øÐÐ×ÛºÏÅж¨£¬Õ˺ÅÃÜÂëÕýÈ·ÒÔ¼°É豸ÐÅϢͨ¹ý¹æÔòÒýÇæÑéÖ¤Ö®ºó£¬»á¼ÌÐøÌø×ªµ½ÐèÒª YubiKey µÇ¼½çÃæ£¬Ã¿¸ö Google µÄÔ±¹¤¶¼»áÓÐ Yubikey£¬Í¨¹ý Yubikey À´×ö¶þ´ÎÑéÖ¤¡£

Yubikey µÄ¼ÛÖµ£¬Google ÈÏΪÊÇ¿ÉÒÔÍêÈ«¶Å¾øµöÓã¹¥»÷µÄ¡£ÁíÍâÀàËÆµÄ¾ÍÊÇ Amazon µÄ Midway-Auth ·½Ê½¡£

Kubernetes ÏÂÈÝÆ÷ÁãÐÅÈÎÄ£ÐÍ

1. ÈÝÆ÷ÏÂÍøÂçÁãÐÅÈÎ

Ê×ÏȽéÉÜÒ»ÏÂÈÝÆ÷ϵÄÍøÂçÁãÐÅÈÎ×é¼þ Calico£¬Calico ÊÇÕë¶ÔÈÝÆ÷£¬ÐéÄâ»úºÍ»ùÓÚÖ÷»úµÄ±¾»ú Workload µÄ¿ªÔ´ÍøÂçºÍÍøÂ簲ȫ½â¾ö·½°¸²úÆ·¡£

Calico Ö§³Ö¹ã·ºµÄƽ̨£¬°üÀ¨ Kubernetes¡¢OpenShift¡¢Docker EE¡¢OpenStack ºÍÂã½ðÊô·þÎñ¡£ÁãÐÅÈÎ×î´óµÄ¼ÛÖµ¾ÍÊǼ´Ê¹¹¥»÷Õßͨ¹ýÆäËû¸÷ÖÖÊÖ·¨ÆÆ»µÓ¦ÓóÌÐò»ò»ù´¡¼Ü¹¹£¬ÁãÐÅÈÎÍøÂçÒ²¾ßÓе¯ÐÔ¡£ÁãÐÅÈμܹ¹Ê¹µÃʹ¹¥»÷ÕßÄÑÒÔºáÏòÒÆ¶¯£¬Õë¶ÔÐԵIJȵã»î¶¯Ò²¸üÈÝÒ×·¢ÏÖ¡£

ÔÚÈÝÆ÷ÍøÂçÁãÐÅÈÎÌåϵÏ£¬Calico+Istio ĿǰÊDZȽÏÈȵÄÒ»Ì×½â¾ö·½°¸£»ÏÈÀ´¿´¿´Á½ÕßµÄһЩ²î±ð£¬´Ó²î±ðÉÏ¿ÉÒÔ¿´µ½ Istio ÊÇÕë¶Ô Pod ²ã Workload µÄ·ÃÎÊ¿ØÖÆ£¬ÒÔ¼° Calico Õë¶Ô Node ²ãµÄ·ÃÎÊ¿ØÖÆ£º

ÏÂÃæÖØµã½²½âһϠCalico ×é¼þºÍ Istio µÄһЩ¼¼Êõϸ½Ú£¬Calico ¹¹½¨ÁËÒ»¸ö 3 ²ã¿É·ÓÉÍøÂ磬ͨ¹ý Calico µÄ Felix£¨ÊÇÔËÐÐÔÚ Node µÄÊØ»¤³ÌÐò£¬ËüÔÚÿ¸ö Node ×ÊÔ´ÉÏÔËÐС£

Felix ¸ºÔð±àÖÆÂ·ÓÉºÍ ACL ¹æÔòÒÔ¼°Ôڸà Node Ö÷»úÉÏËùÐèµÄÈÎºÎÆäËûÄÚÈÝ£¬ÒÔ±ãΪ¸ÃÖ÷»úÉϵÄ×ÊÔ´Õý³£ÔËÐÐÌṩËùÐèµÄÍøÂçÁ¬½Ó£©ÔËÐÐÔÚÿ¸ö Node ÉÏ£¬Ö÷Òª×ö·ÓÉºÍ ACL µÄ²ßÂÔÒÔ¼°´î½¨ÍøÂ磻ͨ¹ýÔËÐÐÔÚ Node É쵀 Iptables ½øÐÐϸÁ£¶ÈµÄ·ÃÎÊ¿ØÖÆ¡£

¿ÉÒÔͨ¹ý Calico ÉèÖÃĬÈÏ Deny µÄ²ßÂÔ£¬È»ºóͨ¹ý×ÔÊÊÓ¦µÄ·ÃÎÊ¿ØÖÆÀ´½øÐÐ×îС»¯µÄ·ÃÎÊ¿ØÖƲßÂÔµÄÖ´ÐУ¬´Ó¶ø¹¹½¨ÈÝÆ÷ϵÄÁãÐÅÈÎÌåϵ£»Dikastes/Envoy£º¿ÉÑ¡µÄ Kubernetes sidecars£¬¿ÉÒÔͨ¹ýÏ໥ TLS Éí·ÝÑéÖ¤±£»¤ Workload µ½ Workload µÄͨÐÅ£¬²¢Ôö¼ÓÏà¹ØµÄ¿ØÖƲßÂÔ¡£

2. Istio

ÔÚ½²½â Istio ֮ǰÏȽ²Ò»ÏÂ΢·þÎñµÄһЩ°²È«ÐèÇóºÍ·çÏÕ·ÖÎö£º

΢·þÎñ±»Í»ÆÆÖ®ºóͨ¹ý Sniffer ¼à¿ØÁ÷Á¿£¬½ø¶ø½øÐÐÖмäÈ˹¥»÷£¬ÎªÁ˽â¾öÕâÖÖ·çÏÕÐèÒª¶ÔÁ÷Á¿½øÐмÓÃÜ£»

ΪÁËÕë¶Ô΢·þÎñºÍ΢·þÎñÖ®¼äµÄ·ÃÎÊ¿ØÖÆ£¬ÐèҪ˫Ïò TLS ºÍϸÁ£¶ÈµÄ·ÃÎʲßÂÔ£»

ÒªÉóºËË­ÔÚʲôʱºò×öÁËʲô£¬ÐèÒªÉ󼯹¤¾ß¡£

·ÖÎöÁ˶ÔÓ¦µÄ·çÏÕÖ®ºó£¬ÏÂÃæÀ´½âÊÍһϠIstio ÈçºÎʵÏÖµÄÁãÐÅÈμܹ¹¡£

Ê×ÏȺÜÃ÷ÏÔµÄÒ»¸öÌØµã¾ÍÊÇÈ«Á´Â·¶¼ÊÇË«Ïò mTLS ½øÐмÓÃܵģ¬µÚ¶þ¸öÌØµã¾ÍÊÇ΢·þÎñºÍ΢·þÎñÖ®¼äµÄ·ÃÎÊÒ²¿ÉÒÔ½øÐмøÈ¨£¬Í¨¹ýȨÏÞ·ÃÎÊÖ®ºó»¹ÐèÒª½øÐÐÉ󼯡£Istio ÊÇÊý¾ÝÃæºÍ¿ØÖÆÃæ½øÐзÖÀëµÄ£¬¿ØÖÆÃæÊÇͨ¹ý Pilot ½«ÊÚȨ²ßÂԺͰ²È«ÃüÃûÐÅÏ¢·Ö·¢¸ø Envoy£¬È»ºóÊý¾ÝÃæÍ¨¹ý Envoy À´½øÐÐ΢·þÎñµÄͨÐÅ¡£

ÔÚÿ¸ö΢·þÎñµÄ Workload É϶¼»á²¿Êð Envoy£¬Ã¿¸ö Envoy ´úÀí¶¼ÔËÐÐÒ»¸öÊÚȨÒýÇæ£¬¸ÃÒýÇæÔÚÔËÐÐʱÊÚȨÇëÇó¡£µ±ÇëÇóµ½´ï´úÀíʱ£¬ÊÚȨÒýÇæ¸ù¾Ýµ±Ç°ÊÚȨ²ßÂÔÆÀ¹ÀÇëÇóÉÏÏÂÎÄ£¬²¢·µ»ØÊÚȨ½á¹û ALLOW »ò DENY¡£

3. ΢·þÎñÏ嵀 Zero Trust API °²È«

42Crunch ½« API °²È«´ÓÆóÒµ±ßÔµÀ©Õ¹µ½ÁËÿ¸öµ¥¶ÀµÄ΢·þÎñ£¬²¢Í¨¹ý¿É´ó¹æÄ£²¿ÊðµÄ³¬µÍÑÓ³Ù΢ API ·À»ðǽÀ´½øÐб£»¤¡£

42Crunch API ·À»ðǽµÄ²¿ÊðģʽÊÇÒÔ Kubernetes Pod ÖÐÒÔ Sidecar ´úÀíģʽ²¿Ê𣬺ÁÃë¼¶±ðµÄÐÔÄÜÏìÓ¦£¬ÕâʡȥÁ˱àдºÍά»¤µ¥¸ö API °²È«²ßÂÔ¹ý³Ì£¬²¢ÊµÊ©ÁËÁãÐÅÈΰ²È«Ìåϵ½á¹¹£¬ÌáÉýÁË΢·þÎñÏ嵀 API °²È«ÐÔ¡£42Crunch µÄ API °²È«ÄÜÁ¦°üÀ¨£º

ÉóºË£ºÔËÐÐ 200 ¶à¸ö OpenAPI ¹æ·¶¶¨ÒåµÄ°²È«ÉóºË²âÊÔ£¬²¢½øÐÐÏêϸµÄ°²È«ÆÀ·Ö£¬ÒÔ°ïÖú¿ª·¢ÈËÔ±¶¨ÒåºÍ¼ÓÇ¿ API °²È«£»

ɨÃ裺ɨÃèʵʱ API ¶Ëµã£¬ÒÔ·¢ÏÖDZÔڵĩ¶´£»

±£»¤£º±£»¤ API ²¢ÔÚÓ¦ÓÃÉϲ¿ÊðÇáÁ¿¼¶£¬µÍÑÓ³Ù Micro API Firewall¡£

4. ÂìÒÏÁãÐÅÈμܹ¹ÌåϵÂ䵨×î¼Ñʵ¼ù

Ëæ×Å Service Mesh ¼Ü¹¹µÄÑݽø£¬ÂìÒÏÒѾ­¿ªÊ¼ÔÚÄÚ²¿Â䵨 Workload ³¡¾°ÏµķþÎñ¼øÈ¨ÄÜÁ¦£¬ÈçºÎ½¨ÉèÒ»Ì×·ûºÏÂìÒϼܹ¹µÄ

Workload ¼äµÄ·þÎñ¼øÈ¨ÄÜÁ¦£¬ÎÒÃǽ«ÎÊÌâ·ÖΪһÏÂÈý¸ö×ÓÎÊÌ⣺

Workload µÄÉí·ÝÈçºÎ¶¨Ò壬ÈçºÎÄܹ»ÊµÏÖÒ»Ì×ͨÓõÄÉí·Ý±êʶµÄÌåϵ£»

Workload ¼ä·ÃÎʵÄÊÚȨģÐ͵ÄʵÏÖ£»

·ÃÎÊ¿ØÖÆÖ´ÐеãÈçºÎÑ¡Ôñ¡£

Workload Éí·Ý¶¨Òå & ÈÏÖ¤·½Ê½

ÂìÒÏÄÚ²¿Ê¹Óà SPIFFE ÏîÄ¿Öиø³öµÄ Identity ¸ñʽÀ´ÃèÊö Workload µÄÉí·Ý£¬¼´£º

spiffe://<domain>/cluster/<cluster>/ns/<namespace>

²»¹ýÔÚ¹¤³ÌÂ䵨¹ý³ÌÖз¢ÏÖ£¬ÕâÖÖά¶ÈµÄÉí·Ý¸ñʽÁ£¶È²»¹»Ï¸£¬²¢ÇÒÓë Kubernetes ¶ÔÓÚ namespace µÄ»®·Ö¹æÔòÓнÏÇ¿µÄñîºÏ¡£ÂìÒϵÄÌåÁ¿½Ï´ó£¬³¡¾°½Ï¶à£¬²»Í¬³¡¾°Ï namespace µÄ»®·Ö¹æÔò¶¼²»ÍêȫһÖ¡£Òò´ËÎÒÃǶԸñʽ½øÐÐÁ˵÷Õû£¬ÔÚÿһ³¡¾°ÏÂÊáÀí³öÄܹ»±êʶһ¸ö Workload ʾÀýËùÐëÒªµÄÒ»×鱨±¸ÊôÐÔ£¨ÀýÈçÓ¦ÓÃÃû£¬»·¾³ÐÅÏ¢µÈ£©£¬²¢½«ÕâЩÊôÐÔЯ´øÔÚ Pod µÄ Labels ÖС£µ÷ÕûºóµÄ¸ñʽÈçÏ£º

spiffe://<domain>/cluster/<cluster>
/<required_attr_1_name>/<required_attr_1_value>
/<required_attr_2_name>
/<required_attr_2_value>

ÅäºÏÕâ¸öÉí·Ý¸ñʽ±ê×¼£¬ÎÒÃÇÔÚ Kubernetes API Server ÖÐÌí¼ÓÁË Validating Webhook ×é¼þ£¬¶ÔÉÏÊö Labels ÖбØÐëЯ´øµÄÊôÐÔÐÅÏ¢½øÐÐУÑé¡£Èç¹ûȱÉÙÆäÖÐÒ»ÏîÊôÐÔÐÅÏ¢£¬ÔòʵÀý Pod ½«ÎÞ·¨´´½¨¡£ÈçÏÂͼËùʾ£º

ÔÚ½â¾öÁË Workload Éí·Ý¶¨ÒåµÄÎÊÌâºó£¬Ê£ÏµľÍÊÇÈçºÎ½«Éí·Ýת»»³ÉijÖÖ¿ÉУÑéµÄ¸ñʽ£¬ÔÚ Workload Ö®¼äµÄ·þÎñµ÷ÓÃÁ´Â·ÖÐ͸´«¡£ÎªÁËÖ§³Ö²»Í¬µÄʹÓó¡¾°£¬ÎÒÃÇÑ¡ÔñÁË X.509 Ö¤ÊéÓë JWT ÕâÁ½ÖÖ¸ñʽ¡£

¶ÔÓÚ Service Mesh ¼Ü¹¹µÄ³¡¾°£¬ÎÒÃǽ«Éí·ÝÐÅÏ¢´æ·ÅÔÚ X.509 Ö¤ÊéµÄ Subject ×Ö¶ÎÖУ¬ÒÔ´ËÀ´Ð¯´ø Workload µÄÉí·ÝÐÅÏ¢¡£ÈçÏÂͼËùʾ£º

¶ÔÓÚÆäËû³¡¾°£¬ÎÒÃǽ«Éí·ÝÐÅÏ¢´æ·ÅÔÚ JWT µÄ Claims ÖУ¬¶ø JWT µÄ°ä·¢ÓëУÑ飬²ÉÓÃÁË Secure Sidecar Ìṩ·þÎñ¡£ÈçÏÂͼËùʾ£º

ÊÚȨģÐÍ

ÔÚÏîÄ¿Â䵨µÄ³õÆÚ£¬Ê¹Óà RBAC Ä£ÐÍÀ´ÃèÊö Workload ¼ä·þÎñµ÷ÓõÄÊÚȨ²ßÂÔ¡£¾ÙÀýÃèÊö£¬Ó¦Óà A µÄijһ¸ö·þÎñ£¬Ö»Äܱ»Ó¦Óà B µ÷Óá£ÕâÖÖÊÚȨ²ßÂÔÔÚ´ó¶àÊý³¡¾°Ï¶¼Ã»ÓÐÎÊÌ⣬²»¹ýÔÚÏîÄ¿ÍÆ½ø¹ý³ÌÖУ¬ÎÒÃÇ·¢ÏÖÕâÖÖÊÚȨ²ßÂÔ²»ÊÊÓÃÓÚ²¿·ÖÌØÊⳡ¾°¡£

ÎÒÃÇ¿¼ÂÇÕâÑùÒ»¸ö³¡¾°£¬Éú²úÍøÄÚ²¿ÓÐÒ»¸öÓ¦Óà A£¬Ö°ÔðÊǶÔÉú²úÍøÄÚ²¿µÄËùÓÐÓ¦ÓÃÔÚÔËÐÐʱËùÐèҪʹÓõÄһЩ¶¯Ì¬ÅäÖÃÌṩÖÐÐÄ»¯µÄ·þÎñ¡£Õâ¸ö·þÎñµÄ¶¨ÒåÈçÏ£º

A Ó¦Óà - »ñÈ¡¶¯Ì¬ÅäÖÃµÄ RPC ·þÎñ£º

message FetchResourceRequest {// The appname of invokerstring appname = 1;//
The ID of resourcestring resource_id = 2;}
message FetchResourceResponse {string data = 1;}
service DynamicResourceService {rpc FetchResource (FetchResourceRequest) returns (FetchResourceResponse) {}}

Ôڴ˳¡¾°Ï£¬Èç¹ûÒÀȻʹÓà RBAC Ä£ÐÍ£¬Ó¦Óà A µÄ·ÃÎÊ¿ØÖƲßÂÔ½«ÎÞ·¨ÃèÊö£¬ÒòΪËùÓÐÓ¦Óö¼ÐèÒª·ÃÎÊ A Ó¦ÓõķþÎñ¡£µ«ÊÇÕâÑù»áµ¼ÖÂÏÔ¶øÒ×¼ûµÄ°²È«ÎÊÌ⣬µ÷Ó÷½Ó¦Óà B ¿ÉÒÔͨ¹ý¸Ã·þÎñ»ñÈ¡µ½ÆäËüÓ¦ÓõÄ×ÊÔ´¡£

Òò´ËÎÒÃǽ« RBAC Ä£ÐÍÉý¼¶Îª ABAC Ä£ÐÍÀ´½â¾öÉÏÊöÎÊÌâ¡£ÎÒÃDzÉÓà DSL ÓïÑÔÀ´ÃèÊö ABAC µÄÂß¼­£¬²¢ÇÒ¼¯³ÉÔÚ Secure Sidecar ÖС£

·ÃÎÊ¿ØÖÆÖ´ÐеãµÄÑ¡Ôñ

ÔÚÖ´ÐеãÑ¡Ôñ·½Ã棬¿¼Âǵ½ Service Mesh ¼Ü¹¹ÍƽøÐèÒªÒ»¶¨µÄʱ¼ä£¬ÎÒÃÇÌṩÁËÁ½²»Í¬µÄ·½Ê½£¬¿ÉÒÔ¼æÈÝ Service Mesh µÄ¼Ü¹¹£¬Ò²¿ÉÒÔ¼æÈݵ±Ç°³¡¾°¡£

ÔÚ Service Mesh ¼Ü¹¹³¡¾°Ï£¬RBAC Filter ºÍ ABAC Filter£¨Access Control Filter£©¼¯³ÉÔÚ Mesh Sidecar ÖС£

ÔÚµ±Ç°³¡¾°Ï£¬ÎÒÃÇĿǰÌṩÁË JAVA SDK£¬Ó¦ÓÃÐèÒª¼¯³É SDK À´Íê³ÉËùÓÐÈÏÖ¤ºÍÊÚȨÏà¹ØµÄÂß¼­¡£Óë Service Mesh ¼Ü¹¹³¡¾°ÀàËÆ£¬ËùÓÐ Identity µÄ°ä·¢¡¢Ð£Ñ飬ÊÚȨÓë Secure Sidecar ½»»¥£¬ÓÉ Secure Sidecar Íê³É¡£

½áÓï

ÁãÐÅÈεĺËÐÄÊÇ "Never Trust, Always Verify"£¬Î´À´»á¼ÌÐøÉÁãÐÅÈÎÔÚÕû¸ö°¢Àï°Í°ÍµÄʵ¼ù£¬¸³Ó費ͬµÄ½ÇÉ«²»Í¬µÄÉí·Ý£¬ÀýÈçÆóÒµÔ±¹¤¡¢Ó¦ÓᢻúÆ÷£¬²¢½«·ÃÎÊ¿ØÖƵãϳÁµ½ÔÆÔ­Éú»ù´¡ÉèÊ©µÄ¸÷¸öµã£¬ÊµÏÖÈ«¾ÖϸÁ£¶ÈµÄ¿ØÖÆ£¬´òÔ찲ȫ·À»¤µÄб߽硣

±¾ÎÄ´ÓÒµ½çµÄÁãÐÅÈÎÌåϵµÄÂ䵨×î¼Ñʵ¼ù£¬µ½»ùÓÚ Kubernetes µÄÁãÐÅÈÎÂ䵨·½Ê½½øÐÐÁ˼òµ¥µÄÃèÊö£¬±¾ÎÄÖ»ÊÇÅ×שÒýÓñ£¬Ï£ÍûÄÜÒý·¢¸ü¶à¹ØÓÚ ¡£

   
2199 ´Îä¯ÀÀ       29
 
Ïà¹ØÎÄÕÂ

iOSÓ¦Óð²È«¿ª·¢£¬Äã²»ÖªµÀµÄÄÇЩÊÂÊõ
Web°²È«Ö®SQL×¢Èë¹¥»÷
ÒÆ¶¯APP°²È«ÔÚÉøÍ¸²âÊÔÖеÄÓ¦ÓÃ
´ÓGoogle±¸·Ý»¥ÁªÍø¿´¡°Êý¾Ý°²È«¡±
 
Ïà¹ØÎĵµ

web°²È«Éè¼ÆÓë·À»¤
»¥ÁªÍøº£Á¿ÄÚÈݰ²È«´¦Àí¼¼Êõ
ºÚ¿Í¹¥»÷Óë·À·¶¼¼Êõ
WEBºÚºÐ°²È«¼ì²â
 
Ïà¹Ø¿Î³Ì

WEBÍøÕ¾ÓëÓ¦Óð²È«Ô­ÀíÓëʵ¼ù
webÓ¦Óð²È«¼Ü¹¹Éè¼Æ
´´½¨°²È«µÄJ2EE WebÓ¦ÓôúÂë
ÐÅÏ¢°²È«ÎÊÌâÓë·À·¶
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÎïÁªÍø°²È«¸ÅÊö
Ê·ÉÏ×îÏêϸµÄÇø¿éÁ´¼¼Êõ¼Ü¹¹·ÖÎö
Ò»ÎĶÁ¶®Çø¿éÁ´ÕûÌå¼Ü¹¹¼°Ó¦Óð¸Àý
Çø¿éÁ´¼¼Êõ¼Ü¹¹
°²È«¼Ü¹¹ÆÀÉóʵս
×îпγÌ
WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ÎïÁªÍø¹Ø¼ü¼¼Êõ¡¢°²È«Óë±ßÔµ¼ÆËã
Çø¿éÁ´°²È«¼¼Êõʵ¼ùÖ¸ÄÏ
ÔÆ·þÎñÓ밲ȫ¼Ü¹¹
»¥ÁªÍø°²È«¿ª·¢·½·¨Óëʵ¼ù
³É¹¦°¸Àý
ÖйúÒøÐÐ ÐÅÏ¢°²È«¼¼Êõ¼°Éî¶È·ÀÓù
±±¾© WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ij²ÆË°ÁìÓòÖªÃûIT·þÎñÉÌ Web°²È«²âÊÔ
ÆÕÈð¿Ë˹ web°²È«Éè¼Æ¡¢²âÊÔÓëÓÅ»¯
±±¾©ºÍÀûʱ ÐÔÄܺͰ²È«ÐÔ²âÊÔ