Authenticating and Authorizing Every Connection at Uber
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn how Uber built and scaled a platform-level authentication and authorization solution for one of the world's largest microservice architectures in this 36-minute conference talk from KubeCon + CloudNativeCon. Discover the architectural approach used to secure thousands of services across diverse languages and independent teams without requiring code changes. Explore the implementation of a Zero Trust architecture based on Envoy, SPIRE, and the SPIFFE standard that secures every service interaction with mTLS, authenticates workloads using SPIFFE identities, and enforces fine-grained policies through a unified control plane. Gain insights into the 3-year rollout journey, including architectural decisions, operational challenges, and user-experience tradeoffs encountered during real-world deployment at massive scale. Understand practical considerations for implementing Zero Trust security or scaling Envoy/SPIRE solutions across large organizations through lessons learned from Uber's production environment.
Syllabus
Authenticating and Authorizing Every Connection at Uber - Yangmin Zhu & Matt Mathew, Uber
Taught by
CNCF [Cloud Native Computing Foundation]