DevOps Conference
The Conference for Continuous Delivery, Microservices,
Containers, Clouds and Lean Business

Microservice Authentication and Authorization

Session

This talk originates from the archive. Click here for the current program of Munich or Singapore

Until Conference starts:
✓ Group Discount
✓ Freelancer Special
Register now
Bis 31. Oktober
✓ Kollegenrabatt
✓ Bis zu 375 € sparen
Jetzt anmelden
Until December 12:
✓ Workshop Day for free
✓ Raspberry Pi or C64 Mini for free
✓ Save up to $690
Register now
Until December 12:
✓ Workshop Day for free
✓ Raspberry Pi or C64 Mini for free
✓ Save up to $690
Register now
Until January 30:
✓ Team Discounts
✓ Raspberry Pi or C64 Mini for free
✓ Save over £329
Register Now

Until January 30:
✓ Team Discounts
✓ Raspberry Pi or C64 Mini for free
✓ Save over £329
Register Now

Until March 5:
✓ Transformation Day for free
✓ Raspberry Pi or C64 Mini for free
✓ Save over 850 €
Register now
Bis 5. März:
✓ Transformation Day for free
✓ Raspberry Pi oder C64 Mini for free
✓ Über 850 € sparen
Jetzt anmelden
Until June 18:
✓ Workshop Day for free
✓ Raspberry Pi or C64 Mini for free
✓ Save over $840
Register now
Until June 18:
✓ Workshop Day for free
✓ Raspberry Pi or C64 Mini for free
✓ Save over $840
Register now
Infos
Tuesday, May 29 2018
11:45 - 12:45
Room:
MOA 7+8

In this talk we will look at how you can secure your microservices, we will identify the difference between authentication and authorization and why both are required. We will investigate some common patterns for request validation, including HMAC and JWT to avoid the confused deputy problem, and also how you can manage and secure secret information. Finally, we will see how we can leverage tools like the open source HashiCorp Vault as well as features from cloud providers like AWS and GCP, to keep your systems and users secure. Takeaways: 

  • Using JWT for Authz
  • How to implement two factor authentication into your applications
  • Securing microservice secrets 
  • Implementing TLS and MTLS
  • Securing database access, don’t be the next Equifax
  • Encryption in transit, secure your data
  • Building a secure secret access policy

Stay tuned:

Behind the Tracks

 

Kubernetes Ecosystem

Docker, Kubernetes & Co

Microservices & Software Architecture

Maximize development productivity

Continuous Delivery & Automation

Build, test and deploy agile

Cloud Platforms & Serverless

Cloud-based & native apps

Monitoring, Traceability & Diagnostics

Handle the complexity of microservices applications

Security

DevSecOps for safer applications

Business & Company Culture

Radically optimize IT

Organizational Change

Overcome obstacles on the way towards DevOps

Live Demo #slideless

Showing how technology really works