Kiến Trúc Bảo Mật Zero-Trust Cho Microservices: mTLS, SPIFFE/SPIRE & Identity Control

Kiến Trúc Bảo Mật Zero-Trust Cho Microservices: mTLS, SPIFFE/SPIRE & Identity Control

← Chương trước: Temporal Workflow SDK trong Go | Mục lục Series | Chương tiếp theo: So Sánh Vector Database Cho RAG → Answer-first: Zero-Trust Architecture (ZTA) for microservices eliminates implicit internal network trust through continuous identity verification. By coupling Workload Identity (mTLS via SPIFFE/SPIRE short-lived X.509 certificates) with User Identity (OAuth 2.1 JWT token propagation), ZTA secures distributed systems against lateral attacker movement with under 2ms of cryptographic latency overhead. Zero-Trust Architecture for Microservices: mTLS & Production Go Guide As a systems engineer building high-concurrency systems in Golang, I have observed traditional internal network designs relying entirely on perimeter defenses such as VPNs or static firewalls. In cloud-native microservice environments, this perimeter model presents critical security vulnerabilities. Once an attacker breaches any single internal microservice, implicit trust between internal nodes exposes the entire service mesh to lateral movement. ...

10 tháng 5, 2026 · 10 phút · Lê Tuấn Anh
Tech Radar: eBPF Zero-Trust Security for AI Agents with Tetragon 1.4

eBPF Zero-Trust Security for AI Agents: Tetragon 1.4

Tech Radar: eBPF Zero-Trust Security for AI Agents with Tetragon 1.4 Answer-First: Granting tool-execution permissions to AI Agents dramatically expands the attack surface for Remote Code Execution (RCE) via Indirect Prompt Injection. Cilium Tetragon 1.4 leverages eBPF probes inside the Linux kernel to intercept unauthorized system calls (execve, socket, openat), executing in-kernel SIGKILL enforcement in under 15 microseconds before malicious payloads can spawn reverse shells or exfiltrate credentials. 1. The Emerging Threat Vector: Autonomous Agent Prompt Injection RCE In modern agentic architectures, autonomous agents are granted tool execution permissions across the host environment: ...

29 tháng 8, 2026 · 4 phút · Lê Tuấn Anh
Tech Radar: NIST AI 600-1 & OWASP ASI01–ASI10 — Hardening Enterprise Agent Gateways in Kubernetes

NIST AI 600-1 & OWASP ASI01–ASI10: AI Gateways in Kubernetes

Tech Radar: NIST AI 600-1 & OWASP ASI01–ASI10 — Hardening Enterprise Agent Gateways in Kubernetes Answer-first: Deploying autonomous AI agent swarms into enterprise Kubernetes clusters demands a paradigm shift from Least Privilege to Least Agency. By unifying NIST AI 600-1 (the 12 GenAI Risk Categories across GOVERN/MAP/MEASURE/MANAGE) with the OWASP ASI Top 10 (2026 Agentic Security Standards), production architectures enforce a 4-tier defense: L7 Kubernetes Gateway API with CEL expressions for tool parameter sanitization, SPIFFE/SPIRE for ephemeral Non-Human Identity (NHI) mTLS attestation, and Cilium Tetragon eBPF for real-time Linux kernel syscall termination (SIGKILL < 15µs). ...

21 tháng 8, 2026 · 8 phút · Lê Tuấn Anh
Zero-Trust Service Mesh Security SPIFFE SPIRE Istio Golang

Bảo mật Zero-Trust Service Mesh trong Go

Answer-first: Bảo mật Zero-Trust trong Go microservices chuẩn PCI-DSS 4.0 thay thế xác thực IP tĩnh bằng định danh cryptographic SPIFFE/SPIRE từ kernel attestation (cgroups, K8s SA, image SHA256). Kết hợp chứng chỉ X.509 SVID xoay vòng trong bộ nhớ mỗi giờ và Istio STRICT mTLS với AuthorizationPolicy giúp triệt tiêu nguy cơ di chuyển ngang. 🇬🇧 Read the English version of this article on tanhdev.com 🛡️ Bài viết này thuộc chuyên đề bảo mật và thiết kế hệ thống phân tán. Xem thêm tại Series Thiết Kế Hệ Thống Phân Tán High-Concurrency. ...

23 tháng 7, 2026 · 21 phút · Lê Tuấn Anh

Tech Radar 14/07: Zero-Trust Security cho AI Swarms & MCP

🇬🇧 Read the English version of this article on tanhdev.com Welcome to this week’s Tech Radar. In our previous issue, we discussed Cloud-Native AI Architecture. Khi chúng ta đã có hạ tầng mạnh mẽ (Envoy, K8s Inference), vấn đề tiếp theo lập tức xuất hiện: Làm sao để kiểm soát bầy AI (AI Swarm) này? Đừng “thả rông” AI Agents trong production. Hôm nay, chúng ta đào sâu vào Zero-Trust Security cho Multi-Agent Swarms. ...

14 tháng 7, 2026 · 5 phút · Lê Tuấn Anh