Loading…
Attending this event?
Virtual
September 25-26, 2023
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for IstioCon Virtual 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in EDT. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above “Filter by Date.”

Back To Schedule
Monday, September 25 • 3:40pm - 4:10pm
Identity Theft Is Not a Joke, Jim! How Istio Ambient Mesh Safeguards Our Pod Identities - Marino Wijay, Solo.io

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Log in to leave feedback.
Impersonation and Identity theft are serious crimes in the world of Kubernetes! Who's checking IDs and making sure imposters haven't made their way into our cluster? When considering protecting our services and providing identity for authorization, we'll always turn to a Service Mesh as an insertion/interception point. However, with this new mode of Istio called Ambient Mesh, some questions arise: - How does Ambient prevent impersonation? - What's the Ztunnel have to do with identity? - Where do we maintain mTLS? - How does authorization get enforced at L4 and L7?? - What did you do to my sidecar??? In this talk, we break down the key security features of Istio Ambient Mesh, and provide proof that Ambient Mesh truly prevents identity theft while still providing the same key capabilities as the Istio Service Mesh. We'll demonstrate how Ambient Mesh provides Ztunnel as a daemonset to provide a complete security posture and node-to-node encryption vs. pod-to-pod within the node.

Speakers
avatar for Marino Wijay

Marino Wijay

Developer and Platform Advocate, Solo.io
Marino Wijay is a Canadian, Traveller, International Speaker, Open Source Advocate for Service Mesh, Kubernetes, and Networking. He is an Ambassador @ EddieHub, and Lead Organizer for KubeHuddle Toronto. He is passionate about technology and modern distributed systems. He will always... Read More →


Monday September 25, 2023 3:40pm - 4:10pm EDT
Virtual
  Istio Recipes