Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Ev Kontsevoy, Sakshyam Shah, Peter Conrad

Rating No ratings yet

Traditional secret-based credentials can't scale to meet the complexity and size of cloud and on-premises infrastructure. Today's applications are spread across a diverse range of clouds and colocation facilities, as well as on-prem data centers. Each layer of this modern stack has its own attack vectors and protocols to consider. How can you secure access to diverse infrastructure components, from bare metal to ephemeral containers, consistently and simply? In this practical book, authors Ev Kontsevoy, Sakshyam Shah, and Peter Conrad break this topic down into manageable pieces. You'll discover how different parts of the approach fit together in a way that enables engineering teams to build more secure applications without slowing down productivity. With this book, you'll learn • The four pillars of access: connectivity, authentication, authorization, and audit • Why every attack follows the same pattern, and how to make this threat impossible • How to implement identity-based access across your entire infrastructure with digital certificates • Why it's time for secret-based credentials to go away • How to securely connect to remote resources including servers, databases, K8s Pods, and internal applications such as Jenkins and GitLab • Authentication and authorization methods for gaining access to and permission for using protected resources

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Identity-Native Infrastructure Access Management ## 【One-Line Pitch】 A practical guide for DevOps engineers, security professionals, and IT leaders who want to replace fragile secret-based credentials with identity-based access control across modern, heterogeneous infrastructure—from bare metal to Kubernetes clusters. If you're tired of managing endless passwords, tokens, and SSH keys, this book shows you a scalable alternative built on four pillars: connectivity, authentication, authorization, and audit. ## 【Book Arc】 - **Opening (~0%–6%)**: Establishes the core problem—traditional secret-based credentials and perimeter defenses can't scale with modern infrastructure complexity. Introduces the book's promise: identity-native access as the solution. - **Early (~6%–19%)**: Lays the conceptual foundation by defining the four pillars of access (secure connectivity, authentication, authorization, audit) and explaining why every successful attack follows the same "human error + pivot" pattern. Includes a chapter-by-chapter roadmap. - **Early (~19%–34%)**: Deepens the critique of secrets and perimeter-based security, detailing why they fail at scale. Introduces the vision of unifying access control across humans, machines, and applications to reduce complexity and improve auditability. - **Middle (~34%–47%)**: Explores the concept of identity itself—distinguishing true identity (physical, non-transferable) from credentials (data, stealable). Covers centralized identity management (IdM) systems like Okta and Active Directory, and explains the SSO login flow. - **Middle (~47%–53%)**: Examines authentication methods in depth, including secret-based, public key, and certificate-based approaches, plus multifactor authentication and WebAuthn. Discusses identity proofing, device attestation, and authenticating machines. - **Late (~53%–end)**: Moves to implementation—authorization frameworks, auditing practices, a real-world example using Teleport and open source tools, and a final call to action for building trust in technology. ## 【Key Takeaways】 - **The four pillars of access are connectivity, authentication, authorization, and audit** (Early): These components work together to ensure the right client has the right kind of access to protected resources, with visibility into what's happening. Understanding this framework is essential before diving into any specific tool or technique. - **Every successful attack follows the same pattern: human error + pivot** (Middle): Attackers exploit a leaked or misused secret to gain a foothold, then move laterally to adjacent systems, expanding their blast radius. This pattern is consistent across the most common breach types—compromised credentials, phishing, and social engineering. - **Secrets are data, and data is vulnerable to human error** (Middle): Passwords, tokens, and private keys can be stolen, lost, shared, or duplicated. True identity—who you are—cannot be copied or stolen. The fundamental challenge is representing physical identity digitally without introducing the weaknesses of secrets. - **Credentials are an identity proxy, not identity itself** (Middle): When someone steals your driver's license or password, they don't become you—but they can pretend to be you. This distinction is the root of all access control vulnerabilities because it gives human error a foothold into identity. - **Perimeter-based security merges all users into a single "guest" or "admin"** (Early): When internal network resources aren't individually protected, audit logs become useless because you can't tell who did what. Moving access control to the resource and application level enables granular, meaningful auditing. - **Centralized identity management (IdM) was the first step away from secrets** (Middle): Systems like Okta and Active Directory consolidate user accounts and provide standardized APIs, using SSO flows where the IdM authenticates the user and issues a token representing their identity. This reduces the number of secrets but doesn't eliminate them. - **Authorization is separate from authentication but relies on it** (Early): Policy definition (who can access what) and policy enforcement (making those decisions stick) are the two halves of authorization. Grouping resources simplifies management but increases blast radius when credentials are stolen. - **Unifying access control across humans, machines, and applications reduces complexity** (Early): When software needs to communicate autonomously for CI/CD, monitoring, and microservices, traditional token-based methods don't scale and provide no way to track human errors. A unified approach makes consistent auditability possible and gets security out of the way of productivity. ## 【Reading Tips】 - **Skim the preface and introduction (first ~10%)** for the core argument and chapter roadmap—this gives you the mental model you need for everything that follows. The four pillars framework introduced here is the book's backbone. - **Deep-read Chapter 2 on Identity (around 35%–50%)**—this is where the conceptual heart of the book lives. The distinction between true identity and credentials, and the "human error + pivot" attack pattern, are the ideas that justify everything else. - **Pay close attention to the authentication methods comparison (around 50%–60%)**: The book evaluates secret-based, public key, and certificate-based authentication against criteria like robustness, ubiquity, and scalability. This framework is useful for evaluating any access solution you encounter. - **If you're a practitioner, jump ahead to the Teleport example in Chapter 7 (late in the book)** to see how the principles are applied in a real-world, open source implementation. The earlier chapters provide the "why," but this chapter shows the "how." - **Don't get bogged down in the cryptography primer (around 6%–9%)** if you're already familiar with hashing, symmetric/asymmetric encryption, and certificates—it's a refresher, not the book's main contribution. ## 【Coverage Limits】 This guide covers the book's conceptual framework and early-to-middle chapters in depth. The excerpts do not cover the detailed content of the later chapters on authorization frameworks, auditing practices, the Teleport implementation example, or the final call to action—these are summarized only at a high level from the table of contents. ##
Page 4
rchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://oreilly.com). For more information, c...
View in text
Page 11
experts and innovators share their knowledge and expertise through books, articles, and our online learning platform. O’Reilly’s online learning platform giv...
View in text
Page 19
ally know and control what is going on in your environment. Identity-native infrastructure access management provides a great deal of control over individual...
View in text
Excerpt 4
appropriate access to resources. An account is a simplistic way of establishing identity because it can be used by any client that can provide a valid creden...
View in text
Excerpt 5
the other hand, hangs around for a long time and can become a long-standing point of vulnerability if it’s compromised. One of the biggest security threats h...
View in text
Excerpt 6
013-0169 (the Lucky 13 attack) that allows a rogue party to carry out a man-in-the-middle (MITM) attack and recover plain-text data, and Cryptography | 39 al...
View in text
Excerpt 7
formed from a rarity to a necessity for business continuity. Work-from-home requirements have pushed the security of remote network connections from a corpor...
View in text
Excerpt 8
mplemented anywhere. Evaluating Authentication Methods | 57 over an open, unencrypted network connection, because the private key is never exchanged. For a q...
View in text
Tags
AI categories
Cloud NativeCybersecurityDevOps
ISBN: 1098131894
Publisher: O'Reilly Media
Publish Year: 2023
Language: English
Pages: 155
File Format: PDF
File Size: 2.4 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…