Identity-Native Infrastructure Access Management Preventing Breaches by Eliminating Secrets and Adopting Zero Trust (Ev Kontsevoy, Sakshyam Shah, Peter Conrad)(Z-Library)
Traditional secret-based credentials can't scale to meet the complexity and size of cloud and on-premises infrastructure. Today's applications are spread across a diverse range of clouds and colocation facilities, as well as on-prem data centers. Each layer of this modern stack has its own attack vectors and protocols to consider.
How can you secure access to diverse infrastructure components, from bare metal to ephemeral containers, consistently and simply? In this practical book, authors Ev Kontsevoy, Sakshyam Shah, and Peter Conrad break this topic down into manageable pieces. You'll discover how different parts of the approach fit together in a way that enables engineering teams to build more secure applications without slowing down productivity.
With this book, you'll learn
• The four pillars of access: connectivity, authentication, authorization, and audit
• Why every attack follows the same pattern, and how to make this threat impossible
• How to implement identity-based access across your entire infrastructure with digital certificates
• Why it's time for secret-based credentials to go away
• How to securely connect to remote resources including servers, databases, K8s Pods, and internal applications such as Jenkins and GitLab
• Authentication and authorization methods for gaining access to and permission for using protected resources
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
# Identity-Native Infrastructure Access Management
## 【One-Line Pitch】
A practical guide for DevOps engineers, security professionals, and IT leaders who want to replace fragile secret-based credentials with identity-based access control across modern, heterogeneous infrastructure—from bare metal to Kubernetes clusters. If you're tired of managing endless passwords, tokens, and SSH keys, this book shows you a scalable alternative built on four pillars: connectivity, authentication, authorization, and audit.
## 【Book Arc】
- **Opening (~0%–6%)**: Establishes the core problem—traditional secret-based credentials and perimeter defenses can't scale with modern infrastructure complexity. Introduces the book's promise: identity-native access as the solution.
- **Early (~6%–19%)**: Lays the conceptual foundation by defining the four pillars of access (secure connectivity, authentication, authorization, audit) and explaining why every successful attack follows the same "human error + pivot" pattern. Includes a chapter-by-chapter roadmap.
- **Early (~19%–34%)**: Deepens the critique of secrets and perimeter-based security, detailing why they fail at scale. Introduces the vision of unifying access control across humans, machines, and applications to reduce complexity and improve auditability.
- **Middle (~34%–47%)**: Explores the concept of identity itself—distinguishing true identity (physical, non-transferable) from credentials (data, stealable). Covers centralized identity management (IdM) systems like Okta and Active Directory, and explains the SSO login flow.
- **Middle (~47%–53%)**: Examines authentication methods in depth, including secret-based, public key, and certificate-based approaches, plus multifactor authentication and WebAuthn. Discusses identity proofing, device attestation, and authenticating machines.
- **Late (~53%–end)**: Moves to implementation—authorization frameworks, auditing practices, a real-world example using Teleport and open source tools, and a final call to action for building trust in technology.
## 【Key Takeaways】
- **The four pillars of access are connectivity, authentication, authorization, and audit** (Early): These components work together to ensure the right client has the right kind of access to protected resources, with visibility into what's happening. Understanding this framework is essential before diving into any specific tool or technique.
- **Every successful attack follows the same pattern: human error + pivot** (Middle): Attackers exploit a leaked or misused secret to gain a foothold, then move laterally to adjacent systems, expanding their blast radius. This pattern is consistent across the most common breach types—compromised credentials, phishing, and social engineering.
- **Secrets are data, and data is vulnerable to human error** (Middle): Passwords, tokens, and private keys can be stolen, lost, shared, or duplicated. True identity—who you are—cannot be copied or stolen. The fundamental challenge is representing physical identity digitally without introducing the weaknesses of secrets.
- **Credentials are an identity proxy, not identity itself** (Middle): When someone steals your driver's license or password, they don't become you—but they can pretend to be you. This distinction is the root of all access control vulnerabilities because it gives human error a foothold into identity.
- **Perimeter-based security merges all users into a single "guest" or "admin"** (Early): When internal network resources aren't individually protected, audit logs become useless because you can't tell who did what. Moving access control to the resource and application level enables granular, meaningful auditing.
- **Centralized identity management (IdM) was the first step away from secrets** (Middle): Systems like Okta and Active Directory consolidate user accounts and provide standardized APIs, using SSO flows where the IdM authenticates the user and issues a token representing their identity. This reduces the number of secrets but doesn't eliminate them.
- **Authorization is separate from authentication but relies on it** (Early): Policy definition (who can access what) and policy enforcement (making those decisions stick) are the two halves of authorization. Grouping resources simplifies management but increases blast radius when credentials are stolen.
- **Unifying access control across humans, machines, and applications reduces complexity** (Early): When software needs to communicate autonomously for CI/CD, monitoring, and microservices, traditional token-based methods don't scale and provide no way to track human errors. A unified approach makes consistent auditability possible and gets security out of the way of productivity.
## 【Reading Tips】
- **Skim the preface and introduction (first ~10%)** for the core argument and chapter roadmap—this gives you the mental model you need for everything that follows. The four pillars framework introduced here is the book's backbone.
- **Deep-read Chapter 2 on Identity (around 35%–50%)**—this is where the conceptual heart of the book lives. The distinction between true identity and credentials, and the "human error + pivot" attack pattern, are the ideas that justify everything else.
- **Pay close attention to the authentication methods comparison (around 50%–60%)**: The book evaluates secret-based, public key, and certificate-based authentication against criteria like robustness, ubiquity, and scalability. This framework is useful for evaluating any access solution you encounter.
- **If you're a practitioner, jump ahead to the Teleport example in Chapter 7 (late in the book)** to see how the principles are applied in a real-world, open source implementation. The earlier chapters provide the "why," but this chapter shows the "how."
- **Don't get bogged down in the cryptography primer (around 6%–9%)** if you're already familiar with hashing, symmetric/asymmetric encryption, and certificates—it's a refresher, not the book's main contribution.
## 【Coverage Limits】
This guide covers the book's conceptual framework and early-to-middle chapters in depth. The excerpts do not cover the detailed content of the later chapters on authorization frameworks, auditing practices, the Teleport implementation example, or the final call to action—these are summarized only at a high level from the table of contents.
##
Page 4
rchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://oreilly.com). For more information, c...
experts and innovators share their knowledge and expertise through books, articles, and our online learning platform. O’Reilly’s online learning platform giv...
ally know and control what is going on in your environment. Identity-native infrastructure access management provides a great deal of control over individual...
appropriate access to resources. An account is a simplistic way of establishing identity because it can be used by any client that can provide a valid creden...
the other hand, hangs around for a long time and can become a long-standing point of vulnerability if it’s compromised. One of the biggest security threats h...
013-0169 (the Lucky 13 attack) that allows a rogue party to carry out a man-in-the-middle (MITM) attack and recover plain-text data, and Cryptography | 39 al...
formed from a rarity to a necessity for business continuity. Work-from-home requirements have pushed the security of remote network connections from a corpor...
mplemented anywhere. Evaluating Authentication Methods | 57 over an open, unencrypted network connection, because the private key is never exchanged. For a q...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Identity-Native Infrastructure Access Management Preventing Breaches by Eliminating Secrets and Adopting Zero Trust (Ev Kontsevoy, Sakshyam Shah, Peter Conrad)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Identity-Native Infrastructure Access Management Preventing Breaches by Eliminating Secrets and Adopting Zero Trust (Ev Kontsevoy, Sakshyam Shah, Peter Conrad)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment