Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a comprehensive conference talk on bridging security infrastructure between data centers and AWS Lambda. Delve into Square's journey of migrating to the cloud while maintaining secure communication between microservices. Learn about workload identity architecture in AWS Lambda, identity sharing between data centers and cloud environments, and the challenges of integrating serverless technology with existing infrastructure. Discover various options for identity issuance, architectural decisions, and system components. Gain insights into application secrets management, security boundaries, and risk mitigation strategies. Understand the onboarding process and key considerations for implementing a secure serverless infrastructure that seamlessly integrates with traditional data center services.
Syllabus
Intro
Overview
How does it work?
The problem with serverless
System Goals
Square data center
Workload identity at Square
Shape of identity for Lambda
Identity issuance: what options were available?
Identity issuance decision
Architecture for identity issuance
Architecture Decision
System components
Hellol Lambda calling
Application Secrets: Keywhiz
Full decentralization?
Application secrets decision
Security Boundaries
Secrets Availability
How to onboard
Risk Mitigation Access all secrets
Summary
Taught by
Black Hat