Overview
Syllabus
Intro
Briefly about Cilium...
Cilium: Identity Aware
Components of Identity?
Our need for SPIFFE
Integration Challenges • Cilium deploys Envoy in Node-Singleton Model Does not use side-car model Advantages, Disadvantages?
Ensuring appropriate API access spiff
Upgrading to secure connections • TLS origination and termination support
Other perks of using SPIFFE • Integrated certificate management solution Integrates well with existing CA providers Nested SPIRE allows hard-isolation of resources • Readily integrates with Vault for secrets management • Active developer community
To sum up...
Credits
References
Taught by
CNCF [Cloud Native Computing Foundation]