Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Designing Zero Trust Systems
Search
Posedio
PRO
February 25, 2025
Programming
0
11
Designing Zero Trust Systems
Posedio
PRO
February 25, 2025
Tweet
Share
More Decks by Posedio
See All by Posedio
Lost Jobs, Zombie Tasks and AirFlow Nightmares: A debugging Deep Dive
posedio
PRO
0
7
Platform user's remorse
posedio
PRO
0
120
Go KonMari on your SQL
posedio
PRO
0
17
Rolling out digital receipts on GCP infrastructure
posedio
PRO
0
12
API First revisited - where did we take a left turn?
posedio
PRO
0
55
Solving Multi-Tenant Challenges: Apache Airflow and Cloud Composer in Action
posedio
PRO
0
37
Contract testing with Java
posedio
PRO
0
33
Flink in two nutshells
posedio
PRO
0
32
Taming the Codebase: Strategies for Refactoring Legacy Code
posedio
PRO
0
31
Other Decks in Programming
See All in Programming
自分のために作ったアプリが、グローバルに使われるまで / Indie App Development Lunch LT
pixyzehn
1
120
Node.js, Deno, Bun 最新動向とその所感について
yosuke_furukawa
PRO
6
3k
NestJSのコードからOpenAPIを自動生成する際の最適解を探す
astatsuya
0
180
goにおける コネクションプールの仕組み を軽く掘って見た
aronokuyama
0
120
プログラミング教育のコスパの話
superkinoko
0
110
AI時代のプログラミング教育 / programming education in ai era
kishida
22
20k
remix + cloudflare workers (DO) docker上でいい感じに開発する
yoshidatomoaki
0
120
RailsでCQRS/ESをやってみたきづき
suzukimar
2
1.5k
爆速スッキリ! Rspack 移行の成果と道のり - Muddy Web #11
dora1998
1
140
なぜselectはselectではないのか
taiyow
2
290
データベースエンジニアの仕事を楽にする。PgAssistantの紹介
nnaka2992
9
4.1k
新卒から4年間、20年もののWebサービスと 向き合って学んだソフトウェア考古学
oguri
7
6.5k
Featured
See All Featured
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
118
51k
Git: the NoSQL Database
bkeepers
PRO
429
65k
How to train your dragon (web standard)
notwaldorf
91
5.9k
Why Our Code Smells
bkeepers
PRO
336
57k
How to Think Like a Performance Engineer
csswizardry
22
1.5k
Unsuck your backbone
ammeep
670
57k
Measuring & Analyzing Core Web Vitals
bluesmoon
6
320
Evolution of real-time – Irina Nazarova, EuRuKo, 2024
irinanazarova
7
610
Designing for humans not robots
tammielis
250
25k
Typedesign – Prime Four
hannesfritz
41
2.6k
Optimising Largest Contentful Paint
csswizardry
35
3.2k
Large-scale JavaScript Application Architecture
addyosmani
511
110k
Transcript
Designing Zero Trust Systems Damjan Gjurovski, CTO of Posedio Cloud
Native Meetup Linz 25.02.2025
Do it RIGHT. Hello 2 • Head of Technology of
Posedio • Work on Software/Data/Platform Engineering • Largest online transaction processing engine in AT • Largest GCP developer platform in AT • Enjoys building secure systems • How can we build secure systems?
Do it RIGHT. Security, the old way 01
Do it RIGHT. The good old days 4
Do it RIGHT. Becoming useful 5
Do it RIGHT. What about a nice frontend? 6
Do it RIGHT. Admin access needed 7
Do it RIGHT. Load balancing to the rescue 8
Do it RIGHT. Who can access our services 9
Do it RIGHT. Let’s keep things private 10
Do it RIGHT. The crown jewels 11
Do it RIGHT. Compartmentalisation is the solution 12
Do it RIGHT. Or is it? 13
Do it RIGHT. What is security? 02
Do it RIGHT. The glossary 15 CIA triad
Do it RIGHT. The glossary 16 Triple A
Do it RIGHT. The glossary 17 Root of trust
Do it RIGHT. The glossary 18 Identity
Do it RIGHT. How can we secure our systems 03
Do it RIGHT. IdP - Keycloak 20
Do it RIGHT. Workload Identity – SPIFFIE/SPIRE 21
Do it RIGHT. Policy - OPA 22
Do it RIGHT. Permissions - SpiceDB 23
Do it RIGHT. Secrets - Vault 24
Do it RIGHT. mTLS - ISTIO 25
Do it RIGHT. Image scanning - Trivy 26
Do it RIGHT. Image signing – cosign (honourable mention –
chainguard) 27
Do it RIGHT. Threat detection - Falco 28
Do it RIGHT. The Application 29
Do it RIGHT. The Platform 30
Do it RIGHT. THANK YOU! CONTACT US: Weyringergasse 1-3/DG 1040
Wien www.posedio.com office@posedio.com 31