Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A cloud development team is implementing a new microservices architecture. They need to ensure that each microservice can securely identify itself when communicating with other microservices within the same cloud environment, without relying on shared secrets or manual credential rotation. Which of the following identity mechanisms is most appropriate for this scenario?
- AOAuth 2.0 client credentials flow
- BService mesh with mutual TLS (mTLS)
- CJSON Web Tokens (JWTs) for inter-service authentication
- DAPI keys managed by a central secrets manager
Show answer & explanationAnswer & explanation
Correct answer: B. Service mesh with mutual TLS (mTLS)
Mutual TLS (mTLS) within a service mesh provides strong, baked-in identity for services, enabling automatic certificate rotation and secure, encrypted communication without manual credential management. This is ideal for inter-service communication in a microservices architecture.
Why the other options are wrong
- A. OAuth 2.0 client credentials flow is typically used for service-to-service authentication, but a service mesh with mTLS offers more comprehensive identity, encryption, and policy enforcement at the network layer for microservices.
- C. JWTs can be used for authentication but don't inherently provide the mutual authentication and secure channel of mTLS for service-to-service communication.
- D. API keys require manual management and rotation, which is not ideal for dynamic microservices and doesn't provide mutual authentication or encryption.
Service Mesh with Mutual TLS (mTLS)
A service mesh provides network-based communication control, and mTLS within it establishes mutual authentication and encryption between services using certificates.
- Automates service identity and certificate management.
- Encrypts all inter-service communication.
- Enforces policies at the network layer.
Memory trick: Mesh with mTLS makes microservices mutually trusted and secure.