Professional Cloud ArchitectManage implementationMedium
A large enterprise is migrating its monolithic application to a microservices architecture on Google Kubernetes Engine (GKE). The development team is creating new services that need to communicate securely and efficiently with each other. They want to ensure that service-to-service authentication and authorization are handled robustly without extensive manual configuration. Which Google Cloud service should be integrated into their GKE environment to manage and enforce these security policies?
- ACloud Armor
- BCloud Identity-Aware Proxy (IAP)
- CAnthos Service Mesh
- DIdentity Platform
Show answer & explanationAnswer & explanation
Correct answer: C. Anthos Service Mesh
Anthos Service Mesh (ASM) provides traffic management, mTLS for strong service-to-service authentication, and fine-grained authorization policies within a microservices architecture, which is crucial for secure and efficient communication in GKE.
Why the other options are wrong
- A. Cloud Armor is a DDoS protection and WAF service, primarily for protecting external-facing applications from attacks, not for internal service-to-service authentication.
- B. Cloud Identity-Aware Proxy (IAP) secures access to applications running on Google Cloud by verifying user identity and context, which is for user-to-service access, not service-to-service.
- D. Identity Platform is for customer identity and access management (CIAM), focusing on user authentication for applications, not service-to-service within a mesh.
Anthos Service Mesh (ASM)
A managed service mesh for Google Kubernetes Engine (GKE) that simplifies the management, security, and observability of microservices.
- Provides mTLS for service-to-service authentication.
- Enables fine-grained traffic management (routing, policies).
- Offers advanced telemetry and observability for microservices.
- Based on Istio open-source project.
Memory trick: Mesh secures and controls micro-pieces.