Professional Cloud ArchitectManage implementationMedium

A large enterprise is migrating its monolithic application to a microservices architecture on Google Kubernetes Engine (GKE). The development team is creating new services that need to communicate securely and efficiently with each other. They want to ensure that service-to-service authentication and authorization are handled robustly without extensive manual configuration. Which Google Cloud service should be integrated into their GKE environment to manage and enforce these security policies?

  1. ACloud Armor
  2. BCloud Identity-Aware Proxy (IAP)
  3. CAnthos Service Mesh
  4. DIdentity Platform
Show answer & explanation

Correct answer: C. Anthos Service Mesh

Anthos Service Mesh (ASM) provides traffic management, mTLS for strong service-to-service authentication, and fine-grained authorization policies within a microservices architecture, which is crucial for secure and efficient communication in GKE.

Why the other options are wrong

  • A. Cloud Armor is a DDoS protection and WAF service, primarily for protecting external-facing applications from attacks, not for internal service-to-service authentication.
  • B. Cloud Identity-Aware Proxy (IAP) secures access to applications running on Google Cloud by verifying user identity and context, which is for user-to-service access, not service-to-service.
  • D. Identity Platform is for customer identity and access management (CIAM), focusing on user authentication for applications, not service-to-service within a mesh.

Anthos Service Mesh (ASM)

A managed service mesh for Google Kubernetes Engine (GKE) that simplifies the management, security, and observability of microservices.

  • Provides mTLS for service-to-service authentication.
  • Enables fine-grained traffic management (routing, policies).
  • Offers advanced telemetry and observability for microservices.
  • Based on Istio open-source project.

Memory trick: Mesh secures and controls micro-pieces.

More Manage implementation questions