Skip to main content
SERVICE-MESH5 MIN READ

Write AuthorizationPolicy from Evidence

Draft a least-privilege AuthorizationPolicy from caller identity, path, and method evidence.

risk-api should allow fraud score reads only from checkout-api and fraud-worker, while blocking broad namespace access. Authorization evidence chain: caller identity, operation, path, owner, validation. The common shortcut is to allow a whole namespace because it prevents tickets today, but it preserves lateral movement tomorrow. Before risk-api has a broad allow for namespace finance. Twelve workloads can reach paths that only two service roles need. After risk-api allows specific workload principals to GET /scores/ and keeps deny telemetry visible for unexpected callers. Identify principals Use mTLS telemetry to list callers and map them to service accounts: checkout-api and fraud-worker are…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us