Write AuthorizationPolicy from Evidence
Draft a least-privilege AuthorizationPolicy from caller identity, path, and method evidence.
risk-api should allow fraud score reads only from checkout-api and fraud-worker, while blocking broad namespace access. Authorization evidence chain: caller identity, operation, path, owner, validation. The common shortcut is to allow a whole namespace because it prevents tickets today, but it preserves lateral movement tomorrow. Before risk-api has a broad allow for namespace finance. Twelve workloads can reach paths that only two service roles need. After risk-api allows specific workload principals to GET /scores/ and keeps deny telemetry visible for unexpected callers. Identify principals Use mTLS telemetry to list callers and map them to service accounts: checkout-api and fraud-worker are…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in