Securing Application Telemetry & Tracing with SPIFFE and Envoy
Application telemetry, such as Prometheus metrics, distributed logs, and tracing, offer a surplus of information on how an app works, how it's performing, what its communicating with and how. However …
Talk Title | Securing Application Telemetry & Tracing with SPIFFE and Envoy |
Speakers | Sabree Blackmon (Senior Security Engineer, Docker) |
Conference | KubeCon + CloudNativeCon North America |
Conf Tag | |
Location | Seattle, WA, USA |
Date | Dec 9-14, 2018 |
URL | Talk Page |
Slides | Talk Slides |
Video | |
Application telemetry, such as Prometheus metrics, distributed logs, and tracing, offer a surplus of information on how an app works, how it’s performing, what it’s communicating with and how. However, even when these streams do not contain PII, this information can be invaluable to malicious actors in the days of highly distributed systems. In this talk, we will demonstrate how to use Envoy proxy and SPIRE to protect your telemetry endpoints, in both push and pull use cases, utilizing fluentd, Prometheus, and OpenTracing & Jaeger.