SlideShare a Scribd company logo
Athenz:
The Open-Source Solution
to Provide Access Control in Dynamic Infrastructures
Tatsuya Yano / Yahoo Japan Corporation
Athenz: Open Source System
Created by Yahoo Inc.
• Service Authentication
– Provide secure identity in the form x.509
certificate to every workload / service in
modern environments
• Authorization
– Provides fine-grained Role Based Access
Control (RBAC)
3
Service Authentication
Authentication
• User Authentication
– AD / LDAP / Okta / etc
• Service Authentication
– Instances within a service with a unique
identity to enable secure communication
• IP / Networks ACLs / iptable
• Mutual TLS with x.509 certificates
Why does this matter?
• Many persistent large scale infrastructure
problems are rooted in identity and policy
– Network ACL complexity
– Federated “Single” Sign On (SSO) systems
– Headless/Automation users
– Shared secrets
Certificate Based Authentication
• Every instance / service in your cloud has
its own identity
• Stronger security by Mutual TLS
Authentication
• Short Lived Certificates
Copper Argos
• Generalized model for authorized service
providers to launch other service identities
in an authorized way through a callback-
based verification model.
Providers OpenStack Kubernetes Screwdriver
Amazon EC2 AWS ECS AWS Lambda
Bootstrapping Athenz Identity
9
Authorization
Athenz Data Model
Single source of truth
• Most infrastructures in Cloud computing environments (e.g.
Kubernetes, OpenStack, AWS, etc) have their own system of
access control.
• Athenz provides interface to integrate with each infrastructure to
run multi environments with a single access control model.
Cloud computing
environments
OpenStack Kubernetes Screwdriver
Amazon EC2 AWS ECS AWS Lambda
Authorization - Centralized Access Control
Authorization - Decentralized Access Control
Demo
14
Advantages of Athenz
• To provide service identity X.509 certificates
for services running in common providers like
Kubernetes, OpenStack or AWS that can be
used for mutual TLS authentication.
• To have precise and frequently configurable
access controls with single source of truth.
Future plans
• To support SPIFFE ID in SAN field of x509
certificate
• To integrate with Istio envoy for
authorization
Resources
• Athenz Website : http://www.athenz.io
• Athenz Github: https://github.com/yahoo/athenz
• Athenz Slack Channel: https://athenz.slack.com/
• Athenz Discussion Groups:
– Google Group: Athenz-Users
• Questions or Comments:
– Tatsuya Yano: tatyano@yahoo-corp.jp
Join US
http://www.athenz.io
Q & A
19
Athenz - The Open-Source Solution to Provide Access Control in Dynamic Infrastructures - Tatsuya Yano, Yahoo Japan

More Related Content

PDF
Athenz with Istio - Single Access Control Model in Cloud Infrastructures, Tat...
PPTX
Cybera Summit
PPTX
Azure network and infrastructure
PPTX
JECRC iWeekend Cloud Day
PPTX
Advanced development with Windows Azure
PPTX
Azure Operational Insight Preview
PPTX
Cloud Native London - 2019: What is a Service Mesh, and if I Get One Will it ...
PPTX
Deployment options for Kentico CMS on Windows Azure
Athenz with Istio - Single Access Control Model in Cloud Infrastructures, Tat...
Cybera Summit
Azure network and infrastructure
JECRC iWeekend Cloud Day
Advanced development with Windows Azure
Azure Operational Insight Preview
Cloud Native London - 2019: What is a Service Mesh, and if I Get One Will it ...
Deployment options for Kentico CMS on Windows Azure

What's hot (20)

PPT
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
PPTX
Microsoft Azure Training - [2] Introduction to the Cloud (Exam 70-533)
PPTX
Azure Service Bus Overview
PPTX
Webservice security considerations and measures
PPTX
Azure Container Service
PPTX
Azure service bus based on cloud computing
PPTX
Azure Service Bus
PPTX
Meetup CNCF Torino - Amazon EKS March 29th 2019
PPTX
Windows Azure Service Bus
PPTX
Windows Azure
PDF
Network security with Azure PaaS services by Erwin Staal from 4DotNet at Azur...
PPTX
Azure IAAS architecture with High Availability for beginners and developers -...
PPTX
An Intro to AS4, the Successor of AS2
PPTX
Cloud Bursting with A10 Lightning ADS
PPTX
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
PPTX
Serverless Architecture - introduction + AWS demo
PPTX
Azure Microservices in Practice - Radu Vunvulea ITCamp Community Timisoara 07...
PDF
Using Azure Managed Identities for your App Services by Jan de Vries from 4Do...
PPT
Windows Server 2008
PPTX
Manage and Operate Azure Stack Hub Stamps at Scale
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
Microsoft Azure Training - [2] Introduction to the Cloud (Exam 70-533)
Azure Service Bus Overview
Webservice security considerations and measures
Azure Container Service
Azure service bus based on cloud computing
Azure Service Bus
Meetup CNCF Torino - Amazon EKS March 29th 2019
Windows Azure Service Bus
Windows Azure
Network security with Azure PaaS services by Erwin Staal from 4DotNet at Azur...
Azure IAAS architecture with High Availability for beginners and developers -...
An Intro to AS4, the Successor of AS2
Cloud Bursting with A10 Lightning ADS
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Serverless Architecture - introduction + AWS demo
Azure Microservices in Practice - Radu Vunvulea ITCamp Community Timisoara 07...
Using Azure Managed Identities for your App Services by Jan de Vries from 4Do...
Windows Server 2008
Manage and Operate Azure Stack Hub Stamps at Scale
Ad

Similar to Athenz - The Open-Source Solution to Provide Access Control in Dynamic Infrastructures - Tatsuya Yano, Yahoo Japan (20)

PDF
Athenz introduction
ODP
Zarafa SummerCamp 2012 - Keynote Peter Ganten
PDF
Anil saldhana oasisid_cloud
PDF
Oasis IDCloud TC - Anil Saldhana
DOCX
Directions Answer each question individual and respond with full .docx
PDF
IaaS Cloud Providers: A comparative analysis
PDF
CIS14: Lean In: Enterprise Cloud Identity
PDF
Oasis Identity In The Cloud Technical Committee
DOCX
School of Computer & Information SciencesITS-532 Cloud C.docx
PPTX
Identity in Openstack Icehouse
PPTX
Building IAM for OpenStack
PDF
Open am and_radiantone
PDF
Why the future of the cloud is open
PPT
Cloud computing 2
PPTX
Identity Management: Using OIDC to Empower the Next-Generation Apps
PDF
OpenStack Identity - Keystone (liberty) by Lorenzo Carnevale and Silvio Tavilla
PPTX
Oow con7393
PPTX
Federated Identity Architectures Integrating With The Cloud
PDF
Oracle Open World Preso on Cloud Economics
PDF
Bridging the Enterprise and the Cloud from Layer 7
Athenz introduction
Zarafa SummerCamp 2012 - Keynote Peter Ganten
Anil saldhana oasisid_cloud
Oasis IDCloud TC - Anil Saldhana
Directions Answer each question individual and respond with full .docx
IaaS Cloud Providers: A comparative analysis
CIS14: Lean In: Enterprise Cloud Identity
Oasis Identity In The Cloud Technical Committee
School of Computer & Information SciencesITS-532 Cloud C.docx
Identity in Openstack Icehouse
Building IAM for OpenStack
Open am and_radiantone
Why the future of the cloud is open
Cloud computing 2
Identity Management: Using OIDC to Empower the Next-Generation Apps
OpenStack Identity - Keystone (liberty) by Lorenzo Carnevale and Silvio Tavilla
Oow con7393
Federated Identity Architectures Integrating With The Cloud
Oracle Open World Preso on Cloud Economics
Bridging the Enterprise and the Cloud from Layer 7
Ad

More from Yahoo Developer Network (20)

PDF
Developing Mobile Apps for Performance - Swapnil Patel, Verizon Media
PDF
Athenz & SPIFFE, Tatsuya Yano, Yahoo Japan
PDF
CICD at Oath using Screwdriver
PDF
Big Data Serving with Vespa - Jon Bratseth, Distinguished Architect, Oath
PPTX
How @TwitterHadoop Chose Google Cloud, Joep Rottinghuis, Lohit VijayaRenu
PDF
The Future of Hadoop in an AI World, Milind Bhandarkar, CEO, Ampool
PPTX
Apache YARN Federation and Tez at Microsoft, Anupam Upadhyay, Adrian Nicoara,...
PPTX
Containerized Services on Apache Hadoop YARN: Past, Present, and Future, Shan...
PDF
HDFS Scalability and Security, Daryn Sharp, Senior Engineer, Oath
PPTX
Hadoop {Submarine} Project: Running deep learning workloads on YARN, Wangda T...
PDF
Moving the Oath Grid to Docker, Eric Badger, Oath
PDF
Architecting Petabyte Scale AI Applications
PDF
Introduction to Vespa – The Open Source Big Data Serving Engine, Jon Bratseth...
PPTX
Jun 2017 HUG: YARN Scheduling – A Step Beyond
PDF
Jun 2017 HUG: Large-Scale Machine Learning: Use Cases and Technologies
PPTX
February 2017 HUG: Slow, Stuck, or Runaway Apps? Learn How to Quickly Fix Pro...
PPTX
February 2017 HUG: Exactly-once end-to-end processing with Apache Apex
PPTX
February 2017 HUG: Data Sketches: A required toolkit for Big Data Analytics
PDF
October 2016 HUG: Pulsar,  a highly scalable, low latency pub-sub messaging s...
PPTX
October 2016 HUG: Architecture of an Open Source RDBMS powered by HBase and ...
Developing Mobile Apps for Performance - Swapnil Patel, Verizon Media
Athenz & SPIFFE, Tatsuya Yano, Yahoo Japan
CICD at Oath using Screwdriver
Big Data Serving with Vespa - Jon Bratseth, Distinguished Architect, Oath
How @TwitterHadoop Chose Google Cloud, Joep Rottinghuis, Lohit VijayaRenu
The Future of Hadoop in an AI World, Milind Bhandarkar, CEO, Ampool
Apache YARN Federation and Tez at Microsoft, Anupam Upadhyay, Adrian Nicoara,...
Containerized Services on Apache Hadoop YARN: Past, Present, and Future, Shan...
HDFS Scalability and Security, Daryn Sharp, Senior Engineer, Oath
Hadoop {Submarine} Project: Running deep learning workloads on YARN, Wangda T...
Moving the Oath Grid to Docker, Eric Badger, Oath
Architecting Petabyte Scale AI Applications
Introduction to Vespa – The Open Source Big Data Serving Engine, Jon Bratseth...
Jun 2017 HUG: YARN Scheduling – A Step Beyond
Jun 2017 HUG: Large-Scale Machine Learning: Use Cases and Technologies
February 2017 HUG: Slow, Stuck, or Runaway Apps? Learn How to Quickly Fix Pro...
February 2017 HUG: Exactly-once end-to-end processing with Apache Apex
February 2017 HUG: Data Sketches: A required toolkit for Big Data Analytics
October 2016 HUG: Pulsar,  a highly scalable, low latency pub-sub messaging s...
October 2016 HUG: Architecture of an Open Source RDBMS powered by HBase and ...

Recently uploaded (20)

PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
A Presentation on Artificial Intelligence
PDF
cuic standard and advanced reporting.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Cloud computing and distributed systems.
PDF
Encapsulation theory and applications.pdf
PDF
Empathic Computing: Creating Shared Understanding
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Encapsulation_ Review paper, used for researhc scholars
A Presentation on Artificial Intelligence
cuic standard and advanced reporting.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Reach Out and Touch Someone: Haptics and Empathic Computing
Building Integrated photovoltaic BIPV_UPV.pdf
Review of recent advances in non-invasive hemoglobin estimation
NewMind AI Weekly Chronicles - August'25 Week I
Unlocking AI with Model Context Protocol (MCP)
Advanced methodologies resolving dimensionality complications for autism neur...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Per capita expenditure prediction using model stacking based on satellite ima...
The Rise and Fall of 3GPP – Time for a Sabbatical?
“AI and Expert System Decision Support & Business Intelligence Systems”
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Cloud computing and distributed systems.
Encapsulation theory and applications.pdf
Empathic Computing: Creating Shared Understanding

Athenz - The Open-Source Solution to Provide Access Control in Dynamic Infrastructures - Tatsuya Yano, Yahoo Japan

  • 1. Athenz: The Open-Source Solution to Provide Access Control in Dynamic Infrastructures Tatsuya Yano / Yahoo Japan Corporation
  • 2. Athenz: Open Source System Created by Yahoo Inc. • Service Authentication – Provide secure identity in the form x.509 certificate to every workload / service in modern environments • Authorization – Provides fine-grained Role Based Access Control (RBAC)
  • 4. Authentication • User Authentication – AD / LDAP / Okta / etc • Service Authentication – Instances within a service with a unique identity to enable secure communication • IP / Networks ACLs / iptable • Mutual TLS with x.509 certificates
  • 5. Why does this matter? • Many persistent large scale infrastructure problems are rooted in identity and policy – Network ACL complexity – Federated “Single” Sign On (SSO) systems – Headless/Automation users – Shared secrets
  • 6. Certificate Based Authentication • Every instance / service in your cloud has its own identity • Stronger security by Mutual TLS Authentication • Short Lived Certificates
  • 7. Copper Argos • Generalized model for authorized service providers to launch other service identities in an authorized way through a callback- based verification model. Providers OpenStack Kubernetes Screwdriver Amazon EC2 AWS ECS AWS Lambda
  • 11. Single source of truth • Most infrastructures in Cloud computing environments (e.g. Kubernetes, OpenStack, AWS, etc) have their own system of access control. • Athenz provides interface to integrate with each infrastructure to run multi environments with a single access control model. Cloud computing environments OpenStack Kubernetes Screwdriver Amazon EC2 AWS ECS AWS Lambda
  • 12. Authorization - Centralized Access Control
  • 15. Advantages of Athenz • To provide service identity X.509 certificates for services running in common providers like Kubernetes, OpenStack or AWS that can be used for mutual TLS authentication. • To have precise and frequently configurable access controls with single source of truth.
  • 16. Future plans • To support SPIFFE ID in SAN field of x509 certificate • To integrate with Istio envoy for authorization
  • 17. Resources • Athenz Website : http://www.athenz.io • Athenz Github: https://github.com/yahoo/athenz • Athenz Slack Channel: https://athenz.slack.com/ • Athenz Discussion Groups: – Google Group: Athenz-Users • Questions or Comments: – Tatsuya Yano: tatyano@yahoo-corp.jp