Securing the Service-to-Service Call Chain Patterns and Protocols with Adib Saikali

April 19, 2023

A single request arriving at a service can spawn many requests to downstream services. Securing the service-to-service call chain is a critical but challenging problem. This talk covers the key patterns for securing the service-to-service call chain and the technologies required to implement them. We explore patterns for using API Gateways, Service Mesh, SPIFFE, mTLS, JWT, and OpenID Connect using Spring-based demo apps. By the end of the talk, you’ll be familiar with all the key patterns along with technical and security tradeoffs for each of the patterns, allowing you to choose the patterns that will best fit your specific requirements. We’ll provide a GitHub repo containing implementations of all the patterns discussed in the talk, so you can apply what you learn on your projects.

Previous
The Golden Path to SpringOne: Five Simple Rules about Problems with Kevin Clark
The Golden Path to SpringOne: Five Simple Rules about Problems with Kevin Clark

Problem solving is central to an agile product team. But how do you know which problems to solve? More impo...

Next Video
Transformation Journey of a Wealth Management Portal Toward a Modern Cloud Native Architecture
Transformation Journey of a Wealth Management Portal Toward a Modern Cloud Native Architecture

In 2018, Publicis Sapient began the uphill task of re-engineering a decade-old monolith wealth management a...