Zero Trust

 View Only

Recording: Zero Trust at the API Layer: Strategies for Securing Microservices in Multi-Cloud Environments 

Jun 24, 2025 02:40:07 PM

Recording: Zero Trust at the API Layer: Strategies for Securing Microservices in Multi-Cloud Environments

CSA ZT Workgroup Informational presentation: Zero Trust at the API Layer: Strategies for Securing Microservices in Multi-Cloud Environments by Hariharan Ragothaman, Lead Software Engineer and DevSecOps practitioner at AMD

Abstract: Zero Trust is no longer just about endpoints and users—it’s about services, APIs, and dynamic communication across distributed systems. In a cloud-native world where microservices span multiple environments, APIs become the core trust boundary.
This talk dives deep into how organizations can implement Zero Trust at the API and service mesh layer, enforcing strong identity, access control, and behavioral baselines for service-to-service communication. Topics covered include:

  • Implementing mutual TLS (mTLS) across services using SPIFFE/SPIRE for cryptographic identity.
  • Using service meshes (Istio, Linkerd) to enforce Zero Trust policies, rate limiting, and telemetry.
  • Designing API Gateways with attribute-based access control (ABAC) and fine-grained policies.
  • Establishing behavioral norms and detecting anomalies in API interactions

The session will also include a real-world reference architecture for securing microservices in a hybrid multi-cloud deployment, along with tips on avoiding common design pitfalls.

Key Takeaways:

  • Learn how to enforce Zero Trust for east-west traffic in microservice-based systems
  • Explore open-source tools and cloud-native service meshes for API-level security
  • Understand how to use SPIFFE identities and mTLS to replace implicit trust with verified communication
  • Gain architectural insights for multi-cloud deployments with Zero Trust enforcement at the service layer

Target Audience: Platform engineers, DevSecOps leads, cloud architects, API security specialists, Security leaders at SaaS
companies
Speaker Bio: Hariharan Ragothaman is a Lead Software Engineer and DevSecOps practitioner with over a decade of experience building secure, scalable deployment pipelines in cloud environments. He has spoken at multiple conferences including OWASP, JFrog SwampUP, conf42 and IEEE Conferences. His expertise lies at the intersection of application security, automation, and AI-driven DevSecOps strategies.
LinkedIn: https://www.linkedin.com/in/hariharanragothaman/

Statistics
0 Favorited
8 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.