Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it's somewhat of a requirement to also secure your microservices. There are a ton of ways to do it, but bidirectional TLS is often overlooked: https://www.tinfoilsecurity.com/blog/securing-your-microserv...


I agree that securing the services is important.

I don't think bidirectional TLS is enough in many cases. Defense in depth is required. You need to ensure that when services access other services, they aren't granted wide open privileges because you (hopefully, still) own them.

I would add a reasonable authentication and authorization model to this list of prereqs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: