29
Authentication in microservices
(feddit.dk)
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev
I mean, both sound valid. I'd say the first option is likely the most common: some kinda firewall or private network that keeps your microservices isolated from the public internet. In a practical sense, odds are all of this stuff is physically co-located anyway, so it could even be that the networks are physically isolated as well.
Thanks for the answer :)
The walled garden (micro services in an isolated network) is the first line of defense. In case a malicious actor finds a way into that network, the second line of defense would be to authenticate the service-service traffic, so the micro services reject direct requests from clients they aren't expecting.