Buoyant released the latest version of the Linkerd service mesh platform to enhance its zero-trust security capabilities in Kubernetes environments.
Linkerd was developed as an open-source network proxy designed to be deployed as a service mesh. A service mesh is a dedicated layer for managing, controlling, and monitoring service-to-service communication within an application.
Buoyant added port-based policies in earlier releases of Linkerd included a network policy feature that extends zero-trust security capabilities to Kubernetes environments. The latest update continues to focus on security, Buoyant CEO William Morgan told SDxCentral. “The big driver for Linkerd is network security, and especially this idea of zero-trust security for Kubernetes.”
The new Linkerd 2.12 version includes route-based authorization policies that are designed to provide finer-grained management over microservices communications by controlling access to individual paths or routes for each microservice.
“What we've added is the ability to do policy based on not just the port or the connection, but also based on the actual traffic,” Morgan said, adding this route-based policy is “an important part of zero trust.”
Additionally, he noted service mesh platforms like Linkerd turn out to be a great tool for zero-trust security because it operates at a level that is above the raw network.
Network security traditionally is based on layer 4 of the network, while Linkerd has been operating at layer 7 — the application layer, and “that actually is where most of the zero-trust features come into play,” Morgan argues.
Linkerd’s authorization policies are based on cryptographic workload identity, and the enforcement is “at the most granular level possible” — the pod, he explained. And it relies on mutual TLS, a method for mutual identification based on cryptographic security, to provide encryption and fine-grained user identification.
Linkerd vs. IstioLinkerd was the first service mesh to graduate from the open source-focused organization Cloud Native Computing Foundation (CNCF).
And another service mesh — the Google-backed Istio project, was finally donated to CNCF this April. Even though it was the right move, Morgan didn’t see a big market impact. “I think it would have been important three years ago. At this point, I think people are making their decision based on what are the features, what's the complexity, what's the reputation that this project has, and what kind of relationship I have with the maintainers.”
“The number one reason people tell us [why they are] adopting Linkerd is for mutual TLS, whether that's in support of zero trust, or whether it's just because they want encryption,” he added. “The other thing we're seeing is Istio is known to be very complex, and it's known to be difficult to operate. And if all you want is to improve your security, you don't want to add a lot of complexity into your system.”
As security becomes the differentiation among service mesh platforms, Morgan noted “complexity is basically the opposite of security,” and customers are attracted to Linkerd because of its simplicity.
Comments