Lightning Talk: Using Keycloak Authorization Service for Kubernetes Service-to-Service… H. Özkan

CNCF
AI summary

This lightning talk demonstrates using Keycloak Authorization Services as a centralized authorization control plane for Kubernetes service-to-service communication. The architecture uses Istio Ambient mode with waypoint proxies and a WebAssembly extension to enforce authorization decisions at the platform layer without modifying application code. It covers implementation patterns, fail-closed handling, latency trade-offs, and includes a live demo for platform and security engineers implementing zero-trust in Kubernetes environments.