PrepZone Logo
PrepZone

Security Defence in Depth

OAuth2, OIDC, mTLS, WAF and zero-trust layers that protect APIs at every boundary.

Read these first

Why this matters

  • StreamHub processes payments, stores PII, and streams content to minors — a single misconfigured S3 bucket or missing auth check becomes a headline.
  • Zero-trust means never assuming internal network traffic is safe; verify identity and authorisation on every request, even service-to-service.
  • OAuth2/OIDC for user auth, mTLS for service auth, and WAF for edge protection are the 2024–2026 baseline.

Security layers for StreamHub

  • Edge (WAF + CDN) — DDoS protection, rate limiting, OWASP rule sets, bot detection.
  • API gateway — JWT validation, OAuth2 token introspection, request size limits.
  • Service mesh — mTLS between all pods, network policies, egress control.
  • Application — input validation, RBAC, secrets from vault (not env files).
  • Data — encryption at rest (AES-256), column-level encryption for PII, audit logging.

Defence-in-depth on AWS

NETWORK
Internetuntrusted
SECURITY
WAF + Shieldedge filter
NETWORK
CloudFront / …
COMPUTE
VPC privateEKS · RDS · MSK
SECURITY
IAM / IRSAleast privilege
SECURITY
KMSencrypt at rest
WAF at edge, VPC private subnets, IAM IRSA, KMS encryption.

Authentication with OAuth2 and OIDC

Java
POST /oauth/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=AUTH_CODE_HERE
&redirect_uri=https://streamhub.com/callback
&client_id=streamhub-web
&client_secret=<from-vault>
Java
{
  "access_token": "eyJhbGciOiJSUzI1NiIs...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "dGhpcyBpcyBhIHJlZnJlc2g...",
  "scope": "read:profile write:streams"
}

JWT access tokens carry claims validated at the API gateway:

Java
{
  "sub": "usr_42",
  "iss": "https://auth.streamhub.com",
  "aud": "streamhub-api",
  "exp": 1740850800,
  "scope": "read:profile write:streams",
  "roles": ["creator", "moderator"]
}

Service-to-service security

Internal traffic uses mTLS via the service mesh — no plaintext HTTP between pods.

Java
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
  name: streamhub-payment-policy
  namespace: streamhub
spec:
  selector:
    matchLabels:
      app: streamhub-payment
  action: ALLOW
  rules:
    - from:
        - source:
            principals: ["cluster.local/ns/streamhub/sa/checkout-service"]
      to:
        - operation:
            methods: ["POST"]
            paths: ["/v1/charges"]

Network policies

Restrict pod-to-pod communication at the Kubernetes network layer.

Java
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: streamhub-api-ingress
spec:
  podSelector:
    matchLabels:
      app: streamhub-api
  policyTypes: [Ingress]
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: streamhub-gateway
        - namespaceSelector:
            matchLabels:
              name: istio-system
      ports:
        - protocol: TCP
          port: 8080
AspectControlProtects against
WAF (Cloudflare/AWS)SQL injection, XSS, DDoSExternal attackers
OAuth2 / OIDCUnauthenticated accessStolen sessions, impersonation
mTLS (service mesh)Man-in-the-middle, lateral movementCompromised pod scanning internal network
RBACPrivilege escalationUser accessing admin endpoints
Secrets managerCredential leakage in code/reposHardcoded API keys in git history
  • WAF (Cloudflare/AWS)

    ControlSQL injection, XSS, DDoS
    Protects againstExternal attackers
  • OAuth2 / OIDC

    ControlUnauthenticated access
    Protects againstStolen sessions, impersonation
  • mTLS (service mesh)

    ControlMan-in-the-middle, lateral movement
    Protects againstCompromised pod scanning internal network
  • RBAC

    ControlPrivilege escalation
    Protects againstUser accessing admin endpoints
  • Secrets manager

    ControlCredential leakage in code/repos
    Protects againstHardcoded API keys in git history

Layer controls so a WAF bypass does not automatically grant database access.

Secrets management

Never store secrets in source code, ConfigMaps, or plain environment variables.

Java
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
  name: streamhub-db-credentials
spec:
  refreshInterval: 1h
  secretStoreRef:
    name: aws-secrets-manager
    kind: ClusterSecretStore
  target:
    name: streamhub-db-secret
  data:
    - secretKey: password
      remoteRef:
        key: prod/streamhub/database
        property: password

Security monitoring

Detection and response

  • Audit logging — every auth event, permission change, and admin action logged immutably.
  • Anomaly detection — alert on unusual login patterns, bulk data exports, privilege escalations.
  • Vulnerability scanning — Trivy/Grype on container images in CI; block deploy on critical CVEs.
  • Penetration testing — annual third-party pentest; quarterly internal red-team exercises.

Quick recall

Everything you need if you only revisit this box.

  • Defence in depth: WAF → API gateway (OAuth2) → mesh (mTLS) → app (RBAC) → data (encryption).
  • OAuth2/OIDC for user auth; JWT claims validated at gateway before reaching services.
  • mTLS + AuthorizationPolicy restricts which services can call which endpoints.
  • Secrets in vault (AWS Secrets Manager, HashiCorp Vault) — never in code or ConfigMaps.
  • Audit logs, vulnerability scanning, and regular pentests close the detection loop.

Test yourself

Answer these before moving on — recall is what makes it stick.