Why this matters
- StreamHub processes payments, stores PII, and streams content to minors — a single misconfigured S3 bucket or missing auth check becomes a headline.
- Zero-trust means never assuming internal network traffic is safe; verify identity and authorisation on every request, even service-to-service.
- OAuth2/OIDC for user auth, mTLS for service auth, and WAF for edge protection are the 2024–2026 baseline.
Security layers for StreamHub
- Edge (WAF + CDN) — DDoS protection, rate limiting, OWASP rule sets, bot detection.
- API gateway — JWT validation, OAuth2 token introspection, request size limits.
- Service mesh — mTLS between all pods, network policies, egress control.
- Application — input validation, RBAC, secrets from vault (not env files).
- Data — encryption at rest (AES-256), column-level encryption for PII, audit logging.
Defence-in-depth on AWS
Authentication with OAuth2 and OIDC
POST /oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=authorization_code
&code=AUTH_CODE_HERE
&redirect_uri=https://streamhub.com/callback
&client_id=streamhub-web
&client_secret=<from-vault>
{
"access_token": "eyJhbGciOiJSUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "dGhpcyBpcyBhIHJlZnJlc2g...",
"scope": "read:profile write:streams"
}
JWT access tokens carry claims validated at the API gateway:
{
"sub": "usr_42",
"iss": "https://auth.streamhub.com",
"aud": "streamhub-api",
"exp": 1740850800,
"scope": "read:profile write:streams",
"roles": ["creator", "moderator"]
}
Service-to-service security
Internal traffic uses mTLS via the service mesh — no plaintext HTTP between pods.
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: streamhub-payment-policy
namespace: streamhub
spec:
selector:
matchLabels:
app: streamhub-payment
action: ALLOW
rules:
- from:
- source:
principals: ["cluster.local/ns/streamhub/sa/checkout-service"]
to:
- operation:
methods: ["POST"]
paths: ["/v1/charges"]
Network policies
Restrict pod-to-pod communication at the Kubernetes network layer.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: streamhub-api-ingress
spec:
podSelector:
matchLabels:
app: streamhub-api
policyTypes: [Ingress]
ingress:
- from:
- podSelector:
matchLabels:
app: streamhub-gateway
- namespaceSelector:
matchLabels:
name: istio-system
ports:
- protocol: TCP
port: 8080
| Aspect | Control | Protects against |
|---|---|---|
| WAF (Cloudflare/AWS) | SQL injection, XSS, DDoS | External attackers |
| OAuth2 / OIDC | Unauthenticated access | Stolen sessions, impersonation |
| mTLS (service mesh) | Man-in-the-middle, lateral movement | Compromised pod scanning internal network |
| RBAC | Privilege escalation | User accessing admin endpoints |
| Secrets manager | Credential leakage in code/repos | Hardcoded API keys in git history |
WAF (Cloudflare/AWS)
ControlSQL injection, XSS, DDoSProtects againstExternal attackersOAuth2 / OIDC
ControlUnauthenticated accessProtects againstStolen sessions, impersonationmTLS (service mesh)
ControlMan-in-the-middle, lateral movementProtects againstCompromised pod scanning internal networkRBAC
ControlPrivilege escalationProtects againstUser accessing admin endpointsSecrets manager
ControlCredential leakage in code/reposProtects againstHardcoded API keys in git history
Layer controls so a WAF bypass does not automatically grant database access.
Secrets management
Never store secrets in source code, ConfigMaps, or plain environment variables.
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: streamhub-db-credentials
spec:
refreshInterval: 1h
secretStoreRef:
name: aws-secrets-manager
kind: ClusterSecretStore
target:
name: streamhub-db-secret
data:
- secretKey: password
remoteRef:
key: prod/streamhub/database
property: password
Security monitoring
Detection and response
- Audit logging — every auth event, permission change, and admin action logged immutably.
- Anomaly detection — alert on unusual login patterns, bulk data exports, privilege escalations.
- Vulnerability scanning — Trivy/Grype on container images in CI; block deploy on critical CVEs.
- Penetration testing — annual third-party pentest; quarterly internal red-team exercises.
Quick recall
Everything you need if you only revisit this box.
- Defence in depth: WAF → API gateway (OAuth2) → mesh (mTLS) → app (RBAC) → data (encryption).
- OAuth2/OIDC for user auth; JWT claims validated at gateway before reaching services.
- mTLS + AuthorizationPolicy restricts which services can call which endpoints.
- Secrets in vault (AWS Secrets Manager, HashiCorp Vault) — never in code or ConfigMaps.
- Audit logs, vulnerability scanning, and regular pentests close the detection loop.
Test yourself
Answer these before moving on — recall is what makes it stick.