5 ms·
Ask HN: How do you handle authentication and authorization between microservices
- matchmike1313 9y agoAPI keys typically
- deleted 9y ago[deleted]
- nickserv 9y agoSystem user permissions with public/private keys for lower level APIs (SSH tunnels, basically). Centralized token services for ReST APIs
- carlosdp 9y agoJWT tokens are a decent approach
- toomuchtodo 9y agoVaulted API keys with lifecycle management.
- exabrial 9y agoTake a look at the Microprofile JWT specifications. It provides a standard set of jwt claims: https://www.eclipse.org/community/eclipse_newsletter/2017/september/article2.php https://www.eclipse.org/community/eclipse_newsletter/2017/se...
- jwhitlark 9y agohttps://istio.io https://istio.io
- exabrial 9y agoI used to work for a company that has a solution for this exact problem: http://www.tribestream.io http://www.tribestream.io Great product and the people couldn't be a more diverse and all around good group of people.
- jhoh 9y agoYour www link doesn't work for me. https://tribestream.io https://tribestream.io
- borncrusader 9y agoJWTs are a good approach. I've also seen folks using mTLS with gRPC.
- codegladiator 9y agoA central server which maintain all authorization information. The client can request token to access a particular service. The service verifies the token by calling the central server and gets in response the permissions available for that token. Also, a TTLed cache on the servers.
- hkarthik 9y agoI assume the "central server" is actually an HA cluster of servers with consistency checking of the token data. Otherwise it sounds like a pretty bad SPOF. Any lessons you learned along the way with setting this up?
- codegladiator 9y agoYou are correct, single would be disaster. One of the lesson learnt, every network call is going add at least 10ms.
- segmondy 9y agokeycloak
- steve_taylor 9y agoDocker secrets.
- Rjevski 9y agoClient certs for service to service communication. Auth tokens validated by a central entity (a bunch of servers really) for user (mobile apps, etc) to service communication.