
Zero-code SSO for legacy apps with an eBPF proxy
How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.
4 posts

How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.

How services prove who they are to each other with mTLS, workload identity and short-lived certificates, and why a shared static API key is the wrong tool for the job.

A shared kubeconfig tells the cluster nothing about who is calling. How OIDC, RBAC subjects and short-lived credentials tie Kubernetes access to a person or workload.