Kochubeev Nikolay Sergeevich (Teacher, ITMO National Research University)
Savelieva Zoya Viktorovna (ITMO National Research University)
| |
The evolution of microservice architecture and cloud computing has intensified the challenge of securely managing sensitive data (secrets), such as API keys, certificates, and passwords. Traditional approaches involving the static storage of secrets in configuration files or environment variables fail to provide the required level of security, auditability, and scalability in a dynamic environment. This paper proposes an architecture for an adaptive secrets management system designed to operate in orchestrated environments like Kubernetes. The proposed solution is based on the principles of dynamic privilege granting, automatic credential rotation, and centralized auditing. The system integrates with cloud service providers (AWS Secrets Manager, HashiCorp Vault) and Kubernetes pod identity mechanisms to ensure the principle of least privilege. The testing conducted confirms that the proposed approach reduces the risk of secret compromise compared to traditional methods and also lowers the operational costs of their maintenance.
Keywords:secrets management, microservice architecture, cybersecurity, cloud computing, Kubernetes, automatic rotation, access control.
|
|
| |
|
Read the full article …
|
Citation link: Kochubeev N. S., Savelieva Z. V. ADAPTIVE SECURITY AND ACCESS MANAGEMENT SYSTEM FOR CLOUD-BASED MICROSERVICES ARCHITECTURE // Современная наука: актуальные проблемы теории и практики. Серия: Естественные и Технические Науки. -2025. -№12. -С. 81-84 DOI 10.37882/2223-2966.2025.12.20 |
|
|