Security

Trust boundaries you can reason about.

Each plane gets only the access it needs. Consumer traffic never reaches the management plane. Gateway pods hold no database connection. Every deployment is validated first.

Security posture

Separation is the first control.

Start with topology. Then add identity, authorization, validation, signed content, audit, and runtime policy.

TRUST ZONES

Split-plane architecture

Management, machine-facing services, and the request path have separate jobs and separate connections.

CHANGE CONTROL

Immutable revisions

Published bundles cannot be edited. An environment picks a revision, and that choice is recorded.

LEAST AUTHORITY

Memory-only gateways

Gateway pods get compiled config only. No database credentials, no authoring workspace.

Platform controls

Defense at authoring and runtime.

  • RBAC and auditEvery management action is authorized and logged.
  • Schema validationBundle structure and policy settings are checked before deployment.
  • Content verificationRuntime files are addressed and checked by content hash.
  • Last known goodA failed generation never replaces a healthy one.
  • Credential isolationConsumer and upstream secrets live in purpose-built stores.
  • Fail-closed pathsSecurity-sensitive cache misses and identity failures have defined outcomes.

Runtime identity

Identity is checked at the edge.

The gateway backend owns the consumer registry and token services. Gateways cache what they resolve, within set bounds, and fail closed when a security-sensitive lookup misses.

WHO IS CALLING

API keys, OAuth2, JWT

Verify credentials and tokens before a request reaches a route.

PROOF OF ORIGIN

HMAC and mTLS

Signed requests and client certificates for machine-to-machine calls.

SHAPE OF THE REQUEST

Limits and threat protection

IP rules, request size, request validation, bot detection, and threat protection.