Zero Trust Architecture concept page. "Never trust, always verify." BeyondCorp-style identity-aware proxy with device posture + MFA, microsegmentation via service mesh (sidecar PEP + SPIFFE mTLS), and contrast vs legacy VPN castle-and-moat. 3 scenarios: BeyondCorp access flow, microsegment allow/deny, Colonial Pipeline–style breach blocked by ZT. ADR on adoption strategy (BeyondCorp vs Cloudflare Access vs Tailscale vs Zscaler).
Zero trust removes implicit trust based on network location or ownership. Subjects, devices, and workloads obtain resource-specific access through policy decision and enforcement points using current identity, posture, and threat evidence.
| Component | Responsibility |
|---|---|
user | User |
device | Device and Client |
identity-provider | Identity Evidence |
policy-enforcement | Policy Enforcement Point |
policy-decision | Policy Engine and Administrator |
posture-service | Device and Workload Posture |
telemetry | Telemetry and Threat Signals |
resource | Protected Enterprise Resource |
workload | Calling Service Workload |
service-enforcement | Service Policy Enforcement |
data | Resource Data |
Topology edges represent authenticated or otherwise explicit communication paths. Responses reuse those physical paths in reverse; no response-only or bypass edges are added.
per-resource-decision — Evaluate every resource requestAccess is granted to a specific resource and action after identity, device, policy, and risk evidence are evaluated at the enforcement point.
network-location-is-not-trust — Network location does not grant accessBeing on a corporate subnet or VPN supplies context but never bypasses authentication and resource authorization.
posture-change — Respond to a posture changeDevice or workload state is dynamic evidence. A newly noncompliant device loses or narrows subsequent access without treating the prior session as permanent trust.
service-to-service — Apply zero trust to workloadsA service identity reaches another service through an application-level enforcement point; network reachability alone grants no method permission.
least-privilege-session — Limit authority and durationA grant is scoped to the minimum resource, action, and duration; it does not become broad lateral network access.
policy-service-outage — Policy outage fails closedThe enforcement point does not interpret an unavailable policy decision as allow; explicitly designed low-risk continuity policies remain narrow and auditable.
continuous-reevaluation — Reevaluate on new threat evidenceTelemetry does not magically inspect every packet, but material risk changes can trigger a new decision, session restriction, or reauthentication.
Введите числа или выберите пресет