Security
Zero-trust between services, identity, authorization, secrets, and protecting data in a distributed system — what seniors must own beyond the perimeter.
Microservices multiply the attack surface: more network paths, more credentials, more places to mishandle data. Perimeter security is not enough. Seniors design as if the internal network is hostile — because eventually something inside it will be.
Authenticate every hop
Service-to-service calls need a real identity, not “we’re on the private VPC.”
Common patterns:
- mTLS between services (mesh or sidecar)
- Signed service tokens (JWT/OAuth2 client credentials) with short lifetime
- Workload identity from the platform (SPIFFE / cloud IAM roles)
Anonymous internal APIs invite lateral movement after one compromised pod or leaked job credential.
Authorize for the action, not the network
Authentication answers who; authorization answers what they may do.
- Prefer least privilege per service: the refund service does not need write access to user PII stores
- Check authorization on every sensitive command, including async consumers
- Do not trust headers like
X-User-Idunless they are set by a verified gateway and stripped from external clients
Confused-deputy bugs are common when a trusted service forwards unchecked caller claims.
Protect data in motion and at rest
- TLS everywhere that carries credentials or personal/financial data
- Encrypt sensitive fields at rest when the threat model demands it (tokens, secrets, payment instruments)
- Minimize what each service stores — data you do not hold cannot leak from that service
In payments, PCI and privacy rules often force clear boundaries: card data stays in a vault or PSP; orchestration holds references, not PANs.
Secrets are not config files
Never bake secrets into images or commit them to git. Use a secrets manager or platform injection, rotate routinely, and scope credentials per service.
Long-lived shared “deploy keys” and god-mode DB users turn every service compromise into a platform compromise.
Gateways and exposure
Public traffic should enter through a controlled edge: authn, rate limits, request size limits, WAF as appropriate. Internal services stay off the public internet.
Do not expose admin or debug endpoints without the same controls as production APIs.
Supply chain and runtime
- Pin and scan dependencies; watch for malicious packages
- Run with a non-root user, read-only filesystem where possible, and locked-down egress if the platform allows
- Keep base images patched; treat image provenance as part of the release
Threat modeling as a habit
For each new service or integration, ask:
- What can an attacker do if they compromise this service?
- What can they do with its credentials against peers?
- What PII or money-movement power does it hold?
- How do we detect misuse quickly?
Security in microservices is continuous design work — identity, authorization, data minimization, and blast-radius control — not a checklist at the end.