P58 · Cloud & Network Security

zero-trust, segmentation, service-to-service mTLS

Reducing and controlling network exposure: default-deny firewalls and binding choices, zero trust that decides on identity rather than IP, and service-to-service mutual TLS with workload identity.

A service that nothing can reach is difficult to attack. That sounds trivial, and it is the reason network security remains the highest-leverage control in the discipline: the cheapest fix for a whole class of incidents is a binding address and a default-deny rule, decided once, before any of the sophisticated defences above it are needed. This pillar treats exposure as something you read and control deliberately rather than inherit from a default.

It begins with the surface itself — what a bind address actually means, how a first-match rule set with a default deny evaluates, and how to classify a service as loopback, private or public from its configuration rather than by hoping. Then comes the shift that undid the perimeter. When workloads run everywhere and users connect from anywhere, the fact that a request came from inside the network stops being evidence of anything, so zero trust decides each request on user identity and device posture instead of source address, and micro-segmentation limits what any single compromised workload can go on to reach. The pillar ends between services, where one-sided TLS is not enough: with mutual TLS both ends prove who they are, and the practical questions become where a workload's identity comes from, why its certificates should be short-lived, and how rotation happens without an outage — which is what makes this operationally real rather than a diagram.

Surfacebindings and default-deny rulesZero trustidentity over source addressSegmentlimit the blast radiusmTLSworkload identity, short-lived certs
Reduce what can be reached, stop trusting the network, then make services prove identity to each other.
P58 · Cloud & Network Security — TransformerLab