# identity management

Published articles for identity management.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

DevFeed: [Identity Everywhere: Bringing Infrastructure Identity to Agentic IT](<https://devfeed.tech/articles/identity-everywhere-bringing-infrastructure-identity-to-agentic-it-29604.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/cisco-teleport-partnership/>)

Author: info@goteleport.com (Peter Bailey, Ev Kontsevoy)

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cisco](<https://devfeed.tech/topics/cisco.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Cisco and Teleport announce a strategic partnership involving technology integration, licensing, and investment. The article presents Infrastructure Identity as a cryptographic model intended to connect secure identity with human and machine actions, including activity by workloads, automation, and AI agents.

### Source excerpt

Cisco and Teleport are announcing a strategic partnership centered on deep technology integration, licensing, and investment.

## What is an Agentic Data Plane?

DevFeed: [What is an Agentic Data Plane?](<https://devfeed.tech/articles/what-is-an-agentic-data-plane-12781.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/what-is-an-agentic-data-plane>)

Author: Marc Millstone

Published: 2026-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [Amazon API Gateway](<https://devfeed.tech/topics/amazon-api-gateway.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [observability](<https://devfeed.tech/topics/observability.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api](<https://devfeed.tech/tags/api.md>), [api-gateway](<https://devfeed.tech/tags/api-gateway.md>), [aws](<https://devfeed.tech/tags/aws.md>), [bedrock](<https://devfeed.tech/tags/bedrock.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [governance](<https://devfeed.tech/tags/governance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [llm](<https://devfeed.tech/tags/llm.md>), [models](<https://devfeed.tech/tags/models.md>), [observability](<https://devfeed.tech/tags/observability.md>), [siem](<https://devfeed.tech/tags/siem.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [token](<https://devfeed.tech/tags/token.md>), [tool](<https://devfeed.tech/tags/tool.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

The article defines an Agentic Data Plane as a governed governance and runtime layer between enterprise AI agents and the data, tools, identities, and models they access. It explains why existing IAM, API gateways, and observability or SIEM systems do not adequately govern agent-specific actions, identity propagation, model selection, token spending, policy enforcement, and end-to-end tracing.

### Source excerpt

The Agentic Data Plane is the governance and runtime layer that connects your AI agents to everything they act on. Learn what it does, why existing tools can't replace it, and what to look for in an enterprise-grade one.

## Meet the Sales Leader Who Leads From the Front -- and Won't Let You Settle for Less

DevFeed: [Meet the Sales Leader Who Leads From the Front -- and Won't Let You Settle for Less](<https://devfeed.tech/articles/meet-the-sales-leader-who-leads-from-the-front-and-won-t-let-you-settle-for-less-29761.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/meet-the-sales-leader-leading-from-the-front/>)

Author: amanda.erickson@goteleport.com (Amanda Erickson)

Published: 2026-04-15T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [okta](<https://devfeed.tech/topics/okta.md>)

Tags: [coaching](<https://devfeed.tech/tags/coaching.md>), [deals](<https://devfeed.tech/tags/deals.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [management](<https://devfeed.tech/tags/management.md>), [sales](<https://devfeed.tech/tags/sales.md>), [security](<https://devfeed.tech/tags/security.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

An interview with John Solazzo, Teleport's Senior Sales Director, about leading the company's mid-market sales organization through hands-on coaching, customer engagement, and deal leadership. Solazzo also explains why he joined Teleport and describes its infrastructure security approach, which uses identity and policy-based tools.

### Source excerpt

Meet John Solazzo, Teleport's Senior Sales Director leading mid-market sales from the front -- on calls, in deals, and coaching by example every single day.

## 2026 Cybersecurity Predictions by Teleport CEO Ev Kontsevoy

DevFeed: [2026 Cybersecurity Predictions by Teleport CEO Ev Kontsevoy](<https://devfeed.tech/articles/2026-cybersecurity-predictions-by-teleport-ceo-ev-kontsevoy-29541.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/2026-cybersecurity-predictions/>)

Author: ev@goteleport.com (Ev Kontsevoy)

Published: 2025-12-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [non-human-identity](<https://devfeed.tech/tags/non-human-identity.md>), [predictions](<https://devfeed.tech/tags/predictions.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Teleport CEO Ev Kontsevoy presents predictions for 2026 cybersecurity, arguing that AI identities will drive a unified approach to identity management, greater engineering involvement in security, and more granular definitions of agentic AI.

### Source excerpt

AI has broken identity security--2026 is when the cracks become impossible to ignore. Teleport CEO Ev Kontsevoy shares predictions and what leaders should do.

## Automating Administrative Tasks with Workflows in Keycloak 26.4 (experimental)

DevFeed: [Automating Administrative Tasks with Workflows in Keycloak 26.4 (experimental)](<https://devfeed.tech/articles/automating-administrative-tasks-with-workflows-in-keycloak-26-4-experimental-31734.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2025/10/workflows-experimental-26-4>)

Author: Stefan Guilhen

Published: 2025-10-02T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [automation](<https://devfeed.tech/tags/automation.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [experimental](<https://devfeed.tech/tags/experimental.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [onboarding-and-offboarding](<https://devfeed.tech/tags/onboarding-and-offboarding.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [triggers](<https://devfeed.tech/tags/triggers.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Keycloak 26.4 introduces an experimental Workflows feature that automates administrative tasks through event-triggered, conditional sequences of steps. The initial release focuses on user-resource management, including lifecycle operations such as onboarding and offboarding, with possible future expansion to other realm components.

### Source excerpt

What are Workflows and What Problems Do They Solve? At its core, the Workflows feature is an automation engine for administrative tasks. It empowers Keycloak administrators to define a series of steps that run automatically in response to specific events. The primary motivation behind this feature is to build a robust identity governance model within Keycloak while reducing manual, repetitive work. In any organization, managing the lifecycle of users and other resources is a critical but often time-consuming task. For example, failing to disable or remove inactive user accounts can create significant security vulnerabilities. Similarly, manually onboarding new users to specific roles or groups is inefficient and prone to error. Workflows aim to solve these problems by providing a flexible framework to automate these essential processes. Workflows and Identity Governance and Administration (IGA) The introduction of Workflows is a significant step forward for Keycloak in the realm of Identity Governance and Administration (IGA). IGA is a policy-based approach to identity management and access control that helps organizations strengthen security, meet compliance requirements, and improve operational efficiency. By allowing administrators to define automated processes for managing the user lifecycle, Workflows directly address key IGA principles. This automation not only enhances security by addressing inactive accounts but also reduces the administrative burden on processes that can be fully automated, like onboarding and offboarding users. Core Capabilities In its initial experimental release, the Workflows feature focuses on the following core capabilities: User-Centric Automation: In this first iteration, the feature is primarily targeted at automating tasks related to the management of user resources. However, the concept is designed to be extensible and could be enhanced in the future to manage other realm components like clients, organizations, or identity provid

## Trusted Computing: The Role of Infrastructure IAM

DevFeed: [Trusted Computing: The Role of Infrastructure IAM](<https://devfeed.tech/articles/trusted-computing-the-role-of-infrastructure-iam-29949.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/trusted-computing-role-of-iam/>)

Author: info@thecyberhut.com (Simon Moffatt)

Published: 2025-02-26T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [trust](<https://devfeed.tech/topics/trust.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [frameworks](<https://devfeed.tech/tags/frameworks.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article examines how Infrastructure IAM and trusted computing extend trust beyond data and applications to the infrastructure that delivers services. It discusses zero trust, software attestation, cryptographic challenge-response authentication, and trusted platform modules, while noting the complexity and security risks of modern infrastructure.

### Source excerpt

Discover how Infrastructure IAM enhances trust in modern computing with zero trust principles and identity management for people, machines, and workloads.

## KeyConf24 program announced & livestream

DevFeed: [KeyConf24 program announced & livestream](<https://devfeed.tech/articles/keyconf24-program-announced-livestream-31653.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/08/keyconf24-program-published>)

Author: Alexander Schwartz

Published: 2024-08-30T00:00:00Z

Content type: news

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [JOIN](<https://devfeed.tech/topics/join.md>)

Tags: [event](<https://devfeed.tech/tags/event.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [idm](<https://devfeed.tech/tags/idm.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [livestream](<https://devfeed.tech/tags/livestream.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

KeyConf24, the 2024 Keycloak Identity Summit, will take place on September 19, 2024, with its program available online. Due to high demand and limited on-site capacity, the event will offer a livestream for remote attendees. Topics include the European Digital Identity Wallet, verifiable credentials, Keycloak integrations, and new and upcoming Keycloak features.

### Source excerpt

KeyConf24, our 2024 Keycloak Identity Summit, will happen on September 19th, which is just around the corner! This year's event promises to be even bigger and better, with a program packed full of relevant, cutting-edge topics. This year due to high demand and limited space on-site, we're offering for the first time a live stream, so the Keycloak community can join remotely. What to Expect at KeyConf24 The talks have been selected, and the program is now online at https://keyconf.dev/. Expect talks about: European Digital Identity Wallet: Deep dives into the European Union's ambitious initiative and its impact on identity management. Verifiable Credentials: Explore the exciting potential of decentralized identity verification and the role of Keycloak. Real-world Keycloak integrations: Technical sessions on Keycloak's capabilities and how to leverage them in real world scenarios like the banking industry. New and upcoming features in Keycloak: Hear about the new organisations and user profile features which are available in the latest releases of Keycloak, as well as the next upcoming features. Save the Date and join us in the live stream! You can register for the live stream at https://keyconf.dev/. We're excited and are looking forward to meeting you at our event. Let's continue to shape the future of identity together!

## Audited least privilege

DevFeed: [Audited least privilege](<https://devfeed.tech/articles/audited-least-privilege-12893.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/audited-least-privilege>)

Published: 2024-05-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [ephemerality](<https://devfeed.tech/tags/ephemerality.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [logs](<https://devfeed.tech/tags/logs.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

The article presents audited least privilege as a cloud security model that complements fine-grained IAM grants with fine-grained IAM audit log policies. It emphasizes minimizing access by level, scope, and duration, then monitoring resource access to verify that only expected identities use provisioned resources.

### Source excerpt

Strengthen your software supply chain security with audited least privilege. Learn how Chainguard's approach minimizes risk and enhances trust.

## Temporal Cloud is now HIPAA compliant

DevFeed: [Temporal Cloud is now HIPAA compliant](<https://devfeed.tech/articles/temporal-cloud-is-now-hipaa-compliant-36009.md>)

Original publisher: [Read original article](<https://temporal.io/blog/temporal-cloud-is-now-hipaa-compliant>)

Author: Jim Walker

Published: 2024-02-05T16:00:00Z

Content type: release

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [data-security](<https://devfeed.tech/tags/data-security.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [health](<https://devfeed.tech/tags/health.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [product-news](<https://devfeed.tech/tags/product-news.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Temporal Cloud has achieved HIPAA compliance, enabling organizations handling protected health information to use the managed service while meeting applicable legal requirements. The article describes identity management, access controls, encryption settings, and data conversion capabilities that support sensitive health information security.

### Source excerpt

Temporal Cloud has achieved compliance with HIPAA, the national privacy and security standard for health-related information.

## Ultimate Go Episode 16: Adding Transaction Validation and Security to a Blockchain

DevFeed: [Ultimate Go Episode 16: Adding Transaction Validation and Security to a Blockchain](<https://devfeed.tech/articles/ultimate-go-advanced-engineering-episode-16-22205.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2023/01/ultimate-go-advanced-engineering-episode-16.html>)

Published: 2023-01-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Security](<https://devfeed.tech/topics/security.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [go](<https://devfeed.tech/tags/go.md>), [go-blockchain](<https://devfeed.tech/tags/go-blockchain.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [learn](<https://devfeed.tech/tags/learn.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [public-address](<https://devfeed.tech/tags/public-address.md>), [secure-blockchain](<https://devfeed.tech/tags/secure-blockchain.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

This video explains how to add validation mechanisms to blockchain nodes. It covers checking a transaction's destination, verifying signature rules defined by the protocol, and calculating a user's address from a transaction signature.

### Source excerpt

Introduction In episode 15, Bill architected a solution to ensure all the users on his blockchain were given a unique identifier. His approach consisted of essentially leveraging the randomness of a user's private key to ensure each identifier is unique. A disadvantage Bill pointed out with this is that a user may forget their private key and ultimately lose access to their account. To circumvent this issue, Bill proposed the usage of a mnemonic, that is composed of 12 to 24 words, to act as the private key since it's simpler to keep track of and hard to guess.

## Ethereum Identity Verification with ECDSA for a Decentralized Blockchain

DevFeed: [Ethereum Identity Verification with ECDSA for a Decentralized Blockchain](<https://devfeed.tech/articles/ultimate-go-advanced-engineering-episode-11-22200.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2023/01/ultimate-go-advanced-engineering-episode-11.html>)

Published: 2023-01-03T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [blockchain-asset](<https://devfeed.tech/tags/blockchain-asset.md>), [digital-signature](<https://devfeed.tech/tags/digital-signature.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [ecdsa-encryption](<https://devfeed.tech/tags/ecdsa-encryption.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [ethereum-authentication](<https://devfeed.tech/tags/ethereum-authentication.md>), [genesis-record](<https://devfeed.tech/tags/genesis-record.md>), [go-blockchain](<https://devfeed.tech/tags/go-blockchain.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

This video tutorial explores how Ethereum confirms user identity and explains how ECDSA can verify transaction authenticity without relying on a central key store.

### Source excerpt

Introduction In episode 10, Bill dove into the technical implementation of his genesis record and defined a custom Go type representing the record. While doing so, he provided an in-depth look at the reasoning behind the fields he included.. After declaring this type, Bill wrote a function that loads the genesis record from disk and onto memory. His function will use the standard library encoding/json package to load JSON data from a hard-coded file path.

## How Headspace Scaled Identity and Minimized Security Risk with Auth0 CIAM on AWS

DevFeed: [How Headspace Scaled Identity and Minimized Security Risk with Auth0 CIAM on AWS](<https://devfeed.tech/articles/how-headspace-scaled-identity-and-minimized-security-risk-with-auth0-ciam-on-aws-24575.md>)

Original publisher: [Read original article](<https://medium.com/headspace-engineering/how-headspace-scaled-identity-and-minimized-security-risk-with-auth0-ciam-on-aws-686e58f4420f?source=rss-3da90e297190------2>)

Author: Headspace

Published: 2021-12-21T22:41:06Z

Content type: article

Language: en

Sources: [Stories by Headspace on Medium](<https://devfeed.tech/sources/stories-by-headspace-on-medium.md>)

Topics: [Auth0](<https://devfeed.tech/topics/auth0.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [headspace](<https://devfeed.tech/tags/headspace.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [security](<https://devfeed.tech/tags/security.md>), [security-risk-management](<https://devfeed.tech/tags/security-risk-management.md>)

### AI overview

The article promotes a webinar featuring Headspace, AWS, and Auth0 about scaling customer identity and reducing security risk. It describes Headspace's need for a secure identity solution for its large monthly user base and enterprise customers, and presents authentication, authorization, and identity and access management as services delivered with AWS and Auth0.

### Source excerpt

George Torres, Director of Engineering at Headspace recently participated in an AWS and AWS Partner Auth0 webinar on scaling identity and minimizing security risk. You can use this link to register and watch the webinar. Delivering security and mindfulness at scale Headspace's mission is to improve the health and happiness of the world by providing guided meditations and mindfulness content through its mobile application. The company sought out a scalable and secure identity solution to support its millions of monthly active users and accommodate continued growth. Additionally, it needed to support its enterprise customers who were including Headspace services in their employee benefits packages. With Amazon Web Services (AWS) and AWS Partner Auth0, Headspace was able to achieve both. In this webinar, hear how to implement a frictionless digital experience with authentication and authorization as a service. Watch this webinar, and see how to: Focus on innovation instead of building and maintaining identity solutions Incorporate identity into any customer-facing application quickly, securely, and at scale Enable secure identity and access management across your environments Who should watch? CTOs, CIOs, CISOs, VPs of IT, IT Managers, IT Directors, IT Supervisors, Software Developers, Software Development Managers, System Architects, C-Level or LOB Managers, CEOs, CMOs, COOs, LOB Directors, Sr. Solution Architects, Sr. Security Architects, Sr. Security Engineers, Sr. Identity Engineers, IT Security Directors, Tech Leads, Engineering Managers, Technology Executives, Product Managers, Security Identity Managers, ITOps Webinar SpeakersClare Nelson Sr. Partner Development Manager, Amazon Web Services (AWS), Inc. Shiven Ramji Chief Product Officer, Auth0 George Torres Director of Engineering, Headspace How Headspace Scaled Identity and Minimized Security Risk with Auth0 CIAM on AWS was originally published in Headspace-engineering on Medium, where people are continuing the

## Consolidating Identity-Based Access

DevFeed: [Consolidating Identity-Based Access](<https://devfeed.tech/articles/consolidating-identity-based-access-29704.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/identity-based-management/>)

Author: info@goteleport.com (Virag Mody)

Published: 2020-12-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Authorization](<https://devfeed.tech/topics/authorization.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Server](<https://devfeed.tech/topics/server.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [databases](<https://devfeed.tech/tags/databases.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [slack](<https://devfeed.tech/tags/slack.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

The article argues for identity-based management that unifies access controls across cloud infrastructure. It describes the challenge of tracking users, secrets, sessions, and activity across servers, containers, databases, Kubernetes environments, and other resources, and highlights secret sprawl as a security risk.

### Source excerpt

Unify identity access controls across the entire stack with a single place to define, enforce, view, and manage global authorization.

## How Twitch Addresses Scalability and Authentication

DevFeed: [How Twitch Addresses Scalability and Authentication](<https://devfeed.tech/articles/how-twitch-addresses-scalability-and-authentication-20451.md>)

Original publisher: [Read original article](<https://medium.com/twitch-news/how-twitch-addresses-scalability-and-authentication-718d6ed3c471?source=rss----3ae745429979--engineering>)

Author: Eugene Pivovarov

Published: 2019-03-15T19:13:30Z

Content type: article

Language: en

Sources: [Twitch](<https://devfeed.tech/sources/twitch.md>)

Topics: [Twitch](<https://devfeed.tech/topics/twitch.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [latency](<https://devfeed.tech/tags/latency.md>), [lazy-loading](<https://devfeed.tech/tags/lazy-loading.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [tls](<https://devfeed.tech/tags/tls.md>), [twitch](<https://devfeed.tech/tags/twitch.md>)

### AI overview

This article explains how Twitch's Identity team addressed authentication scalability and performance. It describes reducing login-form latency through prefetching and lazy loading, and reducing downstream validation workload by exchanging OAuth 2.0 access tokens for short-lived JWTs containing user information, scopes, and a digital signature.

### Source excerpt

Curious how Twitch Identity services addresses scalability and performance challenges related to authentication? Last Tuesday, the Twitch Identity team -- which helps Twitch users create and manage their digital identity and owns the services that provide authentication, authorization, and user metadata management -- hosted a Meetup.com event to explain just that. But we're recapping here just for you! First challenge: Login form load The goal of authentication is to verify who the user is. In a typical login flow, the user supplies a password along with a username and the service validates the credentials. Login user interface The Twitch Login form used to load very slowly, as long as 10 seconds in some Asian and Pacific countries. The browser had to make a DNS request for the authentication backend, initiate a TLS connection to authentication service, make a request to load the page, and then make additional requests for more assets. Altogether, there were five round trips and over 150 KB of data transfer. To improve load latency, the team considered a few options: prefetching, connection reuse, inlining, and lazy loading. Ultimately, the solution relies mostly on prefetching by making the login modal part of the main page, but it employs lazy load for fetching heavy assets. As a result, the median load latency dropped as much as 20x from 4.1 sec to 0.2 sec. Second challenge: User session validation At the end of the login flow, the browser obtains a long-lived OAuth 2.0 access token and stores it in a cookie. This token is required for subsequent requests to the Twitch API and the corresponding downstream services. If each service had to validate the OAuth token directly against the token dispensary, the latter would need to handle calls from multiple services for every API request. To reduce the workload, the Identity team implemented an approach that employs self-contained JSON Web Tokens (JWT). Login and request flow In this approach, before forwarding the reque

## Easily secure your Spring Boot applications with Keycloak

DevFeed: [Easily secure your Spring Boot applications with Keycloak](<https://devfeed.tech/articles/easily-secure-your-spring-boot-applications-with-keycloak-31564.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2017/05/easily-secure-your-spring-boot>)

Author: Sébastien Blanc

Published: 2017-05-29T00:00:00Z

Content type: tutorial

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [backend](<https://devfeed.tech/tags/backend.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [spring-boot](<https://devfeed.tech/tags/spring-boot.md>), [sso](<https://devfeed.tech/tags/sso.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A tutorial showing how to secure Spring Boot applications with Keycloak. It explains Keycloak's authentication, authorization, and identity-management capabilities, then walks through setting up a server, creating a realm, configuring a client, and defining a role and user.

### Source excerpt

What is Keycloak? Although security is a crucial aspect of any application, its implementation can be difficult. Worse, it is often neglected, poorly implemented and intrusive in the code. But lately, security servers have appeared which allow for outsourcing and delegating all the authentication and authorization aspects. Of these servers, one of the most promising is Keycloak, open-source, flexible, and agnostic of any technology, it is easily deployable/adaptable in its own infrastructure. Moreover, Keycloak is more than just an authentication server, it also provides a complete Identity Management system, user federation for third parties like LDAP and a lot more ... Check it out on here. The project can also be found on Github Spring Boot and Keycloak Keycloak provides adapters for an application that needs to interact with a Keycloak instance. There are adapters for WildFly/EAP, NodeJS, Javascript and of course for Spring Boot. Setting up a Keycloak server You have different options to set up a Keycloak server but the easiest one is probably to grab a standalone distribution, unzip it and voila! Open a terminal and go to your unzipped Keycloak server and from the bin directory simply run: ./standalone.sh(bat) Then open a browser and go to http://localhost:8080/auth. Since it's the first time that the server runs you will have to create an admin user, so let's create an admin user with admin as username and admin for the password: Now you can log in into your administration console and start configuring Keycloak. Creating a new Realm Keycloak defines the concept of a realm in which you will define your clients, which in Keycloak terminology means an application that will be secured by Keycloak, it can be a Web App, a Java EE backend, a Spring Boot etc. So let's create a new realm by simply clicking the "Add realm" button: Let's call it "SpringBoot". Creating the client, the role, and the user Now we need to define a client, which will be our Spring Boot app. Go

## Target open-sources Winnaker to audit Spinnaker deployments

DevFeed: [Target open-sources Winnaker to audit Spinnaker deployments](<https://devfeed.tech/articles/win-the-cloud-with-winnaker-20405.md>)

Original publisher: [Read original article](<https://target.github.io/infrastructure/Win_the_cloud_with_Winnaker>)

Author: Target Brands, Inc

Published: 2017-02-13T06:00:00Z

Content type: release

Language: en

Sources: [Target](<https://devfeed.tech/sources/target.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [Continuous Delivery (CD)](<https://devfeed.tech/topics/continuous-delivery.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Deployment Strategies](<https://devfeed.tech/topics/deployment-strategies.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [audit](<https://devfeed.tech/tags/audit.md>), [automation](<https://devfeed.tech/tags/automation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [deployment-strategies](<https://devfeed.tech/tags/deployment-strategies.md>), [health-checks](<https://devfeed.tech/tags/health-checks.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform](<https://devfeed.tech/tags/platform.md>), [spinnaker](<https://devfeed.tech/tags/spinnaker.md>), [winnaker](<https://devfeed.tech/tags/winnaker.md>)

### AI overview

Target announces Winnaker, an open-source tool for auditing Spinnaker deployments from an end-user perspective. The article explains how Winnaker automates whole-system deployment testing and helps identify connectivity, API rate-limit, and infrastructure-configuration problems.

### Source excerpt

Win the cloud with Winnaker! I am happy to announce that we, at Target, decided to open source a tool called Winnaker. This tool will allow the user to audit Spinnaker from an end user point of view. But first what is Spinnaker? The first time I heard the word Spinnaker, my reaction was, "wait, what does that even mean in English?" Shortly after, I found myself implementing a demo of Spinnaker as a potential replacement for our internal cloud deployment tool. Spinnaker is a cloud agnostic continuous delivery tool, which means we can push our code to any cloud provider we like. In fact, Spinnaker takes agnosticism to the next level by introducing three abstractions. Load balancers Server groups Security groups By enforcing this level of simplicity, it allows the implementation of deployment strategies such as Highlander, Red/Black on a vast different type of infrastructure (VM, Container, Kubernetes, public cloud, private cloud) with a high level of confidence and an incredible level of ease of use for the app developers. Spinnaker also roots for the immutable infrastructure design pattern. Baking your image once and deploying the image everywhere is another bold move that differentiates Spinnaker from the other tools. Why Winnaker ? Short answer is because of automation! Test the functionality of the CD system as a whole. Spinnaker has different components (CloudDriver, Rosco, Deck,...). Each of these components have their own unit tests and health checks that can be monitored. We learned the hard way that relying only on component health checks is not effective enough to ensure developers won't face any error when they deploy their apps. A few things can go wrong when off monitoring radar: Connectivity between the separate components Maxing out cloud provider API rate limit Base infrastructure configurations (subnet address space, identity management roles) So we decided to audit Spinnaker and cloud's whole functionality with a sample app. If baking and deploying our