传统安全模型的假设是"内网=安全、VPN接入=可信",而在云原生、远程办公、供应链攻击(SolarWinds级)频繁的今天,边界早已不存在。NIST SP 800-207 零信任定义:每一次访问都显式认证授权、最小权限授予、所有流量加密、全程可审计。
六大核心支柱落地
身份(Identity)是新的边界:OIDC/SAML 统一登录,强制 MFA(TOTP + Passkey 二选一+以上),按风险评分加挑战。设备(Device)健康:MDM 验证 OS 补丁、杀毒、磁盘加密,非受管设备只允许访问隔离沙箱。微隔离:服务间严格 mTLS,授权策略按服务身份 + 方法 + 路径三元组,绝不按网段放行。
# ====== 1. SPIFFE SPIRE 颁发服务身份(Workload Identity)======
# 注册 workload registration entry
spire-server entry create -parentID "spiffe://example.com/k8s-ns/production" -spiffeID "spiffe://example.com/svc/payment-gateway" -selector "k8s:ns" -selector "k8s:sa" -value "payment-sa" -dns "payment.internal.example.com" -ttl 3600
# ====== 2. Istio 授权策略(服务粒度 mTLS + RBAC)======
cat <<'EOF' | kubectl apply -f -
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
name: default
namespace: production
spec:
mtls:
mode: STRICT
---
apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
name: payment-rbac
namespace: production
spec:
selector:
matchLabels:
app.kubernetes.io/name: payment-gateway
action: ALLOW
rules:
- from:
- source:
principals:
- "cluster.local/ns/production/sa/order-service"
- "cluster.local/ns/production/sa/checkout-worker"
to:
- operation:
methods: ["POST"]
paths: ["/v1/charges", "/v1/refunds"]
when:
- key: request.auth.claims[roles]
values: ["payments:write"]
EOF
# ====== 3. OPA Gatekeeper 命名空间隔离 ======
cat <<'EOF' | kubectl apply -f -
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sRequiredLabels
metadata:
name: namespace-must-have-owner-and-tier
spec:
match:
kinds: [{ apiGroups: [""], kinds: ["Namespace"] }]
parameters:
labels:
- key: "security.example.com/owner"
- key: "security.example.com/data-tier"
allowedRegex: "^(public|internal|restricted)$"
---
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sDisallowedPrivileged
metadata:
name: block-privileged-containers-in-restricted
spec:
match:
scope: Namespaced
kinds: [{ apiGroups: [""], kinds: ["Pod"] }]
labelSelector:
matchExpressions:
- key: security.example.com/data-tier
operator: In
values: ["restricted"]
EOF
# ====== 4. 身份层:Keycloak MFA + 条件访问策略 ======
# 启用 TOTP OTP + WebAuthn (Passkey) 双重挑战
kcadm.sh update authentication/flows -r master --alias "browser" -b '{
"authenticationExecutions": [
{"authenticator":"auth-cookie","requirement":"ALTERNATIVE"},
{"authenticator":"identity-provider-redirector","requirement":"ALTERNATIVE"},
{"level":"1","required":"true","requirement":"CONDITIONAL"},
{"authenticator":"basic-auth","requirement":"REQUIRED"},
{"authenticator":"conditional-user-configured","requirement":"REQUIRED"},
{"authenticator":"otp-form","requirement":"REQUIRED"},
{"authenticator":"webauthn-authenticator","requirement":"ALTERNATIVE"}
]}'
# 按风险评分拒访:异常IP + 非受管设备
kcadm.sh create clients -r master -s clientId=risk-engine -s 'attributes."risk.score.threshold"=70' -s 'attributes."risk.check.geo_anomaly"=true' -s 'attributes."risk.check.managed_device"=true'
# ====== 5. 审计事件转发 SIEM ======
# Falco 运行时异常规则
cat <<'EOF' > /etc/falco/rules.d/zero-trust-rules.yaml
- rule: DB 服务向外建立可疑连接
desc: MySQL/PG 不应主动发起外连,可能发生数据外泄
condition: >
spawned_process and proc.name in (mysql, postgres) and
outbound and not fd.sip in (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
output: >
DB 服务疑似数据外泄 user=%user.name proc=%proc.name
dst_ip=%fd.sip dst_port=%fd.sport cmd=%proc.cmdline
priority: CRITICAL
tags: [zero-trust, data-exfiltration, mitre:T1041]
EOF
systemctl restart falco
falco -r /etc/falco/falco_rules.yaml -r /etc/falco/rules.d/zero-trust-rules.yaml
# ====== 6. Tailscale + OIDC 取代 VPN:每用户按设备入网 ======
tailscale up --ssh --accept-dns --accept-routes --exit-node="" --auth-key="tskey-client-XXX" --advertise-tags=tag:backend,tag:production
# 在 Tailscale ACL 控制台写入最小权限
# "acls": [ { "action": "accept", "src": ["group:sre"],
# "dst": ["tag:production:*", "tag:backend:22"] } ]
控制面 + 数据面 + 审计面三层
控制面用 SPIRE/Istio 签发短生命周期 X.509/SVID 身份(1小时TTL,泄漏可快速吊销),OPA/Gatekeeper 静态约束策略。数据面每个服务的 Sidecar/内核 eBPF(Cilium)按授权策略逐包过滤。审计面:Falco 运行时异常规则、K8s Audit Log、Keycloak 登录事件全部汇聚 SIEM(Splunk/Elastic),关联用户身份+设备指纹+服务请求,支撑事后溯源与合规。
| 旧边界模型 | Zero Trust 模型 |
|---|---|
| 信任前提:内部网段自动可信 | 信任前提:每一次请求显式验证 |
| 认证点:一次登录进VPN通行全程 | 认证点:身份+设备+信任评分 每请求或每小时重评估 |
| 网络层:VLAN/ACL 分段 | 网络层:默认拒绝,服务粒度 mTLS 微隔离 |
| 权限:Role 粗粒度 过度授权 | 权限:ABAC 动态属性 + JIT 临时提权 用完收回 |
| 日志:分散设备/应用各存一份 | 日志:结构化聚合 可溯源整条访问链路 UID |
| 响应:入侵后修复 以天计 | 响应:实时吊销身份 秒级阻断 |
最佳实践
三阶段路线图:P1(1-3月)统一身份+强制MFA+VPN替换为ZTNA;P2(3-6月)K8s mTLS STRICT + 授权策略落地;P3(6-12月)运行时 eBPF 检测+全链路审计+ABAC 动态授信。零信任不是产品,是架构演进,需要持续投资。