Zero Trust 安全架构入门:永不信任,始终验证

Choyeon· 2026年9月29日· 3 分钟阅读· 431 阅读· 796 字· 1,890 字符· 更新于 2026年10月1日
Zero Trust 安全架构入门:永不信任,始终验证

传统安全模型的假设是"内网=安全、VPN接入=可信",而在云原生、远程办公、供应链攻击(SolarWinds级)频繁的今天,边界早已不存在。NIST SP 800-207 零信任定义:每一次访问都显式认证授权、最小权限授予、所有流量加密、全程可审计。

六大核心支柱落地

身份(Identity)是新的边界:OIDC/SAML 统一登录,强制 MFA(TOTP + Passkey 二选一+以上),按风险评分加挑战。设备(Device)健康:MDM 验证 OS 补丁、杀毒、磁盘加密,非受管设备只允许访问隔离沙箱。微隔离:服务间严格 mTLS,授权策略按服务身份 + 方法 + 路径三元组,绝不按网段放行。

# ====== 1. SPIFFE SPIRE 颁发服务身份(Workload Identity)======
# 注册 workload registration entry
spire-server entry create   -parentID "spiffe://example.com/k8s-ns/production"   -spiffeID "spiffe://example.com/svc/payment-gateway"   -selector "k8s:ns"   -selector "k8s:sa"   -value "payment-sa"   -dns "payment.internal.example.com"   -ttl 3600

# ====== 2. Istio 授权策略(服务粒度 mTLS + RBAC)======
cat <<'EOF' | kubectl apply -f -
apiVersion: security.istio.io/v1
kind: PeerAuthentication
metadata:
  name: default
  namespace: production
spec:
  mtls:
    mode: STRICT
---
apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
  name: payment-rbac
  namespace: production
spec:
  selector:
    matchLabels:
      app.kubernetes.io/name: payment-gateway
  action: ALLOW
  rules:
    - from:
        - source:
            principals:
              - "cluster.local/ns/production/sa/order-service"
              - "cluster.local/ns/production/sa/checkout-worker"
      to:
        - operation:
            methods: ["POST"]
            paths: ["/v1/charges", "/v1/refunds"]
      when:
        - key: request.auth.claims[roles]
          values: ["payments:write"]
EOF

# ====== 3. OPA Gatekeeper 命名空间隔离 ======
cat <<'EOF' | kubectl apply -f -
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sRequiredLabels
metadata:
  name: namespace-must-have-owner-and-tier
spec:
  match:
    kinds: [{ apiGroups: [""], kinds: ["Namespace"] }]
  parameters:
    labels:
      - key: "security.example.com/owner"
      - key: "security.example.com/data-tier"
        allowedRegex: "^(public|internal|restricted)$"
---
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sDisallowedPrivileged
metadata:
  name: block-privileged-containers-in-restricted
spec:
  match:
    scope: Namespaced
    kinds: [{ apiGroups: [""], kinds: ["Pod"] }]
    labelSelector:
      matchExpressions:
        - key: security.example.com/data-tier
          operator: In
          values: ["restricted"]
EOF

# ====== 4. 身份层:Keycloak MFA + 条件访问策略 ======
# 启用 TOTP OTP + WebAuthn (Passkey) 双重挑战
kcadm.sh update authentication/flows -r master   --alias "browser" -b '{
  "authenticationExecutions": [
    {"authenticator":"auth-cookie","requirement":"ALTERNATIVE"},
    {"authenticator":"identity-provider-redirector","requirement":"ALTERNATIVE"},
    {"level":"1","required":"true","requirement":"CONDITIONAL"},
    {"authenticator":"basic-auth","requirement":"REQUIRED"},
    {"authenticator":"conditional-user-configured","requirement":"REQUIRED"},
    {"authenticator":"otp-form","requirement":"REQUIRED"},
    {"authenticator":"webauthn-authenticator","requirement":"ALTERNATIVE"}
  ]}'

# 按风险评分拒访:异常IP + 非受管设备
kcadm.sh create clients -r master -s clientId=risk-engine   -s 'attributes."risk.score.threshold"=70'   -s 'attributes."risk.check.geo_anomaly"=true'   -s 'attributes."risk.check.managed_device"=true'

# ====== 5. 审计事件转发 SIEM ======
# Falco 运行时异常规则
cat <<'EOF' > /etc/falco/rules.d/zero-trust-rules.yaml
- rule: DB 服务向外建立可疑连接
  desc: MySQL/PG 不应主动发起外连,可能发生数据外泄
  condition: >
    spawned_process and proc.name in (mysql, postgres) and
    outbound and not fd.sip in (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
  output: >
    DB 服务疑似数据外泄 user=%user.name proc=%proc.name
    dst_ip=%fd.sip dst_port=%fd.sport cmd=%proc.cmdline
  priority: CRITICAL
  tags: [zero-trust, data-exfiltration, mitre:T1041]
EOF
systemctl restart falco
falco -r /etc/falco/falco_rules.yaml -r /etc/falco/rules.d/zero-trust-rules.yaml

# ====== 6. Tailscale + OIDC 取代 VPN:每用户按设备入网 ======
tailscale up   --ssh   --accept-dns   --accept-routes   --exit-node=""   --auth-key="tskey-client-XXX"   --advertise-tags=tag:backend,tag:production

# 在 Tailscale ACL 控制台写入最小权限
# "acls": [ { "action": "accept", "src": ["group:sre"],
#             "dst": ["tag:production:*", "tag:backend:22"] } ]

控制面 + 数据面 + 审计面三层

控制面用 SPIRE/Istio 签发短生命周期 X.509/SVID 身份(1小时TTL,泄漏可快速吊销),OPA/Gatekeeper 静态约束策略。数据面每个服务的 Sidecar/内核 eBPF(Cilium)按授权策略逐包过滤。审计面:Falco 运行时异常规则、K8s Audit Log、Keycloak 登录事件全部汇聚 SIEM(Splunk/Elastic),关联用户身份+设备指纹+服务请求,支撑事后溯源与合规。

旧边界模型 Zero Trust 模型
信任前提:内部网段自动可信 信任前提:每一次请求显式验证
认证点:一次登录进VPN通行全程 认证点:身份+设备+信任评分 每请求或每小时重评估
网络层:VLAN/ACL 分段 网络层:默认拒绝,服务粒度 mTLS 微隔离
权限:Role 粗粒度 过度授权 权限:ABAC 动态属性 + JIT 临时提权 用完收回
日志:分散设备/应用各存一份 日志:结构化聚合 可溯源整条访问链路 UID
响应:入侵后修复 以天计 响应:实时吊销身份 秒级阻断

最佳实践

三阶段路线图:P1(1-3月)统一身份+强制MFA+VPN替换为ZTNA;P2(3-6月)K8s mTLS STRICT + 授权策略落地;P3(6-12月)运行时 eBPF 检测+全链路审计+ABAC 动态授信。零信任不是产品,是架构演进,需要持续投资。

本文作者

评论 (0)

暂无评论,来抢沙发吧。