[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"public:announcements":3,"public:navigations:zh":4,"footer:categories:zh":56,"post:detail:post-31-ZeroTrust:zh":177},[],[5,18,25,33,41,49],{"id":6,"title":7,"url":12,"icon":13,"parent_id":13,"location":14,"order":6,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},1,{"zh":8,"en":9,"ja":10,"zh_TW":11},"首页","Home","ホーム","首頁","\u002F",null,"header",true,false,"2026-09-30T18:09:54.251095Z",{"id":19,"title":20,"url":24,"icon":13,"parent_id":13,"location":14,"order":19,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},2,{"zh":21,"en":22,"ja":23,"zh_TW":21},"文章","Posts","記事","\u002Fposts",{"id":26,"title":27,"url":32,"icon":13,"parent_id":13,"location":14,"order":26,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},3,{"zh":28,"en":29,"ja":30,"zh_TW":31},"分类","Categories","カテゴリー","分類","\u002Fcategories",{"id":34,"title":35,"url":40,"icon":13,"parent_id":13,"location":14,"order":34,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},4,{"zh":36,"en":37,"ja":38,"zh_TW":39},"标签","Tags","タグ","標籤","\u002Ftags",{"id":42,"title":43,"url":48,"icon":13,"parent_id":13,"location":14,"order":42,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},5,{"zh":44,"en":45,"ja":46,"zh_TW":47},"关于","About","概要","關於","\u002Fpage\u002Fabout",{"id":50,"title":51,"url":55,"icon":13,"parent_id":13,"location":14,"order":50,"is_active":15,"target_blank":16,"created_at":17,"updated_at":13},6,{"zh":52,"en":53,"ja":54,"zh_TW":52},"留言板","Guestbook","ゲストブック","\u002Fpage\u002Fguestbook",[57,73,87,102,117,133,148,162],{"id":6,"name":58,"slug":63,"description":64,"icon":69,"color":70,"cover_image":13,"created_at":71,"post_count":72},{"en":59,"ja":60,"zh":61,"zh_Hant":62},"Technology","テクノロジー","技术","技術","technology",{"en":65,"ja":66,"zh":67,"zh_Hant":68},"Cutting-edge technology exploration and in-depth analysis covering programming languages, frameworks, and architecture design","プログラミング言語、フレームワーク、アーキテクチャ設計を含む先端技術の探究","前沿技术探索与深度分析，涵盖编程语言、框架、架构设计等核心领域","前沿技術探索與深度分析，涵蓋編程語言、框架、架構設計等核心領域","heroicons:cog-6-tooth","#6366f1","2026-09-30T18:09:53.633610Z",8,{"id":19,"name":74,"slug":78,"description":79,"icon":84,"color":85,"cover_image":13,"created_at":86,"post_count":50},{"en":75,"ja":76,"zh":77,"zh_Hant":77},"Tutorial","チュートリアル","教程","tutorial",{"en":80,"ja":81,"zh":82,"zh_Hant":83},"Hands-on tutorials from scratch with clear steps and complete code for developers at all levels","ゼロから始める実践的なチュートリアル。明確な手順と完全なコードで、全てのレベルの開発者に最適","从零开始的实战教程，步骤清晰，代码完整，适合各阶段开发者学习","從零開始的實戰教程，步驟清晰，代碼完整，適合各階段開發者學習","heroicons:academic-cap","#10b981","2026-09-30T18:09:53.641581Z",{"id":26,"name":88,"slug":92,"description":93,"icon":98,"color":99,"cover_image":13,"created_at":100,"post_count":101},{"en":89,"ja":90,"zh":91,"zh_Hant":91},"Frontend","フロントエンド","前端","frontend",{"en":94,"ja":95,"zh":96,"zh_Hant":97},"Full coverage of web frontend development including Vue, React, new CSS features, and performance optimization","Vue、React、CSSの新機能やパフォーマンス最適化を含むWebフロントエンド開発の全領域","Web前端开发全栈覆盖，包括Vue、React、CSS新特性及性能优化等话题","Web前端開發全棧覆蓋，包括Vue、React、CSS新特性及性能優化等話題","heroicons:computer-desktop","#ec4899","2026-09-30T18:09:53.644838Z",7,{"id":34,"name":103,"slug":108,"description":109,"icon":114,"color":115,"cover_image":13,"created_at":116,"post_count":26},{"en":104,"ja":105,"zh":106,"zh_Hant":107},"Backend","バックエンド","后端","後端","backend",{"en":110,"ja":111,"zh":112,"zh_Hant":113},"Server-side development best practices including API design, database optimization, and microservices architecture","API設計、データベース最適化、マイクロサービスアーキテクチャを含むサーバーサイド開発の実践","服务端开发实战经验，API设计、数据库优化、微服务架构等深度内容","服務端開發實戰經驗，API設計、數據庫優化、微服務架構等深度內容","heroicons:server-stack","#f59e0b","2026-09-30T18:09:53.647836Z",{"id":42,"name":118,"slug":123,"description":124,"icon":129,"color":130,"cover_image":13,"created_at":131,"post_count":132},{"en":119,"ja":120,"zh":121,"zh_Hant":122},"Fullstack","フルスタック","全栈","全棧","fullstack",{"en":125,"ja":126,"zh":127,"zh_Hant":128},"End-to-end development guides covering the full project lifecycle and technology stack selection","フロントエンドからバックエンドまでの開発プロセス全体をカバーするガイド","从前端到后端的全流程开发指南，覆盖完整项目生命周期与技术选型","從前端到後端的全流程開發指南，覆蓋完整項目生命週期與技術選型","heroicons:swatch","#8b5cf6","2026-09-30T18:09:53.650513Z",0,{"id":50,"name":134,"slug":139,"description":140,"icon":145,"color":146,"cover_image":13,"created_at":147,"post_count":34},{"en":135,"ja":136,"zh":137,"zh_Hant":138},"Essays","エッセイ","随笔","隨筆","essays",{"en":141,"ja":142,"zh":143,"zh_Hant":144},"Technical reflections and development insights recording the programmer's growth journey","プログラマーの成長の軌跡を記録する技術的考察と開発の洞察","技术思考与开发心得分享，记录程序员成长路上的点滴感悟","技術思考與開發心得分享，記錄程序員成長路上的點滴感悟","heroicons:pencil-square","#f43f5e","2026-09-30T18:09:53.653105Z",{"id":101,"name":149,"slug":153,"description":154,"icon":159,"color":160,"cover_image":13,"created_at":161,"post_count":34},{"en":150,"ja":151,"zh":152,"zh_Hant":152},"Tools","ツール","工具","tools",{"en":155,"ja":156,"zh":157,"zh_Hant":158},"Development toolchain and productivity tool recommendations to supercharge your development experience","開発効率を飛躍的に向上させるツールチェーンと生産性ツールの推奨","开发工具链与效率提升利器推荐，让你的开发体验如虎添翼","開發工具鏈與效率提升利器推薦，讓你的開發體驗如虎添翼","heroicons:wrench-screwdriver","#06b6d4","2026-09-30T18:09:53.655605Z",{"id":72,"name":163,"slug":168,"description":169,"icon":174,"color":175,"cover_image":13,"created_at":176,"post_count":132},{"en":164,"ja":165,"zh":166,"zh_Hant":167},"Translation","翻訳","翻译","翻譯","translation",{"en":170,"ja":171,"zh":172,"zh_Hant":173},"Curated translations of high-quality foreign technical articles to keep up with international trends","国際的な技術トレンドを追うための厳選された海外技術記事の翻訳","优质外文技术文章精选翻译，紧跟国际技术前沿动态","優質外文技術文章精選翻譯，緊跟國際技術前沿動態","heroicons:language","#84cc16","2026-09-30T18:09:53.658041Z",{"id":178,"title":179,"subtitle":13,"slug":180,"source":181,"source_url":13,"audio":13,"video":13,"video_url":13,"content":182,"excerpt":183,"cover_image":13,"author":184,"category":187,"tags":188,"status":213,"visibility":214,"password":13,"views":215,"likes_count":132,"is_pinned":16,"allow_comments":15,"comments_count":190,"is_password_protected":16,"meta_title":179,"meta_description":183,"meta_keywords":216,"created_at":217,"published_at":217,"updated_at":218,"reading_time":6},31,"Zero Trust 安全架构入门：永不信任，始终验证","post-31-ZeroTrust","原创","# Zero Trust 安全架构入门：永不信任，始终验证\n\n传统安全模型的假设是\"内网=安全、VPN接入=可信\"，而在云原生、远程办公、供应链攻击（SolarWinds级）频繁的今天，边界早已不存在。NIST SP 800-207 零信任定义：每一次访问都显式认证授权、最小权限授予、所有流量加密、全程可审计。\n\n## 六大核心支柱落地\n\n身份（Identity）是新的边界：OIDC\u002FSAML 统一登录，强制 MFA（TOTP + Passkey 二选一+以上），按风险评分加挑战。设备（Device）健康：MDM 验证 OS 补丁、杀毒、磁盘加密，非受管设备只允许访问隔离沙箱。微隔离：服务间严格 mTLS，授权策略按服务身份 + 方法 + 路径三元组，绝不按网段放行。\n\n```bash\n```bash\n# ====== 1. SPIFFE SPIRE 颁发服务身份（Workload Identity）======\n# 注册 workload registration entry\nspire-server entry create   -parentID \"spiffe:\u002F\u002Fexample.com\u002Fk8s-ns\u002Fproduction\"   -spiffeID \"spiffe:\u002F\u002Fexample.com\u002Fsvc\u002Fpayment-gateway\"   -selector \"k8s:ns\"   -selector \"k8s:sa\"   -value \"payment-sa\"   -dns \"payment.internal.example.com\"   -ttl 3600\n\n# ====== 2. Istio 授权策略（服务粒度 mTLS + RBAC）======\ncat \u003C\u003C'EOF' | kubectl apply -f -\napiVersion: security.istio.io\u002Fv1\nkind: PeerAuthentication\nmetadata:\n  name: default\n  namespace: production\nspec:\n  mtls:\n    mode: STRICT\n---\napiVersion: security.istio.io\u002Fv1\nkind: AuthorizationPolicy\nmetadata:\n  name: payment-rbac\n  namespace: production\nspec:\n  selector:\n    matchLabels:\n      app.kubernetes.io\u002Fname: payment-gateway\n  action: ALLOW\n  rules:\n    - from:\n        - source:\n            principals:\n              - \"cluster.local\u002Fns\u002Fproduction\u002Fsa\u002Forder-service\"\n              - \"cluster.local\u002Fns\u002Fproduction\u002Fsa\u002Fcheckout-worker\"\n      to:\n        - operation:\n            methods: [\"POST\"]\n            paths: [\"\u002Fv1\u002Fcharges\", \"\u002Fv1\u002Frefunds\"]\n      when:\n        - key: request.auth.claims[roles]\n          values: [\"payments:write\"]\nEOF\n\n# ====== 3. OPA Gatekeeper 命名空间隔离 ======\ncat \u003C\u003C'EOF' | kubectl apply -f -\napiVersion: constraints.gatekeeper.sh\u002Fv1beta1\nkind: K8sRequiredLabels\nmetadata:\n  name: namespace-must-have-owner-and-tier\nspec:\n  match:\n    kinds: [{ apiGroups: [\"\"], kinds: [\"Namespace\"] }]\n  parameters:\n    labels:\n      - key: \"security.example.com\u002Fowner\"\n      - key: \"security.example.com\u002Fdata-tier\"\n        allowedRegex: \"^(public|internal|restricted)$\"\n---\napiVersion: constraints.gatekeeper.sh\u002Fv1beta1\nkind: K8sDisallowedPrivileged\nmetadata:\n  name: block-privileged-containers-in-restricted\nspec:\n  match:\n    scope: Namespaced\n    kinds: [{ apiGroups: [\"\"], kinds: [\"Pod\"] }]\n    labelSelector:\n      matchExpressions:\n        - key: security.example.com\u002Fdata-tier\n          operator: In\n          values: [\"restricted\"]\nEOF\n\n# ====== 4. 身份层：Keycloak MFA + 条件访问策略 ======\n# 启用 TOTP OTP + WebAuthn (Passkey) 双重挑战\nkcadm.sh update authentication\u002Fflows -r master   --alias \"browser\" -b '{\n  \"authenticationExecutions\": [\n    {\"authenticator\":\"auth-cookie\",\"requirement\":\"ALTERNATIVE\"},\n    {\"authenticator\":\"identity-provider-redirector\",\"requirement\":\"ALTERNATIVE\"},\n    {\"level\":\"1\",\"required\":\"true\",\"requirement\":\"CONDITIONAL\"},\n    {\"authenticator\":\"basic-auth\",\"requirement\":\"REQUIRED\"},\n    {\"authenticator\":\"conditional-user-configured\",\"requirement\":\"REQUIRED\"},\n    {\"authenticator\":\"otp-form\",\"requirement\":\"REQUIRED\"},\n    {\"authenticator\":\"webauthn-authenticator\",\"requirement\":\"ALTERNATIVE\"}\n  ]}'\n\n# 按风险评分拒访：异常IP + 非受管设备\nkcadm.sh create clients -r master -s clientId=risk-engine   -s 'attributes.\"risk.score.threshold\"=70'   -s 'attributes.\"risk.check.geo_anomaly\"=true'   -s 'attributes.\"risk.check.managed_device\"=true'\n\n# ====== 5. 审计事件转发 SIEM ======\n# Falco 运行时异常规则\ncat \u003C\u003C'EOF' > \u002Fetc\u002Ffalco\u002Frules.d\u002Fzero-trust-rules.yaml\n- rule: DB 服务向外建立可疑连接\n  desc: MySQL\u002FPG 不应主动发起外连，可能发生数据外泄\n  condition: >\n    spawned_process and proc.name in (mysql, postgres) and\n    outbound and not fd.sip in (10.0.0.0\u002F8, 172.16.0.0\u002F12, 192.168.0.0\u002F16)\n  output: >\n    DB 服务疑似数据外泄 user=%user.name proc=%proc.name\n    dst_ip=%fd.sip dst_port=%fd.sport cmd=%proc.cmdline\n  priority: CRITICAL\n  tags: [zero-trust, data-exfiltration, mitre:T1041]\nEOF\nsystemctl restart falco\nfalco -r \u002Fetc\u002Ffalco\u002Ffalco_rules.yaml -r \u002Fetc\u002Ffalco\u002Frules.d\u002Fzero-trust-rules.yaml\n\n# ====== 6. Tailscale + OIDC 取代 VPN：每用户按设备入网 ======\ntailscale up   --ssh   --accept-dns   --accept-routes   --exit-node=\"\"   --auth-key=\"tskey-client-XXX\"   --advertise-tags=tag:backend,tag:production\n\n# 在 Tailscale ACL 控制台写入最小权限\n# \"acls\": [ { \"action\": \"accept\", \"src\": [\"group:sre\"],\n#             \"dst\": [\"tag:production:*\", \"tag:backend:22\"] } ]\n```\n```\n\n## 控制面 + 数据面 + 审计面三层\n\n控制面用 SPIRE\u002FIstio 签发短生命周期 X.509\u002FSVID 身份（1小时TTL，泄漏可快速吊销），OPA\u002FGatekeeper 静态约束策略。数据面每个服务的 Sidecar\u002F内核 eBPF（Cilium）按授权策略逐包过滤。审计面：Falco 运行时异常规则、K8s Audit Log、Keycloak 登录事件全部汇聚 SIEM（Splunk\u002FElastic），关联用户身份+设备指纹+服务请求，支撑事后溯源与合规。\n\n| 旧边界模型 | Zero Trust 模型 |\n|-----------|----------------|\n| 信任前提：内部网段自动可信 | 信任前提：每一次请求显式验证 |\n| 认证点：一次登录进VPN通行全程 | 认证点：身份+设备+信任评分 每请求或每小时重评估 |\n| 网络层：VLAN\u002FACL 分段 | 网络层：默认拒绝，服务粒度 mTLS 微隔离 |\n| 权限：Role 粗粒度 过度授权 | 权限：ABAC 动态属性 + JIT 临时提权 用完收回 |\n| 日志：分散设备\u002F应用各存一份 | 日志：结构化聚合 可溯源整条访问链路 UID |\n| 响应：入侵后修复 以天计 | 响应：实时吊销身份 秒级阻断 |\n\n## 最佳实践\n\n三阶段路线图：P1（1-3月）统一身份+强制MFA+VPN替换为ZTNA；P2（3-6月）K8s mTLS STRICT + 授权策略落地；P3（6-12月）运行时 eBPF 检测+全链路审计+ABAC 动态授信。零信任不是产品，是架构演进，需要持续投资。","零信任安全模型系统入门：以\"永不信任，始终验证\"为核心原则，打破传统边界防护（VPN=内部可信）的思维。从身份认证（MFA\u002FSAML）、设备健康检查、最小权限 RBAC、微隔离 mTLS、持续信任评分到可观测审计链路的 6 大支柱详解，附落地实施路线。",{"id":6,"username":185,"nickname":185,"avatar":13,"cover_image":13,"bio":13,"website":13,"github":13,"avatar_source":13,"resolved_avatar_url":13,"title":13,"created_at":186},"Choyeon","2026-09-30T18:09:53.330367Z",{"id":6,"name":61,"slug":63,"description":67,"icon":69,"color":70,"cover_image":13,"created_at":71,"post_count":132},[189,195,201,207],{"id":190,"name":191,"slug":192,"color":193,"icon":13,"is_active":15,"created_at":194,"post_count":132},9,"Docker","docker","#2496ed","2026-09-30T18:09:53.688173Z",{"id":196,"name":197,"slug":198,"color":199,"icon":13,"is_active":15,"created_at":200,"post_count":132},16,"安全","security","#14b8a6","2026-09-30T18:09:53.709991Z",{"id":202,"name":203,"slug":204,"color":205,"icon":13,"is_active":15,"created_at":206,"post_count":132},23,"Kubernetes","kubernetes","#326ce5","2026-09-30T18:09:53.729296Z",{"id":208,"name":209,"slug":210,"color":211,"icon":13,"is_active":15,"created_at":212,"post_count":132},24,"Linux","linux","#fcc624","2026-09-30T18:09:53.731844Z","published","public",437,"安全,Kubernetes,Linux,Docker","2026-09-29T00:09:53.733462Z","2026-10-01T10:32:42.253000Z"]