"DataSet for Secrets Gateway for TDSC"
收藏DataCite Commons2026-02-15 更新2026-05-03 收录
下载链接:
https://ieee-dataport.org/documents/dataset-secrets-gateway-tdsc-0
下载链接
链接失效反馈官方服务:
资源简介:
"Organizations running hundreds of microservices on Kubernetes face a scaling problem in secrets management: each workload independently authenticating to a centralized secrets backend produces thousands of concurrent connections, each carrying TLS handshake, authentication, and session maintenance overhead. This paper presents secrets-gateway, an architecture informed by enterprise deployment experience that consolidates per-workload backend connectivity into a small pooled set of connections per cluster while preserving namespace-level tenant isolation through five independent defense layers. We make three contributions: (1) a centralized gateway with cross-account identity federation that replaces hundreds of per-workload IAM configurations with a single identity chain per cluster; (2) an analysis showing that credential lease renewability\u2014not architectural convention\u2014determines when sidecar overhead is justified, and that for non-renewable OAuth2 credentials (the majority in enterprise environments), sidecars provide no renewal benefit; (3) a testbed evaluation across synthetic multi-tenant clusters at enterprise scale demonstrating connection reduction from O(workloads) to O(replicas), substantial backend resource savings, and sustained tenant isolation under adversarial testing.Index Terms\u2014Kubernetes, secrets management, credential injection, multi-tenant security, connection pooling, OAuth2, cloud-native infrastructure."
提供机构:
IEEE DataPort
创建时间:
2026-02-15



