WeAreDevelopers LIVE Mar 23, 2021

Get started with securing your cloud-native Java microservices applications

Thomas Südbröcker

Stop writing boilerplate code to secure your Java microservices. Discover how Quarkus, Keycloak, and Istio seamlessly automate zero-trust network policies without modifying your core business logic.

Pause
Mute Enter Fullscreen
#1 about 2 min

Demo of the secured cloud-native application

End-to-end demonstration of a secured article application running on Kubernetes.

#2 about 3 min

Cloud native starter project architecture

Overview of a basic cloud-native architecture combining Vue front ends with reactive security.

#3 about 3 min

Implementing IAM with Keycloak and OpenID Connect

Modernizing decentralized authentication securely utilizing OAuth 2 standard protocols and token formats.

#4 about 2 min

Utilizing Quarkus for Kubernetes native Java

Optimizing native compilations in Java specifically tuned for lightweight Kubernetes deployments.

#5 about 3 min

Building restful microservices with Eclipse MicroProfile

Extending Jakarta EE standards specifically targeting efficient restful service orchestration.

#6 about 4 min

Authentication workflow and Keycloak realm configuration

Intercepting client requests to establish identity realms, role definitions, and appropriate front end redirects.

#7 about 5 min

Processing JSON web tokens in the front end

Extracting access tokens and decoding payload claims directly from the JavaScript SDK.

#8 about 4 min

Protecting Java microservices with role-based access

Securing backend REST endpoints by automatically forwarding and validating authentication headers via MicroProfile constructs.

#9 about 7 min

Platform security fundamentals using Istio service mesh

Intercepting cross-cluster communications by proxying traffic via transparent Envoy sidecars to enforce ingress limits.

#10 about 7 min

Enforcing mutual TLS and routing within Istio

Isolating workloads explicitly by encrypting peer-to-peer traffic and ensuring complete zero trust observability.

#11 about 11 min

Accessing the cloud shell and Kubernetes cluster

Leveraging managed Kubernetes services and browser-based interfaces to eliminate local prerequisite configurations.

#12 about 7 min

Cloning repository and preparing cloud terminal

Provisioning workspace environment variables and handling git sources securely within the cloud console window.

#13 about 8 min

Installing Istio programmatically with bash scripts

Automating service mesh deployments by executing bash pipelines to bootstrap required Kubernetes control elements.

#14 about 15 min

Configuring TLS certificates for external ingress gateways

Injecting DNS secrets directly into the Istio namespace to activate authorized Let's Encrypt certificates.

#15 about 6 min

Initializing Keycloak and creating identity management realms

Injecting automated authentication states by provisioning the cluster user directory via API uploads.

#16 about 8 min

Deploying article services and front end config maps

Exposing containerized backing services connecting unified API routes via Kubernetes primitives smoothly.

#17 about 7 min

Validating internal zero trust with strict mutual TLS

Emulating unauthorized access attempts to confirm strict mesh policies safely terminate unencrypted connections.

#18 about 9 min

Restricting internal access using service account policies

Replacing permissive mesh identities to lock HTTP operations by strictly enforcing dedicated API service accounts.

#19 about 5 min

Observing microservice traffic telemetry with Kiali

Visualizing explicit mesh routing flows to detect anomalies while actively inspecting live cluster components.

Matching moments

1:18 min

Technology stack for building robust microservices applications

Niklas Heidloff · LIVE

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:39 min

Understanding the four Cs of cloud native security

Rico Komenda Rico Komenda · WWC 2025

8:20 min

Deploying native Quarkus applications to a Knative cluster

Alex Soto Alex Soto · LIVE

4:12 min

Utilizing pre-integrated observability and authentication platform tools

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Microservice Cognitive Index for Deploy Diagnosis and Change Impact

Sachin Gupta

Member of Technical Staff 2 at eBay

Sachin Gupta
Open session

World Congress 2026 North America

From Cloud Native to Multi-Cloud Native: Write Once, Deploy Anywhere

Sandeep Pal

Principal Member of Technical Staff at Salesforce

Sandeep Pal
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic
Open session

World Congress 2026 North America

Look What Java Can Do Now: Live-Coding a GenAI MCP Server with the JAQ Stack

Suren Konathala

Senior Engineering Leader, Marketing & AdTech, AI GTM & Digital Experience Platforms, Java x AI

Suren Konathala