World Congress 2025 Aug 20, 2025 Session details

IP Authentication: A Tale of Performance Pitfalls and Challenges in Prod

Christoph Eicke

A single CIDR typo accidentally granted free platform access to 1.5% of the entire internet. Discover how live mob-debugging saved this turbulent microservices migration from infinite redirect loops.

Pause
Mute Enter Fullscreen
#1 about 1 min

Why you should avoid IP-based authentication

An upfront warning about the severe system challenges involved in authenticating users purely by their IP addresses.

#2 about 2 min

Breaking up a legacy monolith to extract authentication

Migrating a legacy application requires pulling the authentication layer to the front using dedicated microservices.

#3 about 2 min

Managing multiple authentication methods and IP login origins

Supporting numerous proprietary login methods creates backend complexity while accommodating academia networks that rely on IP ranges.

#4 about 2 min

The pros and cons of campus-wide IP authentication

Comparing the benefits of low user friction against the absolute loss of individual tracking and the headaches of network proxies.

#5 about 2 min

Initial architecture for IP authentication migration

Detailing the request flow moving through a content delivery network, a legacy layer, and serverless authentication functions.

#6 about 2 min

First production deployment failure and immediate rollback

A massive traffic bottleneck and an overwhelming error rate force an immediate reversion of the first live deployment.

#7 about 2 min

Debugging serverless timeouts and replacing databases for lookups

Analyzing connection limits that killed serverless functions and optimizing network range lookups by migrating storage platforms.

#8 about 4 min

Successive deployment failures and the fail forward strategy

Adopting a resilient development strategy to persist through production errors and directly collaborate with impacted customers.

#9 about 3 min

Identifying the root cause of the infinite redirect loop

Discovering how disparate infrastructure environments parsed different headers to generate mismatched IP addresses for identical clients.

#10 about 2 min

How transparent proxies interfere with cookies and URLs

Exposing the unexpected reality of corporate networks stripping essential session features and rewriting external resource pathways.

#11 about 2 min

Human errors in IP ranges and team debugging

Demonstrating how a simple notation typo granted massive unauthorized access, and highlighting the value of collaborative swarm sessions.

Matching moments

9:56 min

Final code walk-through and audience Q&A session

Germán Álvarez · LIVE

16:46 min

Audience Q&A on DevOps and passwordless adoption

Yedidya Schwartz · LIVE

2:56 min

Managing authentication proxies and integrating external serverless hosting

Alex Walling Alex Walling · World Congress 2023

2:47 min

Motivations for delegating user authentication frameworks

Alexander Schwartz Alexander Schwartz · World Congress 2025

2:16 min

Addressing single sign-on challenges in enterprise environments

Alexander Schwartz Alexander Schwartz · World Congress 2025

1:56 min

Overcoming secret sprawl and legacy integration challenges

Moritz Johner · World Congress 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 16:50–17:20

Stage 2

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 7

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

Yoav Gal

Product Lead

Yoav Gal
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 4

Boring Failover: Predictable Region Recovery Across 5,000 Microservices

Garvit Kataria, Sahil Sabharwal

Garvit Kataria
Sahil Sabharwal
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 9

Designing APIs That Survive AI Agents at Scale

Phani Pendurthi

Mastercard, Principal Software Engineer

Phani Pendurthi
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner