A Policy-Driven Approach for Securing Microservices Workflow in Kubernetes Cluster
Bilal Ashraf, Satish Kumar, Nawar Jawad · 2025
Kubernetes based microservices deployments are increasingly adopted in modern cloud computing environments. However, securing microservices in Kubernetes cluster is critical because they operate in distributed manner across different nodes and each of which gives a potential entry point for attackers due to weak authentication mechanism or misconfiguration of security policies. To address these issues, we propose two layered policy-driven security mechanism for securing microservices workflow in Kubernetes cluster. The first layer employs mutual TLS (mTLS) for secure service-to-service authentication using the Istio service mesh. The second layer introduces workflow-based authorization policy enforced through Open Policy Agent (OPA) Gatekeeper. Experimental results demonstrate that unauthorized access is effectively blocked at the entry point, confirming that the proposed approach establishes a robust, multi-layered security environment for Kubernetes-based microservices.