Home / Companies / Kong / Blog / Post Details
Content Deep Dive

Secure Applications with Styra DAS and Kong Gateway

Blog post from Kong

Post Details
Company
Date Published
Author
Claudio Acquaviva
Word Count
2,338
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Implementing API Gateway Authentication (AuthN) and Authorization (AuthZ) is crucial for controlling data access through APIs, as explained through the integration of Kong Gateway Enterprise, Styra Declarative Authorization Service (DAS), and external Identity Providers. AuthN verifies a consumer's identity using credentials, while AuthZ determines access to resources post-authentication. The processes enable context-rich, distributed authorization decisions, adhering to the principle of Separation of Concerns, crucial in cloud-native architectures. In microservices, AuthN is centralized while AuthZ is distributed, with API Gateway layers handling low-granularity policies and service meshes managing high-granularity policies. A reference architecture involves API Gateways, Authentication Servers, and Authorization Servers, with Kong Gateway offering plugins for various AuthN methods and open-source OPA for AuthZ policies. Styra DAS, as the control plane for OPA, provides a consistent authorization framework across environments. The document highlights deploying an example application using Kong, OPA, and Styra DAS, demonstrating flexible, combined AuthN and AuthZ decisions, with detailed steps for configuring policies and systems within Kubernetes environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 16 1,195 149 62 +21%
Platform Engineering 8 75 24 18 +50%
Vector Search 1 228 50 32 -5%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.