| dc.contributor.author | Kalubowila, Dinuwan | |
| dc.date.accessioned | 2026-03-11T06:22:04Z | |
| dc.date.available | 2026-03-11T06:22:04Z | |
| dc.date.issued | 2025 | |
| dc.identifier.citation | Kalubowila, Dinuwan (2025) KubeSpector : A Zero Trust Enhancement Model for Microservices Governance. Msc. Dissertation, Informatics Institute of Technology | en_US |
| dc.identifier.issn | 20230686 | |
| dc.identifier.uri | http://dlib.iit.ac.lk/xmlui/handle/123456789/2926 | |
| dc.description.abstract | Problem : Passing over provisioned scopes for access tokens during service-to-service communication in Kubernetes deploy microservices governance is challenging when trying to ensure the Single Responsibility Principle and Zero trust of microservices. This issue often arises due to mistakes made during the development phase, which typically cannot be detected during general integration testing. This project focuses on addressing this issue by developing a integration tool to detect over-provisioned OAuth2 JWT access token scopes during service- to-service communication in a Kubernetes deployment. It is required to ensure a clear indication of expected and actual privileges for each route. Methodology : This research aims to tackle this issue by proposing an independent and separate mechanism for detecting over-scoped tokens within the service mesh pattern, specifically in Kubernetes-based microservices governance. By enhancing the ability to identify and manage over-scoped tokens, the proposed solution seeks to improve the overall security posture of microservices architectures. Results : The developed KubeSpector is designed to detect over-scoped access token requests, and when such over-provisioned requests are identified, it generates the necessary authorization policies. Once these policies are applied, the system achieves over 99% throughput while maintaining minimal impact on the CPU utilization and memory footprint of Kubernetes pods | en_US |
| dc.language.iso | en | en_US |
| dc.subject | Microservices Architecture | en_US |
| dc.subject | Kubernetes | en_US |
| dc.subject | Service Mesh Architecture | en_US |
| dc.title | KubeSpector : A Zero Trust Enhancement Model for Microservices Governance | en_US |
| dc.type | Thesis | en_US |