---
title: "Context-Aware Identity-Aware Proxy (ZTNA) | Zero-Trust Architecture Canon"
description: "Kurumsal VPN'leri ortadan kaldıran, her istekte kullanıcı kimliği, cihaz sağlığı ve coğrafi konumu doğrulayan bağlam duyarlı kimlik doğrulama vekili (ZTNA) mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/beyondcorp-ztna-reverse-proxy"
locale: "tr"
---

# Context-Aware Identity-Aware Proxy (ZTNA) (`zt-arch-02`)

> **Sütun**: IDENTITY | **Arketip**: IDENTITY_ATTESTATION
> **Engellenen MITRE ATT&CK Teknikleri**: T1078, T1133, T1539, T1056

## Mimari Özeti

Kurumsal VPN'leri ortadan kaldıran, her istekte kullanıcı kimliği, cihaz sağlığı ve coğrafi konumu doğrulayan bağlam duyarlı kimlik doğrulama vekili (ZTNA) mimarisi.

## Saldırgan Modeli

Çalınan çalışan parolasının yetkisiz bir kişisel cihazdan veya şüpheli bir yabancı IP aralığından kullanılmaya çalışılması.

## NIST SP 800-207 Temel İlkeleri

- Access to resources is determined by dynamic policy including the observable state of client identity, device, and environmental attributes.
- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: SaaS identity proxy deployed in front of internal admin tools.
- **Kimlik Doğrulama Zorlaması**: Single Sign-On (SSO) with standard TOTP multi-factor auth.
- **Ağ İzolasyonu**: Public internet endpoints hidden behind cloud proxy IP allowlists.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Global Edge ZTNA network covering all internal web applications and SSH bastions.
- **Kimlik Doğrulama Zorlaması**: Mandatory FIDO2 WebAuthn passkeys with device OS version checks.
- **Ağ İzolasyonu**: Outbound-only secure tunnels (e.g. Cloudflare Tunnel / WireGuard) with zero open inbound ports.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: Unified micro-perimeter encompassing web, SSH, database proxies, and Kubernetes APIs.
- **Kimlik Doğrulama Zorlaması**: Continuous per-request risk score recalculation using UEBA and TPM hardware attestation.
- **Ağ İzolasyonu**: Total elimination of internal flat corporate subnets; all endpoints air-gapped from each other.

## Terraform HCL Manifest

```hcl
resource "cloudflare_zero_trust_access_application" "internal_console" {
  zone_id          = var.cloudflare_zone_id
  name             = "TinyCTO Production Console"
  domain           = "console.internal.tinycto.tv"
  type             = "self_hosted"
  session_duration = "1h"
  auto_redirect_to_identity = true
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: internal-console-ingress
  annotations:
    ingress.kubernetes.io/auth-url: "https://auth.tinycto.tv/oauth2/auth"
    ingress.kubernetes.io/auth-signin: "https://auth.tinycto.tv/oauth2/start"
spec:
  rules:
  - host: console.internal.tinycto.tv
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: console-svc
            port:
              number: 8080
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Context-Aware Identity-Aware Proxy (ZTNA) | Zero-Trust Architecture Canon",
  "description": "Kurumsal VPN'leri ortadan kaldıran, her istekte kullanıcı kimliği, cihaz sağlığı ve coğrafi konumu doğrulayan bağlam duyarlı kimlik doğrulama vekili (ZTNA) mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/beyondcorp-ztna-reverse-proxy"
}
```
