Skip to main content

> ARCHITECTURE CATALOG // V1.0

18 Zero-Trust Reference Architectures

54 Maturity Tiers, Hardware Root of Trust, Kernel eBPF Enforcement & Post-Quantum Cryptography

IDENTITYzt-arch-01

SPIFFE/SPIRE Cryptographic Workload Attestation

Hardware and kernel-verified workload identity issuance using SPIFFE IDs and short-lived X.509 SVIDs, establishing mutual TLS between microservices with zero static credentials.

Adversary Model:

Adversary compromises host network or local container namespace, attempting to forge service identity or sniff inter-service RPC payloads.

Blocked MITRE ATT&CK:
T1078.004T1552.004T1021.002
IDENTITYzt-arch-02

Context-Aware Identity-Aware Proxy (ZTNA)

Zero Trust Network Access (ZTNA) model replacing corporate VPNs with a context-aware reverse proxy evaluating user identity, device posture, and geolocation per request.

Adversary Model:

Stolen employee password used from an unauthorized personal machine or hostile geographical IP range.

Blocked MITRE ATT&CK:
T1078T1133T1539
IDENTITYzt-arch-03

Hardware-Bound FIDO2/WebAuthn Enterprise IdP

Zero-password authentication architecture enforcing hardware cryptographic security keys (YubiKey / Secure Enclave) via WebAuthn, mathematically immune to adversary-in-the-middle phishing.

Adversary Model:

Adversary deploys reverse-proxy phishing kits (e.g. Modlishka, Evilginx) capturing usernames, passwords, and TOTP verification codes.

Blocked MITRE ATT&CK:
T1539T1556T1110
IDENTITYzt-arch-04

Secretless Multi-Cloud Workload Identity Federation

Elimination of static cloud API secrets by establishing short-lived OpenID Connect (OIDC) trust relationships between GitHub Actions, Kubernetes, AWS IAM, GCP, and Azure.

Adversary Model:

Adversary extracts long-lived secrets from CI/CD pipeline variables, using them for persistent cloud resource hijacking.

Blocked MITRE ATT&CK:
T1552.001T1078.004T1537
NETWORKSzt-arch-05

Kernel-Level eBPF L3-L7 Kubernetes Microsegmentation

High-performance in-kernel network microsegmentation using Cilium eBPF, replacing slow iptables with cryptographic identity-aware L3/L4/L7 packet filtering and transparent WireGuard encryption.

Adversary Model:

Compromised web container initiates port scanning and attempts lateral HTTP/database exploitation across cluster namespaces.

Blocked MITRE ATT&CK:
T1046T1021T1090
APPLICATIONS_WORKLOADSzt-arch-06

SLSA Level 3 Cryptographic Software Supply Chain

Tamper-proof software supply chain architecture adhering to SLSA Level 3, featuring ephemeral build runners, Cosign keyless image signing via Fulcio/Rekor, and strict Kubernetes admission gates.

Adversary Model:

Adversary breaches developer account or build environment, injecting malicious backdoors into compiled release binaries.

Blocked MITRE ATT&CK:
T1195.001T1195.002T1554
DATAzt-arch-07

Hardware HSM Envelope Encryption & BYOK Data Vault

Multi-layered envelope encryption architecture utilizing dedicated FIPS 140-3 Level 3 Hardware Security Modules (HSM), generating ephemeral data encryption keys (DEK) for database columns and files.

Adversary Model:

Adversary gains raw database dump or storage volume snapshot, attempting offline cryptanalysis to read sensitive customer data.

Blocked MITRE ATT&CK:
T1530T1005T1486
APPLICATIONS_WORKLOADSzt-arch-08

Real-Time Kernel Threat Enforcement via Tetragon

Deep operating system kernel visibility and automated in-kernel attack mitigation using Cilium Tetragon eBPF, killing malicious processes (SIGKILL) before unauthorized syscalls complete.

Adversary Model:

Attacker leverages zero-day vulnerability in container to execute reverse shell, spawn namespace escaping binaries, or read `/etc/shadow`.

Blocked MITRE ATT&CK:
T1059.004T1068T1611
APPLICATIONS_WORKLOADSzt-arch-09

Zero-Trust AI Agent Guardrail & Tool Sandboxing

Zero-Trust defense architecture for autonomous AI agents and LLM tool calling, isolating agent execution behind schema validation proxies, air-gapped WASM/MicroVM sandboxes, and prompt injection filters.

Adversary Model:

Adversary injects concealed prompt payload into crawled web page or customer support ticket, tricking agent into executing destructive commands.

Blocked MITRE ATT&CK:
T1059T1203T1566
DATAzt-arch-10

Post-Quantum Cryptography Hybrid TLS 1.3 Key Exchange

Quantum-resistant cryptographic transition architecture implementing NIST-standardized Post-Quantum Cryptography (PQC) hybrid key encapsulation (X25519 + ML-KEM / Kyber-768), defeating "Harvest Now, Decrypt Later" adversaries.

Adversary Model:

State-sponsored adversary records encrypted network traffic today, intending to decrypt confidential communications using future quantum computers.

Blocked MITRE ATT&CK:
T1040T1565T1005
NETWORKSzt-arch-11

Peer-to-Peer Zero-Trust Mesh with Ephemeral WireGuard

Lightweight, self-hosted, peer-to-peer overlay network powered by WireGuard and Headscale, establishing point-to-point encrypted tunnels with short-lived key pairs and identity-based access control.

Adversary Model:

Adversary taps public cloud WAN or cloud interconnect lines, attempting unauthenticated packet injection into private cluster nodes.

Blocked MITRE ATT&CK:
T1040T1557T1021
APPLICATIONS_WORKLOADSzt-arch-12

Read-Only Immutable OS with Ephemeral Worker Nodes

Ultra-secure container host architecture using Talos Linux, completely eliminating SSH, shells, local package managers, and writable root partitions in favor of immutable, ephemeral node lifecycles.

Adversary Model:

Adversary gains root execution inside a container and attempts to modify host binaries, install rootkits, or establish persistence on disk.

Blocked MITRE ATT&CK:
T1543T1053T1556
DATAzt-arch-13

Confidential Computing with AMD SEV-SNP Memory Encryption

Zero-Trust hardware enclave architecture utilizing AMD SEV-SNP and Intel TDX, encrypting virtual machine memory in-use to protect cryptographic keys and proprietary models from hypervisor and cloud provider access.

Adversary Model:

Rogue cloud provider administrator or compromised hypervisor process inspects RAM memory to extract TLS private keys or proprietary LLM weights.

Blocked MITRE ATT&CK:
T1005T1055T1530
IDENTITYzt-arch-14

Automated Internal PKI with Ephemeral X.509 Certificates

Dynamic certificate authority architecture utilizing HashiCorp Vault PKI Secrets Engine, automatically issuing sub-hour ephemeral X.509 and SSH certificates with automated zero-touch rotation.

Adversary Model:

Adversary exfiltrates internal TLS private key or SSH key, attempting to maintain persistent long-term access.

Blocked MITRE ATT&CK:
T1552.004T1098.004T1021.004
DEVICESzt-arch-15

Distributed Cyber Deception & Active Defense Traps

Active cyber defense and deception mesh embedding canary credentials, bogus AWS access keys, decoy Kubernetes service accounts, and honeypot network ports to trigger high-fidelity instant alarms upon breach attempt.

Adversary Model:

Adversary gains initial foothold and performs internal credential dumping, file search, or lateral network port scanning.

Blocked MITRE ATT&CK:
T1083T1082T1046
APPLICATIONS_WORKLOADSzt-arch-16

Continuous Breach & Attack Simulation (BAS)

Continuous adversarial resilience validation framework executing automated chaos security experiments and MITRE ATT&CK techniques in production to mathematically prove Zero-Trust policy efficacy.

Adversary Model:

Silent policy misconfiguration or firewall bypass remains undetected until exploited by real-world adversary during incident.

Blocked MITRE ATT&CK:
T1078T1059T1046
NETWORKSzt-arch-17

Software-Defined Perimeter (SDP) Dynamic Knocking

Zero-visibility infrastructure architecture using Software-Defined Perimeter (SDP) and Single Packet Authorization (SPA), keeping server ports completely closed (drop 100%) until cryptographically authenticated.

Adversary Model:

Adversary executes port scans (nmap / masscan) across public IP ranges, attempting to locate open administrative ports.

Blocked MITRE ATT&CK:
T1046T1190T1133
APPLICATIONS_WORKLOADSzt-arch-18

Zero-Overhead WebAssembly Micro-Sandboxing for Untrusted Code

High-density, sub-millisecond execution sandboxing using WebAssembly (Wasmtime / WasmEdge) and Capability-Based Security, executing third-party plugins and untrusted customer code with zero access to filesystem, environment, or network.

Adversary Model:

Customer uploads malicious plugin script attempting to execute cryptominers, read memory of co-tenants, or scan local network.

Blocked MITRE ATT&CK:
T1203T1059T1496
AI Summary & Agent Operating Digest
AEO / GEO / Perplexity Indexable

Canonical Zero-Trust Defense per NIST SP 800-207 & CISA ZTMM 2.0: Eliminate static credentials, enforce eBPF microsegmentation, and preempt threats with in-kernel runtime telemetry.

Standards & FrameworksNIST SP 800-207, CISA ZTMM 2.0, MITRE ATT&CK, SLSA v1.0, FIDO2 / WebAuthn
Canon Metrics18 Architectures, 24 Threats, 10 Manuals, 22 Tools
Core Tenet (NIST)Never Trust, Always Verify; Assume Breach; Least Privilege
Agent DirectivesReject static keys; enforce OIDC/SPIFFE mTLS and default-deny eBPF

Frequently Asked Questions

What is the core philosophical difference between traditional perimeter defense and Zero-Trust Architecture (ZTA)?

Traditional perimeter security relies on the "castle-and-moat" paradigm: once a user or machine crosses the network boundary (e.g. via VPN), they are implicitly trusted with wide lateral network access. Zero-Trust Architecture (NIST SP 800-207) asserts "Never Trust, Always Verify, Assume Breach". Every request—whether originating from outside the organization or inside a private Kubernetes cluster—must be dynamically authenticated, authorized, and cryptographically verified based on contextual signals.

How does NIST SP 800-207 define Policy Decision Points (PDP) and Policy Enforcement Points (PEP)?

Under NIST SP 800-207, the Policy Decision Point (PDP) is the logical brain comprising the Policy Engine (which evaluates continuous enterprise access rules) and the Policy Administrator (which issues or revokes access credentials). The Policy Enforcement Point (PEP) is the gatekeeper (e.g. an Envoy proxy, API gateway, or eBPF kernel hook) that intercepts traffic and strictly permits or terminates connections as instructed by the PDP.

Why are static long-lived credentials (API keys, passwords) considered a critical Zero-Trust anti-pattern?

Static credentials lack contextual temporal binding. Once leaked (via GitHub commit, compromised developer workstation, or CI log), an attacker can exploit them indefinitely from any location without triggering traditional perimeter alarms. Modern Zero-Trust mandates ephemeral credentials (TTL < 1 hour) issued via short-lived OpenID Connect (OIDC) federation, SPIFFE/SPIRE mutual TLS certificates, or hardware-bound FIDO2/WebAuthn passkeys.

How does kernel-level eBPF (Cilium/Tetragon) improve upon legacy iptables for microsegmentation?

Legacy iptables scales linearly O(N), causing severe CPU overhead and latency degradation when clusters scale to thousands of pods and network rules. Furthermore, iptables operates blindly on IP addresses and ports without application context. Cilium eBPF replaces iptables with in-kernel BPF hash maps operating in constant O(1) time, enabling cryptographic identity-based filtering, L7 protocol inspection (HTTP/gRPC/Kafka), and automated in-kernel process termination (SIGKILL) without user-space context switches.

What is SPIFFE/SPIRE and how does it establish workload attestation without secrets?

SPIFFE (Secure Production Identity Framework for Everyone) is a CNCF open standard defining uniform, cryptographic identity strings (SPIFFE IDs) for workloads. SPIRE is its reference implementation. A local SPIRE Agent inspects the Linux kernel (/proc) and container runtime to attest workload attributes (container image SHA, namespace, service account) without the workload ever possessing a private key. It dynamically injects an ephemeral X.509 SVID into the workload's memory via the SPIFFE Workload API.

What is SLSA Level 3 and why is keyless signing via Sigstore Cosign critical for software supply chains?

SLSA (Supply-chain Levels for Software Artifacts) Level 3 certifies that source code was built in an isolated, hermetic, and verifiable build platform where intermediate inputs cannot be tampered with. Sigstore Cosign keyless signing uses short-lived OpenID Connect tokens from the CI runner (GitHub Actions / GitLab CI) and Fulcio Certificate Authority to sign artifacts, recording the cryptographic proof permanently in the public Rekor transparency log without developers needing to manage or store private keys.