---
title: "Context-Aware Identity-Aware Proxy (ZTNA) | Zero-Trust Architecture Canon"
description: "Zero Trust Network Access (ZTNA) model replacing corporate VPNs with a context-aware reverse proxy evaluating user identity, device posture, and geolocation per request."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/beyondcorp-ztna-reverse-proxy"
locale: "en"
---

# Context-Aware Identity-Aware Proxy (ZTNA) (`zt-arch-02`)

> **Pillar**: IDENTITY | **Archetype**: IDENTITY_ATTESTATION
> **Blocked MITRE ATT&CK Techniques**: T1078, T1133, T1539, T1056

## Architecture Summary

Zero Trust Network Access (ZTNA) model replacing corporate VPNs with a context-aware reverse proxy evaluating user identity, device posture, and geolocation per request.

## Adversary Model

Stolen employee password used from an unauthorized personal machine or hostile geographical IP range.

## NIST SP 800-207 Core Tenets

- Access to resources is determined by dynamic policy including the observable state of client identity, device, and environmental attributes.
- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: SaaS identity proxy deployed in front of internal admin tools.
- **Authentication Enforcement**: Single Sign-On (SSO) with standard TOTP multi-factor auth.
- **Network Isolation**: Public internet endpoints hidden behind cloud proxy IP allowlists.

### ADVANCED Maturity Target

- **Implementation Scope**: Global Edge ZTNA network covering all internal web applications and SSH bastions.
- **Authentication Enforcement**: Mandatory FIDO2 WebAuthn passkeys with device OS version checks.
- **Network Isolation**: Outbound-only secure tunnels (e.g. Cloudflare Tunnel / WireGuard) with zero open inbound ports.

### OPTIMAL Maturity Target

- **Implementation Scope**: Unified micro-perimeter encompassing web, SSH, database proxies, and Kubernetes APIs.
- **Authentication Enforcement**: Continuous per-request risk score recalculation using UEBA and TPM hardware attestation.
- **Network Isolation**: Total elimination of internal flat corporate subnets; all endpoints air-gapped from each other.

## Terraform HCL Manifest

```hcl
resource "cloudflare_zero_trust_access_application" "internal_console" {
  zone_id          = var.cloudflare_zone_id
  name             = "TinyCTO Production Console"
  domain           = "console.internal.tinycto.tv"
  type             = "self_hosted"
  session_duration = "1h"
  auto_redirect_to_identity = true
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: internal-console-ingress
  annotations:
    ingress.kubernetes.io/auth-url: "https://auth.tinycto.tv/oauth2/auth"
    ingress.kubernetes.io/auth-signin: "https://auth.tinycto.tv/oauth2/start"
spec:
  rules:
  - host: console.internal.tinycto.tv
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: console-svc
            port:
              number: 8080
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Context-Aware Identity-Aware Proxy (ZTNA) | Zero-Trust Architecture Canon",
  "description": "Zero Trust Network Access (ZTNA) model replacing corporate VPNs with a context-aware reverse proxy evaluating user identity, device posture, and geolocation per request.",
  "url": "https://tinycto.tv/zero-trust/architectures/beyondcorp-ztna-reverse-proxy"
}
```
