Kubernetes InfrastructureMulti-Cluster Financial EstatesSOX 404 ยท FINRA 3110 ยท Zero Standing Privileges

Securing Kubernetes Namespace & Cluster Access

An enterprise engineering playbook for financial institutions to govern multi-cluster Kubernetes estates: fine-grained Zanzibar ReBAC namespace scoping, Workload Identity Federation (WIF) for pods, SCIM human owner binding, Zero Standing Privilege (ZSP) JIT escalation, real-time Teleport Lock session termination (<100ms), and automated SOX/FINRA cluster attestation.

Phase 1

1. Architecture & Dual-Track Threat Model Overview

Regulated financial institutions (hedge funds, investment banks, market makers) host latency-sensitive execution pods, pricing services, and quantitative analytics engines on Kubernetes. Native Kubernetes RBAC lacks real-time revocation, is cluster-scoped, and leads to credential sprawl. AuthHub introduces a dual-track governance substrate:

Track A: Human Engineers (SREs & Quants)

Zero Standing Privileges in production. SREs and quants submit Just-In-Time (JIT) access requests with regulatory justifications, requiring dual-control sign-off from Desk Heads before receiving ephemeral 30-minute credentials.

Track B: Automated Workloads & Pods (NHIs)

Algorithmic trading pods, ArgoCD GitOps workers, and telemetry daemons authenticate via RFC 8693 Workload Identity Federation (WIF). Static service account tokens and cluster-admin bindings are strictly eradicated.

Phase 2

2. Enterprise Identity Sync: Users, Groups & Impersonation Headers

Platform Engineers, Quantitative Developers, SREs, and Compliance Auditors are synchronized from enterprise IdPs (Okta, Microsoft Entra ID) into AuthHub via the SCIM 2.0 Ingress (/scim/v2/Users and /scim/v2/Groups).

Kubernetes Impersonation Headers

When an engineer connects via kubectl, the proxy injects verified SCIM attributes into native Kubernetes impersonation headers (Impersonate-User: alex.morgan@hedgefund.internal, Impersonate-Group: quant-researchers), ensuring complete identity audit trails in the Kubernetes API audit log.

Instant JML Departure Cascade

When an employee departs or changes desks, SCIM emits a deactivation (active: false). AuthHub instantly issues a global revocation lock to Teleport, immediately dropping all active TCP streams, exec TTY sessions, and port-forward tunnels across all clusters.

Phase 3

3. Fine-Grained Zanzibar ReBAC Schema for Multi-Cluster K8s

AuthHub models the Kubernetes estate as a four-tier securables hierarchy (infrastructure_region โ†’ k8s_cluster โ†’ k8s_namespace โ†’ k8s_workload), differentiating read-only inspection from intrusive container execution.

k8s-schema.zanzibarZanzibar DSL
definition user {}

definition platform_team {
    relation cluster_admin: user
    relation sre_lead: user
    relation compliance_auditor: user
}

definition k8s_cluster {
    relation platform: platform_team
    relation auditor: user
}

definition k8s_namespace {
    relation parent_cluster: k8s_cluster
    relation namespace_admin: user
    relation developer: user
    relation automated_pod: user
    relation tier0_restricted: user

    // Pod and resource read permissions
    permission view_workloads = developer + namespace_admin + parent_cluster->platform->cluster_admin
    permission view_logs = developer + namespace_admin + parent_cluster->platform->compliance_auditor

    // Container exec / attach requires explicit administrative or JIT delegation,
    // and is completely forbidden if the namespace carries tier0_restricted status.
    permission exec_container = (namespace_admin + parent_cluster->platform->sre_lead) - tier0_restricted
    permission modify_secrets = namespace_admin
}

definition k8s_workload {
    relation parent_namespace: k8s_namespace
    relation technical_owner: user

    permission restart = technical_owner + parent_namespace->namespace_admin
    permission read_status = parent_namespace->view_workloads
}

Tuple Ingestion via Management API

To bind Quant Developer usr-scim-alex-quant to the staging namespace quant-research-staging, write the relationship tuple:

POST/api/v1/tenant/tuples
{
  "writes": [
    {
      "resource": { "objectType": "k8s_namespace", "objectId": "quant-research-staging" },
      "relation": "developer",
      "subject": { "objectType": "user", "objectId": "usr-scim-alex-quant" }
    }
  ]
}
Phase 4

4. Workload Identity Federation (WIF) for Pods & Machine Workloads

Regulated workloads (such as algorithmic execution pods, ArgoCD GitOps sync workers, and telemetry daemons) cannot hold static API tokens or cloud IAM secrets mounted in Secret volumes. AuthHub implements RFC 8693 Workload Identity Federation.

1. Projected ServiceAccount Token Configuration
Kubernetes Pod Manifest

Kubernetes pods mount an ephemeral, short-lived OIDC token with a cryptographic audience bound specifically to AuthHub:

apiVersion: v1
kind: Pod
metadata:
  name: algorithmic-pricing-bot
  namespace: prod-trade-execution-tier0
spec:
  serviceAccountName: pricing-engine-sa
  containers:
  - name: bot
    image: 123456789.dkr.ecr.us-east-1.amazonaws.com/pricing-bot:v2.4.1
    volumeMounts:
    - mountPath: /var/run/secrets/tokens
      name: authhub-token
  volumes:
  - name: authhub-token
    projected:
      sources:
      - serviceAccountToken:
          path: authhub-token
          expirationSeconds: 3600
          audience: "https://api.authhub.cloud"
2. RFC 8693 Token Exchange Workflow

At startup, the pod exchanges its projected Kubernetes token for a scoped AuthHub JWT. AuthHub validates the pod against the cluster's OIDC discovery endpoint (/.well-known/openid-configuration) before issuing access rights, eliminating static credentials entirely.

Phase 5

5. Mandatory Management Ownership Assignment (SCIM Users)

Mandatory Prerequisite: Neither a Kubernetes namespace nor an automated pod identity can be launched or recertified without designated human owners drawn from the SCIM 2.0 user sync.
Role 1: Technical Owner

Lead Platform SRE / DevOps Lead

Responsible for Helm charts, resource quotas, network policies, and pod disruption budgets.

Role 2: Business Owner

Trading Desk Head / Risk Officer

Responsible for verifying that workloads in the namespace serve approved commercial trading objectives.

Role 3: Deputies (Bench โ‰ฅ 2)

Qualified Secondary Reviewers

Mandatory bench of 2+ deputies. Ensures JIT elevation and emergency approvals are never held up.

Role 4: Escalation Contact

Chief Information Security Officer

Escalation recipient if a namespace has unattended attestation tasks or high-severity policy alerts.

Binding SCIM Users to the Namespace (Owner & Bench Depth)

Assign the Technical Owner and at least two Qualified Deputies (mandating bench depth โ‰ฅ 2) using their SCIM-synchronized user IDs:

POST/api/v1/tenant/nhis/k8s-ns-prod-trade-exec/owners (Assign Technical Owner)
{
  "role": "technical_owner",
  "assigneeType": "user",
  "assigneeId": "usr-scim-david-sre",
  "assigneeEmail": "david.ross@hedgefund.internal",
  "orgId": "org-infrastructure-platform",
  "priority": 1
}
POST/api/v1/tenant/nhis/k8s-ns-prod-trade-exec/owners (Assign Deputy 1 โ€” Primary)
{
  "role": "deputy",
  "assigneeType": "user",
  "assigneeId": "usr-scim-elena-lead",
  "assigneeEmail": "elena.rostova@hedgefund.internal",
  "priority": 1
}
POST/api/v1/tenant/nhis/k8s-ns-prod-trade-exec/owners (Assign Deputy 2 โ€” Secondary)
{
  "role": "deputy",
  "assigneeType": "user",
  "assigneeId": "usr-scim-marcus-vp",
  "assigneeEmail": "marcus.vance@hedgefund.internal",
  "priority": 2
}
Phase 6

6. Zero Standing Privileges (ZSP) & Dual-Control JIT Escalation

In production financial environments, engineers possess Zero Standing Privileges. Interactive pod shell access (kubectl exec) or namespace administration requires an ephemeral Just-In-Time (JIT) access request.

POST/api/v1/tenant/access-requests

JIT Request Flow

When an incident occurs, the engineer submits an emergency access request specifying the target namespace, command scope, and ticket justification:

{
  "resourceType": "k8s_namespace",
  "resourceId": "prod-trade-execution-tier0",
  "requestedRole": "namespace_admin",
  "durationSeconds": 1800,
  "justification": "INC-88912: Order routing gateway socket timeout post-market close",
  "requireDualApproval": true
}

Dual-Control Sign-Off & Ephemeral Certificate Issuance

For Tier-0 financial namespaces, AuthHub mandates dual-control approval: both the Business Owner (Desk Head) and a Compliance Lead must confirm via the console or Slack/Teams app. Once signed off, the Teleport Kube proxy generates a client certificate valid for exactly 30 minutes, expiring automatically.

Phase 7

7. Real-Time Governance & Sub-100ms Teleport Lock Kill-Switch

Pre-flight checks alone cannot stop an active session from turning rogue. AuthHub continuously evaluates real-time business telemetry and enforces immediate, streaming session termination:

Clock 1: Signals

Machine Telemetry

The Kubernetes audit log stream and Falco runtime agent detect unauthorized container binary execution. The anomaly signal is emitted into AuthHub's Redis pipeline within 25ms.

Clock 2: Enforcement

Teleport Lock (< 100ms)

AuthHub pushes an instant revocation over WebSocket to the AuthHub-Teleport Connector. The connector calls the native Teleport API to apply an immediate Teleport Lock, terminating the user's active TTY terminal immediately.

Clock 3: Execution

Admissibility Boundary

Policy boundary rules automatically disallow interactive container exec or secret modification during core trading hours (09:30 โ€“ 16:00 EST), failing closed inline.

Phase 8

8. Setting Certification Tasks & SOX/FINRA Attestation Campaigns

Under SOX 404, FINRA Rule 3110, and SEC Rule 17a-4, access to production container infrastructure cannot persist unchecked. Compliance teams configure quarterly Cluster Access Recertification Campaigns.

POST/api/v1/tenant/nhis/campaigns

Chief Risk Officer / CISO Action

Launch a targeted recertification campaign for all Tier-0 Kubernetes namespaces and service accounts:

create-k8s-campaign.json
{
  "name": "Q3 2026 Production Kubernetes Namespace & Cluster Access Attestation",
  "scopeFilter": {
    "environment": "production",
    "tier": 0,
    "actorType": "infrastructure"
  },
  "deadline": "2026-10-31T23:59:59.000Z",
  "completionThreshold": 100.0
}
Attest & Extend Lease
POST .../campaigns/:id/certify

The Business Owner certifies that the namespace bindings remain necessary for live algorithmic trading:

{
  "nhiId": "k8s-ns-prod-trade-exec",
  "newExpiresAt": "2027-01-31T00:00:00Z"
}
Revoke Stale Namespace
POST .../campaigns/:id/revoke

If a quantitative trading strategy was decommissioned, access is permanently revoked:

{
  "nhiId": "k8s-ns-retired-fx-arb",
  "reason": "Strategy decommissioned in Q2 portfolio rebalance"
}
Automated Deadline Sweep: CampaignDeadlineProcessor

Automated Privilege Stripping on Expiry

The campaign_deadlines background worker checks active campaigns every 10 minutes. Any cluster binding uncertified when the deadline elapses is marked expired.

The spicedb_gc worker immediately deletes the corresponding relationship tuples in SpiceDB, and Teleport revokes any associated cluster access roles, preventing compliance drift without manual intervention.

Cryptographic Merkle Audit Trail

HSM: Paid Add-On

Every kubectl exec session, JIT escalation, Teleport Lock event, and campaign attestation is sealed into an append-only SHA-256 Merkle tree with RFC 3161 timestamps using standard ECDSA P-256 signatures. For institutions requiring FIPS 140-2 Level 3 physical key isolation, an optional Thales Luna Cloud HSM dedicated partition (Paid Enterprise Add-on) is available.

Ready to implement in your enterprise?

Explore the dedicated API references for Non-Human Identities (NHI), real-time governance signals, and autonomous policy revisions: