Blog
  • Kubernetes
  • Zero-trust
  • IBAC
  • Dropbox
  • Automation
  • Startups
  • Podcasts

First Person Platform Episode 2 - Andrew Moore on Uber Workload Identity and Authorization

The second episode of First Person Platform, a podcast: platform engineers nerd out with Ori Shoshan on access controls, Kubernetes, and platform engineering.

Written By
Ori Shoshan
Published Date
Apr 16 2024
Read Time
1 minute

Welcome back to First Person Platform, a new podcast for platform engineers. We kick off with a brief series of episodes featuring engineers who have either spearheaded or led teams in building tools for secure workload and service access. Each episode takes a deep dive into the motivation behind building the system, its origin story, lessons learned throughout the process, and provides an opportunity to get to know the brilliant minds working behind the scenes!


Joining me for this second episode is Andrew Moore. Andrew is a Staff Software Engineer leading the Platform Authentication team at Uber and sits on the SPIFFE Steering Committee. Prior to Uber, Andrew was a Software Engineer for various US and foreign Defense and Civil contracts with Lockheed Martin, Leidos, and Earth Resources Technology. Outside of work, Andrew homebrews beer, mead, kombucha, and Dungeons and Dragons campaigns.

In this episode, we’ll be talking about Uber’s use of SPIFFE/SPIRE and Charter for Workload Identity and Authorization. Learn about the design choices, motivations, and lessons learned that led to this setup. Plus, we’ll chat about Kubernetes, how to keep an abstract design mindset over a particular tech choice, and fads and fashion in software fads, and sprinkle in some hot takes and anime references for fun! ;)



Listen or watch below. Keep scrolling for links from the episode:



Uber blog posts mentioned in the podcast:

You can get in touch with Andrew on the SPIFFE Slack, or on LinkedIn.

Like this article?

Sign up for newsletter updates

By subscribing you agree to with our Privacy Policy and to receive updates from us.
Share article
Visit the Otter’s Den

Your go-to hub for Kubernetes security and tech know-how

  • Kubernetes
  • IBAC
  • Zero-trust
  • IAM
  • AWS
  • EKS
  • ACK
Blog
Apr 29 2024
Scheduler vs. API Proxy: Balancing Kubernetes data-plane and control-plane for optimal Zero-Trust IAM security with Otterize

Discover how to automate zero-trust IAM security for EKS applications and AWS resources using AWS Controllers for Kubernetes (ACK) and Otterize.

  • Kubernetes
  • Zero-trust
  • IBAC
  • Dropbox
  • Automation
  • Startups
  • Podcasts
Blog
Apr 16 2024
First Person Platform Episode 2 - Andrew Moore on Uber Workload Identity and Authorization

The second episode of First Person Platform, a podcast: platform engineers nerd out with Ori Shoshan on access controls, Kubernetes, and platform engineering.

  • Network Policy
  • Kubernetes
  • Zero-trust
Blog
Feb 12 2024
Network policies are not the right abstraction (for developers)

We explore the limitations of relying solely on Kubernetes network policies as a solution for achieving zero-trust between pods, identifying multiple flaws that hinder their effectiveness in meeting the demands of real-world use cases, particularly when prioritizing developer experience in a Kubernetes-based platform.