Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Behind the CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems - Yoshiyuki Tabata, Hitachi, Ltd. & Hiroyuki Wada, Nomura Research Institute, Ltd.
In March 2026, CNCF TAG Security and Compliance published the CNCF Identity and Access Management (IAM) Whitepaper, providing practical guidance on how authentication and authorization should be designed and implemented in cloud native systems.
Presented by the authors of the whitepaper, this session explains the intent, scope, and architectural decisions behind the document. Rather than introducing IAM products or implementation details, the talk focuses on how the TAG structured authentication and authorization requirements into two reusable reference patterns, Basic and Advanced, and how each pattern defines its trust boundaries and enforcement responsibilities.
By sharing the reasoning behind these design choices, this session aims to help architects and developers apply the IAM Whitepaper as a shared architectural baseline when designing, reviewing, and evolving authentication and authorization mechanisms in cloud native systems.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Behind the CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems - Yoshiyuki Tabata, Hitachi, Ltd. & Hiroyuki Wada, Nomura Research Institute, Ltd.
In March 2026, CNCF TAG Security and Compliance published the CNCF Identity and Access Management (IAM) Whitepaper, providing practical guidance on how authentication and authorization should be designed and implemented in cloud native systems.
Presented by the authors of the whitepaper, this session explains the intent, scope, and architectural decisions behind the document. Rather than introducing IAM products or implementation details, the talk focuses on how the TAG structured authentication and authorization requirements into two reusable reference patterns, Basic and Advanced, and how each pattern defines its trust boundaries and enforcement responsibilities.
By sharing the reasoning behind these design choices, this session aims to help architects and developers apply the IAM Whitepaper as a shared architectural baseline when designing, reviewing, and evolving authentication and authorization mechanisms in cloud native systems.










