Securing Enterprise DevOps: Zero Trust Architecture in Cloud-Native and Microservices Environments

Abstract—Modern enterprise software engineering has undergone an architectural paradigm shift toward cloud-native architectures, containerized microservices, and high-velocity continuous integration and continuous deployment (CI/CD) pipelines. Concurrently, legacy perimeter-based security models ('castle-and-moat') have proven entirely inadequate in distributed, multi-tenant cloud ecosystems where internal network boundaries are non-existent and lateral movement vectors abound. The integration of Zero Trust Architecture (ZTA)—grounded in the foundational tenet of 'never trust, always verify'—into enterprise DevOps pipelines establishes an end-to-end security framework spanning code authoring, artifact signing, workload attestation, and runtime execution. However, embedding continuous, multi-dimensional verification into automated deployment pipelines introduces acute tensions between developer velocity, cryptographic verification latency, operational overhead, and distributed policy consistency. This paper provides an exshaustive, mathematically grounded technical investigation and architectural synthesis of Zero Trust DevOps (DevSecOps) across cloud-native environments. We formalize workload identity mechanics utilizing the SPIFFE/SPIRE cryptographic framework, model service-mesh-based mutual Transport Layer Security (mTLS) enforcement with sidecar and ambient proxies, and formalize Policy-as-Code (PaC) invariants under Open Policy Agent (OPA) gatekeepers. Furthermore, we implement an empirical enterprise testbed comprising 120 containerized microservices deployed across a production-grade Kubernetes cluster, subjected to automated adversarial red-team injection vectors (including supply-chain dependency poisoning, stolen credential replay, and kernel escape exploits). Our empirical findings demonstrate that an optimized Zero Trust posture reduces lateral attack propagation by 96.4% and halts software supply-chain compromises at the CI boundary with an operational latency penalty of only 4.8% on end-to-end pipeline execution. Finally, we formulate open challenges in post-quantum cryptographic workload attestation, continuous behavioral policy synthesis, and automated zero-knowledge secretless pipelines. Index Terms—Zero Trust Architecture (ZTA), Cloud-Native Systems, Microservices, DevSecOps, SPIFFE/SPIRE, Service Mesh, Policy-as-Code, Open Policy Agent (OPA), Supply Chain Security, eBPF Runtime Security.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-09
DOI
https://doi.org/10.5281/zenodo.23260026
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Securing Enterprise DevOps: Zero Trust Architecture in Cloud-Native and Microservices Environments

Sandeep Choudhary, Ashok Kajla, Ram Babu Buri, Rishabh Kumawat et al.
Zenodo (CERN European Organization for Nuclear Research)
Security and Verification in Computing
article

Securing Enterprise DevOps: Zero Trust Architecture in Cloud-Native and Microservices Environments

Sandeep Choudhary, Ashok Kajla, Ram Babu Buri, Rishabh Kumawat, Dr. Vishal Shrivastava
article en

Abstract

Abstract—Modern enterprise software engineering has undergone an architectural paradigm shift toward cloud-native architectures, containerized microservices, and high-velocity continuous integration and continuous deployment (CI/CD) pipelines. Concurrently, legacy perimeter-based security models ('castle-and-moat') have proven entirely inadequate in distributed, multi-tenant cloud ecosystems where internal network boundaries are non-existent and lateral movement vectors abound. The integration of Zero Trust Architecture (ZTA)—grounded in the foundational tenet of 'never trust, always verify'—into enterprise DevOps pipelines establishes an end-to-end security framework spanning code authoring, artifact signing, workload attestation, and runtime execution. However, embedding continuous, multi-dimensional verification into automated deployment pipelines introduces acute tensions between developer velocity, cryptographic verification latency, operational overhead, and distributed policy consistency. This paper provides an exshaustive, mathematically grounded technical investigation and architectural synthesis of Zero Trust DevOps (DevSecOps) across cloud-native environments. We formalize workload identity mechanics utilizing the SPIFFE/SPIRE cryptographic framework, model service-mesh-based mutual Transport Layer Security (mTLS) enforcement with sidecar and ambient proxies, and formalize Policy-as-Code (PaC) invariants under Open Policy Agent (OPA) gatekeepers. Furthermore, we implement an empirical enterprise testbed comprising 120 containerized microservices deployed across a production-grade Kubernetes cluster, subjected to automated adversarial red-team injection vectors (including supply-chain dependency poisoning, stolen credential replay, and kernel escape exploits). Our empirical findings demonstrate that an optimized Zero Trust posture reduces lateral attack propagation by 96.4% and halts software supply-chain compromises at the CI boundary with an operational latency penalty of only 4.8% on end-to-end pipeline execution. Finally, we formulate open challenges in post-quantum cryptographic workload attestation, continuous behavioral policy synthesis, and automated zero-knowledge secretless pipelines. Index Terms—Zero Trust Architecture (ZTA), Cloud-Native Systems, Microservices, DevSecOps, SPIFFE/SPIRE, Service Mesh, Policy-as-Code, Open Policy Agent (OPA), Supply Chain Security, eBPF Runtime Security.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 12%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.