Securing Enterprise DevOps: Zero Trust Architecture in Cloud-Native and Microservices Environments
Abstract—Modern enterprise software engineering has undergone an architectural paradigm shift toward cloud-native architectures, containerized microservices, and high-velocity continuous integration and continuous deployment (CI/CD) pipelines. Concurrently, legacy perimeter-based security models ('castle-and-moat') have proven entirely inadequate in distributed, multi-tenant cloud ecosystems where internal network boundaries are non-existent and lateral movement vectors abound. The integration of Zero Trust Architecture (ZTA)—grounded in the foundational tenet of 'never trust, always verify'—into enterprise DevOps pipelines establishes an end-to-end security framework spanning code authoring, artifact signing, workload attestation, and runtime execution. However, embedding continuous, multi-dimensional verification into automated deployment pipelines introduces acute tensions between developer velocity, cryptographic verification latency, operational overhead, and distributed policy consistency. This paper provides an exshaustive, mathematically grounded technical investigation and architectural synthesis of Zero Trust DevOps (DevSecOps) across cloud-native environments. We formalize workload identity mechanics utilizing the SPIFFE/SPIRE cryptographic framework, model service-mesh-based mutual Transport Layer Security (mTLS) enforcement with sidecar and ambient proxies, and formalize Policy-as-Code (PaC) invariants under Open Policy Agent (OPA) gatekeepers. Furthermore, we implement an empirical enterprise testbed comprising 120 containerized microservices deployed across a production-grade Kubernetes cluster, subjected to automated adversarial red-team injection vectors (including supply-chain dependency poisoning, stolen credential replay, and kernel escape exploits). Our empirical findings demonstrate that an optimized Zero Trust posture reduces lateral attack propagation by 96.4% and halts software supply-chain compromises at the CI boundary with an operational latency penalty of only 4.8% on end-to-end pipeline execution. Finally, we formulate open challenges in post-quantum cryptographic workload attestation, continuous behavioral policy synthesis, and automated zero-knowledge secretless pipelines. Index Terms—Zero Trust Architecture (ZTA), Cloud-Native Systems, Microservices, DevSecOps, SPIFFE/SPIRE, Service Mesh, Policy-as-Code, Open Policy Agent (OPA), Supply Chain Security, eBPF Runtime Security.
Authors
- Sandeep Choudhary
- Ashok Kajla
- Ram Babu Buri
- Rishabh Kumawat
- Dr. Vishal Shrivastava
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-09
- DOI
- https://doi.org/10.5281/zenodo.23260026
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00