Implementing Security Best Practices

1. Always Using TLS

RuleDetail
ProductionNever insecure.NewCredentials()
MinimumTLS 1.2; prefer 1.3
CiphersModern AEAD only

2. Validating Certificates

CheckDetail
Chain to trusted CAInternal PKI or public CA
SAN matchesServer hostname
Not expired / not revokedHonor CRL or OCSP
Never InsecureSkipVerifyOutside of tests

3. Implementing mTLS

AspectDetail
Server requires client certClientAuth: RequireAndVerifyClientCert
Identity from certSPIFFE ID or SAN
Use SPIRE / IstioAutomated rotation

4. Using Strong Authentication

MechanismDetail
OAuth2 / OIDCFederated identity
mTLSService-to-service
Short-lived tokensMinutes, not days
Avoid static API keysOr rotate aggressively

5. Implementing Authorization

LayerDetail
Method-levelPer-RPC allowlists
Resource-levelOwner / tenant scoping
Policy engineOPA / Cedar
Default denyExplicit allow only

6. Validating Input

ToolDetail
protovalidate MODERNCEL rules in .proto
Server interceptorReject before business logic
Length limitsCap strings/repeated to avoid DoS

7. Sanitizing Output

ConcernDetail
Don't leak internalsMap internal errors → safe codes/messages
Redact PIIFrom responses meant for less-privileged callers
Strip stack tracesNever return to client

8. Implementing Rate Limiting

LayerDetail
Per principalToken bucket keyed on user/IP
GlobalProtect backend capacity
Cost-basedExpensive RPCs cost more tokens

9. Setting Reasonable Limits

LimitDetail
MaxRecvMsgSizeCap inbound (e.g. 4–16 MB)
MaxConcurrentStreamsPer connection
ConnectionTimeoutIdle/age caps
DeadlinesMandatory on every RPC

10. Logging Security Events

EventDetail
Auth failuresPrincipal, IP, method, reason
Authz denialsResource, action, policy
Rate-limit hitsPossible abuse signal
No secrets in logsTokens, keys never logged

11. Performing Security Audits

ActivityDetail
Dependency scangovulncheck, Snyk, Dependabot
Static analysisgosec, CodeQL
Pen testExternal annual
Threat modelingSTRIDE per service