Lesson 17 / 25

TLS, mTLS and Token Authentication

Securing channels and calls.

Channel credentials and call credentials

gRPC separates channel credentials (TLS for the connection) from call credentials (per-call tokens such as OAuth 2.0 or JWT bearer tokens in metadata). Use TLS for all traffic; mutual TLS (mTLS) also authenticates the client with a certificate, which is common between services and often provided automatically by a service mesh. Authorise each method on the server based on the authenticated identity, for example in an interceptor.

TLS channel with a bearer token in Python

Combining channel and call credentials (a sketch).

import grpc

with open("ca.pem", "rb") as f:
    channel_creds = grpc.ssl_channel_credentials(root_certificates=f.read())

call_creds = grpc.access_token_call_credentials(token)     # adds "authorization: Bearer ..."
creds = grpc.composite_channel_credentials(channel_creds, call_creds)

channel = grpc.secure_channel("orders.internal.example.com:443", creds)
stub = order_pb2_grpc.OrderServiceStub(channel)

Let a mesh handle mTLS where available

Service meshes such as Istio or Linkerd issue and rotate workload certificates, removing that burden from application code.

Quick check: What does mutual TLS add over regular TLS?

  • Automatic retries
  • Faster serialisation
  • The client also proves its identity with a certificate
  • Compression of messages
Answer

The client also proves its identity with a certificate — Both sides authenticate.