Lesson 17 / 25
TLS, mTLS and Token Authentication
Securing channels and calls.
Channel credentials and call credentials
gRPC separates channel credentials (TLS for the connection) from call credentials (per-call tokens such as OAuth 2.0 or JWT bearer tokens in metadata). Use TLS for all traffic; mutual TLS (mTLS) also authenticates the client with a certificate, which is common between services and often provided automatically by a service mesh. Authorise each method on the server based on the authenticated identity, for example in an interceptor.
TLS channel with a bearer token in Python
Combining channel and call credentials (a sketch).
import grpc
with open("ca.pem", "rb") as f:
channel_creds = grpc.ssl_channel_credentials(root_certificates=f.read())
call_creds = grpc.access_token_call_credentials(token) # adds "authorization: Bearer ..."
creds = grpc.composite_channel_credentials(channel_creds, call_creds)
channel = grpc.secure_channel("orders.internal.example.com:443", creds)
stub = order_pb2_grpc.OrderServiceStub(channel)Let a mesh handle mTLS where available
Service meshes such as Istio or Linkerd issue and rotate workload certificates, removing that burden from application code.
Quick check: What does mutual TLS add over regular TLS?
- Automatic retries
- Faster serialisation
- The client also proves its identity with a certificate
- Compression of messages
Answer
The client also proves its identity with a certificate — Both sides authenticate.