Component layer
The component layer has many different security responsibilities. A BFF component will deploy its own CDN that is connected to the WAF, as discussed earlier. The BFF component will play a role in DDoS protection as well, by employing an API gateway that will handle throttling and by providing sufficient autoscaling to absorb traffic that reaches its internals. Each component will also monitor for and alert on deviations from normal request rates, as discussed in Chapter 8, Monitoring.
Least privileged access is another important responsibility of each component. Following security-by-design practices, teams will define strict permissions for each component to grant it access to its required resources. For example, an API gateway ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access