MARATTO

article

Security Policy Orchestration in SDN–Microservices Environments

Abstract

Securing SDN-microservices environments requires a coherent orchestration of identity, authentication, and authorization policies. This paper proposes an architecture integrating FreeIPA for centralized identity management, Keycloak for federated authentication using OAuth2/OIDC, Open Policy Agent for declarative policy-as-code authorization, and VXLAN for multitenant network segmentation. The proposed approach ensures end-to-end, multi-layer governance, ranging from applicationlevel access control to the orchestration of the SDN control plane via RESTCONF. Experimental validation in a distributed environment demonstrates the effective integration of federated authentication, dynamic policy evaluation based on JWT claims, and network isolation with 0% inter-tenant leakage. The results confirm the feasibility of secure orchestration aligned with Zero Trust principles, providing a modular and extensible solution for cloud-native SDN-microservices infrastructures.

Research topics

  • Software-Defined Networks and 5G
  • Software System Performance and Reliability
  • Network Packet Processing and Optimization

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/iraset68627.2026.11538708

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.