Should there be authentication/authorization between microservices?

Viewed 5029

I know this may be not a good question.

I was asked a question: do we really need authentication among microservices. And I have no idea the answer. I did read some tutorials on SOA, microservices, and how to add authentication among the services. But I did not have too many ideas why we need authentication/authorization between microservices? Any use cases where they are required? Any use cases where they are not required? Any potential risk without authentication/authorization?

Any comments welcomed. It is better to give some practical examples. Thanks

3 Answers

If your organization is considered with internal threats (and why wouldn't they be?), then yes all microservices need to be protected from malicious use.

Related