Security Architecture
Design security into the system shape — not bolt it on after.
Start with a threat model
- What are we protecting? (assets, data classifications)
- From whom? (threat actors, capabilities)
- Trust boundaries — draw them: where does data/control cross between differently-trusted components? Each crossing is where to authenticate, authorize, validate, and encrypt.
- Enumerate threats (STRIDE: Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation) per boundary; rank by risk; design mitigations.
Architectural principles
- Defense in depth: independent layers so one failure isn't catastrophic.
- Least privilege + least authority: minimal scope per component; capability-based over ambient authority where possible.
- Minimize attack surface & TCB: fewer entry points, smaller trusted base
(favors microkernel/microVM isolation — see
os-kernel-architecture,virtualization). - Fail securely: deny by default; errors don't open access.
- Secure by design/default: safe defaults, secrets never in code, encryption in transit + at rest.
Zero-trust
Drop implicit network trust. Authenticate + authorize every request (identity, device posture, policy) regardless of network location; micro-segment; assume breach. Replaces the "hard perimeter, soft interior" model.
Hardware / platform security
- TEE / enclaves (SGX, TrustZone, SEV-SNP, TDX): run/seal sensitive computation isolated from the OS/host — for untrusted-host or confidential-computing scenarios.
- Secure boot / chain of trust: each stage verifies the next from a hardware root of trust; measured boot + attestation for remote trust.
- Key management: HSM/KMS, rotation, envelope encryption; never hand-roll crypto.
When to invoke this
- New system/platform design, multi-tenant or untrusted-input systems, regulated data, anything internet-facing or handling secrets/PII. Produce a threat model + trust-boundary diagram + mitigations as part of the ADR.