
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Fri, 12 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/iap/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy.en</guid>
    <title>Zero Trust and Identity-Aware Proxy — Building the BeyondCorp Model Yourself</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy.en</link>
    <description>The perimeter is dead and identity-first security is the new default. This post walks through the core of the Google BeyondCorp papers and builds an Identity-Aware Proxy from scratch with oauth2-proxy and Keycloak. We cover the nginx auth_request pattern, device trust, VPN replacement scenarios, a comparison of Cloudflare Access and Pomerium, and access control for AI agents from a 2026 perspective.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>zero-trust</category><category>iap</category><category>beyondcorp</category><category>oauth2-proxy</category><category>keycloak</category><category>security</category><category>devops</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy.ja</guid>
    <title>Zero TrustとIdentity-Aware Proxy — BeyondCorpモデルを自分で構築する</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy.ja</link>
    <description>境界型セキュリティの終焉とidentity-firstセキュリティの時代に、Google BeyondCorp論文の核心を押さえ、oauth2-proxyとKeycloakでIdentity-Aware Proxyをゼロから構築する全過程を解説します。nginx auth_requestパターン、デバイス信頼、VPN代替シナリオ、Cloudflare AccessとPomeriumの比較、そしてAIエージェントのアクセス制御まで2026年の視点で整理します。</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>zero-trust</category><category>iap</category><category>beyondcorp</category><category>oauth2-proxy</category><category>keycloak</category><category>security</category><category>devops</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy</guid>
    <title>Zero Trust와 Identity-Aware Proxy — BeyondCorp 모델 직접 구축하기</title>
    <link>https://www.youngju.dev/blog/devops/2026-06-12-zero-trust-identity-aware-proxy</link>
    <description>경계 보안의 종말과 identity-first 보안 시대, Google BeyondCorp 논문의 핵심을 짚고 oauth2-proxy와 Keycloak으로 Identity-Aware Proxy를 직접 구축하는 전 과정을 다룹니다. nginx auth_request 패턴, 디바이스 신뢰, VPN 대체 시나리오, Cloudflare Access와 Pomerium 비교, 그리고 AI agent 접근 제어까지 2026년 관점에서 정리합니다.</description>
    <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>zero-trust</category><category>iap</category><category>beyondcorp</category><category>oauth2-proxy</category><category>keycloak</category><category>security</category><category>devops</category>
  </item>

    </channel>
  </rss>
