Service-to-service traffic needs identity too

Requests between your own systems deserve the same question as requests from outside: who is this and what may they do?

Internal traffic has historically been trusted because it was internal, which is exactly the assumption that turns one compromised service into all of them. Giving workloads their own identities, and checking them, means an attacker who takes one service still has to justify itself to the next. It is the same idea as zero trust, applied where there is no human to authenticate.

More on Zero trust