ProficientNowTechRFCs

Appendix B: References

RFC-TENANT-SECURITY-0001                                        Appendix B
Category: Standards Track                                       References

Appendix B: References

← Appendix A: Glossary | Index


B.1 Normative References

References that MUST be followed for compliance with this RFC.

IDTitleURL
[RFC2119]Key words for use in RFCs to Indicate Requirement Levelshttps://www.rfc-editor.org/rfc/rfc2119
[RFC8174]Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Wordshttps://www.rfc-editor.org/rfc/rfc8174
[OWASP-TOP10]OWASP Top 10 2021https://owasp.org/Top10/
[OWASP-API-TOP10]OWASP API Security Top 10 2023https://owasp.org/API-Security/
[OWASP-CRS]OWASP Core Rule Sethttps://coreruleset.org/
[K8S-NETPOL]Kubernetes Network Policieshttps://kubernetes.io/docs/concepts/services-networking/network-policies/
[GATEWAY-API]Kubernetes Gateway APIhttps://gateway-api.sigs.k8s.io/

B.2 Informative References

References that provide background information and context.

B.2.1 Technology Documentation

IDTitleURL
[BUNKERWEB]BunkerWeb Documentationhttps://docs.bunkerweb.io/
[BUNKERWEB-GH]BunkerWeb GitHub Repositoryhttps://github.com/bunkerity/bunkerweb
[BUNKERWEB-HELM]BunkerWeb Helm Charthttps://github.com/bunkerity/bunkerweb-helm
[CALICO-DOCS]Calico Documentationhttps://docs.tigera.io/calico/latest/
[CALICO-NETPOL]Calico Network Policyhttps://docs.tigera.io/calico/latest/network-policy/
[CERT-MANAGER]cert-manager Documentationhttps://cert-manager.io/docs/
[LETSENCRYPT]Let's Encrypt Documentationhttps://letsencrypt.org/docs/

B.2.2 Alternatives Evaluated

IDTitleURL
[SAFELINE]SafeLine WAFhttps://github.com/chaitin/SafeLine
[CORAZA]Coraza WAFhttps://coraza.io/
[MODSECURITY]ModSecurityhttps://github.com/SpiderLabs/ModSecurity

B.2.3 Industry Standards

IDTitleURL
[NGINX-RETIRE]Ingress NGINX Retirement Announcementhttps://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/
[CRS-DOCS]OWASP CRS Documentationhttps://coreruleset.org/docs/
[OWASP-WAF]OWASP WAF Projectshttps://waf.owasp.org/

B.2.4 Compliance Standards

IDTitleDescription
[SOC2]SOC 2Service Organization Control 2
[ISO27001]ISO/IEC 27001Information security management
[PCI-DSS]PCI DSSPayment Card Industry Data Security Standard

B.3 Internal References

References to other RFCs and internal documentation.

B.3.1 Normative Internal References

IDTitleRelationship
RFC-IAM-0001Federated Identity and Access Management ArchitectureKeycloak integration patterns; WAF exceptions for auth flows
RFC-SECOPS-0001GitOps-Native, Vault-First Secret Management ArchitectureVault for secrets; ESO for TLS certificate distribution

B.3.2 Informative Internal References

IDTitleRelationship
RFC-WORKLOAD-IDENTITYWorkload Identity ArchitectureService mesh boundary; East-West traffic handling
RFC-PAM-0001Privileged Access Management ArchitectureNetwork policies may affect privileged access
RFC-DEVELOPER-PLATFORMDeveloper Platform Architecture (Planned)Future self-service integration

B.4 Version History

VersionDateAuthorChanges
1.0.02026-02-11Platform Engineering TeamInitial release

B.5 Document Status

FieldValue
StatusDraft
Review StatePending
Last Review
Next Review

B.6 Acknowledgments

This RFC builds upon work from:

  • OWASP Foundation for the Core Rule Set and security guidance
  • BunkerWeb project for the WAF solution
  • Kubernetes community for NetworkPolicy and Gateway API specifications
  • cert-manager project for certificate automation

Document Navigation


End of Appendix B


End of RFC-TENANT-SECURITY-0001