WEBBOOK CHAPTER

외부 인터페이스 엔지니어링: 38장. JWKS Rotation과 Cache Stampede를 막는다

38장. JWKS Rotation과 Cache Stampede를 막는다

JWT kid가 cache에 없을 때 요청마다 JWKS를 fetch하면 provider와 thread를 압도한다. issuer별 cache, max-age, single-flight refresh, timeout과 마지막 정상 key 정책을 둔다. signature 외에 issuer, audience, expiry, nonce/authorized party를 flow에 맞춰 검증한다. algorithm을 token header가 임의 선택하게 하지 않는다.

old/new key overlap, unknown key, JWKS timeout, DNS·TLS failure를 fixture issuer로 재현한다. 검증을 끄는 fallback은 없다. token·authorization header를 log하지 않고 key id와 result class만 관측한다.