Tool Open source
SPIFFE (Secure Production Identity Framework for Everyone) is an open framework and set of standards for assigning strongly attested cryptographic identities to software workloads across heterogeneous infrastructure, including Kubernetes, virtual machines, public clouds, and private data centers. Workloads can use these identities for authenticated service-to-service communication through X.509 or JWT-based mechanisms, including mutually authenticated TLS and zero-trust authentication without passwords or API keys. SPIRE (SPIFFE Runtime Environment) is the companion toolchain that establishes trust and issues workload identities across hosting platforms. SPIFFE and SPIRE are graduated projects of the Cloud Native Computing Foundation.
2 uses taken from transcripts — each links to the moment in the video.
Provides each workload with a short-lived X.509 cryptographic identity.
A workload-identity building block discussed for Kubernetes products and infrastructure. The speakers say it is most appropriate when building lower-level systems such as networking or service-mesh components.
2 in the library.