Tool Open source

SPIRE

SPIRE (the SPIFFE Runtime Environment) is an open-source toolchain and implementation of the SPIFFE workload-identity framework, maintained by the SPIFFE community and hosted as a graduated Cloud Native Computing Foundation project. It exposes the SPIFFE Workload API to attest running software, assign SPIFFE IDs, and issue SPIFFE Verifiable Identity Documents (SVIDs), allowing workloads to establish trust through mTLS or JWT signing and verification and to authenticate securely to services such as secret stores, databases, and cloud providers.

View repository Visit site Mentioned in 1 video ↓

Overview

SPIRE distributes SPIRE Server and SPIRE Agent binaries, with container images also available for those components and its OIDC discovery provider. Its extensible plugin framework supports different hosting environments and integrations, including an Envoy Secret Discovery Service implementation for installing and rotating TLS certificates and trust bundles. The project provides quickstarts for Kubernetes, Linux, and macOS, along with Go and Java client libraries and example repositories.

What SPIRE is used for

1 use taken from transcripts — each links to the moment in the video.

  • A workload-identity implementation and building block used under the hood by other infrastructure products. The speakers distinguish it from higher-level products that provide workload identity without requiring users to manage SPIRE directly.

Videos mentioning SPIRE

1 in the library.