SPIFFE 101 Q: How does SPIFFE describe a workload identity ?
8
Anatomy of a SPIFFE ID
9
Anatomy of an X.509-SVID
10
Anatomy of a JWT-SVID
11
Intro to SPIRE
12
SPIRE Architecture
13
A Day in the Life of an X.509-SVID
14
Anatomy of a SPIRE Registration
15
Workload Attestation
16
What We've Seen So Far
17
What's Coming Next in SPIRE
18
Learn More about SPIFFE/SPIRE
Description:
Explore the implementation of secure workload identity in production environments using SPIRE in this conference talk from KubeCon + CloudNativeCon Europe 2022. Discover how SPIRE, a CNCF Incubating project, provides short-lived, automatically rotated identities for workloads based on the SPIFFE specification. Learn about the core design of SPIRE and its application in cloud-native architectures to enhance defense-in-depth. Gain insights into the journey of service organizations, from three-tier architectures to microservices, and understand the fundamentals of SPIFFE, including workload identity description, SPIFFE ID anatomy, and X.509-SVID structure. Delve into SPIRE's architecture, registration process, and workload attestation. Conclude with an overview of upcoming features that expand SPIRE's capabilities as a production identity platform and discover resources for further learning about SPIFFE and SPIRE.