Beyond Static Secrets: Building Verifiable Workload Identity with SPIFFE and SPIRE
About this session
Modern applications rely on communication among microservices, containers, virtual machines, APIs, and AI agents across dynamic, multi-cloud environments. Yet many workloads still authenticate with long-lived API keys, shared secrets, manually managed certificates, or network location—controls that are difficult to secure and rotate at scale.
This talk introduces SPIFFE, an open standard for assigning cryptographically verifiable identities to software workloads, and SPIRE, its production-ready implementation. We follow a workload’s identity journey—from node and workload attestation to receiving a short-lived identity document and establishing authenticated service-to-service communication. Attendees will learn how to design trust domains and SPIFFE IDs, replace embedded credentials with automatically rotated identities, and connect workload authentication to authorization policies. They will leave with a practical framework for evaluating and piloting SPIFFE in Kubernetes, multi-cloud, service-mesh, and other distributed environments.
Speaker
Key takeaways
- Understand how SPIFFE provides platform-independent, cryptographically verifiable workload identity. • Learn how SPIRE uses node and workload attestation to issue short-lived X.509 and JWT identity documents. • Replace static API keys, shared secrets, and manually managed certificates with automatically rotated credentials. • Design effective trust domains and stable SPIFFE ID structures for distributed environments. • Use SPIFFE identities with mutual TLS and authorization policies for secure service-to-service communication. • Apply a practical approach to piloting SPIFFE across Kubernetes, service-mesh, multi-cloud, and AI-agent workloads.