“Production identity” is a common set of problems facing distributed systems. Many systems spend significant time and effort to establish trusted bi-directional communication between parts of the system. Often these are lacking in many respects: not rooted in sound identity “bedrock”, no ability to rotate credentials, no federation with other systems, and few policy opportunities that are valued and critical for organizations. SPIFFE and SPIRE aim to solve these problems in a common way that can be leveraged across many different types of systems -- not just containerized or cloud native.
Recently, we’ve also been calling SPIFFE/SPIRE an “identity control plane”.
In this talk, we will leverage the identity control plane to demonstrate recommended practices and considerations for doing identity distribution and attestation for service to service communication in complex and heterogeneous environments.