#spiffe — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spiffe, aggregated by home.social.
-
Zero Trust для ИИ-агентов: почему отдельной идентичности недостаточно
Привет, Хабр! Меня зовут Денис Корбаков, я технический директор «Смарт-Софт». Мы разрабатываем NGFW и регулярно разбираем, какие сетевые события можно использовать для независимого контроля автоматизированных систем. Последний год эта задача резко усложнилась. В инфраструктуре массово появился новый операционный тип машинного субъекта: автономный агент, который сам выбирает инструменты, меняет контекст и делегирует полномочия. Zero Trust никогда не ограничивался только людьми. NIST SP 800-207 прямо включает в модель non-person entities: сервисы, приложения, автоматизированное ПО, и обсуждает их ещё с версии 2020 года. Субъект как класс не новый, новыми являются масштаб, автономность и модель поведения. Большинство корпоративных реализаций IAM на практике заточены либо под человека с интерактивной сессией, либо под стабильный сервисный аккаунт, который работает годами с предсказуемым поведением. ИИ-агент находится между этими моделями: не человек, способный самостоятельно оценить допустимый объём своих полномочий, и не полностью статичный сервис с неизменным поведением. Как отмечает исследование Cloud Security Alliance, проведённое при поддержке Aembit , существующие подходы к IAM испытывают нагрузку, на которую изначально не проектировались.
https://habr.com/ru/articles/1071750/
#Zero_Trust #ИИагенты #IAM #машинная_идентичность #workload_identity #prompt_injection #MCP #NIST_SP
800207 #SPIFFE #NGFW -
I could not be more proud of the fact that I got to be part of #KCDNewYork 2026. I learned so much, especially around #Istio Ambient, which builds on top of #SPIFFE, my favorite #CNCF project :)
But there was so much more.
Here is a blog I wrote about the day:
https://blog.gitguardian.com/kcd-new-york-2026/ -
There's a new article in the #Keycloak blog about federated client authentication, where you rely on an external provider (like a #Kubernetes cluster with service account token, or a generic #SPIFFE client) to authenticate confidential clients. https://www.keycloak.org/2026/01/federated-client-authentication
Would love to take a closer look at that functionality at some point, especially for a use case where you authenticate Keycloak service accounts (to get tokens for M2M calls in a microservice architecture) through that method. Might be really great for getting rid of some secrets that have to be frequently rotated. But currently, I have no time to do this. Has anyone already used this? How well does it work? Worth investigating, or still too flaky?
-
Last week, I had the privilege of attending #KubeCon 2025
Seeing #SPIFFE and #SPIRE take a front seat in conversations, driven by #AgenticAI, was mind-blowing.
Here are a few thoughts and reflections from the event:
https://blog.gitguardian.com/kubecon-2025 -
Zero Trust в облаке: практическое руководство
В этом руководстве рассматривается современный подход к безопасности — Zero Trust Network Access (ZTNA) — и показано, как его реализовать с помощью SPIFFE/SPIRE и OpenID Connect (OIDC). Материала много, по этому я предоставлю его в сухой форме. В основе ZTNA лежит принцип «никогда не доверяй, всегда проверяй»: каждый запрос на доступ считается потенциально небезопасным и проходит обязательную аутентификацию и авторизацию. По сравнению с классическими VPN-сетями решения ZTNA на базе SPIFFE/SPIRE и OIDC: Ускоряют процедуру аутентификации в 20–80 раз, Повышают производительность на 46–64 %, В облаках AWS и Google Cloud позволяют снизить задержки до 50–100 мс вместо привычных 2–4 с.
https://habr.com/ru/articles/917440/
#zerotrust #spiffe #spire #oidc #kubernetes #aws #gcp #ztna #security
-
🚀 Excited to share my overview & and demo on
“sharing secrets across clusters with SPIFFE federation” ✨I presented it at sig-spire on Oct 26, 2023.
Dive in and explore! 🛠️:
https://vimeo.com/v0lkan/vsecm-spire -
Novel ways of providing identity to automated cross-#cloud processes – Workload Identity Federation (#workloadidentityfederation) and #SPIFFE
https://zuinnote.eu/blog/?p=2273 -
🚀 Hey, #ZeroTrust enthusiasts! — We’ve kicked off VMware Secrets Manager v0.22.0, codenamed Boötes!
🌟 Curious about what awesomeness lies ahead? Our 🔥Updated Yearly Roadmap🔥 has all the details 👉 https://vsecm.com/docs/roadmap/
🐢⚡️ #TurtlePower
-
🚀 Hey, #ZeroTrust enthusiasts! — We’ve kicked off VMware Secrets Manager v0.22.0, codenamed Boötes!
🌟 Curious about what awesomeness lies ahead? Our 🔥Updated Yearly Roadmap🔥 has all the details 👉 https://vsecm.com/docs/roadmap/
🐢⚡️ #TurtlePower
-
Master the art of local deployment and development of VMware Secrets Manager. Take your #DevOps game to the next level 🛠️🔐
-
Master the art of local deployment and development of VMware Secrets Manager. Take your #DevOps game to the next level 🛠️🔐
-
🎉 Just wrapped up an electric session on today's #TalkSPIFFE! 🚀 We dove deep into the nitty-gritty of open source, business licensing models, and their ripple effects on the open-source ecosystem (I’m looking at you HashiCorp!). 🌐
https://www.twitch.tv/videos/1913673154
#ZeroTrust #Security #SPIFFE #SPIRE #VSecM #TalkSPIFFE #VOD #Twitch
-
🔐 A Milestone in Zero-Trust Architectures: SPIFFE Takes Center Stage in Google Cloud
This week marked a pivotal moment in the journey of zero-trust architectures. Google Cloud announced its standardization of SPIFFE as the unified identity platform across all its environments.
This is not just a technical achievement; it’s’ a paradigm shift in how we approach security in cloud computing.
https://www.linkedin.com/feed/update/urn:li:activity:7103184580895014912/
#SPIFFE #ZeroTrust #GoogleCloud #CyberSecurity #OpenSource #Leadership
1/n
-
NIST said you should use SPIFFE, and you should use it NOW, and Google Cloud is standardizing its workload identity based on SPIFFE.
I cannot emphasize how HUGE this is!
check out this clip:https://www.youtube.com/clip/UgkxcujMWTzWhgep5b0rG0Xk991AQ91PCSmt
-
Keep your secrets… secret.
-
Keep your secrets… secret.
-
🎉 Introducing VMware Secrets Manager; The Next Step for Aegis!
»» https://www.zerotohero.dev/vmware-secrets-manager/ ««I am thrilled to share an update with all of you. Aegis has transformed and landed into its new home! It is now entering a phase as VMware Secrets Manager for Cloud Native workloads!
#ZeroTrust #security #VMware #SecretsManager #secrets #spiffe #SPIRE
-
🎉 Introducing VMware Secrets Manager; The Next Step for Aegis!
»» https://www.zerotohero.dev/vmware-secrets-manager/ ««I am thrilled to share an update with all of you. Aegis has transformed and landed into its new home! It is now entering a phase as VMware Secrets Manager for Cloud Native workloads!
#ZeroTrust #security #VMware #SecretsManager #secrets #spiffe #SPIRE
-
How to configure mTLS using SPIRE and Envoy » https://www.youtube.com/watch?v=7qANSe9ajbE
-
Hi 👋! only 1hr until our #TalkSPIFFE office hours kick off at 8:30am PT. We'll explore demos, use cases & more on unlocking secure comms with SPIFFE/SPIRE. Join us for an enlightening community chat! 🔐 #SPIFFE #SPIRE #Security #ZeroTrust
Join us at https://twitch.tv/ZeroToHeroDev
-
Hi 👋! only 1hr until our #TalkSPIFFE office hours kick off at 8:30am PT. We'll explore demos, use cases & more on unlocking secure comms with SPIFFE/SPIRE. Join us for an enlightening community chat! 🔐 #SPIFFE #SPIRE #Security #ZeroTrust
Join us at https://twitch.tv/ZeroToHeroDev
-
Thanks helm-charters of SPIFFE — You rock 🤘.