home.social

#spiffe — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spiffe, aggregated by home.social.

fetched live
  1. Zero Trust для ИИ-агентов: почему отдельной идентичности недостаточно

    Привет, Хабр! Меня зовут Денис Корбаков, я технический директор «Смарт-Софт». Мы разрабатываем NGFW и регулярно разбираем, какие сетевые события можно использовать для независимого контроля автоматизированных систем. Последний год эта задача резко усложнилась. В инфраструктуре массово появился новый операционный тип машинного субъекта: автономный агент, который сам выбирает инструменты, меняет контекст и делегирует полномочия. Zero Trust никогда не ограничивался только людьми. NIST SP 800-207 прямо включает в модель non-person entities: сервисы, приложения, автоматизированное ПО, и обсуждает их ещё с версии 2020 года. Субъект как класс не новый, новыми являются масштаб, автономность и модель поведения. Большинство корпоративных реализаций IAM на практике заточены либо под человека с интерактивной сессией, либо под стабильный сервисный аккаунт, который работает годами с предсказуемым поведением. ИИ-агент находится между этими моделями: не человек, способный самостоятельно оценить допустимый объём своих полномочий, и не полностью статичный сервис с неизменным поведением. Как отмечает исследование Cloud Security Alliance, проведённое при поддержке Aembit , существующие подходы к IAM испытывают нагрузку, на которую изначально не проектировались.

    habr.com/ru/articles/1071750/

    #Zero_Trust #ИИагенты #IAM #машинная_идентичность #workload_identity #prompt_injection #MCP #NIST_SP
    800207 #SPIFFE #NGFW

  2. I could not be more proud of the fact that I got to be part of #KCDNewYork 2026. I learned so much, especially around #Istio Ambient, which builds on top of #SPIFFE, my favorite #CNCF project :)
    But there was so much more.
    Here is a blog I wrote about the day:
    blog.gitguardian.com/kcd-new-y

  3. There's a new article in the #Keycloak blog about federated client authentication, where you rely on an external provider (like a #Kubernetes cluster with service account token, or a generic #SPIFFE client) to authenticate confidential clients. keycloak.org/2026/01/federated

    Would love to take a closer look at that functionality at some point, especially for a use case where you authenticate Keycloak service accounts (to get tokens for M2M calls in a microservice architecture) through that method. Might be really great for getting rid of some secrets that have to be frequently rotated. But currently, I have no time to do this. Has anyone already used this? How well does it work? Worth investigating, or still too flaky?

  4. Last week, I had the privilege of attending #KubeCon 2025
    Seeing #SPIFFE and #SPIRE take a front seat in conversations, driven by #AgenticAI, was mind-blowing.
    Here are a few thoughts and reflections from the event:
    blog.gitguardian.com/kubecon-2

  5. #KubeCon 2025
    Anchoring Trust in the Age of AI: Identities Across Humans, Machines, and Models - Yuan Tang and Anjali Telang

    KServe is a CNCF incubator project

    kserve.github.io/website/

    #SPIFFE #SPIRE #Keycloak

  6. Zero Trust в облаке: практическое руководство

    В этом руководстве рассматривается современный подход к безопасности — Zero Trust Network Access (ZTNA) — и показано, как его реализовать с помощью SPIFFE/SPIRE и OpenID Connect (OIDC). Материала много, по этому я предоставлю его в сухой форме. В основе ZTNA лежит принцип «никогда не доверяй, всегда проверяй»: каждый запрос на доступ считается потенциально небезопасным и проходит обязательную аутентификацию и авторизацию. По сравнению с классическими VPN-сетями решения ZTNA на базе SPIFFE/SPIRE и OIDC: Ускоряют процедуру аутентификации в 20–80 раз, Повышают производительность на 46–64 %, В облаках AWS и Google Cloud позволяют снизить задержки до 50–100 мс вместо привычных 2–4 с.

    habr.com/ru/articles/917440/

    #zerotrust #spiffe #spire #oidc #kubernetes #aws #gcp #ztna #security

  7. Time to get hands-on at #CNSCon
    Tutorial: Demystifying and Enabling Workload Identity Across the Cloud Native Ecosystem - from Andrew Block, Anjali Telang, and Trilok Geer, Red Hat; and Mariusz Sabath and Maia Iyer, IBM

    #Spiffe #Spire

  8. 🚀 Excited to share my overview & and demo on
    “sharing secrets across clusters with SPIFFE federation” ✨

    I presented it at sig-spire on Oct 26, 2023.

    Dive in and explore! 🛠️:
    vimeo.com/v0lkan/vsecm-spire

    #VSecM #SPIFFE #SPIRE #VMware #TechTalk

  9. Novel ways of providing identity to automated cross-#cloud processes – Workload Identity Federation (#workloadidentityfederation) and #SPIFFE
    zuinnote.eu/blog/?p=2273

  10. 🚀 Hey, #ZeroTrust enthusiasts! — We’ve kicked off VMware Secrets Manager v0.22.0, codenamed Boötes!

    🌟 Curious about what awesomeness lies ahead? Our 🔥Updated Yearly Roadmap🔥 has all the details 👉 vsecm.com/docs/roadmap/

    #SPIFFE #SPIRE #VSecM #VMware

    🐢⚡️ #TurtlePower

  11. 🚀 Hey, #ZeroTrust enthusiasts! — We’ve kicked off VMware Secrets Manager v0.22.0, codenamed Boötes!

    🌟 Curious about what awesomeness lies ahead? Our 🔥Updated Yearly Roadmap🔥 has all the details 👉 vsecm.com/docs/roadmap/

    #SPIFFE #SPIRE #VSecM #VMware

    🐢⚡️ #TurtlePower

  12. 🎉 Just wrapped up an electric session on today's #TalkSPIFFE! 🚀 We dove deep into the nitty-gritty of open source, business licensing models, and their ripple effects on the open-source ecosystem (I’m looking at you HashiCorp!). 🌐

    twitch.tv/videos/1913673154

    #ZeroTrust #Security #SPIFFE #SPIRE #VSecM #TalkSPIFFE #VOD #Twitch

  13. 🔐 A Milestone in Zero-Trust Architectures: SPIFFE Takes Center Stage in Google Cloud

    This week marked a pivotal moment in the journey of zero-trust architectures. Google Cloud announced its standardization of SPIFFE as the unified identity platform across all its environments.

    This is not just a technical achievement; it’s’ a paradigm shift in how we approach security in cloud computing.

    linkedin.com/feed/update/urn:l

    #SPIFFE #ZeroTrust #GoogleCloud #CyberSecurity #OpenSource #Leadership

    1/n

  14. NIST said you should use SPIFFE, and you should use it NOW, and Google Cloud is standardizing its workload identity based on SPIFFE.

    I cannot emphasize how HUGE this is!

    check out this clip:youtube.com/clip/UgkxcujMWTzWh

    #SPIFFE #SPIRE #ZeroTrust #security

  15. 🎉 Introducing VMware Secrets Manager; The Next Step for Aegis!
    »» zerotohero.dev/vmware-secrets- ««

    I am thrilled to share an update with all of you. Aegis has transformed and landed into its new home! It is now entering a phase as VMware Secrets Manager for Cloud Native workloads!

    #ZeroTrust #security #VMware #SecretsManager #secrets #spiffe #SPIRE

  16. 🎉 Introducing VMware Secrets Manager; The Next Step for Aegis!
    »» zerotohero.dev/vmware-secrets- ««

    I am thrilled to share an update with all of you. Aegis has transformed and landed into its new home! It is now entering a phase as VMware Secrets Manager for Cloud Native workloads!

    #ZeroTrust #security #VMware #SecretsManager #secrets #spiffe #SPIRE

  17. Hi 👋! only 1hr until our #TalkSPIFFE office hours kick off at 8:30am PT. We'll explore demos, use cases & more on unlocking secure comms with SPIFFE/SPIRE. Join us for an enlightening community chat! 🔐 #SPIFFE #SPIRE #Security #ZeroTrust

    Join us at twitch.tv/ZeroToHeroDev

  18. Hi 👋! only 1hr until our #TalkSPIFFE office hours kick off at 8:30am PT. We'll explore demos, use cases & more on unlocking secure comms with SPIFFE/SPIRE. Join us for an enlightening community chat! 🔐 #SPIFFE #SPIRE #Security #ZeroTrust

    Join us at twitch.tv/ZeroToHeroDev