<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[What's Up In Workload Identity]]></title><description><![CDATA[A periodic newsletter covering what's happening in the world of Workload Identity. Covering broader topics such as movements in the SPIFFE and WIMSE organisations, and the latest exciting releases of software in the space.]]></description><link>https://workloadidentity.news</link><image><url>https://workloadidentity.news/img/substack.png</url><title>What&apos;s Up In Workload Identity</title><link>https://workloadidentity.news</link></image><generator>Substack</generator><lastBuildDate>Wed, 13 May 2026 11:30:04 GMT</lastBuildDate><atom:link href="https://workloadidentity.news/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Noah Stride]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[workloadidentity@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[workloadidentity@substack.com]]></itunes:email><itunes:name><![CDATA[Noah Stride]]></itunes:name></itunes:owner><itunes:author><![CDATA[Noah Stride]]></itunes:author><googleplay:owner><![CDATA[workloadidentity@substack.com]]></googleplay:owner><googleplay:email><![CDATA[workloadidentity@substack.com]]></googleplay:email><googleplay:author><![CDATA[Noah Stride]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[What's Up In Workload Identity - January 2025]]></title><description><![CDATA[SPIFFE? WIMSE? All that and more inside the January edition of What's Up in Workload Identity.]]></description><link>https://workloadidentity.news/p/whats-up-in-workload-identity-january</link><guid isPermaLink="false">https://workloadidentity.news/p/whats-up-in-workload-identity-january</guid><dc:creator><![CDATA[Noah Stride]]></dc:creator><pubDate>Sat, 01 Feb 2025 12:25:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/13Ltu1Zh8FY" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hey!</p><p>Welcome to the fifth edition of <strong>What&#8217;s Up in Workload Identity</strong>, a monthly review of the world of Workload Identity (SPIFFE, WIMSE and much more&#8230;) - returning after a short break for the Christmas period!</p><p>It&#8217;s a world that&#8217;s moving fast - and it&#8217;s hard to keep up &#128640;</p><p>You can expect to see each edition covering:</p><ul><li><p><strong>News: </strong>significant events in the Workload Identity space</p></li><li><p><strong>Content: </strong>awesome blog posts and talks that have been published</p></li><li><p><strong>Releases: </strong>the latest and greatest changes to Workload Identity tooling</p></li><li><p><strong>Coming Up: </strong>the events and talks you won&#8217;t want to miss</p></li></ul><p><em>Who am I?</em> I&#8217;m Noah. I&#8217;ve been working in the Workload Identity space for the past few years. I currently work at Teleport, leading the development of our Workload Identity product. That being said, this newsletter is in a personal capacity and I&#8217;m keen to keep it unbiased! You can find out more about me on <a href="https://noahstride.co.uk">my website</a>.</p><div><hr></div><h2>News</h2><p><em>The latest news from the Workload Identity space</em></p><h3>OWASP announces 2025 Non-Human Identities Top 10</h3><p>Nothing says &#8220;Happy New Year!&#8221; like a brand new Top Ten from the Open Worldwide Application Security Project (OWASP)! In later December, they unveiled the OWASP 2025 Non-Human Identities Top 10 - their first list focussing on the challenges around securely working with Non-Human/workload identities.</p><p>It&#8217;s a fantastic start for 2025 to see an organization as prestigious as OWASP recognising the need for wider education in industry around the risks and challenges posed by Non-Human identities and a significant symbol of interest in NHI becoming commonplace. Clearly we&#8217;re not the only ones worrying about this!</p><p>I&#8217;ll admit - at a brief glance, the list is not all too surprising. I don&#8217;t think anybody here will be shocked that the likes of &#8220;Long-Lived Secrets&#8221;, &#8220;Overprivileged NHI&#8221; or &#8220;Secret Leakage&#8221; have made it on! What also won&#8217;t be a surprise is comparing this list of challenges to the solutions provided by tools like SPIFFE/SPIRE, and seeing that almost all of them are taken care of by taking a more modern workload-identity-esque approach.</p><p>You can check out the full list at: <a href="https://owasp.org/www-project-non-human-identities-top-10/2025/top-10-2025/">https://owasp.org/www-project-non-human-identities-top-10/2025/top-10-2025/</a></p><div><hr></div><h2>Content</h2><p><em>The best of recent blogs, webinars and talks on Workload Identity</em></p><h4>Why It&#8217;s Time to Rethink Machine and Workload Identity: Lessons from User Security</h4><p><em>January 22nd 2025, on the &#8220;unmitigated risk blog&#8221;.</em></p><p><a href="https://unmitigatedrisk.com/?p=934">https://unmitigatedrisk.com/?p=934</a></p><h4>SPIFFE as a Glue for Large Scale Telco Deployments</h4><p><em>By Rahul Jadhav (AccuKnox) at KubeCon India 2024</em></p><div id="youtube2-13Ltu1Zh8FY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;13Ltu1Zh8FY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/13Ltu1Zh8FY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>SPIFFE runs in the cloud, but can it run on my laptop?</h4><p><em>By Mattias Gees (Venafi) at Cloud Native Rejects 2024</em></p><div id="youtube2-ljS9vqgPtQg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ljS9vqgPtQg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ljS9vqgPtQg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Leveraging Micro-Segmentation, SPIFFE-based Identity Networking, and Immutable Infrastructure</h4><p><em>By Kerry Steele (Coalfire Systems)</em></p><div id="youtube2-3XN1IoBX2BI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;3XN1IoBX2BI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/3XN1IoBX2BI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>Releases</h2><p><em>Highlights from recent releases to Workload Identity tools</em></p><h4>SPIRE - 1.11.1 - December 11th</h4><p>This release includes a variety of minor changes and bugfixes.</p><p>Check out the <a href="https://github.com/spiffe/spire/releases/tag/v1.11.1">GitHub Release</a> for the full list of changes!</p><div><hr></div><h2>Coming Up&#8230;</h2><p><em>What&#8217;s happening soon in the world of Workload Identity</em></p><h4>KubeCon EU</h4><p><strong>April 1st to the 4th - London</strong></p><ul><li><p><a href="https://kccnceu2025.sched.com/event/1tx8O/iam-agent-identity-for-autonomous-ai-matthew-bates-cofide?iframe=no&amp;w=100%&amp;sidebar=yes&amp;bg=no">IAM, Agent: Identity for Autonomous AI - Matthew Bates, Cofide</a></p></li><li><p><a href="https://kccnceu2025.sched.com/event/1tx8U/spiffe-in-practice-universal-identity-for-webassembly-workloads-joonas-bergius-cosmonic-colin-murphy-adobe?iframe=no&amp;w=100%&amp;sidebar=yes&amp;bg=no">&#8203;&#8203;SPIFFE in Practice: Universal Identity for WebAssembly Workloads - Joonas Bergius, Cosmonic &amp; Colin Murphy, Adobe</a></p></li><li><p><a href="https://kccnceu2025.sched.com/event/1td1H/beyond-classical-cryptography-building-quantum-resistant-cloud-native-infrastructure-with-spiffe-andres-vega-m42-hugo-landau-messier42?iframe=no&amp;w=100%&amp;sidebar=yes&amp;bg=no">Beyond Classical Cryptography: Building Quantum-Resistant Cloud Native Infrastructure With SPIFFE - Andr&#233;s Vega, M42 &amp; Hugo Landau, Messier42</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/">https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/</a></p><div><hr></div><p>That&#8217;s all for this month&#8217;s edition of What&#8217;s Up in Workload Identity. If you&#8217;ve found this interesting, please subscribe and share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/p/whats-up-in-workload-identity-january?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/p/whats-up-in-workload-identity-january?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/subscribe?"><span>Subscribe now</span></a></p><p>Got something you&#8217;d love to see in the next edition? I&#8217;m particularly keen to start including some short editorial pieces within WUIWI. Please get in touch at wuiwi@noahstride.co.uk</p>]]></content:encoded></item><item><title><![CDATA[What's Up In Workload Identity - November 2024]]></title><description><![CDATA[SPIFFE? WIMSE? All that and more inside the November edition of What's Up in Workload Identity.]]></description><link>https://workloadidentity.news/p/whats-up-in-workload-identity-november</link><guid isPermaLink="false">https://workloadidentity.news/p/whats-up-in-workload-identity-november</guid><dc:creator><![CDATA[Noah Stride]]></dc:creator><pubDate>Thu, 28 Nov 2024 10:13:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c6f0c61-cb88-40ec-8e7d-0627128f8caf_144x144.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hey!</p><p>Welcome to the fourth edition of <strong>What&#8217;s Up in Workload Identity</strong>, a monthly review of the world of Workload Identity (SPIFFE, WIMSE and much more&#8230;)</p><p>It&#8217;s a world that&#8217;s moving fast - and it&#8217;s hard to keep up &#128640;</p><p>You can expect to see each edition covering:</p><ul><li><p><strong>News: </strong>significant events in the Workload Identity space</p></li><li><p><strong>Content: </strong>awesome blog posts and talks that have been published</p></li><li><p><strong>Releases: </strong>the latest and greatest changes to Workload Identity tooling</p></li><li><p><strong>Coming Up: </strong>the events and talks you won&#8217;t want to miss</p></li></ul><p><em>Who am I?</em> I&#8217;m Noah. I&#8217;ve been working in the Workload Identity space for the past few years. I currently work at Teleport, leading the development of our Workload Identity product. That being said, this newsletter is in a personal capacity and I&#8217;m keen to keep it unbiased! You can find out more about me on <a href="https://noahstride.co.uk">my website</a>.</p><div><hr></div><h2>News</h2><p><em>The latest news from the Workload Identity space</em></p><h3>SPIKE: A Rather <s>SPIFFY</s> SPIFFE Secrets Store</h3><p>Christmas is, <em>the last time I checked</em>, not in November but this month we awoke to rather exciting new project in the workload identity world: SPIKE - Secure Production Identity for Key Encryption.</p><p>SPIKE is a SPIFFE-native take on the world of secrets management. In practice, what this means, is that it safely stores secrets and allows workloads to request access to them using their SPIFFE-compatible credentials as a form of authentication.</p><p>Now, you might be thinking: <em>&#8220;Noah, I could&#8217;ve sworn that you have proclaimed that shared secrets are the devil&#8217;s play-thing - surely a secrets manager is the last thing you&#8217;d be singing the praises of!&#8221;</em> and you&#8217;d be partially right!</p><p>I do think that our end goal, as an ecosystem and community, should be to eliminate the use of long-lived shared secrets. But, the truth is that the complete elimination of these secrets is going to purely aspirational for most organizations, at least if we&#8217;re thinking about the next five to ten years.</p><p>When setting up workload identity in an organization, there&#8217;s a bunch of low hanging fruit - easy opportunities to replace long-lived secrets with X509 or JWT SVIDs. This might be authentication to cloud providers APIs that support workload identity federation (GCP, Azure or AWS) or authentication between services that you control internally.</p><p>There&#8217;s always going to be secrets that are harder to shift, such as those used to authenticate to legacy systems or to third-party APIs that haven&#8217;t quite caught up with the latest and greatest. This is where SPIKE fits in neatly!</p><p>But why SPIKE? and not some existing secrets manager? SPIKE represents a fantastic opportunity to treat your workload identities as first-class citizens, and to enjoy the user experience that will come from a solution that&#8217;s intentionally designed to interface with SPIFFE IDs and SVIDs. It&#8217;s true that you can configure tools like Vault to accept SVIDs as authentication, but, let&#8217;s be honest, do you <em>really</em> want to do that?</p><p>Now, like any recently released project, this probably isn&#8217;t quite ready to be rolled out into production environments yet - but it&#8217;s off to a promising start and over the past few weeks we&#8217;ve seen a slew of new features added. It&#8217;ll definitely be one to keep an eye on, and I highly recommend giving it a try to get a taste of what the future of secrets management looks like!</p><p>Check out the introductory video from the great mind behind SPIKE, Volkan &#214;z&#231;elik:</p><div id="youtube2-zDl9ZaxV7io" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;zDl9ZaxV7io&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/zDl9ZaxV7io?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>To learn more, check out SPIKE&#8217;s website:<a href="https://spike.ist/#/"> https://spike.ist</a></p><div><hr></div><h2>Content</h2><p><em>The best of recent blogs, webinars and talks on Workload Identity</em></p><h4>From Years to Seconds: Rethinking Public Key Infrastructure</h4><p><em>November 27th 2024, on the &#8220;unmitigated risk blog&#8221;.</em></p><p><a href="https://unmitigatedrisk.com/?p=904">https://unmitigatedrisk.com/?p=904</a></p><h4>SPIFFE Deployments in Non-Kubernetes Environments</h4><p><em>By Nadin El-Yabroudi &amp; Eli Nesterov (SPIRL) at KubeCon 2024</em></p><div id="youtube2-sflwuM_baG4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;sflwuM_baG4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/sflwuM_baG4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>SPIFFE the Easy Way: Universal X509 and JWT Identities Using cert-manager</h4><p><em>By Tim Ramlot &amp; Ashley Davis (Venafi) at KubeCon 2024</em></p><div id="youtube2-De2o-urGpQk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;De2o-urGpQk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/De2o-urGpQk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Workload Identity Federation &#8211; Stop Using Long-Lived Credentials</h4><p><em>By Benjamin Dronen (Ford Motor Company) &amp; Anjali Telang (Red Hat)  at KubeCon 2024</em></p><div id="youtube2-qqayHSkiNXU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;qqayHSkiNXU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/qqayHSkiNXU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>Releases</h2><p><em>Highlights from recent releases to Workload Identity tools</em></p><h4>SPIFFE-Helper - 0.9.0 - November 21st</h4><p>This release includes a variety of changes.</p><p>Notably, use of the SPIRE_AGENT_ADDRESS environment variable has been deprecated in favour of SPIFFE_ENDPOINT_SOCKET. This brings it a little more inline with other tools within the community.</p><p>You can also now specify an external process, via a pid file, which should be sent a signal when spiffe-helper has rotated the artefacts that are written to disk. This&#8217;ll be great for legacy services that may not support automatically reloading credentials loaded from disk.</p><p>Check out the <a href="https://github.com/spiffe/spiffe-helper/releases/tag/v0.9.0">GitHub Release</a> for the full list of changes!</p><div><hr></div><h2>Coming Up&#8230;</h2><p><em>What&#8217;s happening soon in the world of Workload Identity</em></p><h4>KubeCon India</h4><p><strong>December 11th to the 12th - Delhi</strong></p><ul><li><p><a href="https://kccncind2024.sched.com/event/1mVT1/spiffe-as-a-glue-for-large-scale-telco-deployments-a-nephio-perspective-rahul-jadhav-accuknox">SPIFFE as a Glue for Large Scale Telco Deployments: A Nephio Perspective - Rahul Jadhav (AccuKnox)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-india/">https://events.linuxfoundation.org/kubecon-cloudnativecon-india/</a></p><div><hr></div><p>That&#8217;s all for this month&#8217;s edition of What&#8217;s Up in Workload Identity. If you&#8217;ve found this interesting, please subscribe and share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/p/whats-up-in-workload-identity-november?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/p/whats-up-in-workload-identity-november?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/subscribe?"><span>Subscribe now</span></a></p><p>Got something you&#8217;d love to see in the next edition? I&#8217;m particularly keen to start including some short editorial pieces within WUIWI. Please get in touch at wuiwi@noahstride.co.uk</p>]]></content:encoded></item><item><title><![CDATA[What's Up In Workload Identity - October 2024]]></title><description><![CDATA[SPIFFE? WIMSE? All that and more inside the October edition of What's Up in Workload Identity.]]></description><link>https://workloadidentity.news/p/whats-up-in-workload-identity-october</link><guid isPermaLink="false">https://workloadidentity.news/p/whats-up-in-workload-identity-october</guid><dc:creator><![CDATA[Noah Stride]]></dc:creator><pubDate>Mon, 28 Oct 2024 18:11:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c6f0c61-cb88-40ec-8e7d-0627128f8caf_144x144.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hey!</p><p>Welcome to the third edition of <strong>What&#8217;s Up in Workload Identity</strong>, a monthly review of the world of Workload Identity (SPIFFE, WIMSE and much more&#8230;)</p><p>It&#8217;s a world that&#8217;s moving fast - and it&#8217;s hard to keep up &#128640;</p><p>You can expect to see each edition covering:</p><ul><li><p><strong>News: </strong>significant events in the Workload Identity space</p></li><li><p><strong>Content: </strong>awesome blog posts and talks that have been published</p></li><li><p><strong>Releases: </strong>the latest and greatest changes to Workload Identity tooling</p></li><li><p><strong>Coming Up: </strong>the events and talks you won&#8217;t want to miss</p></li></ul><p><em>Who am I?</em> I&#8217;m Noah. I&#8217;ve been working in the Workload Identity space for the past few years. I currently work at Teleport, leading the development of our Workload Identity product. That being said, this newsletter is in a personal capacity and I&#8217;m keen to keep it unbiased! You can find out more about me on <a href="https://noahstride.co.uk">my website</a>.</p><div><hr></div><h2>News</h2><p><em>The latest news from the Workload Identity space</em></p><h3>Latest updates on WIMSE drafts</h3><p>Ahead of the IETF 121 meeting in Dublin next week, the WIMSE WG have published new versions of two of their existing internet drafts.</p><p>The <em>Workload Identity in a Multi System Environment (WIMSE) Architecture</em> draft has entered its third (or if you, like the IETF, prefer to count from zero - 02nd) iteration. This document focusses on Workload Identity at a higher level, setting out various fundamental terminology and concepts.</p><p>The latest iteration brings significantly more clarity to several key concepts, such as that of trust domains and workload identifiers. If you&#8217;re familiar with the space, you won&#8217;t be surprised to see the definitions largely encompassing and being compatible with the definitions made by SPIFFE, with the WIMSE draft directly calling out SPIFFE IDs as an example of a compatible workload identifier.</p><p>It&#8217;s also encouraging to see the Workload Identity Token (WIT), which was first introduced in the <em>Service to Service Authentication</em> draft, being deemed notable enough to be mentioned and referred to within the <em>Architecture</em> draft.</p><p>Speaking of <em>Service to Service Authentication</em>, this draft has also received a round of changes as part of a second (uh, 01st) iteration. This document focusses more specifically on techniques and protocols for authenticating workload identity within the context of service to service communication.</p><p>Amongst the changes to this draft is the addition of a new claim to the proposed Workload Proof Token (WPT). The WPT is created by a workload as part of service to service authentication flows to prove its possession of a key pair that is contained within the Workload Identity Token (WIT) that contains claims that describe the workload&#8217;s identity. The new claim, &#8220;wth&#8221;, will contain a SHA256 hash of a WIT that the WPT has been produced for. This creates a more specific binding between the two, particularly in cases where the WIT may have been extended with additional attributes of the workload identity.</p><p>The draft now also includes a temporary comparison as part of the ongoing discussion on which authentication flow become the draft&#8217;s recommendation. Today, the draft describes two options: a flow based on OAuth DPoP using the WPT and a flow based on RFC9421 HTTP message signatures. If you&#8217;re using HTTP for service to service communication, it&#8217;s definitely worth diving into this discussion, there&#8217;s some really interesting trade-offs between the two options. I&#8217;m looking forward to reading up on this discussion as the working group tries to reach consensus.</p><p>You can check out the changes included in the latest revisions over on the IETF Datatracker:</p><ul><li><p><em><a href="https://author-tools.ietf.org/iddiff?url2=draft-ietf-wimse-s2s-protocol-01">WIMSE Service to Service Authentication</a></em></p></li><li><p><em><a href="https://author-tools.ietf.org/iddiff?url2=draft-ietf-wimse-arch-02">Workload Identity in a Multi System Environment (WIMSE) Architecture</a></em></p></li></ul><div><hr></div><h2>Content</h2><p><em>The best of recent blogs, webinars and talks on Workload Identity</em></p><h4>Fortifying gRPC Microservices: Beyond JWT with mTLS and SPIFFE</h4><p><em>By Mehrdad Afshari (Signeen, Inc.) at gRPConf 2024</em></p><div id="youtube2-qFSHoxs8i2Q" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;qFSHoxs8i2Q&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/qFSHoxs8i2Q?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Federating Secrets Across Clusters Using SPIFFE, SPIRE, and VMware Secrets Manager </h4><p><em>By Volkan &#214;z&#231;elik</em></p><div id="youtube2-cD2ZdDgw8PY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;cD2ZdDgw8PY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/cD2ZdDgw8PY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>CNL: Secure workload identities with SPIFFE, cert-manager, trust-manager</h4><p><em>By Mattias Gees (Venafi) on CNCF&#8217;s Cloud Native Live</em></p><div id="youtube2-UnuWkvcug4k" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;UnuWkvcug4k&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/UnuWkvcug4k?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>Releases</h2><p><em>Highlights from recent releases to Workload Identity tools</em></p><h4>SPIRE - 1.11.0 - October 24th</h4><p>Introduces the &#8220;forced rotation and revocation&#8221; functionality which allows administrators to manually rotate certificate authorities and JWT key pairs within SPIRE. It&#8217;s well worth learning more about this functionality if you&#8217;re operating SPIRE in production and need to prepare for how to respond to exfiltration of CA private key material.</p><p>This release also includes a number of bug fixes and optimisations.</p><p><a href="https://github.com/spiffe/spire/releases/tag/v1.11.0">GitHub Release</a></p><h4>VMWare Secrets Manager - 0.28.0 - October 16th</h4><p>Introduced an interesting proof of concept feature to support sharing secrets between clusters, and, support for PostgreSQL as a backing store.</p><p><a href="https://github.com/vmware-tanzu/secrets-manager/discussions/1199">GitHub Discussion</a></p><h4>Teleport Workload Identity - 16.4.3 - October 16th</h4><p>Introduced support for issuing JWT-SVIDs to workloads. This includes compatibility with OIDC for OIDC-based federation and authentication to third-party APIs such as cloud providers.</p><p><a href="https://github.com/gravitational/teleport/releases/tag/v16.4.3">GitHub Release</a></p><div><hr></div><h2>Coming Up&#8230;</h2><p><em>What&#8217;s happening soon in the world of Workload Identity</em></p><h4>KubeCon North America</h4><p><strong>November 12th to the 15th - Salt Lake City, Utah</strong></p><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7n0/poster-session-whats-happening-with-spiffe-and-wimse-daniel-feldman-qusaic">Poster Session: What's Happening with SPIFFE and WIMSE? - Daniel Feldman (Quasic)</a></p></li></ul><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7rz/spiffe-the-easy-way-universal-x509-and-jwt-identities-using-cert-manager-tim-ramlot-ashley-davis-venafi">SPIFFE the Easy Way: Universal X509 and JWT Identities Using Cert-Manager - Tim Ramlot &amp; Ashley Davis (Venafi)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7rW/spiffe-deployments-in-non-kubernetes-environments-nadin-el-yabroudi-eli-nesterov-spirl">SPIFFE Deployments in Non-Kubernetes Environments - Nadin El-Yabroudi &amp; Eli Nesterov (SPIRL)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7s8/workload-identity-federation-stop-using-long-lived-credentials-benjamin-dronen-ford-motor-company-kristen-newcomer-red-hat">Workload Identity Federation &#8211; Stop Using Long-Lived Credentials - Benjamin Dronen (Ford Motor Company) &amp; Kristen Newcomer (Red Hat)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1howH/spire-intro-in-depth-exploration-of-the-upcoming-forced-rotation-and-revocation-feature-agustin-martinez-fayo-marcos-yacob-hewlett-packard-enterprise">SPIRE: Intro &amp; In-Depth Exploration of the Upcoming Forced Rotation and Revocation Feature - Agust&#237;n Mart&#237;nez Fay&#243; &amp; Marcos Yacob (Hewlett Packard Enterprise)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/">https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/</a></p><p>You also won&#8217;t want to miss the &#8220;Workload Identity Day 0&#8221; event being hosted by Venafi at their HQ. The schedule is jam-packed with talks on SPIFFE, SPIRE and the workload identity space as a whole. You can find out more about that at <a href="https://venafi.com/events/workload-identity-day-zero/">https://venafi.com/events/workload-identity-day-zero/</a></p><h4>KubeCon India</h4><p><strong>December 11th to the 12th - Delhi</strong></p><ul><li><p><a href="https://kccncind2024.sched.com/event/1mVT1/spiffe-as-a-glue-for-large-scale-telco-deployments-a-nephio-perspective-rahul-jadhav-accuknox">SPIFFE as a Glue for Large Scale Telco Deployments: A Nephio Perspective - Rahul Jadhav (AccuKnox)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-india/">https://events.linuxfoundation.org/kubecon-cloudnativecon-india/</a></p><div><hr></div><p>That&#8217;s all for this month&#8217;s edition of What&#8217;s Up in Workload Identity. If you&#8217;ve found this interesting, please subscribe and share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/p/whats-up-in-workload-identity-october?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/p/whats-up-in-workload-identity-october?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/subscribe?"><span>Subscribe now</span></a></p><p>Got something you&#8217;d love to see in the next edition? I&#8217;m particularly keen to start including some short editorial pieces within WUIWI. Please get in touch at wuiwi@noahstride.co.uk</p>]]></content:encoded></item><item><title><![CDATA[What's Up In Workload Identity - September 2024]]></title><description><![CDATA[SPIFFE? WIMSE? All that and more inside the September edition of What's Up in Workload Identity.]]></description><link>https://workloadidentity.news/p/whats-up-in-workload-identity-september</link><guid isPermaLink="false">https://workloadidentity.news/p/whats-up-in-workload-identity-september</guid><dc:creator><![CDATA[Noah Stride]]></dc:creator><pubDate>Wed, 11 Sep 2024 11:33:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c6f0c61-cb88-40ec-8e7d-0627128f8caf_144x144.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hey!</p><p>Welcome to the second edition of <strong>What&#8217;s Up in Workload Identity</strong>, a monthly review of the world of Workload Identity (SPIFFE, WIMSE and much more&#8230;)</p><p>It&#8217;s a world that&#8217;s moving fast - and it&#8217;s hard to keep up &#128640;</p><p>You can expect to see each edition covering:</p><ul><li><p><strong>News: </strong>significant events in the Workload Identity space</p></li><li><p><strong>Content: </strong>awesome blog posts and talks that have been published</p></li><li><p><strong>Releases: </strong>the latest and greatest changes to Workload Identity tooling</p></li><li><p><strong>Coming Up: </strong>the events and talks you won&#8217;t want to miss</p></li></ul><p><em>Who am I?</em> I&#8217;m Noah. I&#8217;ve been working in the Workload Identity space for the past few years. I currently work at Teleport, leading the development of our Workload Identity product. That being said, this newsletter is in a personal capacity and I&#8217;m keen to keep it unbiased! You can find out more about me on <a href="https://noahstride.co.uk">my website</a>.</p><div><hr></div><h2>News</h2><p><em>The latest news from the Workload Identity space</em></p><h3>KubeCon NA 2024 Schedule Announced</h3><p>The schedule for KubeCon North America 2024 has dropped and it&#8217;s exciting to see so many talks on the topic of Workload Identity and SPIFFE. There&#8217;s a good range of content, some at a more introductory level and some diving deep into the inner mechanics of Workload Identity. </p><p>Some of the highlights from the schedule:</p><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7n0/poster-session-whats-happening-with-spiffe-and-wimse-daniel-feldman-qusaic">Poster Session: What's Happening with SPIFFE and WIMSE? - Daniel Feldman (Quasic)</a></p></li></ul><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7rz/spiffe-the-easy-way-universal-x509-and-jwt-identities-using-cert-manager-tim-ramlot-ashley-davis-venafi">SPIFFE the Easy Way: Universal X509 and JWT Identities Using Cert-Manager - Tim Ramlot &amp; Ashley Davis (Venafi)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7rW/spiffe-deployments-in-non-kubernetes-environments-nadin-el-yabroudi-eli-nesterov-spirl">SPIFFE Deployments in Non-Kubernetes Environments - Nadin El-Yabroudi &amp; Eli Nesterov (SPIRL)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7s8/workload-identity-federation-stop-using-long-lived-credentials-benjamin-dronen-ford-motor-company-kristen-newcomer-red-hat">Workload Identity Federation &#8211; Stop Using Long-Lived Credentials - Benjamin Dronen (Ford Motor Company) &amp; Kristen Newcomer (Red Hat)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1howH/spire-intro-in-depth-exploration-of-the-upcoming-forced-rotation-and-revocation-feature-agustin-martinez-fayo-marcos-yacob-hewlett-packard-enterprise">SPIRE: Intro &amp; In-Depth Exploration of the Upcoming Forced Rotation and Revocation Feature - Agust&#237;n Mart&#237;nez Fay&#243; &amp; Marcos Yacob (Hewlett Packard Enterprise)</a></p></li></ul><p>If you can&#8217;t make it to KubeCon NA 2024, rest assured, talks are usually recorded and uploaded in the months following the event.</p><div><hr></div><h2>Content</h2><p><em>The best of recent blogs, webinars and talks on Workload Identity</em></p><h4>From keyless to careless: Abusing misconfigured OIDC authentication in cloud environments</h4><p><em>By Christophe Tafani-Dereeper at BSidesLV</em></p><div id="youtube2-x4PcmQKS0Ao" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;x4PcmQKS0Ao&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/x4PcmQKS0Ao?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Long Live Short Lived Credentials - Auto-rotating Secrets At Scale</h4><p><em>By Dwayne McDaniel at BSidesLV</em></p><div id="youtube2-egrGs9qPZPE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;egrGs9qPZPE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/egrGs9qPZPE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Zero-Trust mTLS Automation With HAProxy and SPIFFE/SPIRE</h4><p><em>By Jakub Suchy (HAProxy Technologies)<br></em><a href="https://www.haproxy.com/blog/zero-trust-mtls-automation-with-haproxy-and-spiffe-spire">https://www.haproxy.com/blog/zero-trust-mtls-automation-with-haproxy-and-spiffe-spire</a></p><h4>Getting Started With SPIFFE For Multi-Cloud Secure Workload Authentication</h4><p><em>By Mattias Gees (Venafi)<br></em><a href="https://blog.gitguardian.com/getting-started-with-spiffe/">https://blog.gitguardian.com/getting-started-with-spiffe/</a></p><div><hr></div><h2>Releases</h2><p><em>Highlights from recent releases to Workload Identity tools</em></p><h4>SPIRE - 1.10.2 - September 3rd</h4><p>SPIRE&#8217;s had two releases in the past month, 1.10.2 and 1.10.3. Whilst 1.10.3 was a bugfix release, 1.10.2 contains a handful of new features.</p><p>The introduction of a HTTP challenge based node attestor will be particularly interesting to those running SPIRE in an on-premise environment. It&#8217;s a great alternative to the existing limited options for node attestation in these kinds of environments, especially if you don&#8217;t have pre-existing PKI.</p><p>The release also includes improvements to the experimental SigStore support. This functionality is super exciting to me, allowing you to restrict the issuance of SVIDs to container workloads that are running a container image with a valid signature and attestations. If you&#8217;re looking to shore up your supply chain security, then you won&#8217;t regret looking into container image signing.</p><p><a href="https://github.com/spiffe/spire/releases/tag/v1.10.2">GitHub Release</a></p><div><hr></div><h2>Coming Up&#8230;</h2><p><em>What&#8217;s happening soon in the world of Workload Identity</em></p><h4>Open Source Summit Europe</h4><p><strong>September 16th to 18th - Vienna</strong></p><ul><li><p><a href="https://osseu2024.sched.com/event/1ej7U/securing-workloads-with-transaction-tokens-and-minicloak-dmitry-telegin-backbase?iframe=no">Securing Workloads with Transaction Tokens and Minicloak - Dmitry Telegin (Backbase)</a></p></li><li><p><a href="https://osseu2024.sched.com/event/1ej2Y/let-them-eat-cakes-a-sweet-dive-into-a-modern-cloud-networking-stack-christian-posta-soloio?iframe=no&amp;w=&amp;sidebar=yes&amp;bg=no">Let Them Eat CAKES: A Sweet Dive Into a Modern Cloud Networking Stack. - Christian Posta (Solo.io)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/open-source-summit-europe/">https://events.linuxfoundation.org/open-source-summit-europe/</a></p><h4><strong>Teleport Connect 2024</strong></h4><p><strong>September 25th  - San Francisco</strong></p><ul><li><p><a href="https://goteleport.com/teleport-connect-2024/">Securing Modern Infrastructure with Teleport Workload Identity - Noah Stride and Dave Sudia (Teleport)</a></p></li></ul><p>Find out more at <a href="https://goteleport.com/teleport-connect-2024/">https://goteleport.com/teleport-connect-2024/</a></p><h4>KubeCon North America</h4><p><strong>November 12th to the 15th - Salt Lake City, Utah</strong></p><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7n0/poster-session-whats-happening-with-spiffe-and-wimse-daniel-feldman-qusaic">Poster Session: What's Happening with SPIFFE and WIMSE? - Daniel Feldman (Quasic)</a></p></li></ul><ul><li><p><a href="https://kccncna2024.sched.com/event/1i7rz/spiffe-the-easy-way-universal-x509-and-jwt-identities-using-cert-manager-tim-ramlot-ashley-davis-venafi">SPIFFE the Easy Way: Universal X509 and JWT Identities Using Cert-Manager - Tim Ramlot &amp; Ashley Davis (Venafi)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7rW/spiffe-deployments-in-non-kubernetes-environments-nadin-el-yabroudi-eli-nesterov-spirl">SPIFFE Deployments in Non-Kubernetes Environments - Nadin El-Yabroudi &amp; Eli Nesterov (SPIRL)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1i7s8/workload-identity-federation-stop-using-long-lived-credentials-benjamin-dronen-ford-motor-company-kristen-newcomer-red-hat">Workload Identity Federation &#8211; Stop Using Long-Lived Credentials - Benjamin Dronen (Ford Motor Company) &amp; Kristen Newcomer (Red Hat)</a></p></li><li><p><a href="https://kccncna2024.sched.com/event/1howH/spire-intro-in-depth-exploration-of-the-upcoming-forced-rotation-and-revocation-feature-agustin-martinez-fayo-marcos-yacob-hewlett-packard-enterprise">SPIRE: Intro &amp; In-Depth Exploration of the Upcoming Forced Rotation and Revocation Feature - Agust&#237;n Mart&#237;nez Fay&#243; &amp; Marcos Yacob (Hewlett Packard Enterprise)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/">https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/</a></p><div><hr></div><p>That&#8217;s all for this month&#8217;s edition of What&#8217;s Up in Workload Identity. If you&#8217;ve found this interesting, please subscribe and share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/p/whats-up-in-workload-identity-september?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/p/whats-up-in-workload-identity-september?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/subscribe?"><span>Subscribe now</span></a></p><p>Got something you&#8217;d love to see in the next edition? I&#8217;m particularly keen to start including some short editorial pieces within WUIWI. Please get in touch at wuiwi@noahstride.co.uk</p>]]></content:encoded></item><item><title><![CDATA[What's Up In Workload Identity - August 2024]]></title><description><![CDATA[SPIFFE? WIMSE? All that and more inside the first edition of What's Up in Workload Identity.]]></description><link>https://workloadidentity.news/p/whats-up-in-workload-identity-august</link><guid isPermaLink="false">https://workloadidentity.news/p/whats-up-in-workload-identity-august</guid><dc:creator><![CDATA[Noah Stride]]></dc:creator><pubDate>Tue, 13 Aug 2024 14:39:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a88bb8-fef0-42ed-a30a-3ce090ffaf13_144x144.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hey!</p><p>Welcome to the inaugural edition of <strong>What&#8217;s Up in Workload Identity</strong>, a monthly review of the world of Workload Identity (SPIFFE, WIMSE and much more&#8230;)</p><p>It&#8217;s a world that&#8217;s moving fast - and it&#8217;s hard to keep up &#128640;</p><p>You can expect to see each edition covering:</p><ul><li><p><strong>News: </strong>significant events in the Workload Identity space</p></li><li><p><strong>Content: </strong>awesome blog posts and talks that have been published</p></li><li><p><strong>Releases: </strong>the latest and greatest changes to Workload Identity tooling</p></li><li><p><strong>Coming Up: </strong>the events and talks you won&#8217;t want to miss</p></li></ul><p><em>Who am I?</em> I&#8217;m Noah. I&#8217;ve been working in the Workload Identity space for the past few years. I currently work at Teleport, leading the development of our Workload Identity product. That being said, this newsletter is in a personal capacity and I&#8217;m keen to keep it unbiased! You can find out more about me on <a href="https://noahstride.co.uk">my website</a>.</p><div><hr></div><h2>News</h2><p><em>The latest news from the Workload Identity space</em></p><h4>WIMSE adopts Service to Service Authentication draft</h4><p>On the 13th of August, the IETF Workload Identity in Multi System Environments (WIMSE) working group formally adopted the <a href="https://datatracker.ietf.org/doc/draft-sheffer-wimse-s2s-protocol/">Service to Service Authentication draft</a> following a vote. This is the third draft to have been adopted by the working group since they were established in March of this year.</p><p>The Service to Service Authentication draft is a &#8220;standards track&#8221; document and defines strategies for authentication and authorization between two services. Whilst the draft primarily focusses on authentication and authorization regarding HTTP services, there&#8217;s no reason why these same techniques couldn&#8217;t be applied to the other protocols we know and love (e.g gRPC).</p><p>The draft covers a range of topics, but the most interesting to me is the introduction of the Workload Identity Token (WIT) and Workload Proof Token (WPT). Together, these support an authentication flow similar to OAuth&#8217;s &#8220;Demonstrating Proof of Possession (dPoP)&#8221;. The flow mitigates many of the concerns traditionally associated with using JWTs for authentication, such as replay attacks, without significantly sacrificing performance or flexibility. This provides a strong alternative to mTLS for client authentication - which despite being popular, simply isn&#8217;t feasible in every scenario.</p><p>You can read the draft in full over on the IETF website: <a href="https://datatracker.ietf.org/doc/draft-sheffer-wimse-s2s-protocol/">https://datatracker.ietf.org/doc/draft-sheffer-wimse-s2s-protocol/</a></p><p>Although the document is still in its infancy, and with formalisation as an RFC far on the horizon, it&#8217;s a fantastic sign of the things to come. WIMSE is also working on several other drafts, including setting out an overall architecture for Workload Identity and establishing procedures for Token Translation. Overall, I think we can expect to see their work covered in many of the coming editions of this newsletter.</p><div><hr></div><h2>Content</h2><p><em>The best of recent blogs, webinars and talks on Workload Identity</em></p><h4>Everyone&#8217;s Starting to Look SPIFFE: MTLS and Identity with Linkerd &amp; Teleport</h4><p><em>By Dave Sudia (Teleport) at CloudNativeSecurityCon</em></p><div id="youtube2-8PT7wC9yuCo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;8PT7wC9yuCo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/8PT7wC9yuCo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Solving &#8216;secret zero&#8217;, why you should care about SPIFFE!</h4><p><em>By Mattias Gees (Venafi) at South California Linux Expo</em></p><div id="youtube2-KzYr9vjT_H0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;KzYr9vjT_H0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/KzYr9vjT_H0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Bringing SPIFFE to Linkerd for Mesh Expansion</h4><p><em>By Zahari Dichev (Buoyant) at CloudNativeCon</em></p><div id="youtube2-ZLCJW--J6s0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ZLCJW--J6s0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ZLCJW--J6s0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4>Memory Armor for SPIRE: Fortifying SPIRE with Confidential Containers (CoCo)</h4><p><em>By Matthew Bates (Cofide) and Suraj Deshmukh (Microsoft) at CloudNativeCon</em></p><div id="youtube2-g0uBBGvf9w4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;g0uBBGvf9w4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/g0uBBGvf9w4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>Releases</h2><p><em>Highlights from recent releases to Workload Identity tools</em></p><blockquote><p>I&#8217;d love to cover more releases here! So, if you work on something in this space, please get in contact!</p></blockquote><h4><strong>Teleport Workload Identity - v16.1.3 - August 7th</strong></h4><p>Introduced support for Kubernetes Workload Attestation. This allowing the Workload Identity agent to issue SVIDs with specific SPIFFE IDs to specific Kubernetes workloads.<br><br><a href="https://github.com/gravitational/teleport/releases/tag/v16.1.3">GitHub Release</a></p><h4><strong>SPIRE - v1.10.1 - August 1st</strong></h4><p>Includes a number of bug fixes and support for publishing trust bundles directly to AWS Roles Anywhere as a trust anchor.<br><br><a href="https://github.com/spiffe/spire/releases/tag/v1.10.1">GitHub Release</a></p><div><hr></div><h2>Coming Up&#8230;</h2><p><em>What&#8217;s happening soon in the world of Workload Identity</em></p><h4>Open Source Summit Europe</h4><p><strong>September 16th to 18th - Vienna</strong></p><ul><li><p><a href="https://osseu2024.sched.com/event/1ej7U/securing-workloads-with-transaction-tokens-and-minicloak-dmitry-telegin-backbase?iframe=no">Securing Workloads with Transaction Tokens and Minicloak - Dmitry Telegin (Backbase)</a></p></li><li><p><a href="https://osseu2024.sched.com/event/1ej2Y/let-them-eat-cakes-a-sweet-dive-into-a-modern-cloud-networking-stack-christian-posta-soloio?iframe=no&amp;w=&amp;sidebar=yes&amp;bg=no">Let Them Eat CAKES: A Sweet Dive Into a Modern Cloud Networking Stack. - Christian Posta (Solo.io)</a></p></li></ul><p>Find out more at <a href="https://events.linuxfoundation.org/open-source-summit-europe/">https://events.linuxfoundation.org/open-source-summit-europe/</a></p><h4><strong>Teleport Connect 2024 in San Francisco</strong></h4><p><strong>September 25th  - San Francisco</strong></p><ul><li><p><a href="https://goteleport.com/teleport-connect-2024/">Securing Modern Infrastructure with Teleport Workload Identity - Noah Stride and Dave Sudia (Teleport)</a></p></li></ul><p>Find out more at <a href="https://goteleport.com/teleport-connect-2024/">https://goteleport.com/teleport-connect-2024/</a></p><div><hr></div><p>That&#8217;s all for this month&#8217;s edition of What&#8217;s Up in Workload Identity. If you&#8217;ve found this interesting, please subscribe and share!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/p/whats-up-in-workload-identity-august?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/p/whats-up-in-workload-identity-august?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://workloadidentity.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://workloadidentity.news/subscribe?"><span>Subscribe now</span></a></p><p>Got something you&#8217;d love to see in the next edition? Please get in touch at wuiwi@noahstride.co.uk !</p>]]></content:encoded></item></channel></rss>