Skip to content

Expand the guidance around what you can use SPIFFE to authenticate to #338

@strideynet

Description

@strideynet

Imho, one of the ways in which we can encourage adoption of SPIFFE is to highlight the platforms/tools that you can use SPIFFE SVIDs to authenticate to, and, provide advice/guidance that may not exist elsewhere to aid people in implementation.

I think there's room for us to:

  1. Add more tools/platforms to "Which Tools Work with SPIFFE?"
  2. For each tool, create a distinct documentation page (e.g "Using SPIFFE with X") where we can link to resources relevant to setting up authentication with SPIFFE, and any high-level established advice (e.g known papercuts with using SPIFFE SVIDs)
  3. For the most popular tools, we can produce more detailed step-by-step guidance.

We may also want to include tools/platforms which technically can integrate with SPIFFE even if the UX is not ideal - we can extend the compatibility grid/introduce a scoring system to help distinguish these. For example - e.g PostgreSQL supports authentication with X509 SVIDs however it cannot read the SPIFFE ID from the URI SAN and has limited authorization controls which makes integration more painful.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions