VOOZH about

URL: https://thenewstack.io/spiffe-spire-brings-federated-identity-to-distributed-architectures/

⇱ SPIFFE/SPIRE Brings Federated Identity to Distributed Architectures - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2019-11-19 08:00:18
SPIFFE/SPIRE Brings Federated Identity to Distributed Architectures
news,sponsor-portworx,sponsored,sponsored-event-coverage,
Cloud Native Ecosystem / Microservices / Security

SPIFFE/SPIRE Brings Federated Identity to Distributed Architectures

This week at the Kubecon+CloudNativeCon North America 2019, the SPIFFE and SPIRE projects will showcase their expanded capabilities to offer OpenID Connect (OIDC) federated identity, enabling microservices to employ this security not only between themselves on a single SPIRE instance, but also between shared services, such as databases, service meshes, and public cloud providers, without necessarily using secrets and/or network security controls.
Nov 19th, 2019 8:00am by Mike Melanson
👁 Featued image for: SPIFFE/SPIRE Brings Federated Identity to Distributed Architectures
Portworx by Pure Storage sponsored this post.

Portworx sponsored The New Stack’s coverage of KubeCon + CloudNativeCon in San Diego.

This week at the Kubecon+CloudNativeCon North America 2019, the SPIFFE and SPIRE projects will showcase their expanded capabilities to offer OpenID Connect (OIDC) federated identity, enabling microservices to employ this security not only between themselves on a single SPIRE instance, but also between shared services, such as databases, service meshes, and public cloud providers, without necessarily using secrets and/or network security controls.

With the move to distributed application architectures made up of often-ephemeral microservices running in numerous locations, perimeter security just doesn’t cut it anymore. Instead, microservices can employ a form of security called zero-trust security, wherein each and every component authenticates with any other component it must interact with.

In early 2018, the two projects joined the Cloud Native Computing Foundation (CNCF) to help developers more easily employ this form of security in their cloud native applications.

SPIFFE, which stands for Secure Production Identity Framework for Everyone, is a set of open source standards, and SPIRE, the SPIFFE Runtime Environment, is the software that actually implements that specification. Both joined the CNCF in early 2018 at the sandbox level, and since that time, Scytale, a startup founded specifically for SPIFFE, has also launched Scytale Enterprise, a cloud-based subscription-based on SPIFFE/SPIRE to standardize service authentication across cloud, container, and on-premise infrastructure. Since its creation, the SPIFFE standard has also been adopted by projects like Google’s Istio service mesh and Hashicorp’s Consul, as well as Envoy and gRPC, among others.

Andrew Jessup, co-founder and head of product at Scytale, explained in an interview with The New Stack that, until now, SPIFFE-compatible software was only able to securely communicate with other components using the same identity server. Now, with federated identity, he explained, disparate systems and services are able to securely communicate with each other — something customers have been asking for.

“I’ve got all these different service meshes running around and maybe I’m using other implementations as well, how can I actually start to connect these things together, these little isolated islands? Even if I’ve got two different types of business units running different infrastructure, both running SPIFFE-compatible systems, how can I create like contiguous trust between them?” said Jessup. “If I’m running SPIRE in one data center and Istio in another, even though these are two different implementations of SPIFFE, these things can federate and learn to trust each other, such that software running on an Istio cluster in one and a data center in another can also trust each other.”

Evan Gilman, a staff engineer at Scytale, further explained the importance of these new capabilities in a company statement.

“OIDC federation is a great way for distributed systems to securely interact without distributing shared secrets,” said Gilman. “For example, a system running within an on-premises data center managed by SPIRE can now directly authenticate with cloud platforms like AWS without sharing secrets or private keys.”

Jessup said that this absence of sharing secrets or private keys helps to prevent breaches caused by a leak of passwords, or the recent Capitol One breach, where someone gained access to the shared AWS keys and secrets.

“We’ve seen a lot of early interest around using SPIFFE not just for connecting individual workloads inside a data center or connecting what goes across data centers, but now into connecting into existing legacy software systems as well,” said Jessup. “It seems like a subtle point, but it’s a really important transition for the SPIFFE project because it vastly broadens the reach and utility of what SPIFFE is actually able to do.”

For those attending Kubecon+CloudNativeCon North America 2019 who are interested in learning more, Scytale will be demonstrating SPIRE and Scytale Enterprise, as well as hosting several lightning talks on SPIFFE/SPIRE, at Booth #S21.

Kubecon+CloudNativeCon and HashiCorp are sponsors of The New Stack.

Feature image by David Mark from Pixabay.

Portworx is the leading provider of persistent storage for containers and is used in production by healthcare, global manufacturing, and telecom members of the Fortune Global 500 and other great companies. Learn about Portworx solutions for Kubernetes storage, DCOS storage & more at portworx.com.
Learn More
The latest from Portworx by Pure Storage
TRENDING STORIES
Mike is a freelance writer, editor, and all-around techie wordsmith. Mike has written for publications such as ReadWriteWeb, Venturebeat, and ProgrammableWeb. His first computer was a "portable" suitcase Compaq and he remembers 1200 baud quite clearly.
Read more from Mike Melanson
Portworx by Pure Storage sponsored this post.
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.