Draft SPIFFE workload binding contract for owner fleets #13

Merged
ams-tech merged 1 commit from codex/spiffe-workload-binding into main 2026-09-30 23:48:30 -04:00
ams-tech commented 2026-09-29 00:28:07 -04:00 (Migrated from github.com)

Add an additive 0.5.0-draft.1 WorkloadBinding contract for rotating SPIFFE credentials. Bind authorization to the owner trust domain, logical device, enrollment instance, and workload so replacement cannot reactivate an old instance and quarantine can apply on existing connections.

The draft defines canonical URI and envelope rules, current-state authorization semantics, standalone/server/agent responsibilities, and separate optional provider membership. Existing 0.4.0-draft.1 contracts, certificate-tuple checks, and adoption status remain intact. Includes schema, positive/negative fixtures, conformance checks, and documentation; the fleet prototype pins this commit for fixture conformance only.

Validation: 104 Python tests pass; documentation build passes (3 pages, 19 contracts, 97 links); Node walkthrough tests pass locally on Node 18 (CI targets Node 22); git diff --check passes. Production consumer adoption, DNS integration, and hardware qualification remain separate work.

Add an additive `0.5.0-draft.1` WorkloadBinding contract for rotating SPIFFE credentials. Bind authorization to the owner trust domain, logical device, enrollment instance, and workload so replacement cannot reactivate an old instance and quarantine can apply on existing connections. The draft defines canonical URI and envelope rules, current-state authorization semantics, standalone/server/agent responsibilities, and separate optional provider membership. Existing `0.4.0-draft.1` contracts, certificate-tuple checks, and adoption status remain intact. Includes schema, positive/negative fixtures, conformance checks, and documentation; the fleet prototype pins this commit for fixture conformance only. Validation: 104 Python tests pass; documentation build passes (3 pages, 19 contracts, 97 links); Node walkthrough tests pass locally on Node 18 (CI targets Node 22); `git diff --check` passes. Production consumer adoption, DNS integration, and hardware qualification remain separate work.
Sign in to join this conversation.
No description provided.