Workload identity (NHI)
svc-embedding-batch
Federated batch workload whose SVID expired after renewal failed and whose foreign trust bundle is stale.
Observed at 24 Sep 2026, 06:15 UTCStatus as of fixture 24 Sep 2026, 06:15 UTCSample data
Credential: expired as of fixtureDeclared (not verified)
Issuer & attestation
- SPIFFE ID
- spiffe://data.partner.example/batch/embedding-job
- Trust domain / issuer
- data.partner.example · SPIRE (sample)
- Credential type
- X.509-SVID
- Issued / expires
- 23 Sep 2026, 18:00 UTC → 24 Sep 2026, 06:00 UTCExpiry 15 min before fixture time
- Attestation source
- Partner-domain attestation — declared via federation, not inspected locally
- Bound agent / deployment
- —embedding-batch (partner cluster)
- SVID reference (non-secret)
- SHA256:SAMPLE-51c9…07aaserial SAMPLE-0x1d02 · key k-partner-sample-3 · declared by partner (not local)
- Delegated human
- None recorded
Private keys, raw tokens and certificates are never displayed.
Validation checks
Illustrative trace; X.509 and JWT checks are distinct.
- X.509 chain to federated bundleForeign bundle rev p-311 is 26 h old (refresh 6 h).Stale
- URI SAN matches expected SPIFFE IDMatches federation allowlist entry.Pass
- Validity windowExpired 15 min before fixture time; renewal failed twice.Fail
Credential lifecycle
Short-lived credentials rotate; expiry or bundle change can invalidate a path. Revocation is not instantaneous.
23 Sep 2026, 18:00 UTC
SVID issued (12 h lifetime)PassPass
24 Sep 2026, 00:00 UTC
Renewal attempt failedFailFail
24 Sep 2026, 03:00 UTC
Renewal attempt failedFailFail
24 Sep 2026, 06:00 UTC
SVID expiredStaleStale
Policy & permission bindings
Separate from identity.
Downstream access paths
Potential reach, not observed disclosure.
- — → Shared RAG index → Support KB exportPath invalid while SVID expired
Audit events
Limitations
- Federation proves identity across domains only; it grants no resource access.
- Partner attestation is not locally observable.