Workload identity (NHI)
agent-finance-prod
JWT-SVID presented to the warehouse gateway with the wrong audience. Signature valid, audience rejected — no access should follow.
Observed at 24 Sep 2026, 06:15 UTCStatus as of fixture 24 Sep 2026, 06:15 UTCSample data
Credential: invalid as of fixtureObserved
Issuer & attestation
- SPIFFE ID
- spiffe://prod.zeroshield.example/ns/finance/sa/finance-agent
- Trust domain / issuer
- prod.zeroshield.example · SPIRE (sample)
- Credential type
- JWT-SVID
- Issued / expires
- 24 Sep 2026, 06:00 UTC → 24 Sep 2026, 06:05 UTCExpiry 10 min before fixture time
- Attestation source
- k8s workload attestor (namespace, service account)
- Bound agent / deployment
- Finance Agentfinance-agent@sha256:22bd…10 (prod-us-2)
- SVID reference (non-secret)
- SHA256:SAMPLE-b02d…9e44jti SAMPLE-8c1f · key k-77 (sample) · entry-sample-finance-02
- Delegated human
- None recorded
Private keys, raw tokens and certificates are never displayed.
Validation checks
Illustrative trace; X.509 and JWT checks are distinct.
- JWT signature against bundle JWKSKey id k-77 in bundle rev b-1042.Pass
- aud claimExpected warehouse-gateway, got postgres-query-mcp.Fail
- exp claimExpired 10 min before fixture time (5 min lifetime).Stale
Credential lifecycle
Short-lived credentials rotate; expiry or bundle change can invalidate a path. Revocation is not instantaneous.
24 Sep 2026, 06:00 UTC
JWT-SVID minted for aud=postgres-query-mcpPassPass
24 Sep 2026, 06:01 UTC
Presented to warehouse-gateway — audience mismatchFailFail
24 Sep 2026, 06:05 UTC
Token expiredStaleStale
Policy & permission bindings
Separate from identity.
Downstream access paths
Potential reach, not observed disclosure.
- Finance Agent → postgres-query → Finance warehouseWrite access — review scope
Audit events
Limitations
- Token contents are summarized; the raw JWT is never displayed or stored.