Workload identity (NHI)
svc-support-prod
Healthy SPIFFE-bound workload running the Support Copilot deployment. Identity verified; each action still needs a policy decision.
Issuer & attestation
- SPIFFE ID
- spiffe://prod.zeroshield.example/ns/support/sa/support-agent
- Trust domain / issuer
- prod.zeroshield.example · SPIRE (sample)
- Credential type
- X.509-SVID
- Issued / expires
- 24 Sep 2026, 05:45 UTC → 24 Sep 2026, 06:45 UTCExpiry 30 min after fixture time
- Attestation source
- k8s node + workload attestor (namespace, service account, image digest)
- Bound agent / deployment
- Support Copilotsupport-copilot@sha256:7c1e…a9 (prod-eu-1)
- SVID reference (non-secret)
- SHA256:SAMPLE-7f3a…c21eserial SAMPLE-0x4a91 · key k-sample-12 · entry-sample-support-01
- Delegated human
- Maya Chen (support session)
Private keys, raw tokens and certificates are never displayed.
Validation checks
Illustrative trace; X.509 and JWT checks are distinct.
- X.509 chain to local trust bundleChains to bundle rev b-1042.Pass
- URI SAN matches expected SPIFFE IDExactly one URI SAN, matches registration entry.Pass
- Validity window30 min remaining; renewal expected at 50% lifetime.Pass
Credential lifecycle
Short-lived credentials rotate; expiry or bundle change can invalidate a path. Revocation is not instantaneous.
24 Sep 2026, 04:45 UTC
SVID issued (previous)PassPass
24 Sep 2026, 05:15 UTC
Renewal at 50% lifetimePassPass
24 Sep 2026, 05:45 UTC
Current SVID issuedPassPass
24 Sep 2026, 06:45 UTC
Current SVID expiresNot applicableNot applicable
Policy & permission bindings
Separate from identity.
Downstream access paths
Potential reach, not observed disclosure.
- Support Copilot → Ticket search → Customer ticketsMatches approved purpose
- Support Copilot → Shared RAG index → Employee payrollExcessive grant — review
Audit events
Limitations
- Revocation is not instantaneous: a compromised SVID remains usable until expiry unless the trust bundle changes.