Skip to content

Synthetic demo · No customer connectors attached · Fixture snapshot 24 Sep 2026, 06:15 UTC

Discover / non-human identity

Trust domains & federation

Federation lets one domain validate another's SVIDs using its trust bundle. It proves identity across domains only — it never grants access to resources.

Observed at 24 Sep 2026, 06:15 UTCStatus as of fixture 24 Sep 2026, 06:15 UTCSample data

local domain

prod.zeroshield.example

Bundle b-1042 · 2 h old at fixture
Source:
SPIRE server bundle endpoint (sample)
Digest:
sha256:SAMPLE-prod-9a41…e2
Fetched:
24 Sep 2026, 04:15 UTC

Sample SPIRE server; issuance telemetry from fixture. Public bundle metadata only.

local domain

staging.zeroshield.example

Bundle s-220 · 5 h old at fixture
Source:
SPIRE server bundle endpoint (sample)
Digest:
sha256:SAMPLE-stg-33c0…7b
Fetched:
24 Sep 2026, 01:15 UTC

Rotation failures on 2 nodes. Public bundle metadata only.

foreign domain

data.partner.example

Bundle p-311 · 26 h old at fixture
Source:
https_spiffe federation endpoint (sample)
Digest:
sha256:SAMPLE-ptnr-d17e…40
Fetched:
23 Sep 2026, 04:15 UTC

Foreign issuance is not observable locally. Public bundle metadata only.

foreign domain

ci.vendor.example

No bundle
Source:
none configured
Digest:
—
Fetched:
—

Seen in traffic; no federation configured. Public bundle metadata only.

Federation relationships

Every row states explicitly that federation grants no access.

Scroll table sideways for more columns →

LocalForeignDirectionBundle endpointStateGrants access?
prod.zeroshield.exampledata.partner.examplebidirectionalhttps_spiffe (sample)StaleBundle stale; identity from partner cannot be validated reliably.No — policy decides
prod.zeroshield.examplestaging.zeroshield.exampleone-way (staging trusts prod)https_web (sample)PassTrust only; no staging policy references prod workloads.No — policy decides
prod.zeroshield.exampleci.vendor.examplenone—UnknownCoverage gap: presented SVIDs cannot be validated.No — policy decides

SVID issuance & rotation (24 h)

Scroll table sideways for more columns →

Trust domainSVIDs issuedRotation failuresCoverage
prod.zeroshield.example12840Telemetry present
staging.zeroshield.example3113Failures
data.partner.exampleNot observableNot observableGap
ci.vendor.exampleNot observableNot observableGap

Coverage gaps: ci.vendor.example presents SVIDs without configured federation; foreign issuance telemetry is not visible. See svc-embedding-batch for a path invalidated by a stale bundle.