Skip to content

DESIGN.md: note SPIFFE/SPIRE in the remote-attestation strategic horizon - #35

Open
cptfinch wants to merge 1 commit into
mainfrom
design/spiffe-attestation-note
Open

cptfinch wants to merge 1 commit into
mainfrom
design/spiffe-attestation-note

Conversation

@cptfinch

Copy link
Copy Markdown
Contributor

Adds SPIFFE/SPIRE as a named direction alongside the existing vendor-OIDC/process-tree/TPM options in the strategic horizon section. Surfaced while dogfooding the tool against real IBA infrastructure: the current attestation model is local-session-only, which is fine for a single laptop but doesn't hold once a remote/cloud-run agent session needs to mint (Claude Code supports both). SPIFFE/SPIRE is the actual open standard for this exact problem and wasn't named despite the direction already being shaped like it.

Docs-only, no code change. Companion to #33 and #34 which cover the two concrete (issue-shaped) ideas from the same session.

…ection

The strategic horizon section already covers vendor OIDC, process-tree
attestation, and TPM, but doesn't name SPIFFE/SPIRE despite the whole
direction (short-lived, cryptographically attested workload identity)
being SPIFFE-shaped. Also calls out the concrete forcing function:
Claude Code supports remote/cloud-run agent sessions, not just local
ones, and local-session trust doesn't hold once minting can happen
from a non-local session.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant