Session
SPIFFE Meets OAuth: Federated Identity for Cloud-Native Workloads
Cloud-native systems increasingly operate across multiple trust domains, creating significant challenges for securely propagating identity and authorization. Traditional approaches, such as static credentials or mTLS-only solutions, often introduce operational complexity and fail to scale in dynamic Kubernetes environments.
This session addresses these challenges by introducing federated identity patterns that combine SPIFFE and emerging OAuth extensions. Yoshiyuki Tabata will demonstrate how SPIFFE JWT SVID and OAuth Identity Chaining (draft-ietf-oauth-identity-chaining), together with Assertion Framework (RFC 7521/7523), enable secure multi-hop authorization and scalable identity propagation without relying solely on mTLS.
Attendees will gain practical insights through a demo integrating Keycloak, SPIRE, and OAuth flows, and learn how these patterns improve interoperability and security in multi-cluster Kubernetes environments.
Yoshiyuki Tabata
CNCF TAG Security and Compliance Tech Lead / CNCF Ambassador
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top