IAM
Federation & SPIFFE
CoreLink issues SPIFFE-compatible identities for workloads -- both X.509-SVIDs (certificates) and JWT-SVIDs -- using the standard SPIFFE ID format (spiffe://tenant/namespace/workload). Trust bundle endpoints are exposed automatically so federated trust domains can validate each other's identities.
NHI federation bindings link a CoreLink workload identity to an external trust domain (another CoreLink tenant, a SPIRE deployment, or any SPIFFE-compliant issuer). Cross-domain authentication works without shared secrets or pre-provisioned credentials.
Key Configuration
- Trust domain name
- Federation binding targets
- Trust bundle refresh interval
- JWT-SVID default audience and lifetime