IAM

Federation & SPIFFE

CoreLink issues SPIFFE-compatible identities for workloads -- both X.509-SVIDs (certificates) and JWT-SVIDs -- using the standard SPIFFE ID format (spiffe://tenant/namespace/workload). Trust bundle endpoints are exposed automatically so federated trust domains can validate each other's identities.

NHI federation bindings link a CoreLink workload identity to an external trust domain (another CoreLink tenant, a SPIRE deployment, or any SPIFFE-compliant issuer). Cross-domain authentication works without shared secrets or pre-provisioned credentials.

Federation and SPIFFE screenshot

Key Configuration

  • Trust domain name
  • Federation binding targets
  • Trust bundle refresh interval
  • JWT-SVID default audience and lifetime
All documentation Question about this? Talk to us