Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-9387

OSSM SPIRE (zero trust workload identity manager) integration

XMLWordPrintable

    • Supported integration with ZTWIM (SPIRE) operator
    • False
    • Hide

      None

      Show
      None
    • False
    • Documentation (Ref Guide, User Guide, etc.)
    • In Progress
    • 67% To Do, 33% In Progress, 0% Done

      Red Hat introduced the "Zero Trust Workload Identity Manager" (ZTWIM) Operator as a tech preview feature in OCP 4.19, with GA in a future release. This is productized [SPIRE|https://spiffe.io/docs/latest/spire-about/,] a workload identity manager that integrates with Istio.

      Istio [documents its SPIRE integration here|https://istio.io/latest/docs/ops/integrations/spire/.]

      We should aim to support using OSSM with SPIRE provided by the ZTWIM operator. 

      This includes:

      • Ongoing regression testing to validate the integration of OSSM + SPIRE
      • Any necessary enhancements to make the Sail Operator work with SPIRE (hopefully none)
      • Project Documentation for using the Sail Operator with SPIRE
      • Product Documentation for using OSSM with SPIRE provided by the ZTWIM operator.

      Ideally, this would also include support with Istio ambient mode, in progress upstream:

              frherrer@redhat.com Francisco Herrera Lira
              jlongmui@redhat.com Jamie Longmuir
              Dmitry Kartsev, Francisco Herrera Lira, Jacek Ewertowski
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: