-
Ticket
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
False
-
-
False
-
-
Today ZTWIM support only k8s_psat attestation method.
We need (OSSM team) a mechanism which will allow us to extend attestation methods.
For example, add x509pop attestation without a need to set the CREATE_ONLY_MODE=true.
This can be done by exposing some extra config map which will be joined with the main config map by the ZTWIM. Or add the attestation method directly from the CR.
The implementation is up to you guys. We just need an ability to extend the SPIRE attestation plugin without a need to set CREATE_ONLY_MODE=true.
- is depended on by
-
OSSM-9387 OSSM SPIRE (zero trust workload identity manager) integration
-
- In Progress
-