How SPIFFE Helps Istio in Service Mesh Federation - Yonggang Liu & Wencheng Lu, Google
Abstract
This proposal resolves the fundamental identity federation problem between different trust domains, using the trust domain and bundle standard proposed by SPIFFE. As an important collaborator of SPIFFE/SPIRE, Istio adopts this standard to support federations with SPIRE and other identity systems. The newly proposed standard enables multiple service meshes to securely establish trusts for cross-mesh secure communications. In this talk, we will explain how this new standard can help on federated service meshes and how Istio supports the standard. Finally, we will demonstrate how the federation can be set up between Istio and SPIRE systems.