---
title: "Chapter 02: Cryptographic Workload Attestation with SPIFFE & SPIRE | TinyCTO Zero-Trust Canon"
description: "How to implement production-grade workload identity without API keys or passwords. Deep-dive into SPIFFE Verifiable Identity Documents (SVIDs), node/workload attestation, kernel selectors, and automated mTLS rotation."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_manuals_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/manuals/02-workload-attestation-spiffe-spire"
locale: "en"
---

# Chapter 02: Cryptographic Workload Attestation with SPIFFE & SPIRE

> **Canonical Zero-Trust Engineering Field Manual**
> **Read Time**: 22 min read | **Maturity**: ADVANCED | **NIST SP 800-207**: NIST SP 800-207 Tenet 2 & 4

## Executive Summary

How to implement production-grade workload identity without API keys or passwords. Deep-dive into SPIFFE Verifiable Identity Documents (SVIDs), node/workload attestation, kernel selectors, and automated mTLS rotation.

## Chapter Content

# Cryptographic Workload Attestation with SPIFFE & SPIRE

## The Problem of Workload Identity
In microservice architectures, services must prove their identity to one another. Historically, developers embedded static API tokens, private keys, or passwords inside configuration files or Kubernetes secrets. If a single pod is compromised, the attacker exfiltrates these credentials and moves laterally across the infrastructure.

SPIFFE (Secure Production Identity Framework for Everyone) and SPIRE solve this by establishing **secretless, kernel-verified cryptographic workload attestation**.

## Core Concepts
- **SPIFFE ID:** A standardized URI uniquely identifying a workload:
  `spiffe://tinycto.tv/ns/production/sa/payment-service`
- **SVID (SPIFFE Verifiable Identity Document):** A cryptographically signed document (typically an X.509 certificate) with a short lifetime (e.g. 1 hour).
- **SPIRE Agent:** A node-level daemon that verifies local workloads via the Linux kernel (`/proc`) before issuing SVIDs.
- **SPIRE Server:** The CA that manages the trust domain, issues trust bundles, and signs SVIDs.

## Node & Workload Attestation Flow
1. **Node Attestation:** The SPIRE Agent boots on a host and proves its identity to the SPIRE Server using platform primitives (TPM 2.0, AWS Instance Identity Document, or GCP Token).
2. **Workload Registration:** Operators register selectors that define what constitutes a valid service (e.g., `k8s:ns:production`, `k8s:sa:payment-service`, `docker:image_id:sha256:...`).
3. **Workload Attestation:** When the payment pod initiates a connection to the SPIRE Agent Workload API over a Unix Domain Socket (`/run/spire/sockets/agent.sock`), the Agent calls the Linux kernel to inspect the caller's process ID (`SO_PEERCRED`).
4. **Issuance:** The Agent dynamically injects a short-lived X.509 SVID directly into the process memory. No private keys are ever stored on disk.

```
[ Workload Pod ] ──(Unix Domain Socket)──> [ SPIRE Agent ] ──(mTLS)──> [ SPIRE Server (Root CA) ]
      ▲                                         │
      └────── In-Memory X.509 SVID Injection ───┘
```

## Verification CLI
```bash
# Inspect ephemeral SVID issued to the local payment service
kubectl exec -n production deploy/payment-service -c payment -- \
  spire-agent api fetch x509 -write /tmp/svids/
openssl x509 -in /tmp/svids/svid.0.pem -text -noout | grep -E "Subject:|Validity|URI:"
```


### Canonical Links & Cross References

- **Manuals Library**: https://tinycto.tv/zero-trust/manuals
- **18 Reference Architectures**: https://tinycto.tv/zero-trust/architectures
- **Posture Assessor Wizard**: https://tinycto.tv/zero-trust/wizard
- **Security Tooling Matrix**: https://tinycto.tv/zero-trust/matrix

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Chapter 02: Cryptographic Workload Attestation with SPIFFE & SPIRE | TinyCTO Zero-Trust Canon",
  "description": "How to implement production-grade workload identity without API keys or passwords. Deep-dive into SPIFFE Verifiable Identity Documents (SVIDs), node/workload attestation, kernel selectors, and automated mTLS rotation.",
  "url": "https://tinycto.tv/zero-trust/manuals/02-workload-attestation-spiffe-spire",
  "inLanguage": "en"
}
```
