| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
Implement workload identity federation Allows service accounts to exchange tokens issued by an external IdP for a DT session token via an RFC 8693 compliant endpoint (https://www.rfc-editor.org/info/rfc8693/). This enables service accounts to authenticate without long-lived static credentials such as API keys. The exchange supports both OIDC ID tokens and SPIFFE JWT-SVIDs (https://spiffe.io/docs/latest/spiffe-specs/jwt-svid/). This change includes e2e tests for both using Ory Hydra (for OIDC) and SPIRE (for SPIFFE). See the included ADR for the full details. Signed-off-by: nscuro <nscuro@protonmail.com> | 19 天前 |