<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SPIFFE Blog</title>
    <link>https://spiffe.io/blog/</link>
    <description>News, deep dives, and updates from the maintainers and community behind SPIFFE and SPIRE.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 16 Jun 2022 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://spiffe.io/blog/" rel="self" type="application/rss+xml" />
    <item>
      <title>Hardening Istio security with SPIRE</title>
      <link>https://spiffe.io/blog/2022-06-16-hardening-istio-security-with-spire/</link>
      <pubDate>Thu, 16 Jun 2022 00:00:00 +0000</pubDate><author>Nathalia Satie Gomazako</author>
      <guid>https://spiffe.io/blog/2022-06-16-hardening-istio-security-with-spire/</guid>
      <description>Integrating SPIRE with Istio brings uniform, SPIFFE-based identity to service meshes by letting Envoy&#39;s Secret Discovery Service consume SPIRE identities.</description>
    </item>
    <item>
      <title>SPIRE now runs on Windows!</title>
      <link>https://spiffe.io/blog/2022-05-20-spire-now-runs-on-windows/</link>
      <pubDate>Fri, 20 May 2022 00:00:00 +0000</pubDate><author>Agustín Martínez Fayó</author>
      <guid>https://spiffe.io/blog/2022-05-20-spire-now-runs-on-windows/</guid>
      <description>SPIRE 1.3.0 adds experimental support for running the Server and Agent on Windows, extending workload identity beyond Linux with a Windows workload attestor.</description>
    </item>
    <item>
      <title>Enabling Authenticated Communication for Serverless Workloads with SPIRE</title>
      <link>https://spiffe.io/blog/2021-12-20-enabling-authenticated-communication-for-serverless-workloads-with-spire/</link>
      <pubDate>Mon, 20 Dec 2021 00:00:00 +0000</pubDate><author>Agustín Martínez Fayó</author>
      <guid>https://spiffe.io/blog/2021-12-20-enabling-authenticated-communication-for-serverless-workloads-with-spire/</guid>
      <description>Serverless platforms can&#39;t run a SPIRE Agent next to the workload. The SVIDStore plugin fixes this by pushing X.509-SVIDs to stores like AWS Secrets Manager.</description>
    </item>
    <item>
      <title>Scrutinizing SPIRE to Sensibly Strengthen SPIFFE Security (Part Two)</title>
      <link>https://spiffe.io/blog/2020-09-25-scrutinizing-spire-to-sensibly-strengthen-spiffe-security-part-two/</link>
      <pubDate>Fri, 25 Sep 2020 00:00:00 +0000</pubDate><author>Matt Moyer</author>
      <guid>https://spiffe.io/blog/2020-09-25-scrutinizing-spire-to-sensibly-strengthen-spiffe-security-part-two/</guid>
      <description>Part two scores and ranks attacks on SPIRE by impact and likelihood, finding the biggest risks stem from its centralized signing, plus low-effort mitigations.</description>
    </item>
    <item>
      <title>Scrutinizing SPIRE to Sensibly Strengthen SPIFFE Security (Part One)</title>
      <link>https://spiffe.io/blog/2020-09-25-scrutinizing-spire-security/</link>
      <pubDate>Fri, 25 Sep 2020 00:00:00 +0000</pubDate><author>Matt Moyer</author>
      <guid>https://spiffe.io/blog/2020-09-25-scrutinizing-spire-security/</guid>
      <description>Part one of a security analysis of the SPIFFE Runtime Environment (SPIRE): its architecture, security properties, and a threat model for assessing attacks.</description>
    </item>
    <item>
      <title>SPIFFE/SPIRE move to CNCF Incubation-level hosted projects!</title>
      <link>https://spiffe.io/blog/2020-06-22-spiffe-spire-move-to-cncf-incubation-level-hosted-projects/</link>
      <pubDate>Mon, 22 Jun 2020 00:00:00 +0000</pubDate><author>Andrés Vega</author>
      <guid>https://spiffe.io/blog/2020-06-22-spiffe-spire-move-to-cncf-incubation-level-hosted-projects/</guid>
      <description>SPIFFE and SPIRE have moved from CNCF sandbox to incubation level. A look at the milestones, from a security self-assessment to due diligence, behind the move.</description>
    </item>
    <item>
      <title>[Re-Cap] SPIFFE Community Day: Spring 2020</title>
      <link>https://spiffe.io/blog/2020-06-18-spiffe-community-day-spring-2020/</link>
      <pubDate>Thu, 18 Jun 2020 00:00:00 +0000</pubDate><author>Umair M. Khan</author>
      <guid>https://spiffe.io/blog/2020-06-18-spiffe-community-day-spring-2020/</guid>
      <description>A recap of Spring 2020 SPIFFE Community Day, the first held fully online, with 300+ attendees and deployment stories from ByteDance, Square, and Uber.</description>
    </item>
    <item>
      <title>[Re-Cap] SPIFFE Community Day: Fall 2019</title>
      <link>https://spiffe.io/blog/2020-06-12-re-cap-spiffe-community-day-fall-2019/</link>
      <pubDate>Fri, 12 Jun 2020 00:00:00 +0000</pubDate><author>Umair M. Khan</author>
      <guid>https://spiffe.io/blog/2020-06-12-re-cap-spiffe-community-day-fall-2019/</guid>
      <description>A recap of Fall 2019 SPIFFE Community Day (200+ attendees): TPM node attestation at Bloomberg, Hadoop workloads at Uber, and SPIRE-backed service meshes.</description>
    </item>
    <item>
      <title>[Re-Cap] SPIFFE Community Day: Spring 2019</title>
      <link>https://spiffe.io/blog/2020-06-09-re-cap-spiffe-community-day-spring-2019/</link>
      <pubDate>Tue, 09 Jun 2020 00:00:00 +0000</pubDate><author>Umair M. Khan</author>
      <guid>https://spiffe.io/blog/2020-06-09-re-cap-spiffe-community-day-spring-2019/</guid>
      <description>A recap of the May 2019 SPIFFE Community Day, hosted by Pinterest and Scytale: case studies from Uber and Square plus demos with Kubernetes, Envoy, and Istio.</description>
    </item>
    <item>
      <title>[Re-Cap] SPIFFE Community Day: Fall 2018</title>
      <link>https://spiffe.io/blog/2020-06-08-re-cap-spiffe-community-day-fall-2018/</link>
      <pubDate>Mon, 08 Jun 2020 00:00:00 +0000</pubDate><author>Umair M. Khan</author>
      <guid>https://spiffe.io/blog/2020-06-08-re-cap-spiffe-community-day-fall-2018/</guid>
      <description>A recap of SPIFFE&#39;s seventh Community Day (November 2018): project updates, demos, and talks from Pinterest, Square, and VMware, plus Federation and JWT-SVIDs.</description>
    </item>
  </channel>
</rss>
