Azure AD Workload Identity uses Kubernetes primitives to associate managed identities for Azure resources and identities in Azure Active Directory (AAD) with pods.
-
Updated
Sep 17, 2026 - Go
Azure AD Workload Identity uses Kubernetes primitives to associate managed identities for Azure resources and identities in Azure Active Directory (AAD) with pods.
Securely access AWS services from GKE cluster
AegisSovereignAI: The Cross-Ecosystem Trust Layer for the Distributed Enterprise. Verifiable Identity, Hardware-Rooted Integrity, and Sovereign AI Governance - from Silicon to Prompt. Unifying AI, Cloud-Native, and Decentralized architectures.
AWS SPIFFE Workload Helper is a light-weight tool intended to assist in providing a workload with credentials for AWS using its SPIFFE identity.
Identity Manager Operator
Showcasing the potential of SPIFFE with real-life services
A CLI for Kubernetes workload identity
Harbor Workload Identity Bridge. Pull from Harbor with the Service Account your pod is already running as. No imagePullSecrets, no long-lived credentials in workload namespaces, no per-namespace token-distribution chores.
AEGIVELA Open Core — Agent Identity, Authorization, and Security Fabric. Documentation, versioned contracts, Go PEP SDK, and integration examples.
This repository contains a CredentialComposer plugin for SPIRE that extends the functionality of JWT-SVIDs, adding custom claims based on the workload's SPIFFE identity.
Faster way to switch between tenants and subscriptions with az
SPIFFE-compatible workload identity + OpenID AuthZEN 1.0 authorization in a single Apache-2.0 binary. Cedar PDP, SPIFFE federation, tamper-evident audit log, Kubernetes operator.
Kubernetes admission webhook used to access AWS services from GKE cluster in secure manner using short-lived token
Kubernetes identity management for hybrid workloads
Go node agent for StellGuard zero-trust identity, fetching workload certificates, rotating local keys, and delivering mTLS credentials to services.
Verifiable delegation for AI agents — signed chains rooted in a human sponsor, attenuating at every hop, revocable per link, and evaluated across whole action sequences.
Production-grade control plane for enterprise AI agents, in Go. A provider-agnostic AI gateway with an OpenAI-compatible frozen contract, routing, quotas, resilience and guardrails; workload identity with gated promotion to production; and an OpenTelemetry observability plane with SLOs and chargeback.
secure, production-ready Kubernetes operator that automatically synchronizes TLS Secrets with GCP Certificate Manager, resolving Terraform dependency bottlenecks.
To associate your repository with the workload-identity topic, visit your repo's landing page and select "manage topics."