Workload and Machine Identity — trust lifecycle
securityv1/01 Views
/02 About
Short-lived workload identity with attestation, enrollment, issuance, mutual authentication, per-service authorization, rotation and revocation.
Purpose: Short-lived workload identity with attestation, enrollment, issuance, mutual authentication, per-service authorization, rotation and revocation. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/63/4/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.
Published by Lattix · 20 elements · 20 relationships · validated on publish
/03 Contents
- Application Component
- Workload identity enrollment, Workload provenance verifier, Credential issuer, Requesting workload, Mutual authentication gateway, Service authorization, Workload policy evaluator, Service policy enforcement, Credential expiry monitor, Identity drift detector, Identity incident response
- Data Store
- Issued identity records, Identity issuance and access audit
- Application
- Protected service
- Role
- Service access owner
- Policy
- Machine identity and access policy
- Activity
- Register workload, Rotate expiring credential, Revoke compromised identity, Verify revocation propagation