# Machine identity: what SPIFFE starts and SOC 2 finishes

Canonical: https://brew.new/browse/templates/email/pt1_k97qcgkkrq2d5dm1mynytzqs7x8e5kc3

Brand: goteleport.com
Category: newsletter

![Preview of Machine identity: what SPIFFE starts and SOC 2 finishes](https://cdn.brew.new/email-preview-d11c8ef3593e1024-tracking_r57wb24t8c0ebrkz76g64pjcps8dth0k-1789006025559.png)

## Email content

Teleport

New in Identity

Teleport — New in Identity - Issue #6

Most infrastructure now runs on identities that belong to no human: CI/CD pipelines, microservices, bots, and AI aents that request credentials and move data on their own. The spec that defines workload identity gets the cryptography right but stops short of authorization and delivery. This issue covers what that spec answers and what it leaves open, how to carry workload identity past Kubernetes to VMs and edge without copying secrets, and which SOC 2 controls auditors expect those non-human identities to satisfy.

What SPIFFE Answers for Workload Identity and What It Doesn’t

By Rob Cobbins

SPIFFE grounds trust in platform attestation instead of shared secrets, which is the right bet and the reason CNCF graduated it. But the spec punts on authorization entirely, and it leaves the registration model almost wholly to implementations. Proving a workload is who it claims to be tells you nothing about what it is allowed to do. The post lays out the four properties a mature workload identity platform needs and the 2026 questions SPIFFE was never built to answer, like how an agent proves it is acting on Alice's behalf for thirty minutes.

Read the full post →

How to Extend SPIFFE Beyond Kubernetes: Bring Zero Trust Identity to Your VMs

By Jeffrey Ellin

Copying a client cert onto a VM creates long-lived credentials that outlive the workload, resist rotation, and are slow to revoke. The fix is to separate identity issuance from identity consumption, so each workload requests a short-lived SVID and consumes it through a local API instead of reading keys off disk. With the trust chain held outside any single cluster, identity becomes an organization-wide primitive that VMs, edge gateways, and legacy services all consume. You will see how Envoy fetches rotating identities over a local socket with no private key ever written to the VM.

Read the full post →

SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

By Kayne McGladrey

Most SOC 2 control mappings only address human users, yet CI/CD pipelines, AI agents, microservices, and bots request credentials and move data with the same reach. The post walks the CC6, CC7, and CC8 control families and shows how workload attestation, short-lived certificates, and versioned audit logs satisfy each one. Attestation verifies what a workload actually is, checking its Kubernetes namespace, service account, or Linux user, before any credential is issued. You get the specific evidence an auditor can pull for each control, from WorkloadIdentity rule definitions to timestamped revocation records.

Read the full post →

P.S. We'll be at these events over the next few weeks. Come find us.

Jul 23: CISOMeet -- Orange County, CA

Aug 3-6: Black Hat USA -- Las Vegas, NV

Sept 2026: CPX GISEC -- Dubai, UAE

Sept 15-17: AI Infra Summit -- Santa Clara, CA

Find us near you: https://goteleport.com/events/

Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612

If you no longer wish to receive these emails anymore, click on the following link:

UNSUBSCRIBE

TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97qcgkkrq2d5dm1mynytzqs7x8e5kc3)

[Browse email designs](https://brew.new/browse/templates)
