Abstract

Ephemeral Secrets Runtime For Kubernetes Workloads

ABSTRACT

The present disclosure relates to a system for ephemeral secrets runtime in Kubernetes workloads which includes an ephemeral secrets runtime system configured to receive a request from a Kubernetes workload for accessing a protected downstream resource, collect Kubernetes-workload identity attributes and runtime trust signals associated with the Kubernetes workload, generate a unified trust context by aggregating the collected identity attributes and runtime trust signals, evaluate the unified trust context against authorization policies to determine credential issuance parameters, generate a short-lived credential based on the credential issuance parameters, cryptographically bind the short-lived credential to workload-specific attributes, deliver the workload-bound credential to the Kubernetes workload through a credential delivery interface, and continuously monitor runtime posture conditions and revoke, rotate, or deny renewal of the credential upon detecting trust degradation or policy violations.

Figure 2

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS