Pricing

Zero trust workload identity manager

What is zero trust workload identity manager?

Zero trust workload identity manager is an OpenShift operator that uses a SPIFFE/SPIRE framework to simplify the management of workload identity across multiple clouds, inconsistent identity schemas, and risky, long-lived credentials. Zero trust workload identity manager provides a single, universal identity framework for all your workloads whether they're in containers or virtual machines, on any cloud, datacenter, or edge location. Automatically issue short-lived, verifiable identities so your services can securely connect without juggling API keys—enhancing your organization’s zero trust posture.

What are SPIFFE and SPIRE? article thumbnail

What are SPIFFE and SPIRE?

SPIFFE and SPIRE define a way to enforce zero trust in hybrid cloud environments through identity management in varied computing environments.

Why use zero trust workload identity manager

Juggling different identity schemas and federation setups for each cloud provider is complex, error-prone, and hard to scale. Even static, long-lived credentials like API keys pose significant security risks. Many teams are already overburdened with simply maintaining the platform, and deploying critical security infrastructure like SPIRE is complex and time-consuming.

Zero trust workload identity manager is included with Red Hat Advanced Cluster Management, Red Hat Advanced Cluster Security, and Red Hat OpenShift Platform Plus. It lets you start federating identity and stop juggling credentials, go beyond basic authentication, and deploy workload identity as a Day 2 operation. It abstracts away complex configurations, allowing you to seamlessly issue and rotate verifiable, short-lived identities for every workload in your environment.

With powerful node and workload attestation, zero trust workload identity manager issues identities only after the underlying infrastructure integrity is verified. With a unified identity plane, you can enable secure cross-cloud communication, simplify access to secret stores like HashiCorp Vault, and integrate with tools like Istio and Sigstore to build a true end-to-end zero trust architecture.

Collage of a woman holding a laptop, standing next to a floating OpenShift icon

Features and benefits

SPIFFE/SPIRE Federation

Provides a single, consistent identity plane for every workload, no matter where it runs, so you can connect services securely across any cloud without the risk and overhead of managing secrets.

Node and workload attestation

Automatically attest the state of both the node and the workload before issuing an identity, establishing a hardware root of trust and ensuring only legitimate, unmodified workloads can communicate.

SPIRE Controller Manager for automatic workload registration

Automates the entire lifecycle of SPIRE on OpenShift, from installation to configuration and management, so you can focus on policy, not plumbing.

Keep learning about zero trust security

Article

What is zero trust?

Zero trust is an approach to designing security architectures based on the premise that every interaction begins in an untrusted state.

Blog post

Zero trust and sovereignty for cloud-native and AI workloads

A modern, integrated approach applies the principles of zero trust across the entire application lifecycle, and helps ensure compliance with data residency, privacy, and legal boundaries.

Article

What is confidential computing?

Confidential computing addresses a crucial gap in data security by creating isolated workload environments to secure data while it’s in use, helping organizations improve their zero trust posture.

Talk to a Red Hatter