This is the finished lightboard from my 🌩️Thunder conversation with Volkan Özçelik about SPIFFE and SPIRE.

Bottom line: SPIFFE is a secure and automated way to manage identity, no secrets managers needed.

How does it work? gist.github.com/wiggitywh…

A black lightboard covered in colorful handwritten notes organized into four columns. The leftmost column, headed "Before SPIFFE...", lists problems with service tokens and mTLS certificates and defines SPIFFE and SPIRE. The second column, headed "WHO + WHAT = POLICY," includes a small diagram of pods stacked above a host layer and a machine layer, illustrating where identity is best assigned. The third column, headed "SPIFFE is designed to solve these problems," lists SPIFFE IDs, SVIDs, and how the Workload API attests and issues identity to workloads. The rightmost column covers what happens once attestation completes, a boxed list of "Benefits of SPIFFE," and boxed definitions of SPIRE Server and SPIRE Agent.