youtube image
From YouTube: Deep Dive: Container Identity WG - Greg Castle & Michael Danese, Google


Join us for Kubernetes Forums Seoul, Sydney, Bengaluru and Delhi - learn more at

Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects

Deep Dive: Container Identity WG - Greg Castle & Michael Danese, Google

Over the past year the Container Identity working group has been working on a number of initiatives relating to identity in Kubernetes. These include providing a mechanism to issue scoped JWTs that can be externally validated which improves the security of identity integrations using Kubernetes service accounts, such as Hashicorp Vault. We’ve also made significant progress in providing a new mechanism to issue and mount service account identities inside the cluster that addresses a number of security and scalability issues with existing service accounts. Finally we’ve also enabled new identity integrations by exposing OIDC functionality from the Kubernetes cluster. We’ll discuss these changes, how they can be used today, and where we are headed next.

To learn more: