Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trust domain - workload identity federation #4658

Open
shashankbarsin opened this issue Nov 15, 2024 · 7 comments
Open

Trust domain - workload identity federation #4658

shashankbarsin opened this issue Nov 15, 2024 · 7 comments
Assignees
Labels
feature-request Requested Features security

Comments

@shashankbarsin
Copy link
Contributor

shashankbarsin commented Nov 15, 2024

Trust domains will allow associating multiple AKS clusters so that FICs for workload identity federation can be created on <trust_domain_issuer, namespace, service-account> instead of <aks_cluster_issuer, namespace, service-account> to address the current 20 FIC limitation per identity

Tentative ETA for preview CY2025H1

@colincmac
Copy link

@shashankbarsin Will this resolve these issues?
#3982
#2861

@OmnipotentOwl
Copy link

For the ETA for a preview which type of preview is that expected to be?

@shashankbarsin
Copy link
Contributor Author

@colincmac - It'll address #3982. #2861 will be addressed by structured authentication integration, that's currently being planned and will share an update on that soon too..

@OmnipotentOwl - Most likely a private preview to begin with. Closer to release, we will share a form where you can share your subscriptionId and we will enable the feature flag.

@Richard87
Copy link

All the Subjects in a trust domain will have the same prefix, will it also share the Issuer?

@shashankbarsin
Copy link
Contributor Author

reopening this issue as it was wrongly closed as stale by the bot. this feature is still on the roadmap and still on track for a preview in CY2025H1.

@shashankbarsin
Copy link
Contributor Author

@Richard87 - this feature (trust domain) would result in the same issuer URL for the trust domain and wouldn't impact the subject part, which remains a tuple of <namespace, service-account>. For flexibility on declaration of subjects, we have a different feature on the roadmap to provide the ability to declare the subject using prefix patterns - #4688

@ChrisF987-coles
Copy link

@shashankbarsin will this feature be dependent on Fleet Manager - ie will the clusters have to be a part of a Fleet Manager fleet to be a part of the trust domain?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature-request Requested Features security
Projects
Status: In Progress (Development)
Development

No branches or pull requests

5 participants