Skip to content

Roadmap

Andres Vega edited this page Feb 12, 2020 · 17 revisions

Near-Term

  • Move the SPIFFE/SPIRE projects to CNCF maturity level of incubation
  • Support for JWT-SVID in Nested SPIRE Topologies
  • An updated version of SPIRE Management APIs
  • Documentation and integrations for critical use cases
  • Expand client libraries (Go, Java, C)

Medium-Term

  • Key Revocation and Forced Rotation
  • Clustering of SPIRE Servers without the use of an external database (Simplified HA)
  • Support for supply chain provenance attestation by verification of binary signing (TUF, in-toto)
  • Improve the server and agent install experience
  • Improve the overall Kubernetes experience
  • Expand support of TPM node attestation to provide first-class verification and identification of TPM metadata

Long-Term

  • Use SPIRE on workloads running on platforms where installing an agent is not possible
  • Secretless authentication to Google Compute Platform by expanding OIDC Federation integration support
  • Secretless authentication to Microsoft Azure by expanding OIDC Federation integration support
  • Support for Transitive Identity
Clone this wiki locally