Workload Identity: Authentication Without Secrets

The application connects to MySQL without a password. Not “the password is in a vault.” Not “the password is injected at deploy time.” Not “no password needed because the request comes from an allow-listed IP.” No password at all. There is no string, anywhere, that logs into that database. That sentence is where I recently lost a friend, a senior engineer at one of the biggest tech companies you can name, while explaining my fleet-security work. He made me say it three times. And he is not behind; he is normal. Zero-trust workload identity is still a novelty to most people who run real infrastructure, including very good ones. ...

Who Holds the Keys to Confidential Computing

A friend called last week with a familiar complaint. He had built his workload inside AWS Nitro Enclaves, and he wanted out. His words, not mine: “Pretty easy to get in. Pretty costly to get up. Impossible to get out.” A friendly onboarding pipeline had generated his key for him and left it sitting right there in the console, and he honestly could not tell you whether it was his to take somewhere else. AWS ran the attestation. AWS decided, on every request, whether his own code was allowed to touch his own secrets. Then he asked the question that started this article. How do I port this to another provider? ...