For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.
Workload identity
Manage workload identities in ambient mesh, including SPIRE attestation, identity token access, and certificate lifecycle.
SPIFFE trust domain chain verification Enterprise
Enable strict mode to require that the mTLS certificate chain attests the peer’s SPIFFE trust …
Secure workload identities with SPIRE Enterprise
Use SPIRE node agents to attest and grant identities to ambient mesh workloads, which can be used …
Query workload identity from applications Enterprise
Use the ztunnel metadata server to retrieve your workload’s SPIFFE identity and Workload Identity …
Workload identity tokens (WIMSE) Enterprise Alpha
Use WIMSE Workload Identity Tokens with agentgateway to authenticate service-to-service and egress …
Certificate revocation list (CRL) enforcement Enterprise Alpha
Revoke workload certificates in the ambient mesh using a Certificate Revocation List (CRL).