Skip to content

[Story] Migration docs — ServiceAccount → SPIFFE opt-in path #147

Description

@shreyanshjain7174

Parent

Part of #146 (Cross-Cluster Agent Identity Federation epic).

Status

Blocked by validation gate. Depends on Workload API + A2A v2 + trust-bundle stories.

Goal

Document a step-by-step migration recipe so existing NineVigil users can opt in to SPIFFE per workload without disrupting anything.

Scope

  • docs/security/cross-cluster-identity.md with:
    • "Should I enable SPIFFE?" decision tree
    • Single-cluster opt-in walkthrough (helm flag, CRD field, verify)
    • Two-cluster federation walkthrough (connected mode)
    • Air-gapped two-cluster walkthrough
    • Rollback procedure (disable SPIFFE without losing state)
  • Diagrams (mermaid or SVG) for each scenario
  • Troubleshooting section (SVID not minting, federation handshake failing, trust bundle stale)
  • FAQ: SPIFFE vs ServiceAccount, when to use which
  • Cross-link from docs/05-multi-tenancy.md and docs/07-security.md

Acceptance

  • A new user can follow the doc end-to-end and federate two KinD clusters in <30 minutes
  • Internal dogfood: docs reviewed by 1 person who is not the author

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Nice to have — could slipdocumentationDocs and READMEfederationCross-cluster federationsecuritySecurity hardening and vulnerabilitiestrustIdentity, certificates, mTLS (Phase 2)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions