Skip to content

[Story] Migration docs — ServiceAccount → SPIFFE opt-in path #147

Description

@shreyanshjain7174

Parent

Part of #146 (Cross-Cluster Agent Identity Federation epic).

Status

Blocked by validation gate. Depends on Workload API + A2A v2 + trust-bundle stories.

Goal

Document a step-by-step migration recipe so existing NineVigil users can opt in to SPIFFE per workload without disrupting anything.

Scope

  • docs/security/cross-cluster-identity.md with:
    • "Should I enable SPIFFE?" decision tree
    • Single-cluster opt-in walkthrough (helm flag, CRD field, verify)
    • Two-cluster federation walkthrough (connected mode)
    • Air-gapped two-cluster walkthrough
    • Rollback procedure (disable SPIFFE without losing state)
  • Diagrams (mermaid or SVG) for each scenario
  • Troubleshooting section (SVID not minting, federation handshake failing, trust bundle stale)
  • FAQ: SPIFFE vs ServiceAccount, when to use which
  • Cross-link from docs/05-multi-tenancy.md and docs/07-security.md

Acceptance

  • A new user can follow the doc end-to-end and federate two KinD clusters in <30 minutes
  • Internal dogfood: docs reviewed by 1 person who is not the author

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Nice to have — could slipdocumentationDocs and READMEfederationCross-cluster federationsecuritySecurity hardening and vulnerabilitiestrustIdentity, certificates, mTLS (Phase 2)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions