Learning outcomes
- Separate service identity, workload instance, deployment, and originating human actor.
- Trace credential issuance, presentation, validation, authorization, rotation, and revocation.
- Preserve delegation without token passthrough or identity collapse.
- Test replay, wrong audience, compromised workload, stale policy, and direct-service bypass.
System and boundaries
Include the calling workload, workload identity issuer, deployment platform, access gateway or mesh, authorization service, target workload, target resource, credential stores, and evidence. When a user starts the call, include the originating subject and each acting service.
Distinguish the logical service, running workload instance, deployment environment, machine credential, and human actor. A service name is not proof that the current instance is authorized.
Request and decision flow
The platform or credential service authenticates the workload and issues a short-lived identity for an intended trust domain or audience. The caller presents it over an authenticated channel. The target validates issuer, audience, status, time, and workload identity. Policy evaluates the service, resource, action, environment, and any preserved actor. The target enforces local permission and records evidence.
When acting for a user, exchange or attenuate authority for the target. Preserve subject and actor. Do not forward a broad incoming bearer token through the chain.
Failure domains
- A static service credential is copied to another workload.
- A token for one service is accepted by another.
- Service identity erases the human who initiated the action.
- A compromised workload uses all service authority.
- Policy authorizes a service name without environment or deployment context.
- Credential rotation fails and callers fall back to an old secret.
- Direct cluster or origin traffic bypasses intended policy and evidence.
Design tradeoffs and residual risk
Short-lived workload credentials reduce secret persistence but depend on a trusted issuer and renewal path. Mutual transport authentication binds peers but does not define resource permission. Preserving human context improves authorization and evidence but adds privacy and chain-validation complexity. Shared service identities simplify policy but increase blast radius.
Limit authority by target, action, workload, environment, and time. Treat workload compromise as an expected containment case.
Pomerium boundary
Pomerium can authenticate documented service-account requests, enforce route policy, and preserve original request context for supported flows. Workload platforms and identity systems own instance identity. Target services must validate accepted credentials and authorize their own objects and actions.
Exercise
Trace a web application calling a billing API for a user. Record the user, service, workload instance, credential, issuer, audience, target, action, policy, expiry, rotation, and evidence at each hop.
Test copied credential, wrong audience, wrong environment, revoked user, compromised workload, stale policy, direct service access, and renewal outage.
Evaluation checklist
- Can the target identify the calling workload and originating actor when needed?
- Is each credential bound to a trusted issuer, audience, lifetime, and workload?
- Does policy limit the exact target resource and action?
- Can credential theft and workload compromise be contained and revoked?
- Can evidence trace the service chain without storing bearer credentials?
Next learning unit
Token Exchange
Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.
