Skip to content

🐛 Workload ID Musings 2025-09-06

Whoooooo areeeee yoooouuuuuu?

John
Sep 6, 20251 min read
  • Workload Identity OAuth (or otherwise) Reverse Proxy
    1. Enables fine grained access control around what a workload can do with an API, more so than fine grained tokens, control specific POST data or query parameters allowed. Or potentially response filtering.
    2. For traceability the SCITT policy engine can be used on each OIDC claims validation. The claims can be added to the transparency service.
    3. ATProto can be a place to store SCITT messages, and SCRAPI can be built on top of it. This enables federation.
      1. SCITT content addressable URIs are still interesting for this use case. Need to pull from old version of spec because microsoft didn't like the : character (yes it's that dumb)
  • Using ATProto as the graph
    1. No private accounts yet, these would be ideal for networked ssh-ai swarms
    2. AT-SMS could be promising in that direction
      1. https://boscolo.leaflet.pub/3lxx6eqkga226
      2. https://ngerakines.leaflet.pub/3lxxk3oahzc2f
  • gobengo wasup

Did you enjoy this article?

Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.

Across the AtmosphereDiscussions