OIDC-Scoped RBAC & Workload Identity

Tenant-isolated, OIDC-scoped access control and SPIFFE/SPIRE workload identity.

  • Every REST endpoint requires a JWT Bearer token with OIDC scopes and a mandatory tenant claim, validated before any scope check.
  • Roles — Admin, Maintainer, Viewer — are pre-bundled scope sets, not role-name checks.
  • A nested-trust-domain SPIRE deployment under the spiffe://penguintech.io/<env>/<service> scheme is wired into the Manager, PKI, s3scan, and vault-sync services.
  • S3 credentials and other sensitive material are encrypted at rest; secrets are never persisted in plaintext.

← Back to all features

Full technical documentation →