Zero Trust Workload Identity Manager 1.1 Now available on OpenShift
In this blog, we will learn about Zero Trust Workload Identity Manager 1.1 in Red Hat OpenShift.
Modern cloud-native applications are increasingly distributed across multiple clusters, cloud platforms, and hybrid environments. In these dynamic architectures, conventional approaches such as long-lived credentials, static certificates, and cloud-specific IAM mechanisms can become difficult to manage securely at scale.
Red Hat’s Zero Trust Workload Identity Manager addresses this challenge by providing workloads with short-lived, cryptographically verifiable identities during runtime. Instead of relying primarily on network location or manually managed credentials, applications can establish trust by proving their identity and runtime characteristics.
With version 1.1 now generally available, organizations can extend runtime-attested workload identity across their cloud-native environments and establish a consistent identity foundation for distributed applications.
Built for Production with SPIFFE and SPIRE
Zero Trust Workload Identity Manager is built on the upstream SPIFFE and SPIRE ecosystem. SPIFFE defines a standard approach for identifying workloads, while SPIRE provides the infrastructure needed to verify workloads and issue their identities.
Red Hat packages these capabilities into an enterprise-focused operator designed to simplify ongoing operational management. This helps platform teams implement workload identity without having to manage complex SPIRE configurations manually.
For organizations operating high-volume production environments, the solution provides a centralized identity layer across OpenShift container workloads. Runtime attestation helps reduce dependency on static secrets and minimizes the operational overhead associated with traditional certificate management.
While SPIFFE and SPIRE can support both virtual machines and containers, Red Hat’s Zero Trust Workload Identity Manager focuses specifically on containerized workloads running on Red Hat OpenShift, providing an integrated approach for OpenShift environments.
What’s New in Version 1.1?
The 1.1 release introduces several enhancements aimed at improving workload identity management, application compatibility, and multi-cluster security.
SPIFFE Helper Support for Legacy Applications
Not every application can communicate directly with the SPIRE Workload API. This can make adopting workload identity more difficult, particularly for existing applications.
Version 1.1 adds support for SPIFFE Helper, which acts as a bridge between applications and the workload identity infrastructure. It can retrieve workload credentials and cryptographic keys and make them available to applications through a shared volume.
SPIFFE Helper can also monitor credential validity and handle automatic rotation. Depending on the application requirements, it can notify or trigger applications when credentials change, helping maintain continuous authentication without requiring significant application code changes.
Secure Identity Across Multiple Clusters
Distributed applications often communicate across clusters, regions, and cloud environments. Securing these connections requires trust mechanisms that extend beyond an individual OpenShift cluster.
With version 1.1, Zero Trust Workload Identity Manager integrates with Red Hat OpenShift Service Mesh, based on Istio, to support workload identity across multiple clusters.
SPIRE federation enables separate environments to establish trust with one another. This allows workloads operating in different clusters or locations to authenticate using cryptographically verified identities and establish mutual TLS (mTLS) connections.
As a result, applications can make trust decisions based on verified workload identities rather than relying solely on IP addresses, network boundaries, or firewall rules.
Enterprise PKI Integration
Enterprise environments often have established certificate and PKI infrastructure that must remain part of their security architecture.
Zero Trust Workload Identity Manager 1.1 adds configuration support for cert-manager and HashiCorp Vault plug-ins for UpstreamAuthority. This enables organizations to integrate their existing PKI systems into the workload identity architecture.
By connecting workload identity issuance with existing enterprise trust infrastructure, organizations can maintain their established certificate and compliance processes while introducing runtime-attested identities for OpenShift workloads.
Expanded OpenShift Availability
Another important change in version 1.1 is broader entitlement availability.
Previously available with Red Hat OpenShift Platform Plus, Zero Trust Workload Identity Manager is now also available to customers with Red Hat OpenShift Container Platform entitlements.
This makes workload identity capabilities more accessible to organizations running standard OpenShift environments as well as larger multi-cluster platforms.
Red Hat is also planning an end-to-end example demonstrating integration with Open Policy Agent (OPA) and OpenShift Service Mesh, helping organizations explore practical zero trust implementation patterns.
Why Workload Identity Matters for Agentic AI
The growing adoption of agentic AI makes strong workload identity increasingly important.
AI agents are becoming capable of performing tasks, interacting with applications, making decisions, and initiating actions with increasing levels of autonomy. As these systems become part of enterprise workflows, organizations need reliable ways to determine which workload or agent performed an action and whether that workload was authorized to do so.
Runtime-attested identities can provide AI workloads with verifiable identities that remain tied to their actual runtime environment.
With Zero Trust Workload Identity Manager, organizations can use workload identity to improve:
- Accountability: Associate actions with specific workloads or AI agents.
- Traceability: Follow activity across complex, multi-step workflows.
- Policy enforcement: Apply consistent access controls to workloads.
- Security: Reduce dependence on static credentials and long-lived secrets.
- Trust: Verify workload identity before allowing sensitive interactions.
As AI agents increasingly operate alongside traditional applications and human users, establishing a consistent identity model across these different actors will become an important component of enterprise security.
Building a Stronger Zero Trust Foundation
Zero Trust Workload Identity Manager 1.1 strengthens Red Hat’s approach to workload security by combining SPIFFE-based identity, runtime attestation, multi-cluster federation, enterprise PKI integration, and improved application compatibility.
For organizations running containerized applications on OpenShift, these capabilities can help create a more scalable identity architecture while reducing the operational challenges associated with traditional credentials and certificates.
As cloud-native applications and autonomous AI workloads continue to evolve, establishing verifiable identity at the workload level can provide an important foundation for building secure, distributed, and policy-driven environments.








