SPIFFE/SPIRE 工作负载身份:AI Agent 零信任身份网格深度实战

SPIFFE/SPIRE 工作负载身份:AI Agent 零信任身份网格深度实战

AI Agent 的身份困境

现代 AI Agent 系统正在经历从单体到异构网格的深刻演变。一个典型的生产级 Agent 系统包含数十种异构工作负载:LLM 推理服务、工具执行沙箱、向量数据库代理、A2A 网关、长时间运行的任务编排器、流式 Event Bus……这些组件运行在混合环境(Kubernetes、裸机、边缘节点、Serverless 函数)中,彼此动态通信。

传统安全边界在此彻底瓦解:

  • IP 白名单 → Serverless 没有固定 IP
  • 共享 Secret → 零信任要求"永不信任,始终验证"
  • 静态凭证 → Agent 生命周期以秒为单位
  • 单一控制平面 → 多集群、多云、多 VPC

SPIFFE(Secure Production Identity Framework for Everyone)及其最成熟的实现 SPIRE,正是解决这一困境的利器。


SPIFFE 核心概念全景

SPIFFE 定义了三个核心原语:

1. SPIFFE ID

全局唯一的工作负载身份标识,采用分层 URI 命名空间:

spiffe://trust-domain/service类型/环境/实例
spiffe://ybb.press/agent/planner/prod/spawn-3a7f
spiffe://ybb.press/tool/sandbox/python/wasm-edge
spiffe://ybb.press/gateway/a2a/ingress-1

2. SVID(SPIFFE Verifiable Identity Document)

绑定 SPIFFE ID 的可验证凭证。两种格式:

  • X.509-SVID:标准 X.509 证书,SAN URI 字段携带 SPIFFE ID
  • JWT-SVID:短期 JWT,适合传递上下文到下游

3. Trust Domain

信任域是身份隔离的边界。一个 trust domain 对应一组共享根 CA 的工作负载,跨域通信通过联邦(Federation)实现。

┌─────────────────────────────────────────────────────────┐
│                SPIFFE ID 命名空间设计                       │
├─────────────────────────────────────────────────────────┤
│  spiffe://trust-domain/path                              │
│  ├── /infra/k8s/pod/nginx-xxx                           │
│  ├── /ai/agent/planner/v1/aws                           │
│  ├── /ai/agent/planner/v1/gcp                           │
│  ├── /ai/tool/sandbox/wasm                              │
│  ├── /ai/db/vector/milvus                               │
│  ├── /ai/gateway/a2a                                    │
│  └── /infra/kvm/host/bare-metal-1                       │
└─────────────────────────────────────────────────────────┘

SPIRE 架构深度解析

SPIRE 是 SPIFFE 规范的参考实现,由 Server 和 Agent 组成:

┌──────────────────────────────────────────────────────────────────┐
│                    SPIRE Control Plane                            │
│  ┌────────────┐  ┌──────────────┐  ┌─────────────────────────┐   │
│  │   Server    │  │  Node API    │  │   Workload API          │   │
│  │             │  │  (gRPC)      │  │   (Unix Domain Socket)  │   │
│  │ - CA 管理   │  │              │  │                         │   │
│  │ - 注册条目  │  │ - 节点证明   │  │ - 工作负载证明          │   │
│  │ - 联邦同步  │  │ - SVID 分发  │  │ - SVID 响应             │   │
│  └────────────┘  └──────────────┘  └─────────────────────────┘   │
└──────────────────────────────────────────────────────────────────┘
        │                    │                        │
   节点证明(gRPC)      AgentDaemon               Workload Socket
        │                    │                        │
┌───────▼────────────────────▼────────────────────────▼────────────┐
│                    SPIRE Data Plane                               │
│  ┌─────────────┐  ┌──────────────┐  ┌────────────────────┐       │
│  │ K8s Node    │  │  Bare Metal  │  │  Serverless Pod    │       │
│  │ (k8s_psat)  │  │  (join_token)│  │  (docker/cgroup)   │       │
│  └─────────────┘  └──────────────┘  └────────────────────┘       │
└──────────────────────────────────────────────────────────────────┘

节点证明(Node Attestation)

SPIRE Agent 在启动时必须向 Server 证明"它运行的节点是谁"。SPIRE 支持多种证明器:

证明器 适用场景 原理
k8s_psat Kubernetes Projected Service Account Token
aws_iid AWS EC2/ECS Instance Identity Document
join_token 裸机/边缘 预共享一次性 Token
gcp_iit GCP GCE Instance Identity Token
azure_msi Azure Managed Service Identity

以下是 Kubernetes PSAT 配置的 Server 侧核心配置:

# server.conf - 节点证明配置
server {
    bind_address =                        
                    
点赞(0) 打赏

评论列表 共有 0 条评论

暂无评论
立即
投稿

微信公众账号

微信扫一扫加关注

发表
评论
返回
顶部