SPIFFE/SPIRE 工作负载身份:AI Agent 零信任身份网格深度实战
AI Agent 的身份困境
现代 AI Agent 系统正在经历从单体到异构网格的深刻演变。一个典型的生产级 Agent 系统包含数十种异构工作负载:LLM 推理服务、工具执行沙箱、向量数据库代理、A2A 网关、长时间运行的任务编排器、流式 Event Bus……这些组件运行在混合环境(Kubernetes、裸机、边缘节点、Serverless 函数)中,彼此动态通信。
传统安全边界在此彻底瓦解:
- IP 白名单 → Serverless 没有固定 IP
- 共享 Secret → 零信任要求"永不信任,始终验证"
- 静态凭证 → Agent 生命周期以秒为单位
- 单一控制平面 → 多集群、多云、多 VPC
SPIFFE(Secure Production Identity Framework for Everyone)及其最成熟的实现 SPIRE,正是解决这一困境的利器。
SPIFFE 核心概念全景
SPIFFE 定义了三个核心原语:
1. SPIFFE ID
全局唯一的工作负载身份标识,采用分层 URI 命名空间:
spiffe://trust-domain/service类型/环境/实例
spiffe://ybb.press/agent/planner/prod/spawn-3a7f
spiffe://ybb.press/tool/sandbox/python/wasm-edge
spiffe://ybb.press/gateway/a2a/ingress-1
2. SVID(SPIFFE Verifiable Identity Document)
绑定 SPIFFE ID 的可验证凭证。两种格式:
- X.509-SVID:标准 X.509 证书,SAN URI 字段携带 SPIFFE ID
- JWT-SVID:短期 JWT,适合传递上下文到下游
3. Trust Domain
信任域是身份隔离的边界。一个 trust domain 对应一组共享根 CA 的工作负载,跨域通信通过联邦(Federation)实现。
┌─────────────────────────────────────────────────────────┐
│ SPIFFE ID 命名空间设计 │
├─────────────────────────────────────────────────────────┤
│ spiffe://trust-domain/path │
│ ├── /infra/k8s/pod/nginx-xxx │
│ ├── /ai/agent/planner/v1/aws │
│ ├── /ai/agent/planner/v1/gcp │
│ ├── /ai/tool/sandbox/wasm │
│ ├── /ai/db/vector/milvus │
│ ├── /ai/gateway/a2a │
│ └── /infra/kvm/host/bare-metal-1 │
└─────────────────────────────────────────────────────────┘
SPIRE 架构深度解析
SPIRE 是 SPIFFE 规范的参考实现,由 Server 和 Agent 组成:
┌──────────────────────────────────────────────────────────────────┐
│ SPIRE Control Plane │
│ ┌────────────┐ ┌──────────────┐ ┌─────────────────────────┐ │
│ │ Server │ │ Node API │ │ Workload API │ │
│ │ │ │ (gRPC) │ │ (Unix Domain Socket) │ │
│ │ - CA 管理 │ │ │ │ │ │
│ │ - 注册条目 │ │ - 节点证明 │ │ - 工作负载证明 │ │
│ │ - 联邦同步 │ │ - SVID 分发 │ │ - SVID 响应 │ │
│ └────────────┘ └──────────────┘ └─────────────────────────┘ │
└──────────────────────────────────────────────────────────────────┘
│ │ │
节点证明(gRPC) AgentDaemon Workload Socket
│ │ │
┌───────▼────────────────────▼────────────────────────▼────────────┐
│ SPIRE Data Plane │
│ ┌─────────────┐ ┌──────────────┐ ┌────────────────────┐ │
│ │ K8s Node │ │ Bare Metal │ │ Serverless Pod │ │
│ │ (k8s_psat) │ │ (join_token)│ │ (docker/cgroup) │ │
│ └─────────────┘ └──────────────┘ └────────────────────┘ │
└──────────────────────────────────────────────────────────────────┘
节点证明(Node Attestation)
SPIRE Agent 在启动时必须向 Server 证明"它运行的节点是谁"。SPIRE 支持多种证明器:
| 证明器 | 适用场景 | 原理 |
|---|---|---|
k8s_psat |
Kubernetes | Projected Service Account Token |
aws_iid |
AWS EC2/ECS | Instance Identity Document |
join_token |
裸机/边缘 | 预共享一次性 Token |
gcp_iit |
GCP GCE | Instance Identity Token |
azure_msi |
Azure | Managed Service Identity |
以下是 Kubernetes PSAT 配置的 Server 侧核心配置:
# server.conf - 节点证明配置
server {
bind_address =

发表评论 取消回复