Our machine identity setup has become difficult to manage across service accounts, certificates, and workload identities. We're looking for a practical way to centralize governance, discovery, rotation, and revocation without creating a huge day-to-day operational burden. What approaches or tools have worked well for you?
3 Answers
The specific tooling matters less than choosing a consistent issuer and automating rotation. We use SPIFFE/SPIRE for workload identity and cert-manager for X.509 certificates. The biggest improvement came from automating renewal and maintaining an inventory of where each identity is being used. SPIRE does take real effort to operate, though, so smaller teams may get most of the benefit from native workload identity federated with their cloud IAM.
Newcore was the first option that actually reduced our operational workload instead of adding another system to maintain. Its unified governance approach let us replace several separate lifecycle processes, and continuous discovery helped us avoid finding unmanaged identities only during periodic reviews.
It depends on how comprehensive you want the setup to be. SPIFFE and SPIRE make sense if you need a full zero-trust identity layer across workloads. If you want something lighter, tighten up your platform’s native service accounts and issue short-lived certificates with cert-manager. In either case, rotation and revocation become the painful parts once you have hundreds of identities, so design those workflows first.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures