Skip to content

Integrate MIAF and WFM identity profile SUPs - #25

Open
matlec wants to merge 2 commits into
pre-draftfrom
feat/miaf-integration
Open

Integrate MIAF and WFM identity profile SUPs#25
matlec wants to merge 2 commits into
pre-draftfrom
feat/miaf-integration

Conversation

@matlec

@matlec matlec commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Description

Integrates the two voted MIAF SUPs into the concepts and lexicon. This is the non-normative companion to the specification PR.

What changes

  • Adds an Identity and Trust concept page under a new Concepts > Identity section. It explains the Trust Domain model, SVIDs, the MIS role, and mutual TLS, with a diagram and links into the normative spec.
  • Rewrites Device Client Onboarding around MIAF. Operator-provisioned identities and mutual TLS replace the root-CA download, the WFM-assigned client identifier, and per-request payload signatures.
  • Updates the Device Capabilities wording so capability reporting happens when the client first connects rather than at onboarding.
  • Adds an Identity Terms group to the technical lexicon: Trust Domain, SPIFFE ID, SVID, Trust Bundle, Margo Identity Service, Principal, WFM Identity, and WFM Client Identity.

Issues Addressed

Change Type

Please select the relevant options:

  • Fix (change that resolves an issue)
  • New enhancement (change that adds specification content)
  • Content edits (change that edits existing content)

Checklist

  • I have read the CONTRIBUTING document.
  • My changes adhere to the established patterns, and best practices.

Integrate the MIAF and WFM Identity Profile SUPs
into the concepts and lexicon: add the Identity and
Trust page, rewrite device client onboarding around
operator-provisioned SVIDs and mTLS, and add MIAF
identity terms.

Signed-off-by: Matthias Lechner <matlec.public@gmail.com>
@matlec
matlec requested a review from a team as a code owner July 20, 2026 19:39
@phil-abb
phil-abb self-requested a review July 21, 2026 10:21

@phil-abb phil-abb left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I did an initial review and didn't spot anything to comment on.

The trust bundle is served as a single SPIFFE bundle, not a
SPIFFE Bundle Map.

Signed-off-by: Matthias Lechner <matlec.public@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants