4 papers
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
Surya Teja Avirneni
This paper introduces the Identity Control Plane (ICP), an architectural framework for enforcing identity-aware Zero Trust access across human users, workloads, and automation syst…
Intent-Aware Authorization for Zero Trust CI/CD
Surya Teja Avirneni
This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether…
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
Surya Teja Avirneni
Credential brokers offer a way to separate identity from access in CI/CD systems. This paper shows how verifiable identities issued at runtime, such as those from SPIFFE, can be us…
Establishing Workload Identity for Zero Trust CI/CD: From Secrets to SPIFFE-Based Authentication
Surya Teja Avirneni
CI/CD systems have become privileged automation agents in modern infrastructure, but their identity is still based on secrets or temporary credentials passed between systems. In en…