Workload Identity Lab
Zero Trust Network Builder
Design secure service-to-service communication with SPIFFE workload identity, mTLS, and trust federation. Each scenario drops you into a real architectural decision before any workload issues its first SVID.
6 scenarios~12 minutesHard
Hard
How the simulator works
- Each scenario shows a real SPIFFE/SPIRE configuration, mTLS handshake flow, or federation setup with a hidden design or security flaw.
- Identify the issue from four plausible options; the wrong answers explain why they look tempting but are not the root cause.
- Read the production explanation, follow the linked SPIFFE/SPIRE module, and move to the next scenario.
- Score yourself across six rounds covering SPIFFE ID design, workload attestation, mTLS bootstrap, authorization, federation, and SVID rotation.