Workload Identity Lab

Zero Trust Network Builder

Design secure service-to-service communication with SPIFFE workload identity, mTLS, and trust federation. Each scenario drops you into a real architectural decision before any workload issues its first SVID.

6 scenarios~12 minutesHard
RUNHard

How the simulator works

  • Each scenario shows a real SPIFFE/SPIRE configuration, mTLS handshake flow, or federation setup with a hidden design or security flaw.
  • Identify the issue from four plausible options; the wrong answers explain why they look tempting but are not the root cause.
  • Read the production explanation, follow the linked SPIFFE/SPIRE module, and move to the next scenario.
  • Score yourself across six rounds covering SPIFFE ID design, workload attestation, mTLS bootstrap, authorization, federation, and SVID rotation.