spiffe / spiffe/spiffe

Workload API spec refers to undefined "SPIFFE id of the trust domain"

Open
#396 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Shell
Stars
1.9k
Forks
207
Avg merge
7d 19h
Merged PRs (30d)
1

Description

At several places in the SPIFFE Workload API spec, including in comments in the gRPC schema as well as the spec document itself, there is reference to a "SPIFFE id of the trust domain" and "SPIFFE id of the foreign trust domain". The problem is, at no place in the specification can I find anywhere that defines what the SPIFFE id of the trust domain is. What is defined in Section 3.1 of the SPIFFE ID spec is a "SPIFFE id for the signing authority". Presumably, these two things are intended to be the same thing, but nothing in the spec makes that clear.

Either the Workload API specification should explicitly state "SPIFFE id of the signing authority of the trust domain", or section 3.1 of the SPIFFE Id spec should have statement along the lines of "The SPIFFE id of the signing authority for the trust domain is also referred to as the SPIFFE id of the trust domain".

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read the SPIFFE Workload API specification, including its gRPC schema comments, and Section 3.1 of the SPIFFE ID specification. Compare the terms for the trust domain and signing authority, then make the terminology consistent and explicit; done means both specifications clearly define the relationship.

Written by the indexing model from the issue text.

Assessment

Tech stack
grpc
Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.