Stay organized with collectionsSave and categorize content based on your preferences.
Identity reflection for federated workloads
You can use Certificate Authority Service withworkload identity poolsand identity reflection to federate a third-party identity and obtain a certificate
that attests to this identity.
Identity reflection is a special certificate issuance mode that limits an
unprivileged certificate requester to requesting certificates with asubject
alternative name (SAN)corresponding to the identity in their credential. For
example, an Cloud Service Mesh
workload with a federated third-party identity token might be able to request a
certificate with a SAN corresponding to its Mesh identity, but cannot request a
certificate with any other SAN.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-11-11 UTC."],[],[]]