CONCEPT Cited by 3 sources
Workload identity¶
A workload identity is a stable, fine-grained identifier naming the logical unit of software running on a host — typically more specific than "this instance" (AMI/VM) and as specific as "this container" or "this service". Workload identities are the canonical resolution target for ip-attribution: any given packet or flow should be attributable to the workload identity that owns it.
Provisioning¶
Two canonical shapes appear in Netflix's architecture:
- EC2-instance path. A boot-time provisioning service (Metatron at Netflix) issues an identity certificate per instance; the identity is readable from local disk by any process running on the instance.
- Container path. A per-host daemon
(IPManAgent) writes
IP → workload-ID(and(IP, port) → workload-IDfor shared-IP scenarios) into an eBPF map when each container starts; kernel-resident observers can resolve the workload owning a socket without a userspace round-trip (ebpf-map-for-local-attribution).
Why this matters¶
Workload identities turn "who is at this IP?" from a topology question into a queryable fact at capture time. Local workload identity resolution is the load-bearing move that makes accurate heartbeat-based ownership possible — every flow emerges pre-tagged with the local identity, so downstream attribution doesn't need to reconstruct it.
Adjacent but distinct¶
Workload identity ≠ concepts/workload-identity in the IAM / SPIFFE sense (which concerns authenticating a workload to other services). The Netflix post uses the term for the attribution side: who owns the packet, not who is allowed to send it. Both problems benefit from the same substrate (the Metatron cert), but the consumer surfaces are different.
Seen in¶
- sources/2025-04-08-netflix-how-netflix-accurately-attributes-ebpf-flow-logs — canonical instance; names Metatron certs (EC2 path) and IPMan's eBPF map (container path) as the two substrates from which FlowExporter resolves the local workload identity at flow-capture time.
- sources/2026-06-19-netflix-data-projects-managing-data-assets-at-netflix-scale — extends the concept to authorization: Data Projects provision a durable synthetic identity that scheduled workloads execute under, surviving personnel changes. Demonstrates workload identity as both attribution substrate (flow logs) and authorization substrate (workflow execution).
- sources/2026-09-24-zalando-agentic-platform-open-sourcing-the-agentic-identity-broker — SPIFFE as the planned substrate to separate an agent's machine identity from the human's. Zalando's Agentic Identity Broker today leans on plain OAuth 2.0 access tokens that tie the user's and the agent's identities together; from running their microservice identity infra they know a central STS called on every hop can become expensive or prohibitive in latency, so they plan to adopt SPIFFE (and track the IETF WIMSE WG + AIMS draft) to attest the agent's identity independently of the human's. Canonical agentic-identity instance of workload identity in the IAM/SPIFFE sense — the "who is allowed to send it" side named explicitly distinct from the human principal.
Related¶
- ip-attribution
- durable-synthetic-identity · identity-umbrella
- systems/netflix-metatron · systems/netflix-ipman · systems/netflix-flowexporter · systems/netflix-titus
- systems/netflix-data-projects · systems/netflix-maestro
- ebpf-map-for-local-attribution
- project-scoped-identity-for-workloads