So far it seems to be a spec for how to define and then use standard naming (and naturally tokens/certs) to identify and then of course authenticate workloads #KubeCon
Best of all, a quick Google shows that there are already people playing with #SPIFFE and #OpenPolicyAgent
https://github.com/spiffe/spire-tutorials/blob/main/k8s/envoy-opa/k8s/backend/config/opa-policy.rego
This session is showing off integration with #CertManager
#kubecon #SPIFFE #OpenPolicyAgent #certmanager