<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-wimse-workload-identity-practices" target="https://datatracker.ietf.org/doc/html/draft-ietf-wimse-workload-identity-practices-03">
   <front>
      <title>Workload Identity Practices</title>
      <author initials="A." surname="Schwenkschuster" fullname="Arndt Schwenkschuster">
         <organization>SPIRL</organization>
      </author>
      <author initials="Y." surname="Rosomakho" fullname="Yaroslav Rosomakho">
         <organization>Zscaler</organization>
      </author>
      <date month="October" day="17" year="2025" />
      <abstract>
	 <t>   This document describes industry practices for providing secure
   identities to workloads in container orchestration, cloud platforms,
   and other workload platforms.  It explains how workloads obtain
   credentials for external authentication purposes, without managing
   long-lived secrets directly.  It does not take into account the
   standards work in progress for the WIMSE architecture
   [I-D.ietf-wimse-arch] and other protocols, such as
   [I-D.ietf-wimse-s2s-protocol].

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-wimse-workload-identity-practices-03" />
   
</reference>
