Infrastructure Identity for Platform Engineers

Infrastructure Identity for Platform Engineers

The weather has been perfect in Barcelona for the last week. Perfect for sitting in my room, taking our latest course on Platform Engineering University - Infrastructure Identity for Platform Engineers.

 The value prop is pretty simple. If you care about security, the experience of everyone and everything interacting with your infra, humans, services, or just not having your environment blow up… this is a must.

 So what is Infrastructure Identity? It's basically the practice of assigning cryptographically verified identities to every entity (Devs, AI, angry interns, services, and all kinds of our other machine friends) in your environment and using those identities to control access, rather than relying on passwords, static API keys, or VPN-based perimeters.

 In the last 10 years, we’ve massively scaled our infrastructure. And AI makes this even harder. Autoscaling clusters, microservices, CI/CD pipelines, AI workloads, and more. While at the same time, our access controls are stuck in the 1990s… It’s insane. Shared SSH keys, tokens that live forever, manual provisioning, etc etc. The kind of setup where a three-year-old API key is silently sitting in your environment, basically itching for the day it gets the chance to fulfil it’s dream and blow everything up.

 In the agentic era, it's not an outlandish argument that every static secret is a live vulnerability. And platform engineers, not just security teams, are the ones who need to fix it by treating identity as a platform-level capability alongside policy and state, shifting security load down into the platform, and making secure-by-design the path of least resistance.

 Our machine identities are getting smarter, faster, more capable, but most of all, there are just plain MORE of them. 100x more, and that number will keep growing. Agents multiply whatever already exists. If your baseline is shared keys and static secrets, you don't get agent-powered productivity, you get 100x exposure to the same failure modes. You cannot enable a future like that on top of access control that's locked in the past.

 Four modules. All bangers. Go check it out and tell me what you think.

Inicia sesión para ver o añadir un comentario.

Más artículos de Luca Galante

  • My advice for surviving layoffs

    This is a more serious and intense Platform Weekly than I have written in a long time. Yesterday, I had dinner with a…

    2 comentarios
  • 5 lessons from Nvidia, Kubecon & RSAC

    We’ve had one of the most hectic few weeks in Platform Engineering Community history - 6 in person events, 5…

    1 comentario
  • Platform engineering, AI &... tequila. What more do you need?

    This week the team and I were at KubeCon for a workshop, a roundtable, an exec dinner, a Meetup and of course… the one…

    1 comentario
  • PlatformCon is going worldwide

    I am extremely excited to announce that PlatformCon is launching Live Days in 2026 in both Sydney, and Sao Paulo! In…

    3 comentarios
  • 3 reasons AI needs platform engineering

    If you’ve read anything from me or the wider community in the last 6 months you’ve probably heard “Platform engineering…

  • Stop migrating. Start modernizing.

    Migration is an eternal topic in our world. We are always innovating, adding new tools, systems, workflows - that’s the…

    2 comentarios
  • 5 key principles of modern apps

    There is a lot of fanfare about agentic development at the moment. I was interviewing an engineering leader last week…

    2 comentarios
  • What platform engineers need to know for 2026

    One of the biggest advantages we have in the community is getting a clear eyed view on the data of what 100s of…

    2 comentarios
  • GitOps is the glue for your Platform!

    GitOps has quietly become the backbone of modern platform engineering. According to the State of Platform Engineering…

  • How to secure, control, and strengthen CI/CD artifacts

    If you’ve ever watched a pipeline crawl while it re-downloads the same dependencies (again), or had a build fail…

    2 comentarios

Explora categorías de contenido