Skip to main content

spiffe package

Overview

The spiffe package, part of the py-spiffe library, provides SPIFFE support and essential tools for interacting with the SPIFFE Workload API. It simplifies the management and validation of SPIFFE identities, supporting X509-SVIDs, JWT-SVIDs, and X.509 CA and JWKS Bundles.

Features

  • Automatic Management of SPIFFE Identities: Streamlines fetching, renewing, and validation of X.509 and JWT SVIDs.
  • Seamless Integration with SPIFFE Workload API: Facilitates communication with SPIRE or other SPIFFE Workload API compliant systems.
  • Continuous Update Handling: Automatically receives and applies updates for SVIDs and bundles, ensuring your application always uses valid certificates.

Prerequisites

  • A running instance of SPIRE or another SPIFFE Workload API implementation.
  • The SPIFFE_ENDPOINT_SOCKET environment variable set to the address of the Workload API (e.g., unix: /tmp/spire-agent/public/api.sock), or provided programmatically.

Usage

Below are examples demonstrating the core functionalities of the spiffe package.

WorkloadApiClient

from spiffe import WorkloadApiClient

# Fetch X.509 and JWT SVIDs
with WorkloadApiClient() as client:
    x509_svid = client.fetch_x509_svid()
    print(f'SPIFFE ID: {x509_svid.spiffe_id}')

    jwt_svid = client.fetch_jwt_svid(audience={"test"})
    print(f'SPIFFE ID: {jwt_svid.spiffe_id}')

By default, blocking Workload API calls wait without a deadline. To avoid indefinitely blocking a calling thread when the Workload API is unresponsive, set default_timeout on the client or pass a per-call timeout in seconds:

with WorkloadApiClient(default_timeout=5.0) as client:
    jwt_svid = client.fetch_jwt_svid(audience={"test"})
    jwt_svid = client.fetch_jwt_svid(audience={"test"}, timeout=1.0)

Per-call timeouts override default_timeout. Deadline expiry is reported as the SPIFFE-specific error for the call, such as FetchJwtSvidError. Timeouts do not apply to long-lived streaming methods.

X509Source

from spiffe import X509Source

# Automatically manage X.509 SVIDs and CA bundles
with X509Source() as source:
    x509_svid = source.svid
    print(f'SPIFFE ID: {x509_svid.spiffe_id}')

JwtSource

from spiffe import JwtSource

# Manage and validate JWT SVIDs and JWKS bundles
with JwtSource() as source:
    jwt_svid = source.fetch_svid(audience={'test'})
    print(f'SPIFFE ID: {jwt_svid.spiffe_id}')
    print(f'Token: {jwt_svid.token}')

Contributing

We welcome contributions to the spiffe package! Please see our contribution guidelines for more details. For feedback and issues, please submit them through the GitHub issue tracker.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

spiffe-0.3.1.tar.gz (41.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

spiffe-0.3.1-py3-none-any.whl (59.1 kB view details)

Uploaded Python 3

File details

Details for the file spiffe-0.3.1.tar.gz.

File metadata

  • Download URL: spiffe-0.3.1.tar.gz
  • Upload date:
  • Size: 41.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for spiffe-0.3.1.tar.gz
Algorithm Hash digest
SHA256 61ce83f4af7d41fed1e68f8c67081f169c963a8640a6abc813a7752f7aabbcaf
MD5 b9ff8969092542340d8a91707b1ef9dd
BLAKE2b-256 8587b7e9e103d370960c045b8b9f87ffce579ff159325da081c552d7f3468285

See more details on using hashes here.

File details

Details for the file spiffe-0.3.1-py3-none-any.whl.

File metadata

  • Download URL: spiffe-0.3.1-py3-none-any.whl
  • Upload date:
  • Size: 59.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.3 {"installer":{"name":"uv","version":"0.12.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for spiffe-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 f5d0e7c7a517c270296ec17c7d03a7737fa2ea9ff2dc8bb79e94e8fffcbd165d
MD5 14f22e76e2d17d3cd3e850eb717b02d2
BLAKE2b-256 b1af5a71d12a49ae5e0dfd3829645ee1dc26db7d9ec29a150e6245b0dccd6442

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page