tibet-spiffe
SPIFFE/SPIRE Bridge with TIBET Provenance — your server thinks it's talking to SPIRE, but gets auditable trust.
Part of the TIBET protocol suite by Humotica AI Lab.
The Problem
SPIFFE/SPIRE tells you WHO a workload is. But not WHAT it did, or WHY.
When relay station 3 gets compromised, SPIRE says "yes, this is relay-3." But it can't tell you that relay-3 modified a drone command, changed a payment amount, or poisoned an AI pipeline.
The Solution
tibet-spiffe bridges SPIFFE identities with TIBET provenance:
| SPIFFE/SPIRE | tibet-spiffe adds |
|---|---|
| Workload identity (SVID) | + TIBET provenance chain |
| Node attestation | + Full audit trail |
| SVID rotation | + Rotation history with intent |
| Federation | + Cross-domain trust scoring |
| Trust domain | + FIR/A behavioral trust |
Your existing infrastructure sees standard SPIFFE IDs. TIBET adds the provenance layer underneath.
Install
pip install tibet-spiffe
Quick Start
from tibet_spiffe import AttestationEngine
engine = AttestationEngine(trust_domain="humotica.com")
# Node attestation (like SPIRE node-attestor)
node = engine.attest_node("relay-3", trust_score=0.8)
print(node.svid.spiffe_id) # spiffe://humotica.com/node/relay-3
# Workload attestation (like SPIRE workload-attestor)
api = engine.attest_workload("api-server", node_svid=node.svid)
print(api.svid.spiffe_id) # spiffe://humotica.com/workload/api-server
print(api.svid.jis_did) # jis:api-server
# Identity bridge (SPIFFE ↔ JIS)
did = engine.bridge.spiffe_to_did(api.svid.spiffe_id)
spiffe = engine.bridge.did_to_spiffe(did)
# Full audit trail
for token in engine.audit_trail():
print(f"[{token['action']}] {token['erachter']['intent']}")
CLI
# Interactive demo
tibet-spiffe demo
# Attest a node
tibet-spiffe attest-node relay-3 -d humotica.com -t 0.8
# Attest a workload
tibet-spiffe attest-workload api-server -d humotica.com -j
Architecture
┌─────────────────────────────────────────────────┐
│ Your Infrastructure │
│ (sees standard SPIFFE IDs) │
│ │
│ spiffe://humotica.com/workload/api-server │
│ spiffe://humotica.com/node/relay-3 │
│ │
├─────────────────────────────────────────────────┤
│ tibet-spiffe bridge │
│ │
│ SPIFFE ID ←→ JIS DID (bidirectional) │
│ SVID issuance = TIBET token │
│ SVID rotation = TIBET provenance chain │
│ Attestation = TIBET-audited │
│ Federation = trust-scored │
│ │
├─────────────────────────────────────────────────┤
│ TIBET Layer │
│ • ERIN: what was attested │
│ • ERAAN: what it depends on │
│ • EROMHEEN: where it happened │
│ • ERACHTER: why it was needed │
└─────────────────────────────────────────────────┘
Integration with tibet-workload
from tibet_spiffe import AttestationEngine
from tibet_workload import WorkloadEngine
spiffe = AttestationEngine(trust_domain="humotica.com")
workload = WorkloadEngine()
workload.connect_spiffe(spiffe) # Link workload steps to SPIFFE SVIDs
IETF Drafts
License
MIT — Humotica AI Lab 2025-2026
Credits
Designed by Jasper van de Meent. Built by Jasper and Root AI as part of HumoticaOS.
Stack-positie: Groep substrate · Bootstrap = OSAPI-handshake naar tibet + jis (fail → snaft-rule + tibet-pol-rapport) · ← jis-core · tibet-workload → · See STACK.md · See demo/golden-path/ for the spine end-to-end.
Enterprise
For private hub hosting, SLA support, custom integrations, or compliance guidance:
| Enterprise | enterprise@humotica.com |
| Support | support@humotica.com |
| Security | security@humotica.com |
See ENTERPRISE.md for details.
Metadata
Release files for tibet-spiffe 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tibet_spiffe-0.1.1.tar.gz | 12.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tibet_spiffe-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.2 kB
Release files / tibet_spiffe-0.1.1.tar.gz
| Download URL | tibet_spiffe-0.1.1.tar.gz |
|---|---|
| Size | 12.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8be95c7ba77208c0634a7cbfa71bffa99021113d399df5f8c716859e2b4b852b
|
|
BLAKE2b-256 checksum How to use checksums |
4aa42db0696bc6a03b1e1add5fcd072a356db79842857084bef281d8a0f3f11e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|
Release files / tibet_spiffe-0.1.1-py3-none-any.whl
| Download URL | tibet_spiffe-0.1.1-py3-none-any.whl |
|---|---|
| Size | 13.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3fe65afeb9f351f1560721615782fc3bc9e73bbf69a29d47aa0d16981a988e53
|
|
BLAKE2b-256 checksum How to use checksums |
0deaea45c427da5cc024b4ea20b8037859c52b146c22da7ff7f0b3c098e23271
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|