Skip to main content

tibet-spiffe

SPIFFE/SPIRE Bridge with TIBET Provenance — your server thinks it's talking to SPIRE, but gets auditable trust.

Part of the TIBET protocol suite by Humotica AI Lab.

The Problem

SPIFFE/SPIRE tells you WHO a workload is. But not WHAT it did, or WHY.

When relay station 3 gets compromised, SPIRE says "yes, this is relay-3." But it can't tell you that relay-3 modified a drone command, changed a payment amount, or poisoned an AI pipeline.

The Solution

tibet-spiffe bridges SPIFFE identities with TIBET provenance:

SPIFFE/SPIRE tibet-spiffe adds
Workload identity (SVID) + TIBET provenance chain
Node attestation + Full audit trail
SVID rotation + Rotation history with intent
Federation + Cross-domain trust scoring
Trust domain + FIR/A behavioral trust

Your existing infrastructure sees standard SPIFFE IDs. TIBET adds the provenance layer underneath.

Install

pip install tibet-spiffe

Quick Start

from tibet_spiffe import AttestationEngine

engine = AttestationEngine(trust_domain="humotica.com")

# Node attestation (like SPIRE node-attestor)
node = engine.attest_node("relay-3", trust_score=0.8)
print(node.svid.spiffe_id)  # spiffe://humotica.com/node/relay-3

# Workload attestation (like SPIRE workload-attestor)
api = engine.attest_workload("api-server", node_svid=node.svid)
print(api.svid.spiffe_id)   # spiffe://humotica.com/workload/api-server
print(api.svid.jis_did)     # jis:api-server

# Identity bridge (SPIFFE ↔ JIS)
did = engine.bridge.spiffe_to_did(api.svid.spiffe_id)
spiffe = engine.bridge.did_to_spiffe(did)

# Full audit trail
for token in engine.audit_trail():
    print(f"[{token['action']}] {token['erachter']['intent']}")

CLI

# Interactive demo
tibet-spiffe demo

# Attest a node
tibet-spiffe attest-node relay-3 -d humotica.com -t 0.8

# Attest a workload
tibet-spiffe attest-workload api-server -d humotica.com -j

Architecture

┌─────────────────────────────────────────────────┐
│  Your Infrastructure                            │
│  (sees standard SPIFFE IDs)                     │
│                                                 │
│  spiffe://humotica.com/workload/api-server      │
│  spiffe://humotica.com/node/relay-3             │
│                                                 │
├─────────────────────────────────────────────────┤
│  tibet-spiffe bridge                            │
│                                                 │
│  SPIFFE ID ←→ JIS DID (bidirectional)           │
│  SVID issuance = TIBET token                    │
│  SVID rotation = TIBET provenance chain         │
│  Attestation = TIBET-audited                    │
│  Federation = trust-scored                      │
│                                                 │
├─────────────────────────────────────────────────┤
│  TIBET Layer                                    │
│  • ERIN: what was attested                      │
│  • ERAAN: what it depends on                    │
│  • EROMHEEN: where it happened                  │
│  • ERACHTER: why it was needed                  │
└─────────────────────────────────────────────────┘

Integration with tibet-workload

from tibet_spiffe import AttestationEngine
from tibet_workload import WorkloadEngine

spiffe = AttestationEngine(trust_domain="humotica.com")
workload = WorkloadEngine()
workload.connect_spiffe(spiffe)  # Link workload steps to SPIFFE SVIDs

IETF Drafts

License

MIT — Humotica AI Lab 2025-2026

Credits

Designed by Jasper van de Meent. Built by Jasper and Root AI as part of HumoticaOS.


Stack-positie: Groep substrate · Bootstrap = OSAPI-handshake naar tibet + jis (fail → snaft-rule + tibet-pol-rapport) · ← jis-core · tibet-workload → · See STACK.md · See demo/golden-path/ for the spine end-to-end.

Enterprise

For private hub hosting, SLA support, custom integrations, or compliance guidance:

Enterprise enterprise@humotica.com
Support support@humotica.com
Security security@humotica.com

See ENTERPRISE.md for details.

Metadata

Release files for tibet-spiffe 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tibet-spiffe 0.1.1
File Size Uploaded
tibet_spiffe-0.1.1.tar.gz 12.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tibet-spiffe 0.1.1
File Interpreter ABI Platform
tibet_spiffe-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 25.2 kB

Release files / tibet_spiffe-0.1.1.tar.gz

Download URL tibet_spiffe-0.1.1.tar.gz
Size 12.0 kB
Tags Source
SHA-256 checksum
How to use checksums
8be95c7ba77208c0634a7cbfa71bffa99021113d399df5f8c716859e2b4b852b
BLAKE2b-256 checksum
How to use checksums
4aa42db0696bc6a03b1e1add5fcd072a356db79842857084bef281d8a0f3f11e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / tibet_spiffe-0.1.1-py3-none-any.whl

Download URL tibet_spiffe-0.1.1-py3-none-any.whl
Size 13.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3fe65afeb9f351f1560721615782fc3bc9e73bbf69a29d47aa0d16981a988e53
BLAKE2b-256 checksum
How to use checksums
0deaea45c427da5cc024b4ea20b8037859c52b146c22da7ff7f0b3c098e23271
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page