Broker API
Some workloads cannot fetch their own credentials. The Broker API lets a trusted process on the same node obtain SVIDs on their behalf, over a dedicated mutually authenticated socket on the Agent called the Broker Endpoint.
Overview
How brokers obtain SVIDs on a workload's behalf.
Enabling
Turn on the Broker API and verify it.
Broker Policy
Allowlist brokers and the references they may use.
Reference Types
How a broker names a workload the Agent resolves.
Operations
Caching and metrics to watch.
Troubleshooting
Diagnose common Broker Endpoint issues.