Completing spiffe-analysis.md
Your analysis document should now have four sections:
Section 1: Credential Inventory (Day 1 challenge)
- Every credential your provisioning service uses
- Risk rating for each
- How SPIFFE would change each
Section 2: SPIFFE ID Design (Day 2 challenge)
- SPIFFE IDs for each service component
- Trust domain choices
- mTLS peer relationships
Section 3: Federation Design (Day 6 challenge)
- Peer types (internal, partner, embedded hardware)
- Federation topology
- Limits of SPIFFE for satellite terminals
Section 4: SPIFFE vs. Classical PKI (today)
- The comparison table from this slide, filled in for your service
- One paragraph: "In my provisioning service, SPIFFE would help most with ___
and would not help with ___ because ___."