Agent Identity & Security
How do workload identities differ from service accounts in Kubernetes for AI agents?
Kubernetes service accounts are bound to pods, not to individual agent workflows or instances. Multiple agents running in the same pod share the same service account, recreating the shared-key problem at the cluster level. Catalyst workload identities are scoped to a specific agent's durable execution—even if the pod restarts or scales, the identity remains unique. This allows per-agent authorization and audit that Kubernetes service accounts cannot provide.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Identity & Security
What is a workload identity for an AI agent and why can't I just use a shared API key?
Explains workload identity for AI agents and the security limits of shared API keys in production.
- Agent Identity & Security
How does Catalyst assign a workload identity to an agent runner like LangGraph or CrewAI?
Describes how Catalyst injects workload identities into framework-agnostic agent runners.
- Agent Identity & Security
What security problems do shared API keys cause when multiple agents run in production?
Lists security problems from shared API keys in multi-agent production environments.