Skip to content

Credential Bindings

The Credential Bindings screen is where you connect a credential source to a workload and control how it is delivered. A binding says: this workload identity receives this credential, delivered by injection into its outbound requests, as a secure file, or both.

Open it from Configure → Credential Bindings in the sidebar (/ui/credential-bindings).

Two cards summarize injection status and the credential-type distribution. The table lists each binding with:

  • Status: Active or Inactive.
  • Name.
  • Workload Identity: the workload that receives the credential.
  • Credential Name: the credential source being delivered.
  • Services: the services the binding targets.
  • Usage (1h): recent read and injection counts.

Search by workload identity. Each row’s menu offers Edit and Delete.

Choose Create Binding and fill in:

  • Name (optional, auto-generated from the workload and credential).
  • Workload ID (required): the workload that receives the credential.
  • Credential (required): the credential source to deliver.
  • Human ID (optional): scope the binding to a specific person.
  • Propagation (at least one): Secure File delivers the credential as an identity-enforced file that only the matched workload can read; Injection adds the credential into matching outbound requests. With Injection on, you target services with selector groups, or pick a service to prefill them.

Edit or delete a binding from its row menu. Clicking a binding opens a detail panel showing its workload, credential, and propagation, plus tables for HTTP Injections (credentials added to outbound requests) and Credential Files (credentials delivered as secure files).