Credential Bindings
The Credential Bindings screen is where you connect a credential source to a workload and control how it is delivered. A binding says: this workload identity receives this credential, delivered by injection into its outbound requests, as a secure file, or both.
Open it from Configure → Credential Bindings in the sidebar (/ui/credential-bindings).
What you see
Section titled “What you see”Two cards summarize injection status and the credential-type distribution. The table lists each binding with:
- Status: Active or Inactive.
- Name.
- Workload Identity: the workload that receives the credential.
- Credential Name: the credential source being delivered.
- Services: the services the binding targets.
- Usage (1h): recent read and injection counts.
Search by workload identity. Each row’s ⋯ menu offers Edit and Delete.
Create a binding
Section titled “Create a binding”Choose Create Binding and fill in:
- Name (optional, auto-generated from the workload and credential).
- Workload ID (required): the workload that receives the credential.
- Credential (required): the credential source to deliver.
- Human ID (optional): scope the binding to a specific person.
- Propagation (at least one): Secure File delivers the credential as an identity-enforced file that only the matched workload can read; Injection adds the credential into matching outbound requests. With Injection on, you target services with selector groups, or pick a service to prefill them.
Edit, delete, and detail
Section titled “Edit, delete, and detail”Edit or delete a binding from its row ⋯ menu. Clicking a binding opens a detail panel showing its workload, credential, and propagation, plus tables for HTTP Injections (credentials added to outbound requests) and Credential Files (credentials delivered as secure files).
Next steps
Section titled “Next steps”- Credentials: how credential delivery works.
- Credentials: register the source a binding delivers.
- Services: the destinations injection rules target.