Trading a Cloud Identity for Your Own: Workload Attestation on Managed Compute
Netflix describes a workload attestation method for Apache Spark jobs on Amazon EMR. The system exchanges a cloud IAM role for an internal PKI identity. This allows managed workloads to access encrypted data and enforce table-level access controls. The design relies on a one-to-one mapping between data projects and IAM roles to ensure trust.
Netflix engineers built a bridge that lets a Spark job running on Amazon EMR replace its AWS execution role with a short‑lived X.509 certificate issued by Netflix’s internal PKI, Metatron. The control plane signs a payload that maps the job’s Data Project to a dedicated IAM role, the driver obtains a pre‑signed URL from AWS STS to prove it holds that role, and the identity service validates the claim before issuing the certificate. This exchange turns a cloud‑only identity into a first‑class internal one that can satisfy table‑level ACLs and encrypted‑column reads. The one‑to‑one mapping between a Data Project and an IAM role lets Netflix enforce consistent access control across scheduled and interactive workloads, even when the compute is fully managed. By sharding roles across a small pool of accounts, the design scales to the projected ten thousands of Data Projects while keeping workload roles isolated from the launch control planes. The approach also demonstrates how any managed environment that supplies cloud credentials can produce a verifiable statement of its own identity. It remains unclear whether the signed claim alone can prevent replay attacks in all deployment scenarios, as the payload travels through infrastructure that is not fully under Netflix’s control. Netflix attributes the trust in the mapping to the Data Project service, but the long‑term authority of that service has not been independently verified. The description notes that the pattern is similar to AWS IAM authentication in HashiCorp Vault, yet the equivalence of security guarantees between those systems and Netflix’s implementation is still uncertain.