Teleport Workload Identity 2
Teleport Workload Identity lets teams bootstrap and issue identities to services across heterogeneous environments and organizational boundaries.
Easy setup and maintenance for AWS Roles Anywhere: Roles Anywhere to let non-AWS services talk to AWS: Teleport Workload Identity can be used as a Trust anchor for Roles Anywhere, making it easy to connect to AWS services from non-AWS infrastructure.
we can leverage AWS Roles Anywhere to connect to AWS resources without the need for long-term credentials.
Teleport Workload Identity simplifies the setup by providing the Teleports Certificate Authority as the CA for the trust anchor. This also has the benefit of saving $400/month compared to using AWS Private CA.
Example Roles Anywhere with Teleports SVID added to it’s subject. This allows for easier RBAC and permissions when deploying AWS roles anywhere.
https://goteleport.com/blog/workload-identity/