DL-440
A Kubernetes-hosted Runner authenticates with a projected ServiceAccount token (audience compass-runner, 600 s, kubelet-rotated) verified offline against a config-registered cluster’s OIDC issuer JWKS, bounded by a per-cluster maxTokenLifetime; the verified pod-bound token maps to SubjectRunner with Server-assigned Runner ID <cluster>/<node> (.→_), tenant-agnostic; an admission policy admits Runner-ServiceAccount pods only from the controller manager (per-controller or shared credentials) with the compass-runner DaemonSet as controller owner, lets only a named deployer create or change that DaemonSet, bars every other workload from the ServiceAccount, and grants its tokens only to kubelets; the DaemonSet runs maxSurge: 0; maxTokenLifetime may not be under the 600 s TokenRequest minimum, and a signing key shared across clusters fails every cluster holding it; the DL-316 auth-callout must accept the same token through the same verifier; the minted per-Runner token stays for non-Kubernetes Runners. Rejected: per-node host token file, one fleet-wide token, per-node Kubernetes Secret, TokenReview as the primary check
Status: Active (Matt, 2026-10-06)
Record: ../../platform/compass-runner-workload-identity/design.md#approach