# SPIFFEE Identity Outside of Cluster

**URL:** https://linkerd.buoyant.io/t/spiffee-identity-outside-of-cluster/875
**Category:** Linkerd General Discussion
**Tags:** mtls
**Created:** [June 22, 2026, 9:12am UTC](https://linkerd.buoyant.io/t/spiffee-identity-outside-of-cluster/875 "2026-06-22T09:12:41Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![peacememories](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/peacememories/32/266_2.png) [@peacememories](https://linkerd.buoyant.io/u/peacememories)
#### Post date: [June 22, 2026, 9:12am UTC](https://linkerd.buoyant.io/t/spiffee-identity-outside-of-cluster/875/1 "2026-06-22T09:12:41Z")

</div>

Hi there. I’m pretty new to Linkerd and we’re currently just evaluating it, so please excuse my ignorance if this question has an obvious answer.

As far as I can tell, Linkerd’s automatic mTLS uses SPIFFEE to generate unique service ids. We are currently using mTLS to authenticate our services to Keycloak (an IDP), and have to do a lot of certificate plumbing basically manually.

Of course it would be extremely convenient to just use the Linkerd-generated identities as an mTLS identity towards Keycloak.

Is there a way to _not_ terminate the mTLS connection at one point, and instead connect directly with this identity to a service?

---

<div class="post-metadata">

### Author: ![Flynn](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/flynn/32/41_2.png) [@Flynn](https://linkerd.buoyant.io/u/Flynn)
#### Post date: [July 17, 2026, 4:12pm UTC](https://linkerd.buoyant.io/t/spiffee-identity-outside-of-cluster/875/2 "2026-07-17T16:12:29Z")

</div>

We use SPIFFE _outside_ the cluster for mesh expansion; _inside_ the cluster, our mTLS uses identities based on ServiceAccounts. I don’t know Keycloak very well, but I would think about whether you could use Keycloak to provide the trust anchor and identity issuer certificates to Linkerd… 🤔
