We use it as part of mTLS to provide access to application metadata. It doesn't need to be SPIFFE but it made sense for our use case :)
I see, so a workload spins up and wants to learn something about itself and uses identity verification to gain access to it? My use case was an untrusted node getting a centrally issued key to join a p2p VPN