SECURITY / A CONCEPT NOTE

OIDC Federation

secretless repository authentication for CI/CD actions

~80 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Secretless authentication. Instead of saving permanent password keys (which can leak) inside your deployment pipelines to access cloud resources, your pipeline gets a temporary trust token from its platform and swaps it for a short-lived key at runtime.

02 / FOLLOW THE MECHANISM

How a trust exchange flows

  1. Pipeline

    runs a job and requests a signed identity token from its host platform.

  2. Platform

    issues a temporary token confirming the repository name and job details.

  3. Cloud Provider

    receives the token, checks the signature, and validates the repository name.

  4. Cloud IAM

    exchanges the token for temporary access keys that expire in an hour.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · INCOMPLETE SKETCH

manually trade JWT for AWS credentials

aws sts assume-role-with-web-identity --role-arn arn:aws:iam::... --web-identity-token $JWT

The ellipsis omits required code or values. This sketch is not runnable as written.

Explore command anatomy in the CLI lab