SECURITY / A CONCEPT NOTE
OIDC Federation
secretless repository authentication for CI/CD actions
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Secretless authentication. Instead of saving permanent password keys (which can leak) inside your deployment pipelines to access cloud resources, your pipeline gets a temporary trust token from its platform and swaps it for a short-lived key at runtime.
02 / FOLLOW THE MECHANISM
How a trust exchange flows
Pipeline
runs a job and requests a signed identity token from its host platform.
Platform
issues a temporary token confirming the repository name and job details.
Cloud Provider
receives the token, checks the signature, and validates the repository name.
Cloud IAM
exchanges the token for temporary access keys that expire in an hour.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
manually trade JWT for AWS credentials
aws sts assume-role-with-web-identity --role-arn arn:aws:iam::... --web-identity-token $JWTThe ellipsis omits required code or values. This sketch is not runnable as written.
05 / CHECK YOURSELF
Could you explain OIDC Federation to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityNetwork Policiesin-cluster firewall controls for isolating pod traffic