---
title: "Secretless Multi-Cloud Workload Identity Federation | Zero-Trust Architecture Canon"
description: "Statik bulut API anahtarlarını tamamen ortadan kaldıran; GitHub Actions, Kubernetes, AWS IAM, GCP ve Azure arasında kısa ömürlü OIDC güven ilişkisi kuran sıfır-parola altyapı mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/oidc-workload-identity-federation"
locale: "tr"
---

# Secretless Multi-Cloud Workload Identity Federation (`zt-arch-04`)

> **Sütun**: IDENTITY | **Arketip**: SECRETLESS_INFRASTRUCTURE
> **Engellenen MITRE ATT&CK Teknikleri**: T1552.001, T1078.004, T1537, T1580

## Mimari Özeti

Statik bulut API anahtarlarını tamamen ortadan kaldıran; GitHub Actions, Kubernetes, AWS IAM, GCP ve Azure arasında kısa ömürlü OIDC güven ilişkisi kuran sıfır-parola altyapı mimarisi.

## Saldırgan Modeli

Saldırganın CI/CD ortam değişkenlerindeki kalıcı bulut anahtarlarını çalarak bulut kaynaklarına sınırsız sızması.

## NIST SP 800-207 Temel İlkeleri

- Access to individual enterprise resources is granted on a per-session basis.
- The enterprise collects as much information as possible about the current state of network infrastructure and communications.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: GitHub Actions configured with AWS OIDC provider for production deployments.
- **Kimlik Doğrulama Zorlaması**: Short-lived IAM role assumption (TTL 1 hour) scoped to repository branch.
- **Ağ İzolasyonu**: Standard AWS IAM STS endpoint over public HTTPS.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Cross-cloud federated identity across AWS, GCP Workload Identity, and on-prem Kubernetes.
- **Kimlik Doğrulama Zorlaması**: Claims-based attribute checks enforcing Git commit SHA, environment, and signed tag.
- **Ağ İzolasyonu**: AWS STS VPC Endpoints used exclusively for internal workload token exchange.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: Dynamic multi-cloud mesh with zero long-lived credentials anywhere across edge, cloud, and DBs.
- **Kimlik Doğrulama Zorlaması**: Sub-15-minute ephemeral tokens dynamically bound to SPIFFE IDs and SLSA L3 provenance.
- **Ağ İzolasyonu**: Air-gapped private STS routing with egress identity filtering.

## Terraform HCL Manifest

```hcl
resource "aws_iam_openid_connect_provider" "github" {
  url             = "https://token.actions.githubusercontent.com"
  client_id_list  = ["sts.amazonaws.com"]
  thumbprint_list = ["6938fd4d98bab03faadb97b34396831e3780aea1"]
}

resource "aws_iam_role" "ci_deploy" {
  name = "TinyCTO-GitHub-Deploy"
  assume_role_policy = jsonencode({
    Version = "2012-10-17"
    Statement = [{
      Action = "sts:AssumeRoleWithWebIdentity"
      Effect = "Allow"
      Principal = { Federated = aws_iam_openid_connect_provider.github.arn }
      Condition = {
        StringEquals = {
          "token.actions.githubusercontent.com:aud" = "sts.amazonaws.com"
        }
        StringLike = {
          "token.actions.githubusercontent.com:sub" = "repo:tiny-cto/tinycto-tv:ref:refs/heads/main"
        }
      }
    }]
  })
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: ServiceAccount
metadata:
  name: finops-collector-sa
  namespace: analytics
  annotations:
    eks.amazonaws.com/role-arn: arn:aws:iam::123456789012:role/TinyCTO-Finops-Collector
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Secretless Multi-Cloud Workload Identity Federation | Zero-Trust Architecture Canon",
  "description": "Statik bulut API anahtarlarını tamamen ortadan kaldıran; GitHub Actions, Kubernetes, AWS IAM, GCP ve Azure arasında kısa ömürlü OIDC güven ilişkisi kuran sıfır-parola altyapı mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/oidc-workload-identity-federation"
}
```
