Secretless Infrastructure with Multi-Cloud OIDC Federation
Eliminating long-lived cloud credentials forever. Step-by-step architecture for establishing OIDC trust between GitHub Actions, Kubernetes IRSA, Google Cloud Workload Identity, and Azure Entra ID.
Secretless Infrastructure with Multi-Cloud OIDC Federation
The Critical Risk of Static Cloud Credentials
Statistically, the majority of enterprise cloud compromises originate from leaked static credentials (AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY) accidentally committed to GitHub, leaked in build logs, or exposed via compromised developer laptops. Static credentials have indefinite lifetimes and zero geographic binding.
The Secretless Paradigm: OpenID Connect Federation
Zero-Trust mandates the complete purge of long-lived static credentials. By configuring OpenID Connect (OIDC) identity federation, external entities (GitHub Actions, Kubernetes pods, or developer workstations) exchange short-lived, cryptographically signed JSON Web Tokens (JWTs) for temporary cloud credentials (TTL: 15–60 minutes).
Architecture Flow: GitHub Actions to AWS IAM
- The CI runner requests an ephemeral OIDC token from GitHub's internal token minting service:
- Subject:
repo:tiny-cto/tinycto-tv:ref:refs/heads/main - Issuer:
https://token.actions.githubusercontent.com
- Subject:
- The CI runner calls AWS STS:
AssumeRoleWithWebIdentity. - AWS IAM validates the cryptographic signature of the token against GitHub's public JSON Web Key Set (JWKS).
- AWS IAM evaluates the trust policy: If the repository, branch, and environment match the trust condition, STS issues a temporary 15-minute credential pair.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"token.actions.githubusercontent.com:aud": "sts.amazonaws.com"
},
"StringLike": {
"token.actions.githubusercontent.com:sub": "repo:tiny-cto/tinycto-tv:ref:refs/heads/main"
}
}
}
]
}
Canonical Zero-Trust Defense per NIST SP 800-207 & CISA ZTMM 2.0: Eliminate static credentials, enforce eBPF microsegmentation, and preempt threats with in-kernel runtime telemetry.
