---
title: "Chapter 04: Secretless Infrastructure with Multi-Cloud OIDC Federation | TinyCTO Zero-Trust Canon"
description: "Eliminating long-lived cloud credentials forever. Step-by-step architecture for establishing OIDC trust between GitHub Actions, Kubernetes IRSA, Google Cloud Workload Identity, and Azure Entra ID."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_manuals_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/manuals/04-secretless-infrastructure-oidc-federation"
locale: "en"
---

# Chapter 04: Secretless Infrastructure with Multi-Cloud OIDC Federation

> **Canonical Zero-Trust Engineering Field Manual**
> **Read Time**: 16 min read | **Maturity**: ADVANCED | **NIST SP 800-207**: NIST SP 800-207 Tenet 3

## Executive Summary

Eliminating long-lived cloud credentials forever. Step-by-step architecture for establishing OIDC trust between GitHub Actions, Kubernetes IRSA, Google Cloud Workload Identity, and Azure Entra ID.

## Chapter Content

# Secretless Infrastructure with Multi-Cloud OIDC Federation

## The Critical Risk of Static Cloud Credentials
Statistically, the majority of enterprise cloud compromises originate from leaked static credentials (`AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`) accidentally committed to GitHub, leaked in build logs, or exposed via compromised developer laptops. Static credentials have indefinite lifetimes and zero geographic binding.

## The Secretless Paradigm: OpenID Connect Federation
Zero-Trust mandates the complete purge of long-lived static credentials. By configuring OpenID Connect (OIDC) identity federation, external entities (GitHub Actions, Kubernetes pods, or developer workstations) exchange short-lived, cryptographically signed JSON Web Tokens (JWTs) for temporary cloud credentials (TTL: 15–60 minutes).

## Architecture Flow: GitHub Actions to AWS IAM
1. The CI runner requests an ephemeral OIDC token from GitHub's internal token minting service:
   - Subject: `repo:tiny-cto/tinycto-tv:ref:refs/heads/main`
   - Issuer: `https://token.actions.githubusercontent.com`
2. The CI runner calls AWS STS: `AssumeRoleWithWebIdentity`.
3. AWS IAM validates the cryptographic signature of the token against GitHub's public JSON Web Key Set (JWKS).
4. AWS IAM evaluates the trust policy: If the repository, branch, and environment match the trust condition, STS issues a temporary 15-minute credential pair.

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com"
      },
      "Action": "sts:AssumeRoleWithWebIdentity",
      "Condition": {
        "StringEquals": {
          "token.actions.githubusercontent.com:aud": "sts.amazonaws.com"
        },
        "StringLike": {
          "token.actions.githubusercontent.com:sub": "repo:tiny-cto/tinycto-tv:ref:refs/heads/main"
        }
      }
    }
  ]
}
```


### Canonical Links & Cross References

- **Manuals Library**: https://tinycto.tv/zero-trust/manuals
- **18 Reference Architectures**: https://tinycto.tv/zero-trust/architectures
- **Posture Assessor Wizard**: https://tinycto.tv/zero-trust/wizard
- **Security Tooling Matrix**: https://tinycto.tv/zero-trust/matrix

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Chapter 04: Secretless Infrastructure with Multi-Cloud OIDC Federation | TinyCTO Zero-Trust Canon",
  "description": "Eliminating long-lived cloud credentials forever. Step-by-step architecture for establishing OIDC trust between GitHub Actions, Kubernetes IRSA, Google Cloud Workload Identity, and Azure Entra ID.",
  "url": "https://tinycto.tv/zero-trust/manuals/04-secretless-infrastructure-oidc-federation",
  "inLanguage": "en"
}
```
