Workload identity federation lets an external identity provider's signed assertion be exchanged for short-lived cloud credentials. The trust policy must bind the expected issuer, audience, subject, repository or namespace, and environment. A valid token from the wrong workflow or Pod should not be enough to assume the production role.
Federated workload identity: replace standing cloud keys with scoped trust
Operational decision
A claims deployment pipeline needs permission to update only its production service. Separate build and deploy jobs. The build job produces a signed artifact without cloud deploy rights; the deploy job runs behind an environment gate and requests a short-lived identity assertion. The policy sketch names the checks that the cloud-side trust rule must enforce; it is not a provider-specific policy document. Test negative cases: a pull request, a branch outside the release rule, and a staging environment must all fail to assume the production role. Rotate or revoke the trust mapping when repository ownership changes. Keep the cloud role's resource permissions narrow, because federation removes stored keys but does not automatically enforce least privilege after exchange.
Production deploy trust contract
Issuer: approved CI identity provider
Audience: cloud token-exchange endpoint
Subject: claims repository, release branch, production environment
Role scope: update claims service and read deployment state
Negative tests: pull request, staging job, unrelated repository
Expiry: short-lived credentials; no stored cloud access keyCost and verification
Federation adds an issuer and claim-mapping dependency to deployment. An outage there can delay releases, so retain a controlled, audited emergency path. Short-lived credentials reduce the time a stolen token remains useful; they do not prevent a malicious job within the permitted subject from deploying. Review job permissions, branch protection, environment approvers, and the trust rule together. Log assumption events without logging raw assertions.
Common Mistakes
- Do not trust only the issuer while ignoring subject and audience.
- Do not give build jobs production deployment permission.
- Do not store the exchanged token in a long-lived artifact.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- GitHub Actions: narrow tokens and cloud trust
- Credential incident response: revoke access before rebuilding trust
- Immutable artifacts and release provenance
- Service account tokens: mount only when the workload needs Kubernetes API access
Practice and check
Cloud authority follow-up
- Cloud policy decisions: trace every authorization layer
- Temporary sessions: preserve caller lineage through role chains
