Workload federation can remove stored cloud keys
A workload can prove what it is to a cloud provider using an identity it already has, and receive short-lived credentials in return.
No long-lived key is stored anywhere, so there is nothing to leak or rotate. It is available between most major platforms and CI systems now, and it eliminates the single most common source of cloud credential exposure rather than mitigating it.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
