Workload identity

Giving a workload its own verifiable identity, refreshed automatically, removes the stored key entirely.

The machine proves what it is to the platform and receives short-lived credentials. There is no secret in a config file, nothing to rotate manually and nothing to leak. Where it is available it is one of the few changes that eliminates a class of incident rather than reducing it.

Checked against the primary source.

More on Cloud security