पाठ 6 / 25
Workload Identity Federation
Let GitHub Actions, other clouds and GKE pods authenticate without keys.
Trading outside tokens for Google credentials
Workloads outside Google Cloud, such as a GitHub Actions job, an AWS workload or an on-premises server, still need to call Google APIs. Workload Identity Federation lets them do so without service account keys. You create a workload identity pool and a provider that trusts an external identity provider (GitHub's OIDC issuer, AWS, Azure or any OIDC/SAML provider), with an attribute condition such as "only repository acme/shop". The external token is exchanged through the Security Token Service for a short-lived Google credential, either used directly as a federated principal or to impersonate a service account. Inside GKE, Workload Identity Federation for GKE maps Kubernetes service accounts to IAM principals, so pods get identities without node-wide credentials.
GitHub Actions authenticating with federation
Only resource names are stored in the workflow; there is no secret to rotate.
permissions:
contents: read
id-token: write # lets the job request an OIDC token
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: google-github-actions/auth@v2
with:
workload_identity_provider: projects/123456789/locations/global/workloadIdentityPools/github/providers/github-oidc
service_account: deployer@shop-prod-654321.iam.gserviceaccount.com
- uses: google-github-actions/setup-gcloud@v2
- run: gcloud run deploy orders-api --source . --region asia-south1Always set an attribute condition
A GitHub provider without a condition on assertion.repository (or the repository owner) could accept tokens from any repository on GitHub. Restrict the provider to your organization and repository, and the binding to the right branch or environment.
त्वरित जाँच: What does Workload Identity Federation remove the need for?
- Long-lived service account keys for external workloads
- IAM roles
- Projects
- Audit logs
Answer
Long-lived service account keys for external workloads — External tokens are exchanged for short-lived Google credentials, so no key file is stored.