#WorkloadIdentity

Tremolo Security :kubernetes:tremolo@hachyderm.io
2026-01-13

Static Kubernetes ServiceAccount tokens are a long-standing security risk.
This post walks through authenticating workloads to HashiCorp Vault using JWT/OIDC, exchanging pod identity for short-lived, least-privilege Vault tokens via a Kubernetes-aware STS—without relying on static credentials.

#Kubernetes #HashiCorpVault #OIDC #WorkloadIdentity #ZeroTrust
tremolo.io/post/short-lived-to

2025-04-25

Y'all ever get that feeling that surely you can't be the first one that actually tries to use a software feature as documented, but how could anyone ever have used it considering that it's fundamentally broken? And there are zero bug reports about your issue?!

This is me right now with #Nomad #WorkloadIdentity w/ #Consul. Clearly I'm doing something terribly wrong, because for me the bit that's supposed to keep the Consul token valid and renewed is doing a whole lot of renewing of the JWT token, but not any of the renewing the Consul side access token it gives you. Even worse than that, every JWT renew causes a change_mode trigger, i.e. a task restart, because it's changed! Yeah sure, you fiddled with the JWT yes, but the Consul token is still super valid? So what was there to re-render?

And yeah, the latest Nomad version makes the use of these mandatory. The feature was first published late 2023 but I've been putting it off, because very complex. Going on day 16 now of trying to get ready for the upgrade. :blobcatnotlikethisgoogly:​

:rss: Qiita - 人気の記事qiita@rss-mstdn.studiofreesia.com
2024-11-06

まともなTerraform環境構築に向けたあれこれ:バックエンドGCS、Workload Identity直接アクセス、tfactionによるCI/CD
qiita.com/SoySoySoyB/items/bb3

#qiita #Terraform #CICD #WorkloadIdentity #tfaction

2022-12-12

well that was fun. got #tornjak integrated with #keycloak successfully. Want to try it out for yourself? Theres a great blog to walk you through the process #spiffe #WorkloadIdentity medium.com/universal-workload-

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst