Тёмный

GitHub OIDC and Google Identity Federation 

OutOfDevOps
Подписаться 1,8 тыс.
Просмотров 4,1 тыс.
50% 1

GitHub Action Here → • Multiple GCP Service A...
In this previous tutorial • GitHub Workflow and Wo... I go through many concepts in less 8 minutes. Even though everything is defined as code, I have to admit that it's probably too much for just 8 minutes. So in today's video I decided to proceed with a less scripted approach so that I can show all steps, please bear with me if it's a slower paced video.
Links:
Google STS API token method: cloud.google.com/iam/docs/ref...
Google iamcredentials API generateAccessToken method: cloud.google.com/iam/docs/ref...
Google Principal Identifiers: cloud.google.com/iam/docs/pri...
GitHub OIDC Hardening: docs.github.com/en/actions/de...
GitHub OIDC and configuration in Google Cloud: docs.github.com/en/actions/de...
GitHub Subject claim examples: docs.github.com/en/actions/de...
WHO AM I:
Hey friends, welcome to my RU-vid channel / outofdevops . If you're new here my name is Anto, here I talk about software engineering and software engineers. Don't forget to comment like and subscribe 👍🏻.
RU-vid GEAR:
🎥 My RU-vid Camera Gear - kit.co/outofdevops
MY SOCIAL LINKs:
🐦 Twitter - / outofdevops
📘 Facebook - / outofdevops
📰 My blog - amasucci.com
📸 Instagram - / outofdevops
GET IN TOUCH:
If you’d like to talk, I’d love to hear from you. Tweeting @OutOfDevOps directly will be the quickest way to get a response, but if your question is very long, feel free to email me at hi@OutOfDevOps.com.
PS: Some of the links in this description are affiliate links that I get a kickback from 😜

Опубликовано:

 

3 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 14   
@OutOfDevOps
@OutOfDevOps Год назад
I made another video using the google-github-action/auth ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-9e_ByRt_nCc.html
@antonpopov3650
@antonpopov3650 Год назад
This has been extremely useful. I am using this knowledge to put together a PoC to solve an important problem at work. The quality of production is amazing. Thank you Anto!
@OutOfDevOps
@OutOfDevOps Год назад
Glad you found it useful. Thank you so much!!!
@davidgomez3213
@davidgomez3213 Год назад
Amazing! Thanks !
@arcangeloguerriero8206
@arcangeloguerriero8206 Год назад
@gokulap
@gokulap Год назад
Hello, I need to use this workload identity on any of my github org repos, how can i allow only my github org repos to use this workload identity while other repos outside of it should not be able to access it
@OutOfDevOps
@OutOfDevOps Год назад
Hi Gokul, I made another video where I use the Google Auth GitHub action here: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-9e_ByRt_nCc.html I recommend to watch the entire video but in part four I show the configuration on the Google side, the bit you are interested in is where I use the workflow_ref. You can also use other claims from the token as documented here docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect#understanding-the-oidc-token, the one specific for the GitHub org is repository_owner. Hope this helps.
@gokulap
@gokulap Год назад
@@OutOfDevOps Thank you so much
@gokulap
@gokulap Год назад
Hi, can you make a video on implementing the kubernetes with workload identity pls ?
@OutOfDevOps
@OutOfDevOps Год назад
Hi Gokul, I will work on it soon. Thanks for the suggestion.
@OutOfDevOps
@OutOfDevOps Год назад
Just published this: GKE Workload Identity Example: Use Workload Identity in GKE to fetch data from Google Cloud Storage. ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-cEPP33ScM3s.html
@edarha7183
@edarha7183 Год назад
i tried follow your instruction, configuring attribute mapping, but I still get the error: my SA doesn't have permission.
@OutOfDevOps
@OutOfDevOps Год назад
I made another video using the google-github-action/auth ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-9e_ByRt_nCc.html hope it helps
@84Jasbir
@84Jasbir 11 месяцев назад
Hi does this service account also needs role as Service Account Token Creator? test-wif-sa
Далее
How to SSH into Private VM in GCP
5:02
Просмотров 747
Викторина от ПАПЫ 🆘 | WICSUR #shorts
00:56
An Illustrated Guide to OAuth and OpenID Connect
16:36
Просмотров 572 тыс.
The cloud is over-engineered and overpriced (no music)
14:39
Викторина от ПАПЫ 🆘 | WICSUR #shorts
00:56