Goodbye Service Account Keys, Hello Workload Identity Federation - Building Secure Apps with GCP

  Рет қаралды 5,996

DevOps w/ George

DevOps w/ George

Жыл бұрын

Tired of juggling a million service account keys for your cloud-based application? Want to up your security game without sacrificing the joy in your day? Look no further - Workload Identity Federation is here to save the day!
In this video, i cover the following:
- What is workload identity federation (workload identity pools + IAM)?
- How to set it up on GCP
- Live Example: How to use it up with a GitHub actions workflow
Workload identity federation is simply Keyless authentication for service accounts. It solves the problems of storage of access keys, distribution, and rotation using short live dynamically provided tokens to authenticate your third party applications to Google cloud platform.
To learn more, read the docs: cloud.google.com/iam/docs/wor...
Other links:
=========
Github open id connect setup: docs.github.com/en/actions/de...
Google github auth action:
github.com/google-github-acti...
Code samples repo used in this video:
github.com/galonge/udemy-kust...
==========
To learn more about kubernetes configuration management with Kustomize, see here: www.udemy.com/course/kustomiz...

Пікірлер: 10
@femiibrahim7645
@femiibrahim7645 Ай бұрын
Wow. The most explanatory video I've seen on workflow Identity Federation
@cloudtech273
@cloudtech273 6 ай бұрын
Excellent demo. Thanks !!
@rashmitrathod6873
@rashmitrathod6873 Жыл бұрын
Thanks George for the excellent delivery and diagrams in explaining the GCP Workload Identity federation concept with the demo, it really helped in understanding end to end workflow between GitHub and GCP and the usage of WIF.
@galonge
@galonge Жыл бұрын
You're very welcome! Thanks for watching!
@user-xx8fr6jv5p
@user-xx8fr6jv5p 11 ай бұрын
Thanks George for the wonderful explanation. I have a query related to service account key rotation how with the help of workload identity federation can this be achieved?
@user-rq2dc2xo4b
@user-rq2dc2xo4b 4 ай бұрын
great demo. How would you do this for an application running on a local machine. What would be the identity provider in that scenario?
@ashwinireddyaluri2534
@ashwinireddyaluri2534 Жыл бұрын
Can we create bulk service account keys in diff projects by using groovy script
@leandrojpg
@leandrojpg 5 ай бұрын
the json download part, if I download it can I use it in the same way I would use a service account?
@pedroandredias375
@pedroandredias375 9 ай бұрын
Hi, where you found the documentation to know this sintax: ""repo:galonge/udemy-kustomize-mastery:red:refs/heads/main"?
@galonge
@galonge 4 ай бұрын
HI Pedro, you can find more info on the workload identity federation docs here: cloud.google.com/iam/docs/workload-identity-federation-with-deployment-pipelines#mappings-and-conditions
How to use Github Actions with Google's Workload Identity Federation
11:33
Azure DevOps Workload Identity Federation with Azure Overview. NO MORE SECRETS!
21:56
John Savill's Technical Training
Рет қаралды 12 М.
Пранк пошел не по плану…🥲
00:59
Саша Квашеная
Рет қаралды 5 МЛН
Who has won ?? 😀 #shortvideo #lizzyisaeva
00:24
Lizzy Isaeva
Рет қаралды 65 МЛН
Дарю Самокат Скейтеру !
00:42
Vlad Samokatchik
Рет қаралды 8 МЛН
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 3,7 МЛН
GitHub OIDC and Google Identity Federation
24:39
OutOfDevOps
Рет қаралды 4 М.
Cloud Run user auth for internal apps
15:31
Google Cloud Tech
Рет қаралды 16 М.
How GitHub Actions 10x my productivity
8:18
Beyond Fireship
Рет қаралды 399 М.
Workload Identity (OIDC) for AKS
15:18
Houssem Dellai
Рет қаралды 6 М.
Workload Identity in GKE to fetch data from Google Cloud Storage.
9:39
AWS to GCP sans service account keys!! - Workload Identity Federation
14:56
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,1 МЛН
Красиво, но телефон жаль
0:32
Бесполезные Новости
Рет қаралды 1,5 МЛН
Как правильно выключать звук на телефоне?
0:17
Люди.Идеи, общественная организация
Рет қаралды 1,9 МЛН
Что делать если в телефон попала вода?
0:17
Лена Тропоцел
Рет қаралды 2,5 МЛН
НЕ БЕРУ APPLE VISION PRO!
0:37
ТЕСЛЕР
Рет қаралды 205 М.