Skip to content

Federated auth, no keys to rotate

GCP service accounts and workload identity

How BYOC authenticates on Google Cloud using workload identity federation instead of service account keys.

Service account keys are long-lived JSON credentials that end up in secret stores and stay there long after anyone remembers why. Workload identity federation removes them.

What the module configures

  • A workload identity pool and provider trusting GitHub's OIDC issuer
  • A service account with roles scoped to the runner MIG and cache bucket
  • An IAM binding restricting the trust to your organisation's repositories

Your next build could be twice as fast, at half the price

Start free. Migrating away is the same one line, and we publish that diff too.