Federated auth, no keys to rotate
GCP service accounts and workload identity
How BYOC authenticates on Google Cloud using workload identity federation instead of service account keys.
Service account keys are long-lived JSON credentials that end up in secret stores and stay there long after anyone remembers why. Workload identity federation removes them.
What the module configures
- A workload identity pool and provider trusting GitHub's OIDC issuer
- A service account with roles scoped to the runner MIG and cache bucket
- An IAM binding restricting the trust to your organisation's repositories
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.