Urgent.News

What's breaking now, across thousands of outlets.

Tech

Zero Keys, Two Clouds: How Our AWS-hosted Terraform CI/CD Deploys to Google Cloud

How inDrive extended AWS-hosted Terraform CI/CD to Google Cloud using Workload Identity Federation, with no service-account keys or GCP runners.

Zero Keys, Two Clouds: How Our AWS-hosted Terraform CI/CD Deploys to Google Cloud

InDrive migrated its Terraform CI/CD pipeline from AWS to Google Cloud without generating any service-account keys. This was accomplished using Workload Identity Federation, a feature that allows AWS runners to access Google Cloud APIs without storing keys. The key constraints were that Terraform state remained in Amazon S3, CI runners stayed in AWS, and no service-account keys were used.

The solution was to have an AWS-hosted runner call Google Cloud APIs directly, while reading and writing Terraform state in S3. Google Cloud Workload Identity Federation was chosen as the authentication method because it requires no persistent secrets and offers broad API compatibility. The process involves the runner obtaining temporary Google Cloud credentials and the federated principal impersonating a purpose-scoped Google Cloud service account.

This authentication flow ensures that any single Terraform apply fits within a one-hour token lifetime, a crucial constraint that was tested and confirmed in a test harness before being put into production.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

More from Thursday 13 August →