← Professional Cloud DevOps Engineer: delivery and reliability
04 / 8 · 40 MIN

Identities, secrets, and supply chain

Limit credentials and connect build evidence with admission.

Concept and mechanism

A pipeline identity should have only the access required for its work and environment. For external integrations, Workload Identity Federation can reduce reliance on long-lived keys, but it requires tightly bounded trust in the issuer and workload attributes. Accepting any token from a shared issuer can expand access to unintended repositories or identities. For Google Cloud builds, do not assume a universal default account: project history and policies can influence the identity used. Inspect the effective account before correcting IAM. If the pipeline uses the wrong principal, granting more privileges to the expected account does not fix the source and can create additional exposure.

Guided application

In a fictional example, a password was embedded in an image layer. Correcting the manifest does not clean the distributed artifact. Coordinate exposure response, rotation, access analysis, and rebuilding without the secret. For runtime secrets, pinning an approved version makes configuration reproducible; rotation must remain compatible with the credential-verifying service. Provenance also needs a concrete mechanism: in the documented Cloud Build flow, the images field supports publication with provenance; a docker push step does not generate the same evidence. Finally, Binary Authorization can require attestations before admitting an artifact. Meeting policy demonstrates that configured requirements were satisfied, not that all software is free from present or future vulnerabilities.

IN PRACTICE

A signed=true label does not replace verifiable provenance linked to the digest.

Common pitfalls

Federation without conditions; assumed default; manifest as retroactive cleanup; attestation as universal absence of flaws.

Related topics: Organization, identity, and visibility · Infrastructure, revisions, and environments · Pipelines, promotion, and recovery

Take this idea with you

Connect access, origin, and approval to the effective workload and artifact.

Create account

Reference: Workload Identity Federation · Current linked guide; edition date unconfirmed (2026-09-30 inspection)