Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,332
    • Merge requests 1,332
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #346737
Closed
Open
Issue created Nov 29, 2021 by Joe Randazzo@jrandazzoDeveloper

Customer Feedback and Questions: Update CI_JOB_JWT_V2 to support OIDC cloud providers for deployment hardening

This issue is for general feedback from customer using the new alpha implementation of CI_JOB_JWT_V2.

Documentation

  • OIDC Overview with GitLab: https://docs.gitlab.com/ee/ci/cloud_services/
  • Configure OIDC with AWS: https://docs.gitlab.com/ee/ci/cloud_services/aws/
  • Repository example: https://gitlab.com/guided-explorations/aws/configure-openid-connect-in-aws

Provider Specific

  • Vault
  • AWS
  • GCP

Policy setup

  • Per Branch
  • Per Group
  • Per Project

Context:

Our current CI_JOB_JWT implementation is limited to Vault. @bdowney and contributors have drafted an MR for CI_JOB_JWT_V2 which adds OIDC support for AWS and other cloud providers. This allows customers to use temporary credentials from cloud providers without storing secrets in their GitLab projects.

Edited Jan 05, 2022 by Joe Randazzo
Assignee
Assign to
Time tracking