Skip to content

Use start-tsp v2, which authenticates to GCP with Workload Identity Federation - #177

Merged
skeet70 merged 1 commit into
mainfrom
wif-auth
Sep 3, 2026
Merged

Use start-tsp v2, which authenticates to GCP with Workload Identity Federation#177
skeet70 merged 1 commit into
mainfrom
wif-auth

Conversation

@skeet70

@skeet70 skeet70 commented Sep 3, 2026

Copy link
Copy Markdown
Member

The GCLOUD_AUTH service account key is no longer passed in. The job declares id-token: write for the OIDC token and pull-requests: write for the action's TSP_IMAGE comment reactions; an explicit permissions block zeroes unlisted scopes, and no other step in the job needs more.

Depends on IronCoreLabs/workflows#177 (merged; start-tsp-v2.0.0 exists). Once every consumer is merged, the GCLOUD_AUTH org secret and the depot-ci user-managed key can be deleted.

Verified: actionlint clean on the changed file. This PR's own CI run is the end-to-end proof.

…ederation

The GCLOUD_AUTH service account key is no longer passed in. The job declares id-token: write for the OIDC token and pull-requests: write for the action's comment reactions.
@skeet70
skeet70 merged commit becbba9 into main Sep 3, 2026
7 checks passed
@skeet70
skeet70 deleted the wif-auth branch September 3, 2026 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants