CI/CD Platform  ·  View 21 of 22  ·  Assurance

Identity — Getting a Credential and Losing It

Twelve messages, and two of them are the ones that matter: the audit write, and the refusal.

Editable source SVG draw.io All views
microVM job Job agent Scheduler Identity federation Secret broker Cloud STS Audit trail 1. mint job identity 2. bind tenant, repo, ref, class 3. OIDC token, job TTL 4. needs a secret 5. present token + scope 6. check class and policy 7. record the read 8. value, redaction registered 9. exchange for role 10. short-lived credential 11. untrusted class: refused 12. revoke on job end Identity — How a Job Gets a Credential and Loses It Revocation does not wait for expiry, and the audit record is written before the value is returned, never after. v 1.0 · owner Platform Engineering · date 2026-09

The ordering that matters

  • The audit record is written before the secret value is returned, never after. A read that cannot be recorded does not happen.
  • The refusal for an untrusted class is an explicit, distinct outcome, not an empty value. A job that silently receives no secret fails later with a misleading error.
  • Revocation is pushed at job end and does not wait for token expiry, so a leaked token's useful life is the job's life rather than the TTL.

Realisation

  • Job identity binds tenant, repository, ref and trust class, and is minted per job with the job's TTL.
  • Cloud access is obtained by exchanging that identity for a short-lived role rather than by holding a stored credential.
  • Registered secret values are redacted on the log path out of the sandbox.

Risks

  • Redaction is best-effort against a build that deliberately encodes a secret before printing it. It protects against accident, not against intent — which is why an untrusted run is given nothing to print.