Your organization is using GitHub Actions as a continuous integration and delivery (Cl/CD) platform. You must enable access to Google Cloud resources from the Cl/CD pipelines in the most secure way.
Option C with a GKE cluster and Workload Identity is also a good choice. But if I had to pick one, I'd go with D. Gotta keep those cloud credentials secure, ya know?
I agree, option D is the way to go. Workload identity federation is the recommended approach for this use case. Storing sensitive service account keys in the pipeline config or repository is a big no-no.
Option D seems like the most secure way to enable access to Google Cloud resources from the CI/CD pipelines. Using workload identity federation to integrate GitHub as an identity provider is a best practice.
Felicidad
1 months agoGlory
14 days agoFanny
16 days agoYan
19 days agoPamella
1 months agoJose
7 days agoCyril
15 days agoJuliana
16 days agoKirby
1 months agoJaney
1 months agoChanel
6 days agoDarell
7 days agoAdelle
10 days agoYong
3 months agoKirby
3 months agoReita
3 months ago