Skip to content

Token lifetime for longer running jobs when using Direct Workload Identity Federation #505

@lopter

Description

@lopter

Hello,

I am trying to setup some CI jobs that will run Terraform commands with Terraform configured to use a Google Cloud Storage bucket (docs) to store its state and do its locking.

Due to the nature of Terraform operations, a 10 (or 51) minutes TTL for the authentication token feels short. I don't see how this TTL can be raised. What's my next best option?

Documents I have been through:

Footnotes

  1. This is still unclear to me tbh: if I understand correctly it's 5 minutes when using Workload Identity Federation through a Service Account and 10 minutes when using Direct Workload Identity Federation.

  2. This comment in particular.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions