Authenticate to Cloudsmith with your Google Cloud Identity
Blog post from Cloudsmith
Incorporating Google's workload identity tokens and Cloudsmith's OpenID Connect (OIDC) support, workloads running on Google Cloud can authenticate directly to Cloudsmith without the need for long-lived API keys, thus enhancing security by avoiding key leakage and rotation issues. This process involves swapping a service account identity for a short-lived Cloudsmith token at runtime, using Google's metadata server to issue signed JSON Web Tokens (JWTs) that Cloudsmith verifies with Google's public keys. The setup requires configuring both Google Cloud and Cloudsmith to trust and exchange tokens, ensuring that only valid service accounts can obtain the necessary credentials. This approach is applicable to various Google Cloud services like Compute Engine, Cloud Run, GKE, App Engine, and Cloud Build, allowing them to request and exchange tokens dynamically, thereby removing the burden of managing long-lived credentials.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.