Home / Companies / HashiCorp / Blog / Post Details
Content Deep Dive

Access Azure from HCP Terraform with OIDC federation

Blog post from HashiCorp

Post Details
Company
Date Published
Author
Mattias Fjellstrom
Word Count
1,837
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

HCP Terraform provides a way to securely access Azure using OpenID Connect (OIDC) federation, eliminating the need for long-lived credentials. This allows users to authenticate with Azure as a service principal through a native OIDC integration, obtaining temporary credentials at runtime and discarding them when the run completes. The process involves setting up a trust relationship between HCP Terraform and Azure, configuring Azure platform access, and configuring resources on HCP Terraform to use dynamic credentials. This enables users to securely scale access management within HCP Terraform by delegating access from one workspace to another while precisely restricting Azure access to only what the service principal needs. The solution can be scaled by creating an HCP Terraform variable set for each workspace, configuring environment variables, and sharing the variable set with the targeted workspace. This allows HCP Terraform to automatically obtain and inject temporary credentials, enabling users to securely access Azure without managing long-lived credentials.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 1 198 50 30 -7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.