Home / Companies / Pulumi / Blog / Post Details
Content Deep Dive

Enforce Access Token Expiry Policies in Pulumi Cloud

Blog post from Pulumi

Post Details
Company
Date Published
Author
Devon Grove
Word Count
762
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Pulumi Cloud has introduced a new feature that allows organization administrators to enforce a maximum expiry on access tokens used within their organizations, enhancing security by ensuring compliance with credential rotation policies. This policy allows admins to set a maximum token lifetime in days, ensuring that tokens have an expiration date and comply with the specified lifespan cap. The feature addresses the security risk of never-expiring or overly long-lived tokens by rejecting them and providing users with guidance on how to regain access. The enforcement applies immediately to both new and existing tokens, with different compliance mechanisms for personal, organization, and team tokens. While personal tokens are not blocked at creation, they are rejected if non-compliant when used, and all policy changes are recorded in audit logs. The rollout process includes a preview of affected tokens to mitigate disruptions, especially for CI credentials, and ensures that users are informed about the changes and how to comply with the new requirements.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.