Enforce Access Token Expiry Policies in Pulumi Cloud
Blog post from Pulumi
Pulumi Cloud has introduced a new feature that allows organization administrators to enforce a maximum expiry on access tokens used within their organizations, enhancing security by ensuring compliance with credential rotation policies. This policy allows admins to set a maximum token lifetime in days, ensuring that tokens have an expiration date and comply with the specified lifespan cap. The feature addresses the security risk of never-expiring or overly long-lived tokens by rejecting them and providing users with guidance on how to regain access. The enforcement applies immediately to both new and existing tokens, with different compliance mechanisms for personal, organization, and team tokens. While personal tokens are not blocked at creation, they are rejected if non-compliant when used, and all policy changes are recorded in audit logs. The rollout process includes a preview of affected tokens to mitigate disruptions, especially for CI credentials, and ensures that users are informed about the changes and how to comply with the new requirements.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.