Home / Companies / Pulumi / Blog / Post Details
Content Deep Dive

Native OIDC Token Exchange for Pulumi CLI

Blog post from Pulumi

Post Details
Company
Date Published
Author
Boris Schlosser
Word Count
733
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Pulumi has introduced native OIDC token exchange support in its CLI, addressing the security and management challenges associated with long-lived credentials in CI/CD pipelines. This feature allows CI/CD environments like GitHub Actions, GitLab CI, or Kubernetes to authenticate to Pulumi Cloud using short-lived tokens issued by identity providers, eliminating the need to store long-lived credentials as secrets. The OIDC token exchange mitigates risks such as credential exposure, rotation complexity, over-privileged access, and audit trail gaps by offering short-lived, customizable tokens. The process involves using the `pulumi login` command with OIDC tokens, which can be scoped to specific teams or users, and supports integration with various token delivery systems. This enhancement, compatible with Kubernetes clusters like EKS, GKE, and AKS, requires setting up an OIDC provider and configuring authorization policies within Pulumi Cloud. Pulumi encourages users to update to the latest CLI version and adapt their CI/CD workflows to leverage this new functionality for enhanced security in infrastructure automation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 10 1,540 251 91 +19%
Secrets Management 6 1,206 193 82 -5%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.