Secure deployments on GitHub using OIDC: Hands-on with GCP, Vault, and Terraform
This session showcases how GitHub OIDC enhances security by eliminating static credentials in CI/CD pipelines. Vjosa will cover two main examples of OIDC authentication: accessing GCP resources using Workload Identity Federation and retrieving secrets from Vault using GitHub Actions. The session includes a hands-on demo using GitHub Actions and Terraform, along with best practices for managing access, secrets, and automation. Attendees will learn how to integrate GitHub OIDC for both deployment authentication and secrets management, improving the security and efficiency of cloud-based workflows. Learn more: https://platformcon.com/sessions/secure-deployments-on-github-using-oidc-hands-on-with-gcp-vault-and-terraform
