Use OpenID Connect (OIDC) for cloud authentication?
Short answer: Instead of long-lived access keys, use federated identity: ■ AWS/GCP trusts GitHub’s identity token. ■ Short-lived credentials are issued dynamically. Example for AWS: permissions: id-token: write contents: read Real-world example: In one project, we replaced static AWS keys with OIDC-based auth in GitHub Actions — no more long-lived tokens, and access was automatically scoped per workflow.
Say this in the interview
- Define — one clear sentence (the short answer above).
- Example — relate it to a project like ShopNest or your real work.
- Trade-off — when you would not use it.
Share this Q&A
Share preview image: https://www.toolliyo.com/images/toolliyo-logo.png