dotcom-rendering icon indicating copy to clipboard operation
dotcom-rendering copied to clipboard

Transitioning to Workload Identity Federation for GCP Access

Open abeddow91 opened this issue 9 months ago • 0 comments

WebEx uses service account keys to access the Google Cloud Platform (e.g. BigQuery)

The following service account keys are active in PROD - most with counterparts in CODE:

  • 3 keys used by Grafana (WebEx and DevX)
  • 2 keys used by Fastly (WebEx and Commercial Dev)

Data Tech are encouraging teams to move away from service account keys and use Workload Identity Federation (WIF) instead. WIF provides secure access to GCP resources without managing keys, which reduces risks, improves compliance, and simplifies access management. Some teams that have done this transition successfully in the past are Ophan, Personalisation, and Data Science.

For any questions or assistance, please feel free to reach out to Data Tech.

abeddow91 avatar May 15 '24 08:05 abeddow91