Session

Trust, don't store: how WIF changes your deployment security

Does your deployment pipeline authenticate with a client secret? Then this session is for you. In the best case scenario, secrets live in a vault, get rotated on a schedule nobody loves, and occasionally expire at exactly the wrong moment. In the worst case they are stored somewhere unsecured or never rotate at all. Let's take away the risk with a far better option.

Workload Identity Federation replaces stored credentials with a trust relationship. No secrets that can leak, no expiration at the wrong time, nothing stored outside of Azure.

In this session we'll explore the systems behind WIF and OpenID Connect and how the two relate. We set up WIF from scratch in both GitHub Actions and Azure DevOps, connecting to Azure. You'll see how the trust model works and what configuration is important. We'll also cover the current limitations and what that means for your specific setup.
By the end you will understand exactly how WIF works, have the steps to migrate your existing pipelines and a clear answer if anyone asks you if WIF is the most secure form of authentication

Barbara Forbes

Azure Architect @ Zure | Azure MVP | GitHub Star

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top