identity: OpenTofu is the sole authority over who impersonates cloud-tofu@ #53

Merged
founder merged 1 commit from identity/tofu-sa-authoritative-binding into main 2026-08-16 10:58:11 +00:00
Owner

Follow-up to #43/#50. Authoritative google_service_account_iam_binding for roles/iam.workloadIdentityUser on cloud-tofu@: only attribute.authority/cloud-tofu-{plan,apply}. Applying removes the temporary Authentik cloud-signing binding from the bootstrap. Plan 17176 already ran on the Forgejo job token.

Follow-up to #43/#50. Authoritative google_service_account_iam_binding for roles/iam.workloadIdentityUser on cloud-tofu@: only attribute.authority/cloud-tofu-{plan,apply}. Applying removes the temporary Authentik cloud-signing binding from the bootstrap. Plan 17176 already ran on the Forgejo job token.
identity: OpenTofu is the sole authority over who impersonates cloud-tofu@
Some checks failed
Infra: Cloud OpenTofu / Infra (Cloud OpenTofu) (push) Successful in 39s
Deploy: API / Deploy (API) (push) Has been cancelled
Deploy: Web / Deploy (Web) (push) Has been cancelled
Release: If Needed / Check (Release Needed) (push) Has been cancelled
1431f6dadb
Replace the two non-authoritative workloadIdentityUser members on the
cloud-tofu service account with one authoritative binding listing only the
Forgejo authority principalSets (attribute.authority/cloud-tofu-{plan,apply}).
Applying it removes the temporary Authentik cloud-signing binding the
bootstrap script added, now that cloud-tofu.yml runs on the Forgejo job
token (identity plan run 17176 on main). Recovery from a broken Forgejo path
is the founder bootstrap script, by design.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
founder deleted branch identity/tofu-sa-authoritative-binding 2026-08-16 10:58:11 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
key-store/key.store!53
No description provided.