⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 180 of 186 in AWS & Cloud Architecture
Senior DevOps / SRE Multi-Cloud Multi-Cloud Security & Identity Security Hardening

Q: Your microservice running in Google Kubernetes Engine (GKE) needs to write objects to an AWS S3 bucket and publish events to AWS SQS. Storing static AWS IAM Access Keys and Secret Keys in GCP Secret Manager violates security policy and poses credential leak risks. How do you implement zero-secret cross-cloud IAM role assumption using OIDC federation?

Engineering a zero-static-credential cross-cloud identity federation pipeline enabling Google Kubernetes Engine (GKE) workloads to assume AWS IAM roles using Google OIDC identity tokens.

#Multi-Cloud #AWS #GCP #IAM #OIDC #Workload Identity #Zero Trust
🎙️ Candidate Opening & Architectural Context
"Hardcoded AWS credentials in foreign clouds are one of the most common causes of enterprise data breaches. We eliminated all long-lived AWS IAM access keys in GCP by configuring direct OIDC federation between Google Cloud IAM and AWS IAM."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Configure GKE Workload Identity to Emit Google OIDC Identity Tokens

Equip the GKE pod to acquire cryptographically signed Google JSON Web Tokens (JWT):

  • GKE Workload Identity: Bound Kubernetes Service Account (KSA) to Google Service Account (GSA) gke-s3-writer@proj.iam.gserviceaccount.com.
  • Fetch Identity Token: Application or helper fetches OIDC token from local metadata server: curl -H 'Metadata-Flavor: Google' 'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/identity?audience=aws-crosscloud'.
Pro Tip: Google Cloud metadata server generates an RS256-signed JWT containing Google's issuer URL (accounts.google.com) and the custom audience string.
2️⃣

Create AWS IAM OIDC Identity Provider for Google Accounts

Establish trust in AWS for tokens signed by Google Cloud:

  • Create OIDC Provider in AWS: Executed aws iam create-open-id-connect-provider --url https://accounts.google.com --client-id-list aws-crosscloud --thumbprint-list 2c9c7820....
  • Cryptographic Trust: AWS fetches and validates Google's public JWKS keys from https://www.googleapis.com/oauth2/v3/certs.
Pro Tip: AWS IAM verifies the digital signature of the incoming JWT against Google's public signing certificates without contacting Google APIs during each request.
3️⃣

Create AWS IAM Role with Scoped Condition Keys

Define the AWS role and restrict assumption strictly to the specific GCP service account:

  • Trust Policy JSON: Configured Principal: { Federated: 'arn:aws:iam::ACCOUNT:oidc-provider/accounts.google.com' } with Action: 'sts:AssumeRoleWithWebIdentity'.
  • Condition Keys: Added Condition: { StringEquals: { 'accounts.google.com:aud': 'aws-crosscloud', 'accounts.google.com:sub': '$GSA_UNIQUE_NUMERIC_ID' } }.
Pro Tip: Strictly validating the 'sub' (subject) claim ensures that other GCP customers or unauthorized projects cannot assume your AWS role.
4️⃣

Execute sts:AssumeRoleWithWebIdentity & Access AWS S3

Exchange the short-lived Google token for temporary AWS STS credentials:

  • STS Exchange: Executed aws sts assume-role-with-web-identity --role-arn arn:aws:iam::ACCOUNT:role/gke-s3-role --role-session-name gke-session --web-identity-token $GOOGLE_TOKEN.
  • Temporary Credentials: AWS STS returns temporary AWS access key, secret key, and session token valid for 1 hour.
  • Verification: Pod writes file to S3: aws s3 cp report.parquet s3://prod-lake/ with zero static credentials stored anywhere.
Pro Tip: AWS credentials expire automatically every hour, completely eliminating credential rotation overhead.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"OIDC federation between Google Cloud and AWS IAM replaces dangerous long-lived access keys with short-lived, cryptographically verified tokens exchanged via sts:AssumeRoleWithWebIdentity."
⚡ 60-Second Elevator Pitch Talking Points
  • Configure GKE Workload Identity to fetch Google-signed OIDC identity tokens.
  • Create an OIDC Identity Provider in AWS IAM trusting https://accounts.google.com.
  • Define an AWS IAM role with trust conditions validating the exact Google Service Account ID.
  • Exchange the Google token via sts:AssumeRoleWithWebIdentity to obtain temporary 1-hour credentials.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →