feat(gcp): Added Support of GCP Role Impersonation - #2192
Conversation
|
Hi @alphadev4 / @tzurielweisberg |
|
@fatimaaqua @alphadev4 @tzurielweisberg @rfletcher @mwarkentin — could you please provide some clarity on the status of the short-lived credentials PRs below? Is there a specific technical, security, or architectural reason these changes have not been merged or incorporated into CloudSploit? The current CloudSploit authentication model appears to rely primarily on long-lived credentials. For organizations operating in regulated or security-sensitive environments, this creates significant challenges, as long-lived static credentials are generally discouraged in favor of short-lived, federated authentication mechanisms. In particular, we would like to see support for:
There are already several open PRs addressing these areas:
Multiple members of the open-source community have contributed work toward supporting short-lived credentials, but there does not appear to be clear communication from the Aqua team regarding whether these PRs will be reviewed, merged, superseded by another implementation, or declined. This lack of clarity is creating real integration issues for organizations like ours that want to use CloudSploit within regulated environments where long-lived cloud credentials are not an acceptable authentication pattern. Could the Aqua team please provide a clear position on these PRs? Specifically:
A clear resolution would be greatly appreciated. Even if the decision is not to merge the current implementations, communicating the intended direction would help contributors and users avoid duplicating work and allow us to determine whether CloudSploit can meet our security requirements. |
No description provided.