@tensorcost/gcp-wif
v0.1.0
Published
Mint RS256 subject tokens and build Google external-account credentials for GCP Workload Identity Federation (SaaS-as-OIDC-issuer pattern).
Downloads
34
Maintainers
Readme
@tensorcost/gcp-wif
Helpers for the SaaS-as-OIDC-issuer Workload Identity Federation pattern: mint a short-lived RS256 subject JWT, then build Google external-account credentials that exchange it at STS and impersonate a customer service account — without ever holding a customer SA JSON key.
npm install @tensorcost/gcp-wifSource of truth: developed in the TensorCost monorepo, published to the
@tensorcostnpm org. No separate public GitHub repository. TensorCost services keep usingworkspace:*.
Env vars
Preferred (public) names:
| Variable | Purpose |
|---|---|
| WIF_SIGNING_KEY_PEM | RSA private key (PEM) used to sign subject JWTs |
| WIF_ISSUER | iss claim; must match the issuer URL on the customer's WIF OIDC provider |
Compatibility aliases (still read, so existing TensorCost deploys keep working):
| Alias | Maps to |
|---|---|
| TC_WIF_SIGNING_KEY_PEM | WIF_SIGNING_KEY_PEM |
| TC_WIF_ISSUER | WIF_ISSUER |
Prefer the public names in new code. If both are set, the public name wins.
Usage
import {
mintWifSubjectToken,
buildWifExternalAccountCredentials,
} from "@tensorcost/gcp-wif";
const subjectToken = mintWifSubjectToken({
workloadIdentityProvider:
"projects/123/locations/global/workloadIdentityPools/pool/providers/prov",
tenantId: "tenant-a",
cloudAccountId: "ca-1",
});
const creds = buildWifExternalAccountCredentials({
workloadIdentityProvider:
"projects/123/locations/global/workloadIdentityPools/pool/providers/prov",
serviceAccountEmail: "[email protected]",
tenantId: "tenant-a",
cloudAccountId: "ca-1",
});Serve the public half of the signing key at ${WIF_ISSUER}/.well-known/jwks.json so Google STS can verify minted tokens.
License
Apache-2.0. See LICENSE.
