> ## Content Index
> Fetch the complete content index at: https://insights.cloudacio.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Scope the role, not just the trust policy
- URL: https://insights.cloudacio.com/scope-the-role-not-just-the-trust-policy/
- Published: 2026-07-21T13:00:00.000Z
- Updated: 2026-08-12T19:18:35.000Z
- Description: Long-lived credentials in a pipeline are a liability that grows quietly. The rotation nobody owns, the key that appears in a log, the contractor who left with a copy. OIDC removes the class of…
- Author: Juan Pablo Olivera
- Tags: Engineering

Long-lived credentials in a pipeline are a liability that grows quietly. The rotation nobody owns, the key that appears in a log, the contractor who left with a copy. OIDC removes the class of problem instead of managing it.

## What changes

The workflow asks its host for a short-lived token and exchanges it for a role. Nothing durable is stored:

```yaml
permissions:
  id-token: write
  contents: read

```

Credentials expire in minutes. The audit trail names the workflow rather than a shared key. There is no secret to rotate.

## Scope the trust properly

The condition on the token's subject claim is the whole security boundary, so make it specific. Trust the immutable form as well as the readable one — the numeric IDs survive a repository rename, and the readable string does not:

```
repo:my-org/my-repo:*
repo:my-org@79019803/my-repo@1330095362:*

```

A rename with only the readable form in the policy breaks every deploy, and the error says nothing about renames.

## Scope the role, not just the trust

Trust decides who can assume it. The policy decides what they get. A deploy role that can manage one stack, write to one bucket prefix, and touch IAM only for roles matching its own name is a much smaller blast radius than one with broad access and a tight trust policy. Do both.