Credentials & Identity Federation
Guides for authenticating pipelines to external services using
Concourse-issued JWTs (the idtoken var source)
instead of storing long-lived secrets. For general credential management —
Vault, AWS Secrets Manager, and other cluster-wide credential managers — see
Credential Management in the Docs.
-
Authenticating to Vault via IDToken
Let a pipeline log in to Vault directly, beyond what Concourse's native Vault integration offers.
-
Authenticating to AWS via IDToken
Assume an IAM role from a pipeline without managing IAM users or long-lived access keys.
-
Authenticating to Azure via IDToken
Log in to Azure from a pipeline using a federated credential.
-
Authenticating to GCP via IDToken
Impersonate a GCP service account from a pipeline using workload identity federation.
For details on JWT claims, key rotation, and the subject_scope setting, see the
IDToken credential manager reference page.