Keyless Github OIDC Auth: Snowflake WIDF Setup 🔑
Автор: Kamesh Sampath
Загружено: 2026-01-13
Просмотров: 75
Описание:
Are you still storing long-lived passwords and secrets in your GitHub Actions? 🛑
In this 2-minute "Hacker Mode" demo, I show you the correct way to automate Snowflake: using OpenID Connect (OIDC). By linking a Service User directly to a GitHub repository identity, we eliminate the need for secrets entirely.
To prove it works, I build a "Cost Cop" bot that audits warehouse costs—authenticating securely and automatically without ever touching a password.
🔐 THE "HERO" TECH:
Snowflake OIDC: Keyless authentication.
Service Users: Mapped directly to GitHub OIDC Subjects.
GitHub Actions: Secure id-token exchange.
🚀 THE USE CASE (DEMO):
Automating a "Warehouse Police" script.
Enforcing 60-second Auto-Suspend policies.
100% Terminal-based workflow.
📌 GRAB THE CODE:
https://github.com/kameshsampath/ware...
📚 RESOURCES & DOCS:
Snowflake Workload Identity Federation: https://docs.snowflake.com/en/user-gu...
GitHub Actions OIDC: https://docs.github.com/en/actions/se...
Snowflake CLI: https://docs.snowflake.com/en/develop...
Snowflake CLI GitHub Action: https://github.com/snowflakedb/snowfl...
Snowflake Scripting: https://docs.snowflake.com/en/develop...
👋 CONNECT WITH ME:
LinkedIn: / kameshsampath
Twitter/X: https://x.com/kamesh_sampath
⏱️ TIMESTAMPS:
0:00 The Problem: Managing Costs & Secrets
0:20 The Solution: Warehouse Police Script
0:40 The Security: OIDC Identity Mapping
1:00 The Automation: GitHub Actions "No Secrets" Workflow
1:20 The Demo: Keyless Execution
1:55 The Result: Verified & Secure
2:00 Outro & Next Steps
#Snowflake #OIDC #DevSecOps #GitHubActions #Identity #SnowflakeCLI #KeylessAuth #InfrastructureAsCode
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: