|
|
|
|
|
by arianvanp
49 days ago
|
|
That's not true. Both AWS' as well as GCP's workload identity tokens are not bound to the VM. If you leak the credentials they're valid until they expire. on AWS the expiry is 6 hours (non-configurable). Even if your IAM role has a shorter expiration, the credentials assumed by the VM will always be valid for 6 hours. |
|
My point was that you don't literally have to run the proxy on localhost in order to scope the request.