Hey! I am going to merge this with other tickets that talk about customizing either OIDC `sub` or custom claims. I personally think this work has a great return on investment, I just need to make sure we implement the right thing the right way, and we don’t miss any security aspects.
One of my main questions here is - at which level is the OIDC token customized. The safest bet I can think of is account (perhaps in security settings), but is it granular enough?
Black Breeze
•
May 10, 2025
Thanks for the suggestion! We looked into this, but it’s not something Spacelift can do directly. When authenticating to AWS via OIDC, Spacelift issues a valid identity token. It’s up to the consumer of that token (typically the Terraform AWS provider or other IaC tool) to include STS session tags when assuming a role.
If you need session tags—for example, to improve auditability or control—you’ll want to configure them within your Terraform provider or authentication logic. We’ll look at ways to clarify this in our docs.
Azure Chipmunk
•
May 12, 2025
Ah, understood. I thought they would have to be set in your backend. Admittedly, I am not particularly familiar with IAM session tags.
I’ll investigate setting those on our side.
Black Breeze
•
May 7, 2025
I 100% see your point. Changing an existing claim would not be backwards-compatible, though. Would there be any downside to making this a separate claim, to not break anyone’s token existing usage?
This request was merged into another request
Comments9
Black Breeze
May 14, 2025
Hey! I am going to merge this with other tickets that talk about customizing either OIDC `sub` or custom claims. I personally think this work has a great return on investment, I just need to make sure we implement the right thing the right way, and we don’t miss any security aspects.
One of my main questions here is - at which level is the OIDC token customized. The safest bet I can think of is account (perhaps in security settings), but is it granular enough?
Black Breeze
May 10, 2025
Thanks for the suggestion! We looked into this, but it’s not something Spacelift can do directly. When authenticating to AWS via OIDC, Spacelift issues a valid identity token. It’s up to the consumer of that token (typically the Terraform AWS provider or other IaC tool) to include STS session tags when assuming a role.
If you need session tags—for example, to improve auditability or control—you’ll want to configure them within your Terraform provider or authentication logic. We’ll look at ways to clarify this in our docs.
Azure Chipmunk
May 12, 2025
Ah, understood. I thought they would have to be set in your backend. Admittedly, I am not particularly familiar with IAM session tags.
I’ll investigate setting those on our side.
Black Breeze
May 7, 2025
I 100% see your point. Changing an existing claim would not be backwards-compatible, though. Would there be any downside to making this a separate claim, to not break anyone’s token existing usage?