Registry Credential Generation for OIDC API Integrations
Currently there is no way to generate a registry credential for API Credentials. I find it a bit coutnerintuitive that the suggested fix for getting a registry credential for an OIDC API integration is to “generate an API key” alongside the OIDC API integration. That completely nullifies the point of going keyless with OIDC.
- Workaround
- Problem
Log in to comment and vote
Comments6
Black Breeze
May 8, 2025
Thanks for the detailed request—it’s helpful context.
Before we dive into potential solutions, we’d love to better understand the why behind this setup. Specifically:
What’s the job the system is trying to do that needs access to the registry?
Why does it need to run outside of Spacelift?
What does “keyless” buy you in that scenario—short-lived creds, rotation posture, something else?
Right now, the API key workaround is solving the auth problem at the cost of your security model. But before we consider alternatives, we want to make sure we’re solving the right problem at the right layer.
Appreciate any detail you can share.
Indigo Stew
May 7, 2025
The API, and by extension the Spacelift CLI, should give OIDC-authenticated users/clients to generate a registry credential based on their session.
Indigo Stew
May 7, 2025
the first sentence should read “Currently there is no way to generate a registry credential for OIDC API integrations”