<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloud Security on Latacora</title><link>https://www.latacora.com/categories/cloud-security/</link><description>Recent content in Cloud Security on Latacora</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 04 Nov 2025 10:00:00 -0500</lastBuildDate><atom:link href="https://www.latacora.com/categories/cloud-security/index.xml" rel="self" type="application/rss+xml"/><item><title>OIDC workload identity on AWS</title><link>https://www.latacora.com/blog/2025/11/04/aws-oidc-workload-identity/</link><pubDate>Tue, 04 Nov 2025 10:00:00 -0500</pubDate><guid>https://www.latacora.com/blog/2025/11/04/aws-oidc-workload-identity/</guid><description>&lt;p&gt;&lt;em&gt;Update&lt;/em&gt;: after years of being on the wish list of a ton of top AWS teams, AWS
released &lt;a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_outbound.html" target="_blank" rel="noopener noreferrer"&gt;a built-in version of this feature&lt;/a&gt; about two weeks
after we published this. Never let it be said gentle ribbing doesn&amp;rsquo;t work.
Also, thanks AWS! We meant it when we said that the only thing better than
having something easy to deploy was not needing to deploy anything at all.
Everything in this post about workload identity is still relevant but you
should probably use upstream&amp;rsquo;s implementation unless you have a good reason not
to (for example, private validators for whom you need a VPC endpoint).&lt;/p&gt;</description></item></channel></rss>