AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

AWS IAM Outbound Identity Federation
AWS IAM outbound identity federation now supports Amazon VPC endpoints for the OpenID Connect (OIDC) discovery APIs. You can access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet.
IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints.
What to do
- Create an interface VPC endpoint to reach the OIDC discovery endpoints privately.
- Ensure your workloads can retrieve verification keys within the AWS network.
- Review the IAM User Guide for more details.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



