Episode Details
Back to Episodes
Zero keys, two clouds: how our AWS-hosted Terraform CI/CD deploys to Google Cloud
Description
This story was originally published on HackerNoon at: https://hackernoon.com/zero-keys-two-clouds-how-our-aws-hosted-terraform-cicd-deploys-to-google-cloud.
How inDrive extended AWS-hosted Terraform CI/CD to Google Cloud using Workload Identity Federation, with no service-account keys or GCP runners.
Check more stories related to undefined at: https://hackernoon.com/c/undefined.
You can also check exclusive content about #terraform, #google-cloud-platform, #devops, #ci-cd, #cloud-security, #infrastructure-as-code, #workload-identity-federation, #good-company, and more.
This story was written by: @indrivetech. Learn more about this writer by checking @indrivetech's about page,
and for more stories, please visit hackernoon.com.
inDrive extended its AWS-hosted Terraform CI/CD to Google Cloud without service-account keys or moving runners to GCP. The solution uses Workload Identity Federation with service account impersonation, while Terraform state remains in S3. The biggest challenge turned out not to be authentication, but migrating 131 legacy Terraform states and safely integrating GCP into the existing AWS pipeline.