AWS Workload Identity
AWS outbound identity federation lets an IAM principal request a short-lived OIDC JWT from AWS Security Token Service. Mixlayer verifies that AWS-issued token and exchanges it for a short-lived Mixlayer access token.
For Amazon EKS, use the Kubernetes projected-token guide instead.
1. Enable outbound identity federation
Enable the feature once for the AWS account:
Retrieve the account-specific issuer URL:
AWS hosts OIDC discovery and public signing keys under this issuer.
2. Allow the workload to request tokens
Grant sts:GetWebIdentityToken to the IAM role used by the workload. Restrict the audience and token lifetime:
Attach this policy to a dedicated role rather than sharing a broad application role across unrelated workloads.
3. Inspect an AWS identity token
Request a token from a regional STS endpoint:
GetWebIdentityToken is not available from the STS global endpoint. Decode one sample token locally and record its exact iss, aud, and sub claims. Do not paste production tokens into a web-based decoder or write them to logs.
4. Configure the Mixlayer provider
Create an OIDC provider in Workload Identity:
Map the AWS principal:
Set the admission condition to the exact sub observed in the dedicated role’s token:
AWS-specific values such as principal tags are nested under the https://sts.amazonaws.com/ claim. Map a tag with CEL bracket notation only after verifying its shape in a real token:
Use true as the final authorization rule and grant only the permissions the role needs.
5. Exchange and use the AWS token
Request a new AWS token and exchange again before the Mixlayer token expires. AWS tokens can last from 60 to 3,600 seconds; a short lifetime such as 300 seconds limits exposure.
Do not send SigV4 requests, AWS access keys, or temporary STS credentials as
the subject token. Mixlayer expects the signed JWT returned by
GetWebIdentityToken.