AWS to GCP sans service account keys!! - Workload Identity Federation

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ก.ย. 2021
  • Connect your application running inside AWS to GCP without using service account keys.
    cloud.google.com/iam/docs/wor...
    arn:aws:sts::[aws-accnt-number]:assumed-role/[ec2-iam-role]
    ----------
    PLEASE SUBSCRIBE ➡️bit.ly/36x6qQy ❤️
    If you like my work considering buying me ☕bit.ly/3lumyqx
    ----------
    PLAYLISTS:
    - Associate Cloud Engineer Study Guide: bit.ly/37y1dYl
    - Google Cloud Playlist: bit.ly/37uMZal
    ----------
    - Questions? Thoughts? Disagreements? Tell us here in the comments.
    ----------
    LETS CONNECT:
    👍 Facebook: / multicloudguy
    📸 Instagram - / multicloudguy
    🐦 Twitter - / multicloudguy
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 45

  • @abrahamrohithroy7421
    @abrahamrohithroy7421 ปีที่แล้ว

    Yes, this worked flawlessly. Awesome!

  • @jagdishbelapure7521
    @jagdishbelapure7521 4 หลายเดือนก่อน

    This is awesome explanation, thank you for the video!

  • @arunabhamittra8652
    @arunabhamittra8652 2 ปีที่แล้ว +5

    Happy Teacher's Day GK Sir !!!!! Thank you for enriching our lives !

    • @CloudAdvocate
      @CloudAdvocate  2 ปีที่แล้ว

      Thank you Arunabha!! Wish you the same 🙂

  • @shukrilius
    @shukrilius ปีที่แล้ว

    Thank You for this useful video 👍

  • @MaheshVelicheti
    @MaheshVelicheti 2 ปีที่แล้ว

    Happy Teachers day Cloud Guru.

  • @TheBest-ev3lm
    @TheBest-ev3lm 7 หลายเดือนก่อน +2

    Do you have a Terraform Script to perform the above?

  • @shwetagairos
    @shwetagairos 2 ปีที่แล้ว

    Hi GK, thank you for making these videos. You are my favorite.
    You did not show us the policy you attached to AWS instances. Would have been helpful.

    • @shukrilius
      @shukrilius ปีที่แล้ว

      You can just create a new IAM Role and it is not necessary to add any permission, I created an empty role, attached it into an EC2 and worked.
      You can also use the fisrt option from WIF Granting Access session and do not "bind" it to any EC2/role,as he used in this video.
      It works also 😊👍

  • @su-1337
    @su-1337 2 ปีที่แล้ว

    You are amazing, you are one of few notepad++ IT guys left 😂

  • @VivekYadav-iy5os
    @VivekYadav-iy5os 2 ปีที่แล้ว

    Sir first of all you are a inspiring person. Now my question is i am db2dba(luw) how to shift to cloud or any pathway can u suggest step by step to acheive my goal

  • @lipaacharjee9083
    @lipaacharjee9083 2 ปีที่แล้ว

    Hello GK, I am not from IT background, shall I go for Cloud technology, I want to learn

  • @MrStark-kb7tc
    @MrStark-kb7tc 2 ปีที่แล้ว

    Hi did you used application default credentials method with WIF?

  • @gobindasaluja2097
    @gobindasaluja2097 2 ปีที่แล้ว

    will we able to use gcloud commands on Ec2 instance after all this steps?

  • @mallikarjuna7624
    @mallikarjuna7624 2 ปีที่แล้ว

    Hi sir ,buckets are created in gcp or ec2 instance

  • @Ryan-Gordon
    @Ryan-Gordon ปีที่แล้ว

    Would this be possible to use with the gmail api? We need to be able to define "with_subject"

  • @logicstv
    @logicstv ปีที่แล้ว

    Can this be scoped to a specific gcp project rather than Org?

  • @chaitanyakrishna5873
    @chaitanyakrishna5873 2 ปีที่แล้ว

    First like... I am ready

  • @hardikmittal5740
    @hardikmittal5740 2 ปีที่แล้ว

    Can you pls create a video on workload identity to access inside google cloud kubernetes without RBAC roles?!!

  • @stkmgr00
    @stkmgr00 ปีที่แล้ว

    Hi GK, thanks for great video and it's really helpful.
    One question about the python program you used to list gcp buckets . what is this "GOOGLE_CLOUD_PROJECT" and value you assigned ?

    • @shukrilius
      @shukrilius ปีที่แล้ว

      "GOOGLE_CLOUD_PROJECT" refers to GCP Project ID.

  • @shivakumarnaidu
    @shivakumarnaidu 2 ปีที่แล้ว

    Sir where can I personally chat with u??? Regarding my case

  • @benw305
    @benw305 2 ปีที่แล้ว

    You have to leave an EC2 instance running on AWS?

  • @mynameishappy7126
    @mynameishappy7126 2 ปีที่แล้ว

    Excellent..waiting for this... can we do this between onprem cluster and gcp? Could you prepare a demo on that

    • @CloudAdvocate
      @CloudAdvocate  2 ปีที่แล้ว +1

      You need Identity from onprem. If your onprem vm is part of ldap maybe it is possible. I haven't tried it though.

    • @mynameishappy7126
      @mynameishappy7126 2 ปีที่แล้ว

      @@CloudAdvocate thanks for the reply...will try from my end... all the best ...

  • @ArulThangaRaja
    @ArulThangaRaja 3 หลายเดือนก่อน

    how to authenticate gcloud using aws temporary terminal credentials

  • @adapasrnsdurgarao9342
    @adapasrnsdurgarao9342 2 ปีที่แล้ว

    Hi Gk I took 3 years gap after my graduation(computer science engineering) and I don't have any experience before, now I'm going to learn about cloud but I'm in confusion state which one I pick and which certificate Is beneficial to me to start career in cloud please suggest me Gk

    • @CloudAdvocate
      @CloudAdvocate  2 ปีที่แล้ว

      Pick anyone cloud and start with fundamental certification or associate level certification.

  • @ManishSingh-ll4ws
    @ManishSingh-ll4ws ปีที่แล้ว

    Can we see gk-ec2-role-instance details ?

    • @shukrilius
      @shukrilius ปีที่แล้ว +1

      You can just create a new IAM Role and it is not necessary to add any permission, I created an empty role, attached it into an EC2 and worked.
      You can also use the fisrt option from WIF Granting Access session and do not "bind" it to any EC2/role,as he used in this video.
      It works also 😊👍

  • @saiteju8169
    @saiteju8169 ปีที่แล้ว

    GK. If possible could you make a video to use workload identity for github OIDC token, i wanted to remove SA keys from my github actions so this can be a best fit 😊

    • @CloudAdvocate
      @CloudAdvocate  ปีที่แล้ว

      Dude you read my mind. I will create that

    • @saiteju8169
      @saiteju8169 ปีที่แล้ว

      @@CloudAdvocate thanks a lot 😁

    • @CloudAdvocate
      @CloudAdvocate  ปีที่แล้ว

      th-cam.com/video/zRF5uTWXV8Y/w-d-xo.html there you go

  • @mallikarjuna7624
    @mallikarjuna7624 2 ปีที่แล้ว

    Where you created the buckets ??

  • @SKWonderWanderer
    @SKWonderWanderer ปีที่แล้ว

    Hay Bro, its not working and getting permission denied error while running sample.py.
    Please help!!

    • @shukrilius
      @shukrilius ปีที่แล้ว

      In my case was necessary to inform the "Absolute Path" for the credentials file. Give it a try!

  • @karthimt1306
    @karthimt1306 2 ปีที่แล้ว

    Hello sir. How can I contact you bro. I want some guidance please help me brooo.🥺 I was text you in instagram..

    • @CloudAdvocate
      @CloudAdvocate  2 ปีที่แล้ว

      Sorry, I will check the text on insta.

    • @OutOfDevOps
      @OutOfDevOps 2 ปีที่แล้ว

      @@CloudAdvocate thank you for the amazing content you produce. How would be possible to contact you?