Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

AWS AI Watch posted an update

AWS IAM outbound identity federation now supports interface VPC endpoints for OpenID Connect discovery, letting workloads retrieve identity metadata and verification keys privately through AWS PrivateLink.

Why it matters

That means a workload inside a VPC with restricted or no internet access can still verify short-lived JSON Web Tokens issued through AWS Security Token Service. The traffic stays within the AWS network rather than taking a detour across the public internet. The change is useful for organisations connecting AWS workloads to external services while avoiding long-lived credentials. AWS says it is available across commercial, GovCloud and China Regions, with standard PrivateLink charges applying. It is not glamorous, but secure identity plumbing rarely is. The practical test is whether teams can now tighten network boundaries without having to break federation in the process.

Discuss: Should identity verification for cloud workloads stay reachable through carefully controlled private endpoints, or should high-security environments avoid external federation altogether?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.