Episode

OIDC, bastion hosts, and production safety

Podcast
North Meets South Web Podcast
Published
Mar 19, 2026
Duration seconds
2291
Processing state
not_requested
Canonical source
https://share.transistor.fm/s/f6e205ec
Audio
https://media.transistor.fm/f6e205ec/9eb5acfd.mp3
JSON
/v1/public/podcasts/north-meets-south-web-podcast-706861/episodes/oidc-bastion-hosts-and-production-safety
Markdown
/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/north-meets-south-web-podcast-706861/episodes/oidc-bastion-hosts-and-production-safety/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this episode, Jake and Michael dive into modern infrastructure security practices, sparked by an annual audit and the painful process of rotating AWS IAM tokens. That experience leads into a broader discussion on why long-lived credentials in GitHub Actions are risky, and how OIDC (OpenID Connect) enables a more secure, short-lived, role-based alternative. Show links Scout Suite OpenID Connect (OIDC) Laravel Forge Laravel Horizon Scramble Claude LoRA (Low-Rank Adaptation)