Episode
OIDC, bastion hosts, and production safety
- Published
- Mar 19, 2026
- Duration seconds
- 2291
- Processing state
not_requested- Canonical source
- https://share.transistor.fm/s/f6e205ec
Actions
POST https://stenobird.com/v1/public/podcasts/north-meets-south-web-podcast-706861/episodes/oidc-bastion-hosts-and-production-safety/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
In this episode, Jake and Michael dive into modern infrastructure security practices, sparked by an annual audit and the painful process of rotating AWS IAM tokens. That experience leads into a broader discussion on why long-lived credentials in GitHub Actions are risky, and how OIDC (OpenID Connect) enables a more secure, short-lived, role-based alternative. Show links Scout Suite OpenID Connect (OIDC) Laravel Forge Laravel Horizon Scramble Claude LoRA (Low-Rank Adaptation)