# OIDC, bastion hosts, and production safety Page: https://stenobird.com/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety Text version: https://stenobird.com/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety.md Podcast: [North Meets South Web Podcast](https://stenobird.com/podcast/north-meets-south-web-podcast-706861) Published: 2026-03-19T14:00:00+00:00 Episode link: https://share.transistor.fm/s/f6e205ec Audio file: https://media.transistor.fm/f6e205ec/9eb5acfd.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/north-meets-south-web-podcast-706861/episodes/oidc-bastion-hosts-and-production-safety Duration seconds: 2291 ## Resource In this episode, Jake and Michael dive into modern infrastructure security practices, sparked by an annual audit and the painful process of rotating AWS IAM tokens. That experience leads into a broader discussion on why long-lived credentials in GitHub Actions are risky, and how OIDC (OpenID Connect) enables a more secure, short-lived, role-based alternative. Show links Scout Suite OpenID Connect (OIDC) Laravel Forge Laravel Horizon Scramble Claude LoRA (Low-Rank Adaptation) ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/north-meets-south-web-podcast-706861/episodes/oidc-bastion-hosts-and-production-safety/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/north-meets-south-web-podcast-706861/oidc-bastion-hosts-and-production-safety.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.