Codefresh
Builds authenticate as the pipeline they ran in.
Builds authenticate as the pipeline they ran in.
Identity proof
The token has to come from https://oidc.codefresh.io, and its pipeline_id claim has to match the workload you named. We compare that claim byte for byte, with no wildcards.
pipeline_id is matched rather than sub, which on this platform does not name the workload in a form you can pin.
Every token also has to name your workspace as its audience. Ask for this audience and no other. A token requested for two audiences fails every exchange.
Console fields
| Field | Example | Advanced | What it pins |
|---|---|---|---|
| Pipeline ID | 65e5a53e52853dc51a5b0cc1 | no | Pipeline → Settings → General → Pipeline ID. |
The console also asks which project and environment this identity reaches and which role it gets, with the credential lifetime behind Advanced.
Trust
Built from the example answers above:
| What | Value |
|---|---|
| Issuer | https://oidc.codefresh.io |
| Claim compared | pipeline_id |
| Subject | 65e5a53e52853dc51a5b0cc1 |
| Identity name | codefresh-3dc51a5b0cc1 |
We name the identity for you, so the form never asks for one.
Console snippet
steps:
pull_secrets:
image: YOUR_IMAGE # any image with curl, jq and penv
commands:
- |
T=$(curl -sS -H "Authorization: $CF_OIDC_REQUEST_TOKEN" \
"$CF_OIDC_REQUEST_URL?audience=YOUR_WORKSPACE_ID" | jq -r .id_token)
C=$(curl -sS "https://penv.cloud/api/v1/auth/oidc" \
-H 'content-type: application/json' \
-d "{\"token\":\"$T\"}" | jq -r .credential)
PENV_TOKEN="$C" penv pullThe snippet finishes with penv pull, which writes a file. We recommend penv run for a process; penv pull is for a host that needs a file on disk. Connect your CI has the wrapped step.
Related
- Machine identity
- Connect a Platform in the console
- Codefresh documentation: the subject is the value most often set wrong