GCP WIF
If your infrastructure is hosted on GCP, please adopt this solution.
How to use WIF(Workload Identity Federation), detailed documentation is here.
1. Overview
When a partner’s infrastructure is hosted on Google Cloud Platform (GCP), Klavi uses Workload Identity Federation (WIF) to securely deliver files to the partner's Cloud Storage (GCS) buckets.
This process allows Klavi’s AWS IAM roles to "impersonate" a GCP Service Account. By establishing a trust relationship between AWS and GCP, we ensure that data is transferred securely without managing or rotating static credentials.
2. Partner (Recipient/GCP) Configuration Guide
As the data recipient on GCP, you must configure your environment to trust Klavi’s AWS identity.
2.1 Create a Workload Identity Pool and Provider
You need to create a pool to manage the identity relationship and a provider to specify AWS as the identity source.
- Create a Workload Identity Pool: e.g., klavi-access-pool.
- Add an AWS Provider:
- Provider ID: klavi-aws-provider.
- Issuer (URL): Use the default AWS OIDC issuer.
- AWS Account ID: Provide Klavi’s AWS Account ID (see Section 3.2).
- Attribute Mapping: Map the following to ensure secure identification:
- google.subject = assertion.arn
- attribute.aws_role = assertion.arn.contains('role/') ? assertion.arn.extract('role/{role_name}/') : assertion.arn
2.2 Create and Bind a GCP Service Account
- Create a Service Account: e.g., [email protected].
- Grant Bucket Permissions: Assign the Storage Object Creator (or roles/storage.objectCreator) role to this Service Account on your destination GCS bucket.
- Allow Impersonation: Grant Klavi’s AWS IAM Role the permission to impersonate this Service Account using the roles/iam.workloadIdentityUser role.
3. Information Exchange Checklist
The following technical parameters are required to establish the secure handshake.
3.1 From Partner to Klavi
Please provide the following GCP resource identifiers to the Klavi integration team:
Parameter | Description | Example |
|---|---|---|
GCP Project Number | The numeric ID of your GCP project. | 123456789012 |
Workload Pool ID | The ID of the WIF Pool created in Step 2.1. | klavi-access-pool |
Provider ID | The ID of the AWS Provider. | klavi-aws-provider |
GCP Service Account | The email of the SA Klavi will impersonate. | |
GCS Bucket Name | The destination bucket for file delivery. | partner-data-inbound |
3.2 From Klavi to Partner
Klavi will provide these details to allow you to configure your WIF Provider and IAM policies:
Parameter | Description |
|---|---|
Klavi AWS Account ID | The AWS account from which requests will originate. |
Klavi IAM Role ARN | The specific AWS Role ARN that will request GCP tokens. |
4. Klavi Operational Workflow
Once the configuration is complete, the Klavi automated pipeline will perform the following:
- Token Exchange: Klavi exchanges its AWS STS token for a temporary GCP federated token via the WIF Provider.
- Service Account Impersonation: The federated token is used to generate a short-lived Access Token for the Partner's GCP Service Account.
- Secure Upload: Klavi uploads the files directly to your GCS bucket using the generated token.
- Verification: A test file is uploaded to confirm the handshake is operational.
5. Security Best Practices
- Keyless Auth: Never request or store Klavi’s IAM User keys or GCP Service Account JSON keys.
- Attribute Conditions: We recommend adding a condition to your WIF Provider to only allow the specific Klavi IAM Role ARN to prevent unauthorized AWS accounts from attempting federation.
- Audit Logging: Enable Cloud Audit Logs (Data Access logs) on your GCS bucket to monitor all file write activities by the federated identity.
Support: For technical assistance during setup, please contact our support team at [email protected].