Artifacts
All pages
Docs · SetupMarkdown

Connecting clouds

Artifacts creates buckets in your AWS account, GCP project or Azure subscription and signs URLs for them, without any long-lived cloud key from you.

Federation

The app is an OpenID Connect identity provider. It publishes /.well-known/openid-configuration and its keys at /.well-known/jwks.json, and signs short JWTs whose subject is one connection, org_…:c…. Your cloud trusts that issuer for that one subject and swaps the JWT for its own short-lived credentials.

Nothing you give us can be lifted and used elsewhere. Revoking is deleting the role, the workload identity pool or the federated credential on your side.

Connect

  1. Connections → Connect AWS, GCP or Azure, and name the connection.
  2. The app shows a setup script with your connection's subject, the issuer and the audience filled in. Run it in your account with the cloud's CLI, as an administrator.
  3. The script's last line prints the identifiers it created, key=value pairs. Paste that line back into the app, or fill in the fields.
  4. The app exchanges a token to check the connection works, and marks it active. A connection whose trust was removed shows as broken, with the error.

Then create locations in that cloud: pick the connection and a region, and the app creates the bucket.

Cloud The script creates It grants The app signs with
AWS An IAM OIDC provider for the issuer and a role trusting the subject, max session 12 h Create o41art-* buckets and set their lifecycle; object and multipart operations in them Temporary keys from AssumeRoleWithWebIdentity, cached until shortly before they expire
GCP A workload identity pool and provider for the issuer, a service account the subject may impersonate Create buckets; storage admin on o41art-* buckets only; sign as the service account The service account through IAM signBlob, with the federated token: V4 URLs on the XML API, no key ever made
Azure An app registration with a federated credential for the issuer and subject Storage Account Contributor and Storage Blob Data Contributor on a resource group you name A user delegation key per storage account, refreshed daily; user delegation SAS

The identifiers

Cloud Pasted back
AWS roleArn
GCP projectId, projectNumber, poolId, providerId, serviceAccountEmail
Azure tenantId, clientId, subscriptionId, resourceGroup

Created buckets

  • Named o41art-<random>; on Azure a storage account o41art<random> with a container artifacts.
  • Private, with a lifecycle rule that aborts unfinished multipart uploads after 2 days. Azure drops uncommitted blocks after 7 days by itself.
  • The app never deletes a bucket. A location is retired instead: no new writes go to it and its versions stay readable.
  • A created location whose bucket or first test write fails stays unfinished: it takes no writes and can be removed (locations rm); the bucket, if one was made, stays in your account.

A tenant who cannot set up federation on AWS or GCP adds the bucket as an S3 endpoint with a key instead. Azure Blob has no S3 API, so Azure is federation only.