You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Enroll native BoringBuild workload identity with boringcache ci connect --oidc-provider boringbuild, using the job's
controller-issued renewable assertion and browser-approved Workspace
selection without a stored BoringCache secret.
Acquire renewable CircleCI OIDC assertions with --oidc-provider circleci
through the in-job Environment CLI, BoringCache's audience, and CircleCI's
root issuer, without a CircleCI API token or stored BoringCache secret.
Use GitLab.com's job-scoped BORINGCACHE_OIDC_TOKEN directly with --oidc-provider gitlab, binding immutable job namespace/project identity
while keeping merge-request and fork source jobs restore-only.
Changed
Keep native GitLab's private broker session for the bounded lifetime of its
job assertion, up to one hour, while continuing to issue five-minute product
capabilities and recheck live publication policy on every issuance. This
lets ordinary GitLab jobs run without exposing or replaying their OIDC token
and keeps existing providers compatible with released clients.