A Multi-Cloud Framework for Zero-Trust Workload Authentication
Published: Oct 17, 2025
Last Updated: Oct 17, 2025
Authors:Saurabh Deochake, Ryan Murphy, Jeremiah Gearheart
Abstract
Static, long-lived credentials for workload authentication create untenable security risks that violate Zero-Trust principles. This paper presents a multi-cloud framework using Workload Identity Federation (WIF) and OpenID Connect (OIDC) for secretless authentication. Our approach uses cryptographically-verified, ephemeral tokens, allowing workloads to authenticate without persistent private keys and mitigating credential theft. We validate this framework in an enterprise-scale Kubernetes environment, which significantly reduces the attack surface. The model offers a unified solution to manage workload identities across disparate clouds, enabling future implementation of robust, attribute-based access control.