OIDC & Workload Identity
GitLab OIDC federation with GCP workload identity β CI pipelines impersonate scoped service accounts without long-lived keys.
Golden-path DevOps β from GitLab OIDC to a production-ready workload on GKE Autopilot.
GitLab OIDC federation with GCP workload identity β CI pipelines impersonate scoped service accounts without long-lived keys.
Private GKE Autopilot, NetworkPolicy default-deny, Gateway HTTPS, cert-manager DNS-01, and proxy-subnet ingress controls.
Cookiecutter generator scaffolds bootstrap + app repos with Helm, GitLab CI, and Terraform β repeatable onboarding in minutes.
GitLab Duo AI code review on merge requests β automated security and quality feedback before changes reach production.
Provision Artifact Registry, CI service accounts, WIF bindings, and GKE IAM β infrastructure ready before first deploy.
cert-manager, external-dns, cluster issuers, and gateway ingress policies β shared platform capabilities for every app.