Flow 06 · Machines
The job signs in as itself.
Nobody is in this flow. Client credentials hands the workload a short token for one API. If your platform speaks SPIFFE, it’s the same idea with a different piece of paper.
Watch for
- The subject of the token is the client. Not the employee who set the integration up in 2022.
- Prefer a key the workload can prove it holds, a private-key JWT or mutual TLS, over a shared secret that copies cleanly.
- Scope and audience are the whole decision. “Whatever this client might ever need” is standing access with a shorter name.
Failure modes
- A client secret in a repo, a pipeline log, or a wiki, with no expiry.
- One cloud role shared by every job, because making a separate client felt like paperwork.
- No owner. The integration outlives the team that built it, and nobody remembers what it does.