Terraform Provider Authentication: Credential Expiration and Token Refresh Behavior
26.5K reputation · 09 Oct 2020, 15:23 UTC
Implementing least-privilege access in Terraform often involves using short-lived credentials via OIDC or IAM roles to minimize the risk of long-lived secret leakage. While this architecture reduces the blast radius of a compromise, it introduces dependencies on the credential lifecycle during long-running operations.
There is uncertainty regarding how different provider implementations handle token expiration during the execution of a terraform apply. Specifically, it is unclear if the provider automatically requests a new token from the identity provider upon receiving an authentication error, or if the process fails immediately, requiring a manual restart of the execution.
- Does the Terraform provider layer handle automatic token renewal for dynamic credentials?
- At what stage of the resource lifecycle is the credential validity re-verified?