Secretless Provisioning: Token Exchange, Not Stored Keys

No long-lived secret appears anywhere in this sequence — only short-lived tokens, exchanged just in time.
Provisioning Pipeline Identity Provider Cloud API 1. presents internal workload token verifies & trusts 2. issues short-lived cloud credential 3. calls cloud API with short-lived credential 4. resource created / modified / destroyed Credential expires shortly after (~1 hour) No long-lived secret existed at any point above.