Secretless Provisioning: Token Exchange, Not Stored Keys
No long-lived secret appears anywhere in this sequence — only short-lived tokens, exchanged just in time.
Provisioning Pipeline
Identity Provider
Cloud API
1. presents internal workload token
verifies & trusts
2. issues short-lived cloud credential
3. calls cloud API with short-lived credential
4. resource created / modified / destroyed
Credential expires shortly after (~1 hour)
No long-lived secret existed at any point above.