Identity & Access across clouds
Account-level identity foundations - roles, workload identities and the guardrails each cloud expects you to set once, before anything else lands.
5 verified modules, 4 of them live-tested apply→verify→destroy; the rest are static-validated, live-test pending.
Compare by provider
| Provider | Module | Verification |
|---|---|---|
| AWS | IAM Roles, Policies & OIDC Trust | ✓ live-tested |
| Azure | Entra ID Workload Identity Baseline | ✓ live-tested |
| Azure | User-Assigned Managed Identities | ✓ live-tested |
| Google Cloud | Service Accounts & IAM Bindings | ✓ live-tested |
| Oracle Cloud | OCI IAM Foundation (compartments + policies) | static-validated |
How to choose
There is little portability here: each cloud models identity its own way, so pick the module for the cloud you are landing in rather than a favourite. Everywhere it is offered, prefer a workload identity (service account, managed identity) over a long-lived key - it is the single change that removes the most credential risk.
When not to use
These are foundations, not an identity programme. They do not federate your workforce directory, run access reviews, or manage human joiners and leavers.
Other solutions
Managed Relational Database18Managed Kubernetes15Virtual Machines13Messaging & Pub/Sub11Load Balancer10DNS & Traffic Management10Virtual Private Cloud (VPC)9Serverless Containers7Secrets & Key Management7Serverless Functions6Object Storage5API Gateway5Container Registry3CDN & Edge Delivery3In-Memory Cache3Monitoring & Observability3WAF & Edge Security3Shared File Storage3