FEATURED PROJECT / Cloud identity security
AZ-01 β Azure Workload Identity Attack & Secretless Federation Lab
A validated Azure lab tracing a deliberately vulnerable long-lived workload credential and excessive RBAC through controlled attack validation, secretless federation remediation, revalidation, and verified teardown.
Results apply only to tested actions and known project-owned targets. Baseline and remediated deployments used separate validation windows; the retired credential was not replayed in place. The Azure environment is destroyed. This lab does not establish universal least privilege, penetration-test coverage, production suitability, or broader Azure security assurance.
Engineering evidence
- Objective
- Validate a bounded workload identity attack path and remediate credential and authorization risks using secretless federation and reduced Azure RBAC scope.
- Delivery
- Terraform, controlled Azure CLI validation, and GitHub Actions static security CI
- Validation record
- Sanitized baseline, attack, federation, post-remediation, teardown, and CI validation records
Controls in scope
- Microsoft Entra ID
- Azure RBAC
- GitHub OIDC
- Workload Identity Federation
- Terraform
- Least privilege



