Problem
OTLP export authentication only supports GitHub-issued credentials (static secret header, GitHub App token, GitHub Actions OIDC JWT). There is no way to exchange a GitHub OIDC token for a cloud-issued access token (e.g. Google WIF/STS), so cloud-native OTLP endpoints like telemetry.googleapis.com that require their own tokens cannot be reached without standing up a separate collector.
Context
Original report: github/gh-aw#50013
Root Cause
The per-job OIDC minting path (generateOTLPOIDCMintStep) only produces a raw GitHub OIDC JWT. There is no token-exchange step to swap that JWT for a cloud provider access token via Workload Identity Federation/STS, and no firewall allowlist entries for provider STS endpoints (e.g. sts.googleapis.com).
Proposed Solution
Extend the OTLP OIDC mint path with an optional workload-identity config block (provider, audience, service-account) that performs the STS exchange per span-emitting job (agent, activation, conclusion, safe_outputs) before setting the Authorization header. Automatically grant id-token: write on those jobs and add the provider's token-exchange host(s) to the AWF egress allowlist so the exchange call itself is not blocked.
Generated by Firewall Issue Dispatcher · auto · 32.3 AIC · ⊞ 9K · ◷
Problem
OTLP export authentication only supports GitHub-issued credentials (static secret header, GitHub App token, GitHub Actions OIDC JWT). There is no way to exchange a GitHub OIDC token for a cloud-issued access token (e.g. Google WIF/STS), so cloud-native OTLP endpoints like
telemetry.googleapis.comthat require their own tokens cannot be reached without standing up a separate collector.Context
Original report: github/gh-aw#50013
Root Cause
The per-job OIDC minting path (
generateOTLPOIDCMintStep) only produces a raw GitHub OIDC JWT. There is no token-exchange step to swap that JWT for a cloud provider access token via Workload Identity Federation/STS, and no firewall allowlist entries for provider STS endpoints (e.g.sts.googleapis.com).Proposed Solution
Extend the OTLP OIDC mint path with an optional
workload-identityconfig block (provider,audience,service-account) that performs the STS exchange per span-emitting job (agent, activation, conclusion, safe_outputs) before setting theAuthorizationheader. Automatically grantid-token: writeon those jobs and add the provider's token-exchange host(s) to the AWF egress allowlist so the exchange call itself is not blocked.