ServiceActive

Fly.io OpenID Connect

Short-lived OIDC token service for Fly Machines to authenticate with third-party cloud providers without hardcoded credentials.

Open source page

Field note

What it does

Fly.io OIDC service issues unique JWT tokens per request for Machine authentication with AWS, Azure, GCP, Vault, and other OIDC-supporting providers. Tokens expire in 15 minutes and include customizable audience claims with org/app/Machine identity in the subject claim.

Capabilities

Available capabilities

Tags

Tags

Ways to use it

Ways to use it

rest

Not filed / https://us-east-1.console.aws.amazon.com/iam/home?region=us-east-1#/identity_providers/create

sdk

Not filed / Not filed

Product features

Product features

App configuration files

App configuration (fly.toml)

Config file formats

Console command

How the shutdown sequence works

kill_signal option

kill_timeout option

Primary region

Runtime options

swap_size_mb option

The app name

Ways to get a config file