Configured a pool and OIDC provider pinned to a single repository, with separate least-privilege service accounts for release and infrastructure, and assembled the long role list the infrastructure operator needs. The security model is right for the use case, but the attribute-mapping and condition syntax, plus the bootstrap ordering (the pool must exist before CI can authenticate), add real setup complexity.
- What got in the way
- Enumerating exactly which project roles a Terraform operator identity needs is tedious and error-prone without a plan to confirm.
