Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Terraform in Yandex Cloud
  • Getting started
  • Solution library
    • Overview
    • Release notes
          • iam_oauth_client
          • iam_oauth_client_secret
          • iam_service_account
          • iam_service_account_api_key
          • iam_service_account_iam_binding
          • iam_service_account_iam_member
          • iam_service_account_iam_policy
          • iam_service_account_key
          • iam_service_account_static_access_key
          • iam_workload_identity_federated_credential
          • iam_workload_identity_oidc_federation
          • iam_workload_identity_oidc_federation_iam_binding
          • organizationmanager_saml_federation_user_account

In this article:

  • Example usage
  • Arguments & Attributes Reference
  • Import
  1. Terraform reference
  2. Resources
  3. Identity and Access Management
  4. Resources
  5. iam_workload_identity_oidc_federation

yandex_iam_workload_identity_oidc_federation (Resource)

Written by
Yandex Cloud
Updated at February 12, 2026
  • Example usage
  • Arguments & Attributes Reference
  • Import

A OIDC workload identity federation.

Example usageExample usage

//
// Create a new IAM Workload Identity OIDC Federation.
//
resource "yandex_iam_workload_identity_oidc_federation" "wlif" {
  name        = "some_wlif_name"
  folder_id   = "some_folder_id"
  description = "some description"
  disabled    = false
  audiences   = ["aud1", "aud2"]
  issuer      = "https://example-issuer.com"
  jwks_url    = "https://example-issuer.com/jwks"
  labels = {
    key1 = "value1"
    key2 = "value2"
  }
}

Arguments & Attributes ReferenceArguments & Attributes Reference

  • audiences (Read-Only) (Set Of String). List of trusted values for aud claim.
  • created_at (Read-Only) (String). Creation timestamp.
  • description (Read-Only) (String). Description of the OIDC workload identity federation.
  • disabled (Bool). True - the OIDC workload identity federation is disabled and cannot be used for authentication.
    False - the OIDC workload identity federation is enabled and can be used for authentication.
  • enabled (Read-Only) (Bool). Enabled flag.
  • federation_id (String). Id of the OIDC workload identity federation.
  • folder_id (Read-Only) (String). Id of the folder that the OIDC workload identity federation belongs to.
  • id (String).
  • issuer (Read-Only) (String). Issuer identifier of the external IdP server to be used for authentication.
  • jwks_url (Read-Only) (String). URL reference to trusted keys in format of JSON Web Key Set.
  • labels (Read-Only) (Map Of String). Resource labels as key-value pairs.
  • name (String). Name of the OIDC workload identity federation. The name is unique within the folder.

ImportImport

The resource can be imported by using their resource ID. For getting it you can use Yandex Cloud Web Console or Yandex Cloud CLI.

# terraform import yandex_iam_workload_identity_oidc_federation.<resource Name> <resource Id>
terraform import yandex_iam_workload_identity_oidc_federation.wlif ...

Was the article helpful?

Previous
iam_workload_identity_federated_credential
Next
iam_workload_identity_oidc_federation_iam_binding
© 2026 Direct Cursus Technology L.L.C.