GitHub Actions and Akeyless: Zero Stored Credentials
Use Akeyless OIDC authentication in GitHub Actions to eliminate stored secrets from CI/CD

Lab Overview
In this lab you will configure GitHub Actions to authenticate to Akeyless using OpenID Connect (OIDC) token exchange — no long-lived secrets stored in GitHub. You will create a JWT authentication method in Akeyless, bind it to a specific GitHub repository using sub-claims, build a workflow that fetches secrets at runtime, and verify through the Akeyless audit log that the integration works. This approach eliminates the most common CI/CD credential risk: stored access keys.
What You'll Learn
Create an OAuth2.0/JWT auth method in Akeyless bound to GitHub OIDC tokens
Configure sub-claims to restrict access to a specific repository
Build a GitHub Actions workflow that uses Akeyless OIDC authentication
Verify zero stored credentials in the CI/CD pipeline
Review the Akeyless audit log for CI/CD authentication events
Prerequisites
Akeyless account with API Key access credentials
GitHub account (free tier sufficient)
Basic familiarity with GitHub Actions workflows
git installed and configured with your GitHub credentials
Technologies Covered
Choose your plan
Simple, Transparent Pricing
Unlock full access to TeKanAid courses, labs, and bootcamps
Pro
Course content without labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Full access to all courses
- Progress tracking
- Certificate of completion
- Community access
- Bootcamp participation
- New content access
Premium
Full access with hands-on labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Everything in Pro
- Unlimited hands-on labs
- Lab AI Assistant
- Accelerator bootcamps with live office hours
- Priority support
Prefer a single course?
Purchase individual courses for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.
Browse CoursesTry it free, no credit card
Three free ways to start. All bridge into the paid Premium catalog when you're ready.
Not ready to commit? The crash course is email-only. No academy account required.
Ready to Get Started?
Start this hands-on lab and build real-world Platform Engineering skills
Get Access Now