Skip to Main Content
Cloud and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Created by Guest
Created on Sep 2, 2026

Enhance Automation Hub GCP Plugins with Workload Identity Federation and Secure-by-Default Authentication

Business Need

As enterprise customers increasingly adopt cloud-native security practices, static service account keys are becoming less desirable due to the operational overhead and security risks associated with managing long-lived credentials.

Currently, onboarding several Google Cloud integrations within Automation Hub, such as Cloud Run, Dataflow, and other GCP-based plugins, often relies on static service account credentials. This can create friction for organisations operating under Zero Trust and least-privilege security models.

Modern authentication methods such as Workload Identity Federation and OAuth 2.0 provide a more secure and operationally efficient approach.

IBM should enhance Google Cloud integrations within Automation Hub to support:

  • Workload Identity Federation (WIF)
  • OAuth 2.0 token-based authentication
  • Service Account Impersonation
  • Short-lived credentials instead of long-lived service account keys

This capability should be available across Cloud Run, Dataflow, GKE, and other Google Cloud plugins where applicable.

Where supported, Workload Identity should be presented as the recommended/default authentication method, while retaining support for service account keys for backward compatibility.

Customer Benefits

  • Improved security through keyless authentication.
  • Reduced risk associated with long-lived credentials.
  • Alignment with Zero Trust and least-privilege principles.
  • Simplified operational management by removing key rotation and secret management requirements.
  • Faster onboarding and security approval processes within regulated organisations.
  • Better alignment with Google Cloud security best practices.

Business Value for IBM

  • Reduced onboarding friction for customers.
  • Increased adoption of Automation Hub integrations.
  • Better support for highly regulated industries such as banking, insurance, and government.
  • Reduced support effort related to service account key management.
  • Stronger alignment with modern cloud-native security architectures.
Idea priority Medium