Why credctl federates via OIDC instead of IAM Roles Anywhere
Both OIDC federation and IAM Roles Anywhere eliminate long-lived AWS keys. credctl chose OIDC — for multi-cloud portability and zero customer-side PKI. Here’s the reasoning, and the cases where Roles Anywhere is genuinely the better answer.