Skip to content

Commit e872feb

Browse files
authored
GitHub OIDC token for AWS Creds in all workflows (#48)
1 parent 3e4d43f commit e872feb

File tree

2 files changed

+2
-4
lines changed

2 files changed

+2
-4
lines changed

.github/workflows/integration-testing.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ jobs:
88
name: Publish and Test Apps
99
runs-on: ubuntu-latest
1010
permissions:
11+
id-token: write
1112
packages: write
1213
strategy:
1314
fail-fast: false
@@ -34,8 +35,6 @@ jobs:
3435
- name: Configure AWS Credentials
3536
uses: aws-actions/configure-aws-credentials@v1
3637
with:
37-
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
38-
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
3938
role-to-assume: ${{ secrets.AWS_ASSUME_ROLE_ARN }}
4039
role-duration-seconds: 1200
4140
aws-region: us-east-1

.github/workflows/soak-testing.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ jobs:
3737
runs-on: ubuntu-latest
3838
permissions:
3939
contents: write
40+
id-token: write
4041
issues: write
4142
strategy:
4243
fail-fast: false
@@ -117,8 +118,6 @@ jobs:
117118
- name: Configure AWS Credentials
118119
uses: aws-actions/configure-aws-credentials@v1
119120
with:
120-
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
121-
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
122121
role-to-assume: ${{ secrets.AWS_ASSUME_ROLE_ARN }}
123122
role-duration-seconds: 21600 # 6 Hours
124123
aws-region: ${{ env.AWS_DEFAULT_REGION }}

0 commit comments

Comments
 (0)