Skip to content

Replace static AWS credentials with OIDC role assumption - #4

Merged
psi merged 3 commits into
masterfrom
oidc-app-workflows
Sep 3, 2026
Merged

psi merged 3 commits into
masterfrom
oidc-app-workflows

Conversation

@psi

@psi psi commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Replace static IAM credentials (TRUSS_AWS_ACCESS_KEY_ID / TRUSS_AWS_SECRET_ACCESS_KEY) with OIDC role assumption via aws-actions/configure-aws-credentials
  • Add permissions: id-token: write at the workflow level to enable OIDC token generation
  • Part of org-wide OIDC migration (PIER-821)

Additional fixes (pre-existing issues discovered during CI)

  • Update kubectl from bitnami/kubectl:1.33.2 to direct download of v1.34.11 — Bitnami purged versioned image tags, breaking the COPY --from in the Dockerfile. Now downloads kubectl directly from the official Kubernetes release URL with SHA256 checksum verification. Updated to v1.34.11 to match production.

Test plan

  • CI checks pass on this PR
  • Verify workflow runs succeed after merge

🤖 Generated with Claude Code

Migrate GitHub Actions workflows from static IAM credentials
(TRUSS_AWS_ACCESS_KEY_ID / TRUSS_AWS_SECRET_ACCESS_KEY) to OIDC
role assumption via aws-actions/configure-aws-credentials.

This is part of an org-wide migration to eliminate static AWS
credential usage in CI/CD pipelines (PIER-821).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The bitnami/kubectl:1.33.2 image tag no longer exists (bitnami
purged versioned tags). Download kubectl directly from the
official Kubernetes release URL instead, and update to v1.34.11
to match production.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@psi
psi merged commit ea8f278 into master Sep 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants