From 393c34c25de9966abd345f3111b981f480b29a2e Mon Sep 17 00:00:00 2001 From: JD Harrington Date: Thu, 27 Aug 2026 12:44:26 -0400 Subject: [PATCH 1/3] Replace static AWS credentials with OIDC role assumption Migrate GitHub Actions workflows from static IAM credentials (TRUSS_AWS_ACCESS_KEY_ID / TRUSS_AWS_SECRET_ACCESS_KEY) to OIDC role assumption via aws-actions/configure-aws-credentials. This is part of an org-wide migration to eliminate static AWS credential usage in CI/CD pipelines (PIER-821). Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/upload.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/upload.yml b/.github/workflows/upload.yml index 83c7643..4905601 100644 --- a/.github/workflows/upload.yml +++ b/.github/workflows/upload.yml @@ -4,6 +4,10 @@ on: [push] env: ECR_REPOSITORY: toolbox +permissions: + contents: read + id-token: write + jobs: upload-docker-image: runs-on: ubuntu-latest @@ -14,8 +18,7 @@ jobs: - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v4 with: - aws-access-key-id: ${{ secrets.TRUSS_AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.TRUSS_AWS_SECRET_ACCESS_KEY }} + role-to-assume: arn:aws:iam::127178877223:role/github/github-truss aws-region: us-east-2 - name: Login to AWS ECR From fb69c8b55c35b1186a8d51d855a67d7fc6337ea1 Mon Sep 17 00:00:00 2001 From: JD Harrington Date: Thu, 3 Sep 2026 10:20:33 -0400 Subject: [PATCH 2/3] Update kubectl from bitnami image to direct download at v1.34.11 The bitnami/kubectl:1.33.2 image tag no longer exists (bitnami purged versioned tags). Download kubectl directly from the official Kubernetes release URL instead, and update to v1.34.11 to match production. Co-Authored-By: Claude Opus 4.6 (1M context) --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index c7627d2..e632e9e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,7 +13,8 @@ ENV VAULT_ADDR https://vault.vault.svc:8200 ENV VAULT_SKIP_VERIFY true # kubectl -COPY --from=bitnami/kubectl:1.33.2 /opt/bitnami/kubectl/bin/kubectl /usr/bin/kubectl +ADD https://dl.k8s.io/release/v1.34.11/bin/linux/amd64/kubectl /usr/bin/kubectl +RUN chmod +x /usr/bin/kubectl # AWS CLI RUN apk add --no-cache aws-cli From 581e166a53c7332775059722a5ecea3296895267 Mon Sep 17 00:00:00 2001 From: JD Harrington Date: Thu, 3 Sep 2026 10:24:48 -0400 Subject: [PATCH 3/3] Add checksum verification for kubectl download Co-Authored-By: Claude Opus 4.6 (1M context) --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index e632e9e..118b0ce 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,7 +13,8 @@ ENV VAULT_ADDR https://vault.vault.svc:8200 ENV VAULT_SKIP_VERIFY true # kubectl -ADD https://dl.k8s.io/release/v1.34.11/bin/linux/amd64/kubectl /usr/bin/kubectl +ADD --checksum=sha256:8efbb9435132a190920eb65a47a8c1ecf755ad85ab57a600c9bedbab460bb7a8 \ + https://dl.k8s.io/release/v1.34.11/bin/linux/amd64/kubectl /usr/bin/kubectl RUN chmod +x /usr/bin/kubectl # AWS CLI