Skip to content

Commit 1882332

Browse files
committed
feat: change to use assume role
1 parent fe7a5b4 commit 1882332

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

.github/workflows/terraform.yml

+5-3
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,11 @@ jobs:
2626
- name: Configure AWS credentials
2727
uses: aws-actions/configure-aws-credentials@v4
2828
with:
29-
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
30-
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
31-
aws-region: ${{ vars.AWS_REGION }}
29+
role-to-assume: arn:aws:iam::179916804929:role/BuildRun-GithubActions-Role #change to reflect your IAM role’s ARN
30+
role-session-name: GitHub_to_AWS_via_FederatedOIDC
31+
# aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
32+
# aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
33+
# aws-region: ${{ vars.AWS_REGION }}
3234

3335
- name: Read destroy configuration
3436
id: read-destroy-config

0 commit comments

Comments
 (0)