Skip to content

Commit 9a137a8

Browse files
authored
Switch to OpenID Connect authentication (#383)
1 parent 70a90da commit 9a137a8

File tree

1 file changed

+5
-7
lines changed

1 file changed

+5
-7
lines changed

.github/workflows/ci.yml

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
1-
1+
permissions:
2+
id-token: write # This is required for requesting the JWT
3+
contents: read # This is required for actions/checkout
24
on:
35
pull_request:
46
paths-ignore:
@@ -32,11 +34,9 @@ jobs:
3234
- name: Configure AWS Credentials
3335
uses: aws-actions/configure-aws-credentials@v4
3436
with:
35-
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
36-
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
3737
aws-region: us-east-1
3838
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
39-
role-skip-session-tagging: true
39+
role-session-name: github-actions-ci
4040
- name: 'Terraform Validate cluster'
4141
run: terraform validate
4242
working-directory: 'examples/cluster'
@@ -50,11 +50,9 @@ jobs:
5050
- name: Configure AWS Credentials
5151
uses: aws-actions/configure-aws-credentials@v4
5252
with:
53-
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
54-
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
5553
aws-region: us-east-1
5654
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
57-
role-skip-session-tagging: true
55+
role-session-name: github-actions-ci
5856
- name: 'Terratest'
5957
uses: ./.github/actions/terratest
6058
with:

0 commit comments

Comments
 (0)