-
Notifications
You must be signed in to change notification settings - Fork 11
GitHub OIDC → AWS IAM Role #67
Copy link
Copy link
Open
Labels
awsAmazon Web Services & cloud resourcesAmazon Web Services & cloud resourcesci/cdContinuous Integration & Continuous DeploymentContinuous Integration & Continuous DeploymentgovernancePolicies & standardsPolicies & standardshacktoberfestSpecial issue for HacktoberfestSpecial issue for Hacktoberfesthacktoberfest-2025Special issue for Hacktoberfest 2025Special issue for Hacktoberfest 2025infraInfrastructureInfrastructurepriority: highNeeds attention ASAPNeeds attention ASAPsecuritySecurity & complianceSecurity & compliance
Milestone
Metadata
Metadata
Assignees
Labels
awsAmazon Web Services & cloud resourcesAmazon Web Services & cloud resourcesci/cdContinuous Integration & Continuous DeploymentContinuous Integration & Continuous DeploymentgovernancePolicies & standardsPolicies & standardshacktoberfestSpecial issue for HacktoberfestSpecial issue for Hacktoberfesthacktoberfest-2025Special issue for Hacktoberfest 2025Special issue for Hacktoberfest 2025infraInfrastructureInfrastructurepriority: highNeeds attention ASAPNeeds attention ASAPsecuritySecurity & complianceSecurity & compliance
Type
Projects
Status
In Progress
Priority: High
Difficulty: High
Description:
Set up GitHub Actions OIDC trust with AWS by configuring trust for
token.actions.githubusercontent.com.gha-deploy-role) with minimum privileges required for: Lambda, API Gateway v2, CloudFront (invalidation), S3 (sync), and CloudWatch Logs.Acceptance Criteria:
gha-deploy-roleis created with least privilege access for required AWS services