mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-08-28 05:05:12 +09:00
Compare commits
302 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ffcda53774 | |||
| 39c6a97582 | |||
| 42741432d4 | |||
| 8078ce0ebb | |||
| 70ddaa6bac | |||
| ddbaf5f59a | |||
| d10819b44a | |||
| be8dacf4c9 | |||
| d6cef3c044 | |||
| d73d78f404 | |||
| 5afbaca2ca | |||
| b64a17e6a8 | |||
| 0c14411b23 | |||
| 0dc1a4d7f6 | |||
| 9f5ce9a88b | |||
| 269cbf309a | |||
| 65e7b995bd | |||
| f50cf95a79 | |||
| c4d3b7d849 | |||
| 8847f6fb22 | |||
| 158470e9bf | |||
| 4219453061 | |||
| 54023a9bb9 | |||
| 867cd54918 | |||
| 982ee074df | |||
| 53caebc361 | |||
| 56ab19e885 | |||
| 281eef0dac | |||
| 00177ab388 | |||
| ebd966a3ae | |||
| f4c981cd71 | |||
| 7750261bf0 | |||
| 123342dcd6 | |||
| beb8a76634 | |||
| e39c69b801 | |||
| 77611502ec | |||
| 428bb81241 | |||
| 173f3c3fd6 | |||
| 22bc3c9a3c | |||
| 49981b951b | |||
| aa504e8ee4 | |||
| c7054df179 | |||
| bfcea37f4e | |||
| 56895078ea | |||
| 41a664e882 | |||
| 79531b8a10 | |||
| fad15eaf24 | |||
| 5dec3d3594 | |||
| 25227b9a1e | |||
| 07c4348e4f | |||
| 47337ef769 | |||
| 8d897af323 | |||
| dc74e14b79 | |||
| 375dd25baf | |||
| 230da0e042 | |||
| 1bb4f17501 | |||
| 0c08cbd062 | |||
| cddab27bcc | |||
| 0c8dfd7ac7 | |||
| 67239dbf04 | |||
| e9f0f780ef | |||
| b970b5daca | |||
| 7838721021 | |||
| 11d5373ff3 | |||
| d8d145180a | |||
| 3523ed4748 | |||
| 19114d4d14 | |||
| f8d509b786 | |||
| 234fd6db25 | |||
| 32092f94bf | |||
| 29d92e3c3c | |||
| 7e2225648c | |||
| c4eb366d3f | |||
| e46e6846e2 | |||
| 9ca6b8cb15 | |||
| b512dc6b4d | |||
| f5a1aa74fa | |||
| e14cbfbe41 | |||
| 6239eb860e | |||
| e1c5d41dda | |||
| 8ec073e640 | |||
| e21512a24b | |||
| dfdce0341e | |||
| 6759aac527 | |||
| 2f5db48505 | |||
| 5177388996 | |||
| 8bd33aae60 | |||
| 7ef09d93f2 | |||
| fc003a96b9 | |||
| 971f8e0317 | |||
| 56e74f240c | |||
| e4301e7409 | |||
| 19d30f37ce | |||
| 9f2f301355 | |||
| db0acda0b7 | |||
| f40941831c | |||
| 0299e8b63d | |||
| ab84932bd4 | |||
| e06544f9c1 | |||
| d296a6f9c6 | |||
| 494e828ec2 | |||
| 0d3251cb3d | |||
| de4add5d4b | |||
| f2bbe7ac86 | |||
| 3d63cbfca4 | |||
| a383c284dc | |||
| 4530f64fbe | |||
| f5b07e1980 | |||
| f08ee4b2e6 | |||
| 6bf389cedc | |||
| 1465d9e115 | |||
| ed3e3cea76 | |||
| 6922dfe844 | |||
| 17d9c5808b | |||
| 80a9577c61 | |||
| 93b00b9f38 | |||
| fde601610d | |||
| 064e6ec870 | |||
| aa52599dac | |||
| 5d940a63da | |||
| e6378d2a27 | |||
| 0e2664d7ab | |||
| 62cd6e3dec | |||
| 6bbe648032 | |||
| 055a04228c | |||
| ccc9e92812 | |||
| 71fcc3faee | |||
| 7bbacc5ed6 | |||
| 4a52fc69c7 | |||
| 261fe15aef | |||
| bdd66dd8da | |||
| fcf9d5adaf | |||
| 03cbca5dfa | |||
| 7e97815dc2 | |||
| ddfc625cb3 | |||
| 1ab60e2a5f | |||
| f26a86a6a9 | |||
| 7dbac97349 | |||
| 79be67248b | |||
| 4289e4c080 | |||
| 5e5773df02 | |||
| 437bcdc433 | |||
| 71ea6ac87b | |||
| 09d406fdff | |||
| e0cb2a46c5 | |||
| b244a48622 | |||
| cca0ca44b2 | |||
| 884380eea9 | |||
| af3e5697fc | |||
| b99aa4f17f | |||
| f995bff8ba | |||
| ed3e01c94b | |||
| a370189201 | |||
| 2638671029 | |||
| d40d5c6e33 | |||
| 5e8c1ceefd | |||
| c4719fcb5e | |||
| 4427332c53 | |||
| e04a462c90 | |||
| 887cd2dc54 | |||
| ad3a4f857f | |||
| 2d2d5ba422 | |||
| f24b0909c3 | |||
| 54f30a82cc | |||
| 733b542d71 | |||
| 4042331e3b | |||
| 6f81120cf9 | |||
| 65a09b82c7 | |||
| c5e69c6719 | |||
| f23203556c | |||
| 1bb74cc344 | |||
| d45c3bab4c | |||
| ca5b152543 | |||
| 95f14be4de | |||
| c5aa9e3c63 | |||
| dc5979fde9 | |||
| 531de3628b | |||
| 652e9dc948 | |||
| 1fdc1aba97 | |||
| 1659b53df7 | |||
| c7c26f4db1 | |||
| eed1dbd1b2 | |||
| b279fd518f | |||
| 22801f0b3e | |||
| b32153bf30 | |||
| b35e88274e | |||
| 1da8891971 | |||
| f582de096c | |||
| 9f7522478f | |||
| 6c1d857c8e | |||
| a87d6c80e4 | |||
| 1e2974e965 | |||
| 407f77794e | |||
| cc53b45104 | |||
| 4f27967ba2 | |||
| 7ca811ec04 | |||
| 067391feae | |||
| 7a441ec853 | |||
| 42f3df8c6d | |||
| eef01572f1 | |||
| a20cd9cc10 | |||
| cde0197cb8 | |||
| bf3de7dd3a | |||
| 65b0090178 | |||
| 39f329d57c | |||
| 98b15fd2df | |||
| 6b71242bfc | |||
| 11152182dc | |||
| aa54e61cee | |||
| 01ceb91ccc | |||
| 0c904bae68 | |||
| 26c80239ba | |||
| 2d704ca7de | |||
| 9ec3208b43 | |||
| 7fb675fd75 | |||
| 7f763b8323 | |||
| 91707c0dcf | |||
| 38546e5967 | |||
| 56a1fc0de4 | |||
| 517de21864 | |||
| 11dc2eacea | |||
| 29eeecb757 | |||
| 6f308da2eb | |||
| b850bd494c | |||
| 510f2be2b6 | |||
| 2521a17ac4 | |||
| ef792bc5f4 | |||
| 20e614fd3b | |||
| ca9b7628d1 | |||
| f27dceb0d2 | |||
| 510f5eb309 | |||
| f2a578c7e0 | |||
| e6fc186064 | |||
| 9d755088ad | |||
| 0c4d32edd2 | |||
| 28f5d8aa60 | |||
| c138219391 | |||
| b0d6b4734b | |||
| 8556bd2ba5 | |||
| 927ffbaa01 | |||
| c9af67c14b | |||
| 9573d31cea | |||
| 1d22c37745 | |||
| bc072deb94 | |||
| 2f68b5b77f | |||
| 3e9031ea81 | |||
| e1764007c6 | |||
| 37cf5bc447 | |||
| 476989a346 | |||
| 984e09349b | |||
| 23e0293a93 | |||
| a3809804d4 | |||
| 6194903182 | |||
| 22bbfc93dc | |||
| 66e9528279 | |||
| f4262f41ca | |||
| 0584ad30e8 | |||
| 97ffe1bf59 | |||
| fd6b36600e | |||
| b6753f8cdb | |||
| bb49542c83 | |||
| 7e8479cd78 | |||
| 904314ace9 | |||
| 7617c8446a | |||
| c967f02288 | |||
| da6c56690d | |||
| a3106fc918 | |||
| 2bed79c30a | |||
| fe2f185b53 | |||
| 50bebb45ae | |||
| 79baccafc6 | |||
| e6b3abec18 | |||
| c2187b0f98 | |||
| c5db572eb9 | |||
| 5df9c76314 | |||
| 6cadbafc6e | |||
| 661b774204 | |||
| 2114920f63 | |||
| a2a4e956b7 | |||
| a31179a438 | |||
| 5b76065b77 | |||
| 75ea080d90 | |||
| 5b7c76e806 | |||
| 6ca7d2cf9d | |||
| 4b2f8e7007 | |||
| aa176e0f81 | |||
| be2f672a7e | |||
| 50f9dace0e | |||
| 4009ab8463 | |||
| 4604f0ba35 | |||
| da5798ce57 | |||
| 51211f3751 | |||
| 23214f72d5 | |||
| 230f272080 | |||
| f560fd0ebe | |||
| c967135d79 | |||
| 88285ed915 | |||
| b41429af80 | |||
| 956cf8b7c4 | |||
| f3db7100d8 | |||
| ab24425ffc | |||
| 4be2a92b34 |
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"env": {
|
|
||||||
"commonjs": true,
|
|
||||||
"es6": true,
|
|
||||||
"node": true,
|
|
||||||
"jest": true
|
|
||||||
},
|
|
||||||
"extends": "eslint:recommended",
|
|
||||||
"globals": {
|
|
||||||
"Atomics": "readonly",
|
|
||||||
"SharedArrayBuffer": "readonly"
|
|
||||||
},
|
|
||||||
"parserOptions": {
|
|
||||||
"ecmaVersion": 2018
|
|
||||||
},
|
|
||||||
"rules": {
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,61 +0,0 @@
|
|||||||
---
|
|
||||||
name: "🐛 Bug Report"
|
|
||||||
description: Report a bug
|
|
||||||
title: "short issue description"
|
|
||||||
labels: [bug, needs-triage]
|
|
||||||
assignees: []
|
|
||||||
body:
|
|
||||||
- type: textarea
|
|
||||||
id: description
|
|
||||||
attributes:
|
|
||||||
label: Describe the bug
|
|
||||||
description: What is the problem? A clear and concise description of the bug.
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: expected
|
|
||||||
attributes:
|
|
||||||
label: Expected Behavior
|
|
||||||
description: |
|
|
||||||
What did you expect to happen?
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: current
|
|
||||||
attributes:
|
|
||||||
label: Current Behavior
|
|
||||||
description: |
|
|
||||||
What actually happened?
|
|
||||||
|
|
||||||
Please include full errors, uncaught exceptions, stack traces, and relevant logs.
|
|
||||||
If service responses are relevant, please include wire logs.
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: reproduction
|
|
||||||
attributes:
|
|
||||||
label: Reproduction Steps
|
|
||||||
description: |
|
|
||||||
Provide a self-contained, concise snippet of code that can be used to reproduce the issue.
|
|
||||||
For more complex issues provide a repo with the smallest sample that reproduces the bug.
|
|
||||||
|
|
||||||
Avoid including business logic or unrelated code, it makes diagnosis more difficult.
|
|
||||||
The code sample should be an SSCCE. See http://sscce.org/ for details. In short, please provide a code sample that we can copy/paste, run and reproduce.
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: solution
|
|
||||||
attributes:
|
|
||||||
label: Possible Solution
|
|
||||||
description: |
|
|
||||||
Suggest a fix/reason for the bug
|
|
||||||
validations:
|
|
||||||
required: false
|
|
||||||
- type: textarea
|
|
||||||
id: context
|
|
||||||
attributes:
|
|
||||||
label: Additional Information/Context
|
|
||||||
description: |
|
|
||||||
Anything else that might be relevant for troubleshooting this bug. Providing context helps us come up with a solution that is most useful in the real world.
|
|
||||||
validations:
|
|
||||||
required: false
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
blank_issues_enabled: false
|
|
||||||
contact_links:
|
|
||||||
- name: 💬 General Question
|
|
||||||
url: https://github.com/aws-actions/configure-aws-credentials/discussions/categories/q-a
|
|
||||||
about: Please ask and answer questions as a discussion thread
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
---
|
|
||||||
name: "📕 Documentation Issue"
|
|
||||||
description: Report an issue in the README or a suggestion to improve documentation
|
|
||||||
title: "short issue description"
|
|
||||||
labels: [documentation, needs-triage]
|
|
||||||
assignees: []
|
|
||||||
body:
|
|
||||||
- type: textarea
|
|
||||||
id: description
|
|
||||||
attributes:
|
|
||||||
label: Describe the issue
|
|
||||||
description: A clear and concise description of the issue.
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
---
|
|
||||||
name: 🚀 Feature Request
|
|
||||||
description: Suggest an idea for this project
|
|
||||||
title: "short issue description"
|
|
||||||
labels: [feature-request, needs-triage]
|
|
||||||
assignees: []
|
|
||||||
body:
|
|
||||||
- type: textarea
|
|
||||||
id: description
|
|
||||||
attributes:
|
|
||||||
label: Describe the feature
|
|
||||||
description: A clear and concise description of the feature you are proposing.
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: use-case
|
|
||||||
attributes:
|
|
||||||
label: Use Case
|
|
||||||
description: |
|
|
||||||
Why do you need this feature? For example: "I'm always frustrated when..."
|
|
||||||
validations:
|
|
||||||
required: true
|
|
||||||
- type: textarea
|
|
||||||
id: solution
|
|
||||||
attributes:
|
|
||||||
label: Proposed Solution
|
|
||||||
description: |
|
|
||||||
Suggest how to implement the addition or change. Please include prototype/workaround/sketch/reference implementation.
|
|
||||||
validations:
|
|
||||||
required: false
|
|
||||||
- type: textarea
|
|
||||||
id: other
|
|
||||||
attributes:
|
|
||||||
label: Other Information
|
|
||||||
description: |
|
|
||||||
Any alternative solutions or features you considered, a more detailed explanation, stack traces, related issues, links for context, etc.
|
|
||||||
validations:
|
|
||||||
required: false
|
|
||||||
- type: checkboxes
|
|
||||||
id: ack
|
|
||||||
attributes:
|
|
||||||
label: Acknowledgements
|
|
||||||
options:
|
|
||||||
- label: I may be able to implement this feature request
|
|
||||||
required: false
|
|
||||||
- label: This feature might incur a breaking change
|
|
||||||
required: false
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
*Issue #, if available:*
|
|
||||||
|
|
||||||
*Description of changes:*
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
* [ ] Have you followed the guidelines in our [Contributing guide?](https://github.com/aws-actions/configure-aws-credentials/blob/main/CONTRIBUTING.md)
|
|
||||||
|
|
||||||
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
version: 2
|
|
||||||
updates:
|
|
||||||
- package-ecosystem: npm
|
|
||||||
directory: "/"
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
day: tuesday
|
|
||||||
open-pull-requests-limit: 10
|
|
||||||
target-branch: 'main'
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
on:
|
|
||||||
[pull_request]
|
|
||||||
|
|
||||||
name: Check
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
check:
|
|
||||||
name: Run Unit Tests
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
- name: Run tests
|
|
||||||
run: |
|
|
||||||
npm ci
|
|
||||||
npm test
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
name: "Close Stale Issues"
|
|
||||||
|
|
||||||
# Controls when the action will run.
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
schedule:
|
|
||||||
- cron: "0 */4 * * *"
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
cleanup:
|
|
||||||
permissions:
|
|
||||||
issues: write
|
|
||||||
contents: read
|
|
||||||
pull-requests: write
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
name: Stale issue job
|
|
||||||
steps:
|
|
||||||
- uses: aws-actions/stale-issue-cleanup@v5
|
|
||||||
with:
|
|
||||||
# Setting messages to an empty string will cause the automation to skip
|
|
||||||
# that category
|
|
||||||
ancient-issue-message: This issue has not received any attention in 1 year. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
|
||||||
stale-issue-message: This issue has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
|
||||||
stale-pr-message: This PR has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
|
||||||
|
|
||||||
# These labels are required
|
|
||||||
stale-issue-label: closing-soon
|
|
||||||
exempt-issue-labels: no-autoclose
|
|
||||||
stale-pr-label: closing-soon
|
|
||||||
exempt-pr-labels: no-autoclose
|
|
||||||
response-requested-label: response-requested
|
|
||||||
|
|
||||||
# Don't set closed-for-staleness label to skip closing very old issues
|
|
||||||
# regardless of label
|
|
||||||
closed-for-staleness-label: closed-for-staleness
|
|
||||||
|
|
||||||
# Issue timing
|
|
||||||
days-before-stale: 5
|
|
||||||
days-before-close: 2
|
|
||||||
days-before-ancient: 365
|
|
||||||
|
|
||||||
# If you don't want to mark a issue as being ancient based on a
|
|
||||||
# threshold of "upvotes", you can set this here. An "upvote" is
|
|
||||||
# the total number of +1, heart, hooray, and rocket reactions
|
|
||||||
# on an issue.
|
|
||||||
minimum-upvotes-to-exempt: 5
|
|
||||||
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
loglevel: DEBUG
|
|
||||||
# Set dry-run to true to not perform label or close actions.
|
|
||||||
dry-run: false
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
name: Closed Issue Message
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types: [closed]
|
|
||||||
jobs:
|
|
||||||
auto_comment:
|
|
||||||
permissions:
|
|
||||||
issues: write
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: aws-actions/closed-issue-message@v1
|
|
||||||
with:
|
|
||||||
# These inputs are both required
|
|
||||||
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
|
||||||
message: |
|
|
||||||
Comments on closed issues are hard for our team to see.
|
|
||||||
If you need more assistance, please either tag a team member or open a new issue that references this one.
|
|
||||||
If you wish to keep having a conversation with other community members under this issue feel free to do so.
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
name: Update dist files on
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
paths-ignore:
|
|
||||||
- 'dist/**'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
package:
|
|
||||||
name: Package dist files
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
id-token: write
|
|
||||||
contents: read
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
ref: ${{ github.ref_name }}
|
|
||||||
persist-credentials: false
|
|
||||||
- name: Package
|
|
||||||
run: |
|
|
||||||
npm ci
|
|
||||||
npm test
|
|
||||||
npm run package
|
|
||||||
- name: Configure AWS credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
aws-region: us-west-2
|
|
||||||
role-to-assume: ${{ secrets.SECRETS_AWS_ROLE_TO_ASSUME }}
|
|
||||||
role-duration-seconds: 900
|
|
||||||
role-session-name: SecretsManagerFetch
|
|
||||||
- name: Get bot user token
|
|
||||||
uses: aws-actions/aws-secretsmanager-get-secrets@v1
|
|
||||||
with:
|
|
||||||
parse-json-secrets: true
|
|
||||||
secret-ids: |
|
|
||||||
OSDS,arn:aws:secretsmanager:us-west-2:294535624312:secret:github-aws-sdk-osds-automation-ZHNalp
|
|
||||||
- name: Commit
|
|
||||||
run: |
|
|
||||||
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
|
||||||
git config user.name "GitHub Actions"
|
|
||||||
git config user.email "github-aws-sdk-osds-automation@amazon.com"
|
|
||||||
git remote set-url origin https://${{ env.OSDS_ACCESS_TOKEN }}@github.com/aws-actions/configure-aws-credentials.git
|
|
||||||
git add dist
|
|
||||||
git commit -m "chore: Update dist" || echo "No changes to commit"
|
|
||||||
git push origin
|
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- integ-tests
|
||||||
|
|
||||||
|
name: Integration Test
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
name: Deploy
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Print current build ID
|
||||||
|
run: |
|
||||||
|
echo Integration test run: ConfigureAWSCredentialsDepl-DaaDYhTJsCVq:536d0e31-876d-4508-9147-c9197c1ff49e
|
||||||
|
|
||||||
|
- name: Configure AWS credentials
|
||||||
|
uses: aws-actions/configure-aws-credentials@bab55d3830fe69833c9fecaa51fe2c829a7508f3
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "user/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
|
|
||||||
|
- name: Configure AWS credentials from role
|
||||||
|
uses: aws-actions/configure-aws-credentials@bab55d3830fe69833c9fecaa51fe2c829a7508f3
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
role-to-assume: github-actions-configure-aws-credentials-integ-tests
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: github-actions-integ-test
|
||||||
|
role-external-id: ${{ secrets.INTEG_TEST_ROLE_EXTERNAL_ID }}
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials from role
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "role/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
|
|
||||||
|
- name: Configure AWS credentials from role again
|
||||||
|
uses: aws-actions/configure-aws-credentials@bab55d3830fe69833c9fecaa51fe2c829a7508f3
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
role-to-assume: github-actions-configure-aws-credentials-integ-tests
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: github-actions-integ-test
|
||||||
|
role-external-id: ${{ secrets.INTEG_TEST_ROLE_EXTERNAL_ID }}
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials from role
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "role/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
-66
@@ -1,66 +0,0 @@
|
|||||||
node_modules/
|
|
||||||
|
|
||||||
# Editors
|
|
||||||
.vscode
|
|
||||||
.idea
|
|
||||||
|
|
||||||
# Logs
|
|
||||||
logs
|
|
||||||
*.log
|
|
||||||
npm-debug.log*
|
|
||||||
yarn-debug.log*
|
|
||||||
yarn-error.log*
|
|
||||||
|
|
||||||
# Runtime data
|
|
||||||
pids
|
|
||||||
*.pid
|
|
||||||
*.seed
|
|
||||||
*.pid.lock
|
|
||||||
|
|
||||||
# Directory for instrumented libs generated by jscoverage/JSCover
|
|
||||||
lib-cov
|
|
||||||
|
|
||||||
# Coverage directory used by tools like istanbul
|
|
||||||
coverage
|
|
||||||
|
|
||||||
# nyc test coverage
|
|
||||||
.nyc_output
|
|
||||||
|
|
||||||
# Grunt intermediate storage (http://gruntjs.com/creating-plugins#storing-task-files)
|
|
||||||
.grunt
|
|
||||||
|
|
||||||
# Bower dependency directory (https://bower.io/)
|
|
||||||
bower_components
|
|
||||||
|
|
||||||
# node-waf configuration
|
|
||||||
.lock-wscript
|
|
||||||
|
|
||||||
# Compiled binary addons (https://nodejs.org/api/addons.html)
|
|
||||||
build/Release
|
|
||||||
|
|
||||||
# Other Dependency directories
|
|
||||||
jspm_packages/
|
|
||||||
|
|
||||||
# TypeScript v1 declaration files
|
|
||||||
typings/
|
|
||||||
|
|
||||||
# Optional npm cache directory
|
|
||||||
.npm
|
|
||||||
|
|
||||||
# Optional eslint cache
|
|
||||||
.eslintcache
|
|
||||||
|
|
||||||
# Optional REPL history
|
|
||||||
.node_repl_history
|
|
||||||
|
|
||||||
# Output of 'npm pack'
|
|
||||||
*.tgz
|
|
||||||
|
|
||||||
# Yarn Integrity file
|
|
||||||
.yarn-integrity
|
|
||||||
|
|
||||||
# dotenv environment variables file
|
|
||||||
.env
|
|
||||||
|
|
||||||
# next.js build output
|
|
||||||
.next
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
queue_rules:
|
|
||||||
- name: default
|
|
||||||
conditions:
|
|
||||||
# Conditions to get out of the queue (= merged)
|
|
||||||
- status-success=Run Unit Tests
|
|
||||||
|
|
||||||
pull_request_rules:
|
|
||||||
- name: Automatically merge on CI success and review approval
|
|
||||||
conditions:
|
|
||||||
- base~=main|integ-tests
|
|
||||||
- "#approved-reviews-by>=1"
|
|
||||||
- -approved-reviews-by~=author
|
|
||||||
- status-success=Run Unit Tests
|
|
||||||
- label!=work-in-progress
|
|
||||||
- -title~=(WIP|wip)
|
|
||||||
- -merged
|
|
||||||
- -closed
|
|
||||||
- author!=dependabot[bot]
|
|
||||||
actions:
|
|
||||||
queue:
|
|
||||||
method: squash
|
|
||||||
name: default
|
|
||||||
|
|
||||||
- name: Automatically approve and merge Dependabot PRs
|
|
||||||
conditions:
|
|
||||||
- base~=main
|
|
||||||
- author=dependabot[bot]
|
|
||||||
- status-success=Run Unit Tests
|
|
||||||
- -title~=(WIP|wip)
|
|
||||||
- -label~=(blocked|do-not-merge)
|
|
||||||
- -merged
|
|
||||||
- -closed
|
|
||||||
actions:
|
|
||||||
review:
|
|
||||||
type: APPROVE
|
|
||||||
queue:
|
|
||||||
method: squash
|
|
||||||
name: default
|
|
||||||
-181
@@ -1,181 +0,0 @@
|
|||||||
# Changelog
|
|
||||||
|
|
||||||
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
|
||||||
|
|
||||||
## [2.0.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.7.0...v2.0.0) (2023-03-06)
|
|
||||||
|
|
||||||
### Features
|
|
||||||
* Version bump to use Node 16 by default.
|
|
||||||
|
|
||||||
## [1.7.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.6.1...v1.7.0) (2022-08-03)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* Allow audience to be explicitly specified ([2f8dfd0](https://github.com/aws-actions/configure-aws-credentials/commit/2f8dfd0ed43d880f85b57f0c8727b497af2037de))
|
|
||||||
|
|
||||||
### [1.6.1](https://github.com/aws-actions/configure-aws-credentials/compare/v1.6.0...v1.6.1) (2022-01-18)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* OIDC Parallel Requests error ([133757e](https://github.com/aws-actions/configure-aws-credentials/commit/133757e9b829f4ef44c8e99e3f272879b45fc9c5))
|
|
||||||
* Strict Mode Deprecation ([4c5e1c6](https://github.com/aws-actions/configure-aws-credentials/commit/4c5e1c60ccfc95d0e48bf1bc95fc707a94aa2c60))
|
|
||||||
|
|
||||||
## [1.6.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.11...v1.6.0) (2021-11-23)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* Add the ability to use a web identity token file ([#240](https://github.com/aws-actions/configure-aws-credentials/issues/240)) ([8053174](https://github.com/aws-actions/configure-aws-credentials/commit/8053174404968575ac1dd102dcb1109d2fe6d9ea))
|
|
||||||
* added OIDC ([#262](https://github.com/aws-actions/configure-aws-credentials/issues/262)) ([b8c74de](https://github.com/aws-actions/configure-aws-credentials/commit/b8c74de753fbcb4868bf2011fb2e15826ce973af)), closes [#267](https://github.com/aws-actions/configure-aws-credentials/issues/267)
|
|
||||||
* upgraded to new GH OIDC API ([#284](https://github.com/aws-actions/configure-aws-credentials/issues/284)) ([036a4a1](https://github.com/aws-actions/configure-aws-credentials/commit/036a4a1ddf2c0e7a782dca6e083c6c53e5d90321))
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* reverting update to use new API ([#274](https://github.com/aws-actions/configure-aws-credentials/issues/274)) ([a78fcb0](https://github.com/aws-actions/configure-aws-credentials/commit/a78fcb01f76c8c5c3b05ab82718a6f7919fc0269)), closes [#270](https://github.com/aws-actions/configure-aws-credentials/issues/270)
|
|
||||||
* typo "charcters" in README.md ([#241](https://github.com/aws-actions/configure-aws-credentials/issues/241)) ([c48e1b5](https://github.com/aws-actions/configure-aws-credentials/commit/c48e1b578416f3457ccf757c47385df5c054d23f))
|
|
||||||
* Updated token retrieval to use new API ([#270](https://github.com/aws-actions/configure-aws-credentials/issues/270)) ([20ce4e5](https://github.com/aws-actions/configure-aws-credentials/commit/20ce4e5ba1de2e753d034b5415075a8767d64d4d))
|
|
||||||
|
|
||||||
### [1.5.11](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.10...v1.5.11) (2021-07-19)
|
|
||||||
|
|
||||||
### [1.5.10](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.9...v1.5.10) (2021-06-01)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* skips session tagging ([#209](https://github.com/aws-actions/configure-aws-credentials/issues/209)) ([4900858](https://github.com/aws-actions/configure-aws-credentials/commit/4900858c22f8f07170e3032d4105f99c2aafa9e7))
|
|
||||||
|
|
||||||
### [1.5.9](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.8...v1.5.9) (2021-05-10)
|
|
||||||
|
|
||||||
### [1.5.8](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.7...v1.5.8) (2021-03-02)
|
|
||||||
|
|
||||||
### [1.5.7](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.6...v1.5.7) (2021-02-08)
|
|
||||||
|
|
||||||
### [1.5.6](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.5...v1.5.6) (2021-01-26)
|
|
||||||
|
|
||||||
### [1.5.5](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.4...v1.5.5) (2020-11-24)
|
|
||||||
|
|
||||||
### [1.5.4](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.3...v1.5.4) (2020-10-29)
|
|
||||||
|
|
||||||
### [1.5.3](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.2...v1.5.3) (2020-10-05)
|
|
||||||
|
|
||||||
### [1.5.2](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.1...v1.5.2) (2020-08-25)
|
|
||||||
|
|
||||||
### [1.5.1](https://github.com/aws-actions/configure-aws-credentials/compare/v1.5.0...v1.5.1) (2020-08-11)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* make GITHUB_REF env var optional ([#82](https://github.com/aws-actions/configure-aws-credentials/issues/82)) ([ba5041f](https://github.com/aws-actions/configure-aws-credentials/commit/ba5041f7bb4990ac5d10d9009de69e639ebee3df)), closes [#92](https://github.com/aws-actions/configure-aws-credentials/issues/92)
|
|
||||||
|
|
||||||
## [1.5.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.4.4...v1.5.0) (2020-07-29)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* Add post-job action cleanup of credentials and region env vars ([#101](https://github.com/aws-actions/configure-aws-credentials/issues/101)) ([d19cafc](https://github.com/aws-actions/configure-aws-credentials/commit/d19cafcdd1be7e3358f84574a00df37af494036a))
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* Mask assume role response in debug output ([#102](https://github.com/aws-actions/configure-aws-credentials/issues/102)) ([df7d846](https://github.com/aws-actions/configure-aws-credentials/commit/df7d84616183de7ed37e53e1980284a07e56b216))
|
|
||||||
|
|
||||||
### [1.4.4](https://github.com/aws-actions/configure-aws-credentials/compare/v1.4.3...v1.4.4) (2020-07-17)
|
|
||||||
|
|
||||||
### [1.4.3](https://github.com/aws-actions/configure-aws-credentials/compare/v1.4.2...v1.4.3) (2020-07-14)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* Make tagging optional ([#92](https://github.com/aws-actions/configure-aws-credentials/issues/92)) ([baf85d8](https://github.com/aws-actions/configure-aws-credentials/commit/baf85d8be969f190df9bc9153f06958c32ef3828))
|
|
||||||
|
|
||||||
### [1.4.2](https://github.com/aws-actions/configure-aws-credentials/compare/v1.4.1...v1.4.2) (2020-06-30)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* add comma to set of special characters ([#78](https://github.com/aws-actions/configure-aws-credentials/issues/78)) ([f04843b](https://github.com/aws-actions/configure-aws-credentials/commit/f04843b510a6c8adf77eed907a616cf00a99970d))
|
|
||||||
|
|
||||||
### [1.4.1](https://github.com/aws-actions/configure-aws-credentials/compare/v1.4.0...v1.4.1) (2020-06-09)
|
|
||||||
|
|
||||||
## [1.4.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.5...v1.4.0) (2020-06-03)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* Refresh and validate credentials after setting env var creds ([#71](https://github.com/aws-actions/configure-aws-credentials/issues/71)) ([472e549](https://github.com/aws-actions/configure-aws-credentials/commit/472e549195ba1f153e9fb72e39dc2a094e5de13e))
|
|
||||||
|
|
||||||
### [1.3.5](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.4...v1.3.5) (2020-05-27)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* clear session token env var if present for non-session credentials ([#65](https://github.com/aws-actions/configure-aws-credentials/issues/65)) ([0c2c1f7](https://github.com/aws-actions/configure-aws-credentials/commit/0c2c1f7c129971b6f433551b1f4ba4a6a9cc8b70))
|
|
||||||
|
|
||||||
### [1.3.4](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.3...v1.3.4) (2020-05-18)
|
|
||||||
|
|
||||||
### [1.3.3](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.2...v1.3.3) (2020-04-02)
|
|
||||||
|
|
||||||
### [1.3.2](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.1...v1.3.2) (2020-03-18)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* let the AWS SDK determine the STS regional endpoint ([#48](https://github.com/aws-actions/configure-aws-credentials/issues/48)) ([fc72bd3](https://github.com/aws-actions/configure-aws-credentials/commit/fc72bd38dbe25493f5113760c9c6e1ef2f6f9a0e))
|
|
||||||
|
|
||||||
### [1.3.1](https://github.com/aws-actions/configure-aws-credentials/compare/v1.3.0...v1.3.1) (2020-03-06)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* validate region input string ([#44](https://github.com/aws-actions/configure-aws-credentials/issues/44)) ([3d568d2](https://github.com/aws-actions/configure-aws-credentials/commit/3d568d2c4359304d46d9bd1b4d9f69e088ccbf7b))
|
|
||||||
|
|
||||||
## [1.3.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.2.0...v1.3.0) (2020-03-06)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* don't require access key credentials for self-hosted runners ([#42](https://github.com/aws-actions/configure-aws-credentials/issues/42)) ([a20ed60](https://github.com/aws-actions/configure-aws-credentials/commit/a20ed6025224ca999786c8d4e687f119cfedec65))
|
|
||||||
|
|
||||||
## [1.2.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.1.2...v1.2.0) (2020-03-06)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* Add option to provide external ID ([#32](https://github.com/aws-actions/configure-aws-credentials/issues/32)) ([1c435bb](https://github.com/aws-actions/configure-aws-credentials/commit/1c435bbd5e1f1d36cdd703da5c4d6ee1ad91efac)), closes [#28](https://github.com/aws-actions/configure-aws-credentials/issues/28)
|
|
||||||
* Have an ability to configure session name ([#29](https://github.com/aws-actions/configure-aws-credentials/issues/29)) ([4d0082a](https://github.com/aws-actions/configure-aws-credentials/commit/4d0082acf8b4102597f2570a056a320194f13e63))
|
|
||||||
* infer role ARN if given role name ([#35](https://github.com/aws-actions/configure-aws-credentials/issues/35)) ([96c6f7e](https://github.com/aws-actions/configure-aws-credentials/commit/96c6f7e07b5fabc5a907fce84745ea625eeb005d))
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* mask both source and role credentials ([#40](https://github.com/aws-actions/configure-aws-credentials/issues/40)) ([816f5cc](https://github.com/aws-actions/configure-aws-credentials/commit/816f5cc0cf79541b2a6d639e8f93ae43aadaf09c))
|
|
||||||
|
|
||||||
### [1.1.2](https://github.com/aws-actions/configure-aws-credentials/compare/v1.1.1...v1.1.2) (2020-02-12)
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* change sanitization character from '*' to '_' ([55f6a14](https://github.com/aws-actions/configure-aws-credentials/commit/55f6a14016cb47190b15751dcce450441bba35e3))
|
|
||||||
|
|
||||||
### [1.1.1](https://github.com/aws-actions/configure-aws-credentials/compare/v1.1.0...v1.1.1) (2020-02-07)
|
|
||||||
|
|
||||||
## [1.1.0](https://github.com/aws-actions/configure-aws-credentials/compare/v1.0.1...v1.1.0) (2020-02-06)
|
|
||||||
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
* add support for assuming a role ([#17](https://github.com/aws-actions/configure-aws-credentials/issues/17)) ([25960ab](https://github.com/aws-actions/configure-aws-credentials/commit/25960ab0950f92074b17fa0cb8ff33eeaa1615f0))
|
|
||||||
* Build and integ test scripts for pipeline ([52bc82a](https://github.com/aws-actions/configure-aws-credentials/commit/52bc82a29bb08f2f8f87a92f380149945eb8d6f1))
|
|
||||||
|
|
||||||
|
|
||||||
### Bug Fixes
|
|
||||||
|
|
||||||
* create workflows dir in integ-tests ([3de962e](https://github.com/aws-actions/configure-aws-credentials/commit/3de962edc9fe1169ff6032bef94b934be53211d1))
|
|
||||||
* remove buildspecs ([260c6cc](https://github.com/aws-actions/configure-aws-credentials/commit/260c6cc0ed07cbd8ff2a7a74066ad9f67ecc82f7))
|
|
||||||
* remove release script ([1436a16](https://github.com/aws-actions/configure-aws-credentials/commit/1436a160af84c3a086a812f98daf457a042274cb))
|
|
||||||
* resolve commit ID in integ test script ([77f2df7](https://github.com/aws-actions/configure-aws-credentials/commit/77f2df7a41882637145683bb1acf60bb04fddc24))
|
|
||||||
* sanitize AWS session tags ([#20](https://github.com/aws-actions/configure-aws-credentials/issues/20)) ([4faf8cd](https://github.com/aws-actions/configure-aws-credentials/commit/4faf8cd19a5b6cc50c9c66c89dd32d7e6e51bd8a))
|
|
||||||
* set role credentials as secrets to mask them in logs ([#19](https://github.com/aws-actions/configure-aws-credentials/issues/19)) ([e2fd53a](https://github.com/aws-actions/configure-aws-credentials/commit/e2fd53ab66a094843f790497dcc950894c245786))
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
## Code of Conduct
|
|
||||||
This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct).
|
|
||||||
For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact
|
|
||||||
opensource-codeofconduct@amazon.com with any additional questions or comments.
|
|
||||||
@@ -1,61 +0,0 @@
|
|||||||
# Contributing Guidelines
|
|
||||||
|
|
||||||
Thank you for your interest in contributing to our project. Whether it's a bug report, new feature, correction, or additional
|
|
||||||
documentation, we greatly value feedback and contributions from our community.
|
|
||||||
|
|
||||||
Please read through this document before submitting any issues or pull requests to ensure we have all the necessary
|
|
||||||
information to effectively respond to your bug report or contribution.
|
|
||||||
|
|
||||||
|
|
||||||
## Reporting Bugs/Feature Requests
|
|
||||||
|
|
||||||
We welcome you to use the GitHub issue tracker to report bugs or suggest features.
|
|
||||||
|
|
||||||
When filing an issue, please check [existing open](https://github.com/aws-actions/configure-aws-credentials/issues), or [recently closed](https://github.com/aws-actions/configure-aws-credentials/issues?utf8=%E2%9C%93&q=is%3Aissue%20is%3Aclosed%20), issues to make sure somebody else hasn't already
|
|
||||||
reported the issue. Please try to include as much information as you can. Details like these are incredibly useful:
|
|
||||||
|
|
||||||
* A reproducible test case or series of steps
|
|
||||||
* The version of our code being used
|
|
||||||
* Any modifications you've made relevant to the bug
|
|
||||||
* Anything unusual about your environment or deployment
|
|
||||||
|
|
||||||
|
|
||||||
## Contributing via Pull Requests
|
|
||||||
Contributions via pull requests are much appreciated. Before sending us a pull request, please ensure that:
|
|
||||||
|
|
||||||
1. You are working against the latest source on the *main* branch.
|
|
||||||
2. You check existing open, and recently merged, pull requests to make sure someone else hasn't addressed the problem already.
|
|
||||||
3. You open an issue to discuss any significant work - we would hate for your time to be wasted.
|
|
||||||
|
|
||||||
To send us a pull request, please:
|
|
||||||
|
|
||||||
1. Fork the repository.
|
|
||||||
2. Modify the source; please focus on the specific change you are contributing. If you also reformat all the code, it will be hard for us to focus on your change.
|
|
||||||
3. Ensure local tests pass.
|
|
||||||
4. Commit to your fork using clear commit messages.
|
|
||||||
5. Send us a pull request, answering any default questions in the pull request interface.
|
|
||||||
6. Pay attention to any automated CI failures reported in the pull request, and stay involved in the conversation.
|
|
||||||
|
|
||||||
GitHub provides additional document on [forking a repository](https://help.github.com/articles/fork-a-repo/) and
|
|
||||||
[creating a pull request](https://help.github.com/articles/creating-a-pull-request/).
|
|
||||||
|
|
||||||
|
|
||||||
## Finding contributions to work on
|
|
||||||
Looking at the existing issues is a great way to find something to contribute on. As our projects, by default, use the default GitHub issue labels (enhancement/bug/duplicate/help wanted/invalid/question/wontfix), looking at any ['help wanted'](https://github.com/aws-actions/configure-aws-credentials/labels/help%20wanted) issues is a great place to start.
|
|
||||||
|
|
||||||
|
|
||||||
## Code of Conduct
|
|
||||||
This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct).
|
|
||||||
For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact
|
|
||||||
opensource-codeofconduct@amazon.com with any additional questions or comments.
|
|
||||||
|
|
||||||
|
|
||||||
## Security issue notifications
|
|
||||||
If you discover a potential security issue in this project we ask that you notify AWS/Amazon Security via our [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/). Please do **not** create a public github issue.
|
|
||||||
|
|
||||||
|
|
||||||
## Licensing
|
|
||||||
|
|
||||||
See the [LICENSE](https://github.com/aws-actions/configure-aws-credentials/blob/main/LICENSE) file for our project's licensing. We will ask you to confirm the licensing of your contribution.
|
|
||||||
|
|
||||||
We may ask you to sign a [Contributor License Agreement (CLA)](http://en.wikipedia.org/wiki/Contributor_License_Agreement) for larger changes.
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
MIT License
|
|
||||||
|
|
||||||
Copyright 2019 Amazon.com, Inc. or its affiliates.
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
@@ -1,379 +0,0 @@
|
|||||||
## Configure AWS Credentials for GitHub Actions
|
|
||||||
Configure your AWS credentials and region environment variables for use in other
|
|
||||||
GitHub Actions. This action implements the AWS SDK credential resolution chain
|
|
||||||
and exports environment variables for your other Actions to use. Environment
|
|
||||||
variable exports are detected by both the AWS SDKs and the AWS CLI for AWS API
|
|
||||||
calls.
|
|
||||||
|
|
||||||
### Recent updates
|
|
||||||
We've recently released a `v2` of this action that uses the Node 16 runtime by
|
|
||||||
default. You should update your action references to `v2`. We intend `v2` to be
|
|
||||||
the new default for this action and will no longer be providing updates to the
|
|
||||||
`v1` tag.
|
|
||||||
|
|
||||||
As is usual for GitHub Actions, we provide release tags for you to reference in
|
|
||||||
your repository's workflow files. The `v2` tag is a moving tag that will always
|
|
||||||
apply to the lastest version 2 train release. We will also provide minor version
|
|
||||||
tags on every release, and create a `v3` tag when we are ready for a new major
|
|
||||||
release. If you had been following the development of this action so far, this
|
|
||||||
is a change to previous states release policy.
|
|
||||||
|
|
||||||
### Table of Contents
|
|
||||||
<!-- toc -->
|
|
||||||
- [Usage](#usage)
|
|
||||||
- [Credentials](#credentials)
|
|
||||||
- [Assuming a Role](#assuming-a-role)
|
|
||||||
+ [Session tagging](#session-tagging)
|
|
||||||
+ [Sample IAM Role Permissions](#sample-iam-role-cloudformation-template)
|
|
||||||
- [Self-Hosted Runners](#self-hosted-runners)
|
|
||||||
+ [Proxy Configuration](#proxy-configuration)
|
|
||||||
- [License Summary](#license-summary)
|
|
||||||
- [Security Disclosures](#security-disclosures)
|
|
||||||
<!-- tocstop -->
|
|
||||||
|
|
||||||
## Usage
|
|
||||||
We support four methods for fetching credentials from AWS, but we recommend that
|
|
||||||
you use GitHub's OIDC provider in conjunction with a configured AWS IAM
|
|
||||||
Identity Provider endpoint.
|
|
||||||
|
|
||||||
To to that, you would add the following step to your workflow:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
- name: Configure AWS Credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
|
||||||
aws-region: us-east-2
|
|
||||||
```
|
|
||||||
This will cause the action to perform an `AssumeRoleWithWebIdentity` call and
|
|
||||||
return temporary security credentials for use by other actions. In order for
|
|
||||||
this to work, you'll need to preconfigure the IAM IdP in your AWS account
|
|
||||||
(see [Assuming a Role](#assuming-a-role) for details).
|
|
||||||
|
|
||||||
You can use this action with the AWS CLI available in
|
|
||||||
[GitHub's hosted virtual environments](https://help.github.com/en/actions/reference/software-installed-on-github-hosted-runners) or run this action multiple times
|
|
||||||
to use different AWS accounts, regions, or IAM roles in the same GitHub Actions
|
|
||||||
workflow. As an example, here is a complete workflow file that uploads artifacts
|
|
||||||
to Amazon S3.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
name: Upload to Amazon S3
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
# These permissions are needed to interact with GitHub's OIDC Token endpoint.
|
|
||||||
permissions:
|
|
||||||
id-token: write
|
|
||||||
contents: read
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
- name: Configure AWS credentials from Test account
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
role-to-assume: arn:aws:iam::111111111111:role/my-github-actions-role-test
|
|
||||||
aws-region: us-east-1
|
|
||||||
- name: Copy files to the test website with the AWS CLI
|
|
||||||
run: |
|
|
||||||
aws s3 sync . s3://my-s3-test-website-bucket
|
|
||||||
- name: Configure AWS credentials from Production account
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
role-to-assume: arn:aws:iam::222222222222:role/my-github-actions-role-prod
|
|
||||||
aws-region: us-west-2
|
|
||||||
- name: Copy files to the production website with the AWS CLI
|
|
||||||
run: |
|
|
||||||
aws s3 sync . s3://my-s3-prod-website-bucket
|
|
||||||
```
|
|
||||||
|
|
||||||
See [action.yml](action.yml) for the full documentation for this action's inputs
|
|
||||||
and outputs.
|
|
||||||
|
|
||||||
## Credentials
|
|
||||||
|
|
||||||
We recommend following
|
|
||||||
[Amazon IAM best practices](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html)
|
|
||||||
for the AWS credentials used in GitHub Actions workflows, including:
|
|
||||||
* Do not store credentials in your repository's code.
|
|
||||||
* [Grant least privilege](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege) to the credentials used in GitHub Actions
|
|
||||||
workflows. Grant only the permissions required to perform the actions in your
|
|
||||||
GitHub Actions workflows.
|
|
||||||
* [Monitor the activity](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#keep-a-log) of the credentials used in GitHub Actions workflows.
|
|
||||||
|
|
||||||
## Assuming a Role
|
|
||||||
There are four different supported ways to retrieve credentials. We recommend
|
|
||||||
using [GitHub's OIDC provider](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services)
|
|
||||||
to get short-lived credentials needed for your actions. Specifying
|
|
||||||
`role-to-assume` **without** providing an `aws-access-key-id` or a
|
|
||||||
`web-identity-token-file` will signal to the action that you wish to use the
|
|
||||||
OIDC provider.
|
|
||||||
|
|
||||||
The following table describes which identity is used based on which values are supplied to the Action:
|
|
||||||
|
|
||||||
| **Identity Used** | `aws-access-key-id` | `role-to-assume` | `web-identity-token-file` |
|
|
||||||
| --------------------------------------------------------------- | ------------------- | ---------------- | ------------------------- |
|
|
||||||
| [✅ Recommended] Assume Role directly using GitHub OIDC provider | | ✔ | |
|
|
||||||
| IAM User | ✔ | | |
|
|
||||||
| Assume Role using IAM User credentials | ✔ | ✔ | |
|
|
||||||
| Assume Role using WebIdentity Token File credentials | | ✔ | ✔ |
|
|
||||||
|
|
||||||
### Credential Lifetime
|
|
||||||
The default session duration is **1 hour** when using the OIDC provider to
|
|
||||||
directly assume an IAM Role or when an `aws-session-token` is directly provided.
|
|
||||||
The default session duration is **6 hours** when using an IAM User to assume an
|
|
||||||
IAM Role (by providing an `aws-access-key-id`, `aws-secret-access-key`, and a
|
|
||||||
`role-to-assume`) .
|
|
||||||
|
|
||||||
If you would like to adjust this you can pass a duration to `role-duration-seconds`, but the duration cannot exceed the maximum that was defined when the IAM Role was created.
|
|
||||||
The default session name is GitHubActions, and you can modify it by specifying the desired name in `role-session-name`.
|
|
||||||
The default audience is `sts.amazonaws.com` which you can replace by specifying the desired audience name in `audience`.
|
|
||||||
|
|
||||||
### Examples
|
|
||||||
|
|
||||||
#### AssumeRoleWithWebIdentity (recommended)
|
|
||||||
```yaml
|
|
||||||
- name: Configure AWS Credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
aws-region: us-east-2
|
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
|
||||||
role-session-name: MySessionName
|
|
||||||
```
|
|
||||||
In this example, the Action will load the OIDC token from the GitHub-provided environment variable and use it to assume the role `arn:aws:iam::123456789100:role/my-github-actions-role` with the session name `MySessionName`.
|
|
||||||
|
|
||||||
#### AssumeRole with static IAM credentials in repository secrets
|
|
||||||
```yaml
|
|
||||||
- name: Configure AWS Credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
|
||||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
|
||||||
aws-region: us-east-2
|
|
||||||
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
|
|
||||||
role-external-id: ${{ secrets.AWS_ROLE_EXTERNAL_ID }}
|
|
||||||
role-duration-seconds: 1200
|
|
||||||
role-session-name: MySessionName
|
|
||||||
```
|
|
||||||
In this example, the secret `AWS_ROLE_TO_ASSUME` contains a string like `arn:aws:iam::123456789100:role/my-github-actions-role`. To assume a role in the same account as the static credentials, you can simply specify the role name, like `role-to-assume: my-github-actions-role`.
|
|
||||||
|
|
||||||
#### AssumeRoleWithWebIdentity using a custom audience
|
|
||||||
```yaml
|
|
||||||
- name: Configure AWS Credentials for Beta Customers
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
audience: beta-customers
|
|
||||||
aws-region: us-east-3
|
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
|
||||||
role-session-name: MySessionName
|
|
||||||
```
|
|
||||||
In this example, the audience has been changed from the default to use a different audience name `beta-customers`. This can help ensure that the role can only affect those AWS accounts whose GitHub OIDC providers have explicitly opted in to the `beta-customers` label.
|
|
||||||
|
|
||||||
Changing the default audience may be necessary when using non-default [AWS partitions](https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html).
|
|
||||||
|
|
||||||
#### AssumeRoleWithWebIdentity and disable secure Action outputs
|
|
||||||
```yaml
|
|
||||||
- name: Configure AWS Credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
aws-region: us-east-2
|
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
|
||||||
role-session-name: MySessionName
|
|
||||||
mask-aws-account-id: false
|
|
||||||
```
|
|
||||||
In this example, account ID masking has been disabled. By default, the AWS
|
|
||||||
account ID will be obscured in the action's output. This may be helpful when
|
|
||||||
debugging action failures.
|
|
||||||
|
|
||||||
## Sample IAM OIDC CloudFormation Template
|
|
||||||
If you choose to use GitHub's OIDC provider, you must first set up federation
|
|
||||||
with the provider in as an IAM IdP. The GitHub OIDC provider only needs to be
|
|
||||||
created once per account (i.e. multiple IAM Roles that can be assumed by the
|
|
||||||
GitHub's OIDC can share a single OIDC Provider).
|
|
||||||
|
|
||||||
This CloudFormation template will configure the IdP for you.
|
|
||||||
```yaml
|
|
||||||
Parameters:
|
|
||||||
GitHubOrg:
|
|
||||||
Type: String
|
|
||||||
RepositoryName:
|
|
||||||
Type: String
|
|
||||||
OIDCProviderArn:
|
|
||||||
Description: Arn for the GitHub OIDC Provider.
|
|
||||||
Default: ""
|
|
||||||
Type: String
|
|
||||||
OIDCAudience:
|
|
||||||
Description: Audience supplied to configure-aws-credentials.
|
|
||||||
Default: "sts.amazonaws.com"
|
|
||||||
Type: String
|
|
||||||
|
|
||||||
Conditions:
|
|
||||||
CreateOIDCProvider: !Equals
|
|
||||||
- !Ref OIDCProviderArn
|
|
||||||
- ""
|
|
||||||
|
|
||||||
Resources:
|
|
||||||
Role:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Principal:
|
|
||||||
Federated: !If
|
|
||||||
- CreateOIDCProvider
|
|
||||||
- !Ref GithubOidc
|
|
||||||
- !Ref OIDCProviderArn
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: !Ref OIDCAudience
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/${RepositoryName}:*
|
|
||||||
|
|
||||||
GithubOidc:
|
|
||||||
Type: AWS::IAM::OIDCProvider
|
|
||||||
Condition: CreateOIDCProvider
|
|
||||||
Properties:
|
|
||||||
Url: https://token.actions.githubusercontent.com
|
|
||||||
ClientIdList:
|
|
||||||
- sts.amazonaws.com
|
|
||||||
ThumbprintList:
|
|
||||||
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
|
||||||
|
|
||||||
Outputs:
|
|
||||||
Role:
|
|
||||||
Value: !GetAtt Role.Arn
|
|
||||||
```
|
|
||||||
|
|
||||||
To align with the Amazon IAM best practice of
|
|
||||||
[granting least privilege](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege), the assume role policy document should contain a
|
|
||||||
[`Condition`](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition.html) that specifies a subject allowed to assume the role. Without a subject
|
|
||||||
condition, any GitHub user or repository could potentially assume the role. The
|
|
||||||
subject can be scoped to a GitHub organization and repository as shown in the
|
|
||||||
CloudFormation template. Additional claim conditions can be added for higher
|
|
||||||
specificity as explained in the
|
|
||||||
[GitHub documentation](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect).
|
|
||||||
Due to implementation details, not every OIDC claim is presently supported by
|
|
||||||
IAM.
|
|
||||||
|
|
||||||
For further information on OIDC and GitHub Actions, please see:
|
|
||||||
|
|
||||||
* [AWS docs: Creating OpenID Connect (OIDC) identity providers](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html)
|
|
||||||
* [AWS docs: IAM JSON policy elements: Condition](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition.html)
|
|
||||||
* [GitHub docs: About security hardening with OpenID Connect](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect)
|
|
||||||
* [GitHub docs: Configuring OpenID Connect in Amazon Web Services](https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services)
|
|
||||||
* [GitHub changelog: GitHub Actions: Secure cloud deployments with OpenID Connect](https://github.blog/changelog/2021-10-27-github-actions-secure-cloud-deployments-with-openid-connect/)
|
|
||||||
|
|
||||||
### Session tagging
|
|
||||||
The session will have the name "GitHubActions" and be tagged with the following
|
|
||||||
tags: (`GITHUB_` environment variable definitions can be
|
|
||||||
[found here](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/using-environment-variables#default-environment-variables))
|
|
||||||
|
|
||||||
| Key | Value |
|
|
||||||
| ---------- | ----------------- |
|
|
||||||
| GitHub | "Actions" |
|
|
||||||
| Repository | GITHUB_REPOSITORY |
|
|
||||||
| Workflow | GITHUB_WORKFLOW |
|
|
||||||
| Action | GITHUB_ACTION |
|
|
||||||
| Actor | GITHUB_ACTOR |
|
|
||||||
| Branch | GITHUB_REF |
|
|
||||||
| Commit | GITHUB_SHA |
|
|
||||||
|
|
||||||
_Note: all tag values must conform to
|
|
||||||
[the requirements](https://docs.aws.amazon.com/STS/latest/APIReference/API_Tag.html).
|
|
||||||
Particularly, `GITHUB_WORKFLOW` will be truncated if it's too long. If
|
|
||||||
`GITHUB_ACTOR` or `GITHUB_WORKFLOW` contain invalid characters, the characters
|
|
||||||
will be replaced with an '*'._
|
|
||||||
|
|
||||||
The action will use session tagging by default during role assumption.
|
|
||||||
Note that for WebIdentity role assumption, the session tags have to be included
|
|
||||||
in the encoded WebIdentity token. This means that Tags can only be supplied by
|
|
||||||
the OIDC provider and not set during the AssumeRoleWithWebIdentity API call
|
|
||||||
within the Action. You can skip this session tagging by providing
|
|
||||||
`role-skip-session-tagging` as true in the action's inputs:
|
|
||||||
```yaml
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
role-skip-session-tagging: true
|
|
||||||
```
|
|
||||||
|
|
||||||
## Self-Hosted Runners
|
|
||||||
|
|
||||||
If you run your GitHub Actions in a
|
|
||||||
[self-hosted runner](https://help.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners) that already has access to AWS credentials, such as
|
|
||||||
an EC2 instance, then you do not need to provide IAM user access key credentials
|
|
||||||
to this action. We will use the standard AWS JavaScript SDK credential
|
|
||||||
resolution methods to find your credentials, so if the AWS JS SDK can
|
|
||||||
authenticate on your runner, this Action will as well.
|
|
||||||
|
|
||||||
If no access key credentials are given in the action inputs, this action will
|
|
||||||
use credentials from the runner environment using the
|
|
||||||
[default methods for the AWS SDK for Javascript](https://docs.aws.amazon.com/sdk-for-javascript/v2/developer-guide/setting-credentials-node.html).
|
|
||||||
|
|
||||||
You can use this action to simply configure the region and account ID in the
|
|
||||||
environment, and then use the runner's credentials for all AWS API calls made by
|
|
||||||
your Actions workflow:
|
|
||||||
```yaml
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
aws-region: us-east-2
|
|
||||||
```
|
|
||||||
In this case, your runner's credentials must have permissions to call any AWS
|
|
||||||
APIs called by your Actions workflow.
|
|
||||||
|
|
||||||
Or, you can use this action to assume a role, and then use the role credentials
|
|
||||||
for all AWS API calls made by your Actions workflow:
|
|
||||||
```yaml
|
|
||||||
uses: aws-actions/configure-aws-credentials@v2
|
|
||||||
with:
|
|
||||||
aws-region: us-east-2
|
|
||||||
role-to-assume: my-github-actions-role
|
|
||||||
```
|
|
||||||
In this case, your runner's credentials must have permissions to assume the
|
|
||||||
role.
|
|
||||||
|
|
||||||
You can also assume a role using a web identity token file, such as if using
|
|
||||||
[Amazon EKS IRSA](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts-technical-overview.html). Pods running in EKS
|
|
||||||
worker nodes that do not run as root can use this file to assume a role with a
|
|
||||||
web identity.
|
|
||||||
|
|
||||||
### Proxy Configuration
|
|
||||||
|
|
||||||
If you run in self-hosted environments and in secured environment where you need
|
|
||||||
use a specific proxy you can set it in the action manually.
|
|
||||||
|
|
||||||
Additionally this action will always consider already configured proxy in the
|
|
||||||
environment.
|
|
||||||
|
|
||||||
Manually configured proxy:
|
|
||||||
```yaml
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1
|
|
||||||
with:
|
|
||||||
aws-region: us-east-2
|
|
||||||
role-to-assume: my-github-actions-role
|
|
||||||
http-proxy: "http://companydomain.com:3128"
|
|
||||||
```
|
|
||||||
|
|
||||||
Proxy configured in the environment variable:
|
|
||||||
```bash
|
|
||||||
# Your environment configuration
|
|
||||||
HTTP_PROXY="http://companydomain.com:3128"
|
|
||||||
```
|
|
||||||
|
|
||||||
The action will read the underlying proxy configuration from the environment and
|
|
||||||
you don't need to configure it in the action.
|
|
||||||
|
|
||||||
### Use with the AWS CLI
|
|
||||||
This workflow does _not_ install the [AWS CLI](https://aws.amazon.com/cli/)
|
|
||||||
into your environment. Self-hosted runners that intend to run this action prior
|
|
||||||
to executing `aws` commands need to have the AWS CLI
|
|
||||||
[installed](https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-install.html)
|
|
||||||
if it's not already present.
|
|
||||||
Most [GitHub hosted runner environments](https://github.com/actions/virtual-environments)
|
|
||||||
should include the AWS CLI by default.
|
|
||||||
|
|
||||||
## License Summary
|
|
||||||
This code is made available under the MIT license.
|
|
||||||
|
|
||||||
## Security Disclosures
|
|
||||||
If you would like to report a potential security issue in this project, please do not create a GitHub issue. Instead, please follow the instructions [here](https://aws.amazon.com/security/vulnerability-reporting/) or [email AWS security directly](mailto:aws-security@amazon.com).
|
|
||||||
-231
@@ -1,231 +0,0 @@
|
|||||||
** AWS SDK for JavaScript; version 2.562.0 -- https://github.com/aws/aws-sdk-js
|
|
||||||
Copyright 2012-2018 Amazon.com, Inc. or its affiliates. All Rights Reserved.
|
|
||||||
|
|
||||||
Apache License
|
|
||||||
|
|
||||||
Version 2.0, January 2004
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND
|
|
||||||
DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction, and
|
|
||||||
distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by the
|
|
||||||
copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all other
|
|
||||||
entities that control, are controlled by, or are under common control
|
|
||||||
with that entity. For the purposes of this definition, "control" means
|
|
||||||
(i) the power, direct or indirect, to cause the direction or management
|
|
||||||
of such entity, whether by contract or otherwise, or (ii) ownership of
|
|
||||||
fifty percent (50%) or more of the outstanding shares, or (iii)
|
|
||||||
beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity exercising
|
|
||||||
permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation source,
|
|
||||||
and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but not limited
|
|
||||||
to compiled object code, generated documentation, and conversions to
|
|
||||||
other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or Object
|
|
||||||
form, made available under the License, as indicated by a copyright
|
|
||||||
notice that is included in or attached to the work (an example is
|
|
||||||
provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object form,
|
|
||||||
that is based on (or derived from) the Work and for which the editorial
|
|
||||||
revisions, annotations, elaborations, or other modifications represent,
|
|
||||||
as a whole, an original work of authorship. For the purposes of this
|
|
||||||
License, Derivative Works shall not include works that remain separable
|
|
||||||
from, or merely link (or bind by name) to the interfaces of, the Work and
|
|
||||||
Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including the original
|
|
||||||
version of the Work and any modifications or additions to that Work or
|
|
||||||
Derivative Works thereof, that is intentionally submitted to Licensor for
|
|
||||||
inclusion in the Work by the copyright owner or by an individual or Legal
|
|
||||||
Entity authorized to submit on behalf of the copyright owner. For the
|
|
||||||
purposes of this definition, "submitted" means any form of electronic,
|
|
||||||
verbal, or written communication sent to the Licensor or its
|
|
||||||
representatives, including but not limited to communication on electronic
|
|
||||||
mailing lists, source code control systems, and issue tracking systems
|
|
||||||
that are managed by, or on behalf of, the Licensor for the purpose of
|
|
||||||
discussing and improving the Work, but excluding communication that is
|
|
||||||
conspicuously marked or otherwise designated in writing by the copyright
|
|
||||||
owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity on
|
|
||||||
behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of this
|
|
||||||
License, each Contributor hereby grants to You a perpetual, worldwide,
|
|
||||||
non-exclusive, no-charge, royalty-free, irrevocable copyright license to
|
|
||||||
reproduce, prepare Derivative Works of, publicly display, publicly perform,
|
|
||||||
sublicense, and distribute the Work and such Derivative Works in Source or
|
|
||||||
Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of this
|
|
||||||
License, each Contributor hereby grants to You a perpetual, worldwide,
|
|
||||||
non-exclusive, no-charge, royalty-free, irrevocable (except as stated in
|
|
||||||
this section) patent license to make, have made, use, offer to sell, sell,
|
|
||||||
import, and otherwise transfer the Work, where such license applies only to
|
|
||||||
those patent claims licensable by such Contributor that are necessarily
|
|
||||||
infringed by their Contribution(s) alone or by combination of their
|
|
||||||
Contribution(s) with the Work to which such Contribution(s) was submitted.
|
|
||||||
If You institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work or a
|
|
||||||
Contribution incorporated within the Work constitutes direct or contributory
|
|
||||||
patent infringement, then any patent licenses granted to You under this
|
|
||||||
License for that Work shall terminate as of the date such litigation is
|
|
||||||
filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the Work or
|
|
||||||
Derivative Works thereof in any medium, with or without modifications, and
|
|
||||||
in Source or Object form, provided that You meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or Derivative Works a
|
|
||||||
copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices stating
|
|
||||||
that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works that You
|
|
||||||
distribute, all copyright, patent, trademark, and attribution notices
|
|
||||||
from the Source form of the Work, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must include
|
|
||||||
a readable copy of the attribution notices contained within such NOTICE
|
|
||||||
file, excluding those notices that do not pertain to any part of the
|
|
||||||
Derivative Works, in at least one of the following places: within a
|
|
||||||
NOTICE text file distributed as part of the Derivative Works; within the
|
|
||||||
Source form or documentation, if provided along with the Derivative
|
|
||||||
Works; or, within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents of the
|
|
||||||
NOTICE file are for informational purposes only and do not modify the
|
|
||||||
License. You may add Your own attribution notices within Derivative Works
|
|
||||||
that You distribute, alongside or as an addendum to the NOTICE text from
|
|
||||||
the Work, provided that such additional attribution notices cannot be
|
|
||||||
construed as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and may
|
|
||||||
provide additional or different license terms and conditions for use,
|
|
||||||
reproduction, or distribution of Your modifications, or for any such
|
|
||||||
Derivative Works as a whole, provided Your use, reproduction, and
|
|
||||||
distribution of the Work otherwise complies with the conditions stated in
|
|
||||||
this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise, any
|
|
||||||
Contribution intentionally submitted for inclusion in the Work by You to the
|
|
||||||
Licensor shall be under the terms and conditions of this License, without
|
|
||||||
any additional terms or conditions. Notwithstanding the above, nothing
|
|
||||||
herein shall supersede or modify the terms of any separate license agreement
|
|
||||||
you may have executed with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor, except
|
|
||||||
as required for reasonable and customary use in describing the origin of the
|
|
||||||
Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or agreed to in
|
|
||||||
writing, Licensor provides the Work (and each Contributor provides its
|
|
||||||
Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
|
|
||||||
KIND, either express or implied, including, without limitation, any
|
|
||||||
warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining
|
|
||||||
the appropriateness of using or redistributing the Work and assume any risks
|
|
||||||
associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory, whether
|
|
||||||
in tort (including negligence), contract, or otherwise, unless required by
|
|
||||||
applicable law (such as deliberate and grossly negligent acts) or agreed to
|
|
||||||
in writing, shall any Contributor be liable to You for damages, including
|
|
||||||
any direct, indirect, special, incidental, or consequential damages of any
|
|
||||||
character arising as a result of this License or out of the use or inability
|
|
||||||
to use the Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all other
|
|
||||||
commercial damages or losses), even if such Contributor has been advised of
|
|
||||||
the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing the Work
|
|
||||||
or Derivative Works thereof, You may choose to offer, and charge a fee for,
|
|
||||||
acceptance of support, warranty, indemnity, or other liability obligations
|
|
||||||
and/or rights consistent with this License. However, in accepting such
|
|
||||||
obligations, You may act only on Your own behalf and on Your sole
|
|
||||||
responsibility, not on behalf of any other Contributor, and only if You
|
|
||||||
agree to indemnify, defend, and hold each Contributor harmless for any
|
|
||||||
liability incurred by, or claims asserted against, such Contributor by
|
|
||||||
reason of your accepting any such warranty or additional liability. END OF
|
|
||||||
TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following boilerplate
|
|
||||||
notice, with the fields enclosed by brackets "[]" replaced with your own
|
|
||||||
identifying information. (Don't include the brackets!) The text should be
|
|
||||||
enclosed in the appropriate comment syntax for the file format. We also
|
|
||||||
recommend that a file or class name and description of purpose be included on
|
|
||||||
the same "printed page" as the copyright notice for easier identification
|
|
||||||
within third-party archives.
|
|
||||||
|
|
||||||
Copyright [yyyy] [name of copyright owner]
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
* For AWS SDK for JavaScript see also this required NOTICE:
|
|
||||||
Copyright 2012-2018 Amazon.com, Inc. or its affiliates. All Rights
|
|
||||||
Reserved.
|
|
||||||
|
|
||||||
------
|
|
||||||
|
|
||||||
** GitHub Actions Toolkit; version 1.2.0 -- https://github.com/actions/toolkit
|
|
||||||
Copyright 2019 GitHub
|
|
||||||
|
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) <year> <copyright holders>
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy of
|
|
||||||
this software and associated documentation files (the "Software"), to deal in
|
|
||||||
the Software without restriction, including without limitation the rights to
|
|
||||||
use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies
|
|
||||||
of the Software, and to permit persons to whom the Software is furnished to do
|
|
||||||
so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
-67
@@ -1,67 +0,0 @@
|
|||||||
name: 'Configure AWS Credentials For GitHub Actions'
|
|
||||||
description: 'Configure AWS credential and region environment variables for use with the AWS CLI and AWS SDKs'
|
|
||||||
branding:
|
|
||||||
icon: 'cloud'
|
|
||||||
color: 'orange'
|
|
||||||
inputs:
|
|
||||||
audience:
|
|
||||||
default: 'sts.amazonaws.com'
|
|
||||||
description: 'The audience to use for the OIDC provider'
|
|
||||||
required: false
|
|
||||||
aws-access-key-id:
|
|
||||||
description: >-
|
|
||||||
AWS Access Key ID. This input is required if running in the GitHub hosted environment.
|
|
||||||
It is optional if running in a self-hosted environment that already has AWS credentials,
|
|
||||||
for example on an EC2 instance.
|
|
||||||
required: false
|
|
||||||
aws-secret-access-key:
|
|
||||||
description: >-
|
|
||||||
AWS Secret Access Key. This input is required if running in the GitHub hosted environment.
|
|
||||||
It is optional if running in a self-hosted environment that already has AWS credentials,
|
|
||||||
for example on an EC2 instance.
|
|
||||||
required: false
|
|
||||||
aws-session-token:
|
|
||||||
description: 'AWS Session Token'
|
|
||||||
required: false
|
|
||||||
aws-region:
|
|
||||||
description: 'AWS Region, e.g. us-east-2'
|
|
||||||
required: true
|
|
||||||
mask-aws-account-id:
|
|
||||||
description: >-
|
|
||||||
Whether to set the AWS account ID for these credentials as a secret value,
|
|
||||||
so that it is masked in logs. Valid values are 'true' and 'false'.
|
|
||||||
Defaults to true
|
|
||||||
required: false
|
|
||||||
role-to-assume:
|
|
||||||
description: >-
|
|
||||||
Use the provided credentials to assume an IAM role and configure the Actions
|
|
||||||
environment with the assumed role credentials rather than with the provided
|
|
||||||
credentials
|
|
||||||
required: false
|
|
||||||
web-identity-token-file:
|
|
||||||
description: >-
|
|
||||||
Use the web identity token file from the provided file system path in order to
|
|
||||||
assume an IAM role using a web identity. E.g., from within an Amazon EKS worker node
|
|
||||||
required: false
|
|
||||||
role-duration-seconds:
|
|
||||||
description: "Role duration in seconds (default: 6 hours, 1 hour for OIDC/specified aws-session-token)"
|
|
||||||
required: false
|
|
||||||
role-session-name:
|
|
||||||
description: 'Role session name (default: GitHubActions)'
|
|
||||||
required: false
|
|
||||||
role-external-id:
|
|
||||||
description: 'The external ID of the role to assume'
|
|
||||||
required: false
|
|
||||||
role-skip-session-tagging:
|
|
||||||
description: 'Skip session tagging during role assumption'
|
|
||||||
required: false
|
|
||||||
http-proxy:
|
|
||||||
description: 'Proxy to use for the AWS SDK agent'
|
|
||||||
required: false
|
|
||||||
outputs:
|
|
||||||
aws-account-id:
|
|
||||||
description: 'The AWS account ID for the provided credentials'
|
|
||||||
runs:
|
|
||||||
using: 'node16'
|
|
||||||
main: 'dist/index.js'
|
|
||||||
post: 'dist/cleanup/index.js'
|
|
||||||
-36
@@ -1,36 +0,0 @@
|
|||||||
const core = require('@actions/core');
|
|
||||||
|
|
||||||
/**
|
|
||||||
* When the GitHub Actions job is done, clean up any environment variables that
|
|
||||||
* may have been set by the configure-aws-credentials steps in the job.
|
|
||||||
*
|
|
||||||
* Environment variables are not intended to be shared across different jobs in
|
|
||||||
* the same GitHub Actions workflow: GitHub Actions documentation states that
|
|
||||||
* each job runs in a fresh instance. However, doing our own cleanup will
|
|
||||||
* give us additional assurance that these environment variables are not shared
|
|
||||||
* with any other jobs.
|
|
||||||
*/
|
|
||||||
|
|
||||||
async function cleanup() {
|
|
||||||
try {
|
|
||||||
// The GitHub Actions toolkit does not have an option to completely unset
|
|
||||||
// environment variables, so we overwrite the current value with an empty
|
|
||||||
// string. The AWS CLI and AWS SDKs will behave correctly: they treat an
|
|
||||||
// empty string value as if the environment variable does not exist.
|
|
||||||
core.exportVariable('AWS_ACCESS_KEY_ID', '');
|
|
||||||
core.exportVariable('AWS_SECRET_ACCESS_KEY', '');
|
|
||||||
core.exportVariable('AWS_SESSION_TOKEN', '');
|
|
||||||
core.exportVariable('AWS_DEFAULT_REGION', '');
|
|
||||||
core.exportVariable('AWS_REGION', '');
|
|
||||||
}
|
|
||||||
catch (error) {
|
|
||||||
core.setFailed(error.message);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
module.exports = cleanup;
|
|
||||||
|
|
||||||
/* istanbul ignore next */
|
|
||||||
if (require.main === module) {
|
|
||||||
cleanup();
|
|
||||||
}
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
const core = require('@actions/core');
|
|
||||||
const cleanup = require('./cleanup.js');
|
|
||||||
|
|
||||||
jest.mock('@actions/core');
|
|
||||||
|
|
||||||
const FAKE_ACCESS_KEY_ID = 'MY-AWS-ACCESS-KEY-ID';
|
|
||||||
const FAKE_SECRET_ACCESS_KEY = 'MY-AWS-SECRET-ACCESS-KEY';
|
|
||||||
const FAKE_SESSION_TOKEN = 'MY-AWS-SESSION-TOKEN';
|
|
||||||
const FAKE_REGION = 'fake-region-1';
|
|
||||||
const ACTION_ENVIRONMENT_VARIABLES = {
|
|
||||||
AWS_ACCESS_KEY_ID: FAKE_ACCESS_KEY_ID,
|
|
||||||
AWS_SECRET_ACCESS_KEY: FAKE_SECRET_ACCESS_KEY,
|
|
||||||
AWS_SESSION_TOKEN: FAKE_SESSION_TOKEN,
|
|
||||||
AWS_DEFAULT_REGION: FAKE_REGION,
|
|
||||||
AWS_REGION: FAKE_REGION,
|
|
||||||
};
|
|
||||||
|
|
||||||
describe('Configure AWS Credentials', () => {
|
|
||||||
const OLD_ENV = process.env;
|
|
||||||
|
|
||||||
beforeEach(() => {
|
|
||||||
jest.resetModules();
|
|
||||||
process.env = {...OLD_ENV, ...ACTION_ENVIRONMENT_VARIABLES};
|
|
||||||
});
|
|
||||||
|
|
||||||
afterEach(() => {
|
|
||||||
process.env = OLD_ENV;
|
|
||||||
});
|
|
||||||
|
|
||||||
test('replaces AWS credential and region env vars with empty strings', async () => {
|
|
||||||
await cleanup();
|
|
||||||
expect(core.setFailed).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(5);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_ACCESS_KEY_ID', '');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SECRET_ACCESS_KEY', '');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', '');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', '');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('error is caught and fails the action', async () => {
|
|
||||||
core.exportVariable.mockReset();
|
|
||||||
core.exportVariable.mockImplementation(() => {
|
|
||||||
throw new Error();
|
|
||||||
});
|
|
||||||
|
|
||||||
await cleanup();
|
|
||||||
|
|
||||||
expect(core.setFailed).toBeCalled();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
Vendored
-2868
File diff suppressed because it is too large
Load Diff
Vendored
-47595
File diff suppressed because one or more lines are too long
@@ -1,9 +0,0 @@
|
|||||||
# Examples
|
|
||||||
|
|
||||||
## [federated-setup](./federated-setup/README.md)
|
|
||||||
|
|
||||||
The directory contains templates for setting up the `configure-aws-credentials` federation between your GitHub Organization/repository and your AWS account.
|
|
||||||
|
|
||||||
## [cfn-deploy-example](./cfn-deploy-example/README.md)
|
|
||||||
|
|
||||||
Repository example uses aws-action `configure-aws-credentials` with OIDC federation template [github-actions-oidc-federation-and-role](./github-actions-oidc-federation-and-role.yml). Example demonstrates a repository that deploys AWS CloudFormation template using cfn-deploy GitHub Action.
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
name: 'compliance'
|
|
||||||
## run ci testing on all push events
|
|
||||||
on: [push]
|
|
||||||
jobs:
|
|
||||||
## Guard rule set
|
|
||||||
sast-guard:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v3
|
|
||||||
- uses: grolston/guard-action@main
|
|
||||||
with:
|
|
||||||
data_directory: './cloudformation/' ## change to your template directory
|
|
||||||
rule_set: 'FedRAMP-Moderate'
|
|
||||||
show_summary: 'all'
|
|
||||||
output_format: 'single-line-summary'
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
---
|
|
||||||
name: deploy
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
env:
|
|
||||||
AWS_DEFAULT_REGION: us-east-1
|
|
||||||
AWS_DEFAULT_OUTPUT: json
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
deploy-cfn:
|
|
||||||
name: deploy
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
# These permissions are needed to interact with GitHub’s OIDC Token endpoint.
|
|
||||||
permissions:
|
|
||||||
id-token: write
|
|
||||||
contents: read
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
- name: Configure AWS Credentials
|
|
||||||
uses: aws-actions/configure-aws-credentials@v1-node16
|
|
||||||
with:
|
|
||||||
aws-region: us-east-1
|
|
||||||
## the following creates an ARN based on the values entered into github secrets
|
|
||||||
role-to-assume: arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/${{ secrets.AWS_DEPLOY_ROLE }}
|
|
||||||
role-session-name: myGitHubActions
|
|
||||||
- name: Deploy EC2 Bastion
|
|
||||||
uses: aws-actions/aws-cloudformation-github-deploy@v1.0.3
|
|
||||||
with:
|
|
||||||
name: myEC2bastion
|
|
||||||
## change to path to template in your github repo
|
|
||||||
template: cloudformation/ec2-bastion.yml
|
|
||||||
capabilities: CAPABILITY_IAM, CAPABILITY_NAMED_IAM
|
|
||||||
no-fail-on-empty-changeset: "1"
|
|
||||||
## parameter set in github secrets
|
|
||||||
parameter-overrides: "pVpc=${{ secrets.VPC_ID }},pSubnet=${{ secrets.SUBNET_ID }}"
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
# cfn-deploy example
|
|
||||||
|
|
||||||
Example uses aws-action `configure-aws-credentials` with OIDC federation. Prior to using this example project, the user needs to deploy the [github-actions-oidc-federation-and-role](../federated-setup/github-actions-oidc-federation-and-role.yml) template in the AWS account they want to deploy the CloudFormation template into. Specify the GitHub Organization name, repository name, and the specific branch you want to deploy on.
|
|
||||||
|
|
||||||
Within the [github/workflows](./.github/workflows/) directory there is a [compliance.yml](./.github/workflows/compliance.yml) and a [deploy.yml](./.github/workflows/deploy.yml). The deploy.yml file leverages the aws-action `configure-aws-credentials` and accesses GitHub Action Secrets for some of the variables. The compliance.yml runs static application security testing using cfn-guard.
|
|
||||||
|
|
||||||
To use the example you will need to set the following GitHub Action Secrets:
|
|
||||||
|
|
||||||
| Secret Key | Used With | Description |
|
|
||||||
| --------- | -------- | -----------|
|
|
||||||
| AWS_ACCOUNT_ID | configure-aws-credentials | The AWS account ID |
|
|
||||||
| AWS_DEPLOY_ROLE | configure-aws-credentials | The name of the IAM role |
|
|
||||||
| VPC_ID | aws-cloudformation-github-deploy | VPC ID the EC2 Bastion is deployed to |
|
|
||||||
| SUBNET_ID | aws-cloudformation-github-deploy | Subnet ID the EC2 Bastion is deployed to |
|
|
||||||
@@ -1,150 +0,0 @@
|
|||||||
---
|
|
||||||
AWSTemplateFormatVersion: "2010-09-09"
|
|
||||||
Description: EC2 bastion for latest AWS Linux 2 EC2 deployment
|
|
||||||
Metadata:
|
|
||||||
AWS::CloudFormation::Interface:
|
|
||||||
ParameterGroups:
|
|
||||||
- Label:
|
|
||||||
default: "EC2 Configuration"
|
|
||||||
Parameters:
|
|
||||||
- pTagNameValue
|
|
||||||
- pOperatingSystem
|
|
||||||
- pInstanceType
|
|
||||||
- pVolumeSize
|
|
||||||
- pEbsDeleteOnTermination
|
|
||||||
- Label:
|
|
||||||
default: "Network Configuration"
|
|
||||||
Parameters:
|
|
||||||
- pVpc
|
|
||||||
- pSubnet
|
|
||||||
ParameterLabels:
|
|
||||||
pOperatingSystem:
|
|
||||||
default: "Operating System"
|
|
||||||
pInstanceType:
|
|
||||||
default: "Instance Type"
|
|
||||||
pTagNameValue:
|
|
||||||
default: "EC2 Name"
|
|
||||||
pVolumeSize:
|
|
||||||
default: "Volume Size"
|
|
||||||
pEbsDeleteOnTermination:
|
|
||||||
default: "Delete EBS Volume on Termination"
|
|
||||||
pSubnet:
|
|
||||||
default: "Subnet"
|
|
||||||
pVpc:
|
|
||||||
default: "VPC"
|
|
||||||
Parameters:
|
|
||||||
pSubnet:
|
|
||||||
Description: The subnet to launch the instance in to. It must be part of the VPC chosen above.
|
|
||||||
Type: AWS::EC2::Subnet::Id
|
|
||||||
pVpc:
|
|
||||||
Description: The VPC to launch the EC2 instance in to.
|
|
||||||
Type: AWS::EC2::VPC::Id
|
|
||||||
pOperatingSystem:
|
|
||||||
Type: "AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>"
|
|
||||||
Default: "/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-ebs"
|
|
||||||
pInstanceType:
|
|
||||||
Description: Desired Instance Size
|
|
||||||
Type: String
|
|
||||||
Default: t3.small
|
|
||||||
AllowedValues:
|
|
||||||
- t3.small
|
|
||||||
- t3.medium
|
|
||||||
- t3.nano
|
|
||||||
pTagNameValue:
|
|
||||||
Description: "Required: Enter the tag name you'd like applied to the instance. Tag Name gives the name to the EC2 instance."
|
|
||||||
Type: String
|
|
||||||
MinLength: 1
|
|
||||||
Default: "myBastion"
|
|
||||||
pVolumeSize:
|
|
||||||
Description:
|
|
||||||
Enter the number of GBs you want your volume to be. The minimum value
|
|
||||||
is 8 GBs
|
|
||||||
Type: Number
|
|
||||||
Default: 50
|
|
||||||
MinValue: 8
|
|
||||||
pEbsDeleteOnTermination:
|
|
||||||
Description: "Specify if the EBS volume should be deleted if EC2 is deleted."
|
|
||||||
Type: String
|
|
||||||
Default: true
|
|
||||||
AllowedValues:
|
|
||||||
- true
|
|
||||||
- false
|
|
||||||
Rules:
|
|
||||||
SubnetInVPC:
|
|
||||||
Assertions:
|
|
||||||
- Assert: !EachMemberIn
|
|
||||||
- !ValueOfAll
|
|
||||||
- AWS::EC2::Subnet::Id
|
|
||||||
- VpcId
|
|
||||||
- !RefAll "AWS::EC2::VPC::Id"
|
|
||||||
AssertDescription: All subnets must in the VPC
|
|
||||||
Resources:
|
|
||||||
rSecurityGroupDefault:
|
|
||||||
Type: AWS::EC2::SecurityGroup
|
|
||||||
Properties:
|
|
||||||
GroupDescription: !Sub "Default SG for SC Product ${pTagNameValue} "
|
|
||||||
VpcId: !Ref pVpc
|
|
||||||
SecurityGroupEgress:
|
|
||||||
- Description: Outbound unrestricted traffic
|
|
||||||
IpProtocol: "-1"
|
|
||||||
CidrIp: 0.0.0.0/0
|
|
||||||
Tags:
|
|
||||||
- Key: Name
|
|
||||||
Value: !Ref pTagNameValue
|
|
||||||
rLinuxEc2:
|
|
||||||
Type: AWS::EC2::Instance
|
|
||||||
Metadata:
|
|
||||||
guard:
|
|
||||||
SuppressedRules:
|
|
||||||
- 'EC2_INSTANCE_DETAILED_MONITORING_ENABLED'
|
|
||||||
Properties:
|
|
||||||
ImageId: !Ref pOperatingSystem
|
|
||||||
IamInstanceProfile: !Ref rec2InstanceProfile
|
|
||||||
Monitoring: false
|
|
||||||
InstanceType: !Ref pInstanceType
|
|
||||||
EbsOptimized: true
|
|
||||||
SourceDestCheck: true
|
|
||||||
SubnetId: !Ref pSubnet
|
|
||||||
SecurityGroupIds:
|
|
||||||
- !Ref rSecurityGroupDefault
|
|
||||||
BlockDeviceMappings:
|
|
||||||
- DeviceName: "/dev/xvda"
|
|
||||||
Ebs:
|
|
||||||
VolumeSize: !Ref pVolumeSize
|
|
||||||
DeleteOnTermination: !Ref pEbsDeleteOnTermination
|
|
||||||
Tags:
|
|
||||||
- Key: Name
|
|
||||||
Value: !Ref pTagNameValue
|
|
||||||
UserData:
|
|
||||||
Fn::Base64:
|
|
||||||
yum update -y
|
|
||||||
## Instance Profiles
|
|
||||||
## EC2 IAM Roles
|
|
||||||
rEc2Role:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: !Sub "ec2-role-${AWS::StackName}"
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Service: [ec2.amazonaws.com]
|
|
||||||
Action: ['sts:AssumeRole']
|
|
||||||
Path: /
|
|
||||||
ManagedPolicyArns:
|
|
||||||
- !Sub 'arn:${AWS::Partition}:iam::aws:policy/AmazonSSMManagedInstanceCore'
|
|
||||||
- !Sub 'arn:${AWS::Partition}:iam::aws:policy/CloudWatchAgentServerPolicy'
|
|
||||||
rec2InstanceProfile:
|
|
||||||
Type: AWS::IAM::InstanceProfile
|
|
||||||
Properties:
|
|
||||||
InstanceProfileName: !Sub "ec2-profile-${AWS::StackName}"
|
|
||||||
Path: /
|
|
||||||
Roles:
|
|
||||||
- !Ref rEc2Role
|
|
||||||
Outputs:
|
|
||||||
oLinuxEc2InstanceId:
|
|
||||||
Description: Resource ID of the newly created EC2 instance
|
|
||||||
Value: !Ref rLinuxEc2
|
|
||||||
oLinuxEc2PrivateIP:
|
|
||||||
Description: Private IP Address for EC2
|
|
||||||
Value: !GetAtt rLinuxEc2.PrivateIp
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
# federated-setup
|
|
||||||
|
|
||||||
## [github-action-oidc-federation](./github-actions-odic-federation.yml)
|
|
||||||
|
|
||||||
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account.
|
|
||||||
|
|
||||||
## [github-actions-oidc-federation-and-role](./github-actions-oidc-federation-and-role.yml)
|
|
||||||
|
|
||||||
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account along with a role that only executes on specific branch.
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
---
|
|
||||||
AWSTemplateFormatVersion: "2010-09-09"
|
|
||||||
Description: Github Actions configuration - OIDC IAM IdP Federation
|
|
||||||
|
|
||||||
Parameters:
|
|
||||||
|
|
||||||
GitHubOrganization:
|
|
||||||
Type: String
|
|
||||||
Description: This is the root organization or personal account where repos are stored (Case Sensitive)
|
|
||||||
Default: ""
|
|
||||||
|
|
||||||
RepositoryName:
|
|
||||||
Type: String
|
|
||||||
Description: The repo(s) these roles will have access to. (Use * for all org or personal repos)
|
|
||||||
Default: "*"
|
|
||||||
|
|
||||||
RoleName:
|
|
||||||
Type: String
|
|
||||||
Description: Name the Role
|
|
||||||
Default: ""
|
|
||||||
|
|
||||||
|
|
||||||
Resources:
|
|
||||||
|
|
||||||
IdpGitHubOidc:
|
|
||||||
Type: AWS::IAM::OIDCProvider
|
|
||||||
Properties:
|
|
||||||
Url: https://token.actions.githubusercontent.com
|
|
||||||
ClientIdList:
|
|
||||||
- sts.amazonaws.com
|
|
||||||
- !Sub https://github.com/${GitHubOrganization}/${RepositoryName}
|
|
||||||
ThumbprintList:
|
|
||||||
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
|
||||||
Tags:
|
|
||||||
- Key: Name
|
|
||||||
Value: !Sub ${RoleName}-OIDC-Provider
|
|
||||||
|
|
||||||
|
|
||||||
Outputs:
|
|
||||||
|
|
||||||
IdpGitHubOidc:
|
|
||||||
Description: "ARN of Github OIDC Provider"
|
|
||||||
Value: !GetAtt IdpGitHubOidc.Arn
|
|
||||||
@@ -1,82 +0,0 @@
|
|||||||
---
|
|
||||||
AWSTemplateFormatVersion: "2010-09-09"
|
|
||||||
Description: Github Actions configuration - OIDC IAM IdP and associated role CI/CD
|
|
||||||
|
|
||||||
Parameters:
|
|
||||||
|
|
||||||
GitHubOrganization:
|
|
||||||
Type: String
|
|
||||||
Description: This is the root organization or personal account where repos are stored (Case Sensitive)
|
|
||||||
|
|
||||||
RepositoryName:
|
|
||||||
Type: String
|
|
||||||
Description: The repo(s) these roles will have access to. (Use * for all org or personal repos)
|
|
||||||
Default: "*"
|
|
||||||
|
|
||||||
BranchName:
|
|
||||||
Type: String
|
|
||||||
Description: Name of the git branch to to trust. (Use * for all branches)
|
|
||||||
Default: "*"
|
|
||||||
|
|
||||||
RoleName:
|
|
||||||
Type: String
|
|
||||||
Description: Name the Role
|
|
||||||
|
|
||||||
UseExistingProvider:
|
|
||||||
Type: String
|
|
||||||
Description: "Only one GitHub Provider can exists. Choose yes if one is already present in account"
|
|
||||||
Default: "no"
|
|
||||||
AllowedValues:
|
|
||||||
- "yes"
|
|
||||||
- "no"
|
|
||||||
|
|
||||||
Conditions:
|
|
||||||
|
|
||||||
CreateProvider: !Equals ["no", !Ref UseExistingProvider]
|
|
||||||
|
|
||||||
Resources:
|
|
||||||
|
|
||||||
IdpGitHubOidc:
|
|
||||||
Type: AWS::IAM::OIDCProvider
|
|
||||||
Condition: CreateProvider
|
|
||||||
Properties:
|
|
||||||
Url: https://token.actions.githubusercontent.com
|
|
||||||
ClientIdList:
|
|
||||||
- sts.amazonaws.com
|
|
||||||
- !Sub https://github.com/${GitHubOrganization}/${RepositoryName}
|
|
||||||
ThumbprintList:
|
|
||||||
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
|
||||||
Tags:
|
|
||||||
- Key: Name
|
|
||||||
Value: !Sub ${RoleName}-OIDC-Provider
|
|
||||||
|
|
||||||
RoleGithubActions:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: !Ref RoleName
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Principal:
|
|
||||||
Federated: !If
|
|
||||||
- CreateProvider
|
|
||||||
- !Ref IdpGitHubOidc
|
|
||||||
- !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Condition:
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrganization}/${RepositoryName}:ref:refs/heads/${BranchName}
|
|
||||||
ManagedPolicyArns:
|
|
||||||
## edit the managed policy to give least privileges
|
|
||||||
- !Sub arn:${AWS::Partition}:iam::aws:policy/AdministratorAccess
|
|
||||||
|
|
||||||
Outputs:
|
|
||||||
|
|
||||||
IdpGitHubOidc:
|
|
||||||
Condition: CreateProvider
|
|
||||||
Description: "ARN of Github OIDC Provider"
|
|
||||||
Value: !GetAtt IdpGitHubOidc.Arn
|
|
||||||
|
|
||||||
RoleGithubActionsARN:
|
|
||||||
Description: "CICD Role for GitHub Actions"
|
|
||||||
Value: !GetAtt RoleGithubActions.Arn
|
|
||||||
@@ -1,405 +0,0 @@
|
|||||||
const core = require('@actions/core');
|
|
||||||
const aws = require('aws-sdk');
|
|
||||||
const assert = require('assert');
|
|
||||||
const fs = require('fs');
|
|
||||||
const path = require('path');
|
|
||||||
const proxy = require('https-proxy-agent');
|
|
||||||
|
|
||||||
// Use 1hr as role duration when using session token or OIDC
|
|
||||||
// Otherwise, use the max duration of GitHub action (6hr)
|
|
||||||
const MAX_ACTION_RUNTIME = 6 * 3600;
|
|
||||||
const SESSION_ROLE_DURATION = 3600;
|
|
||||||
const DEFAULT_ROLE_DURATION_FOR_OIDC_ROLES = 3600;
|
|
||||||
const USER_AGENT = 'configure-aws-credentials-for-github-actions';
|
|
||||||
const MAX_TAG_VALUE_LENGTH = 256;
|
|
||||||
const SANITIZATION_CHARACTER = '_';
|
|
||||||
const ROLE_SESSION_NAME = 'GitHubActions';
|
|
||||||
const REGION_REGEX = /^[a-z0-9-]+$/g;
|
|
||||||
|
|
||||||
async function assumeRole(params) {
|
|
||||||
// Assume a role to get short-lived credentials using longer-lived credentials.
|
|
||||||
const isDefined = i => !!i;
|
|
||||||
|
|
||||||
const {
|
|
||||||
sourceAccountId,
|
|
||||||
roleToAssume,
|
|
||||||
roleExternalId,
|
|
||||||
roleDurationSeconds,
|
|
||||||
roleSessionName,
|
|
||||||
region,
|
|
||||||
roleSkipSessionTagging,
|
|
||||||
webIdentityTokenFile,
|
|
||||||
webIdentityToken
|
|
||||||
} = params;
|
|
||||||
assert(
|
|
||||||
[roleToAssume, roleDurationSeconds, roleSessionName, region].every(isDefined),
|
|
||||||
"Missing required input when assuming a Role."
|
|
||||||
);
|
|
||||||
|
|
||||||
const {GITHUB_REPOSITORY, GITHUB_WORKFLOW, GITHUB_ACTION, GITHUB_ACTOR, GITHUB_SHA} = process.env;
|
|
||||||
assert(
|
|
||||||
[GITHUB_REPOSITORY, GITHUB_WORKFLOW, GITHUB_ACTION, GITHUB_ACTOR, GITHUB_SHA].every(isDefined),
|
|
||||||
'Missing required environment value. Are you running in GitHub Actions?'
|
|
||||||
);
|
|
||||||
|
|
||||||
const sts = getStsClient(region);
|
|
||||||
|
|
||||||
let roleArn = roleToAssume;
|
|
||||||
if (!roleArn.startsWith('arn:aws')) {
|
|
||||||
// Supports only 'aws' partition. Customers in other partitions ('aws-cn') will need to provide full ARN
|
|
||||||
assert(
|
|
||||||
isDefined(sourceAccountId),
|
|
||||||
"Source Account ID is needed if the Role Name is provided and not the Role Arn."
|
|
||||||
);
|
|
||||||
roleArn = `arn:aws:iam::${sourceAccountId}:role/${roleArn}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
const tagArray = [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: sanitizeGithubWorkflowName(GITHUB_WORKFLOW)},
|
|
||||||
{Key: 'Action', Value: GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: sanitizeGithubActor(GITHUB_ACTOR)},
|
|
||||||
{Key: 'Commit', Value: GITHUB_SHA},
|
|
||||||
];
|
|
||||||
|
|
||||||
if (isDefined(process.env.GITHUB_REF)) {
|
|
||||||
tagArray.push({Key: 'Branch', Value: process.env.GITHUB_REF});
|
|
||||||
}
|
|
||||||
|
|
||||||
const roleSessionTags = roleSkipSessionTagging ? undefined : tagArray;
|
|
||||||
|
|
||||||
if(roleSessionTags == undefined){
|
|
||||||
core.debug("Role session tagging has been skipped.")
|
|
||||||
} else {
|
|
||||||
core.debug(roleSessionTags.length + " role session tags are being used.")
|
|
||||||
}
|
|
||||||
|
|
||||||
const assumeRoleRequest = {
|
|
||||||
RoleArn: roleArn,
|
|
||||||
RoleSessionName: roleSessionName,
|
|
||||||
DurationSeconds: roleDurationSeconds,
|
|
||||||
Tags: roleSessionTags
|
|
||||||
};
|
|
||||||
|
|
||||||
if (roleExternalId) {
|
|
||||||
assumeRoleRequest.ExternalId = roleExternalId;
|
|
||||||
}
|
|
||||||
|
|
||||||
let assumeFunction = sts.assumeRole.bind(sts);
|
|
||||||
|
|
||||||
// These are customizations needed for the GH OIDC Provider
|
|
||||||
if(isDefined(webIdentityToken)) {
|
|
||||||
delete assumeRoleRequest.Tags;
|
|
||||||
|
|
||||||
assumeRoleRequest.WebIdentityToken = webIdentityToken;
|
|
||||||
assumeFunction = sts.assumeRoleWithWebIdentity.bind(sts);
|
|
||||||
} else if(isDefined(webIdentityTokenFile)) {
|
|
||||||
core.debug("webIdentityTokenFile provided. Will call sts:AssumeRoleWithWebIdentity and take session tags from token contents.");
|
|
||||||
delete assumeRoleRequest.Tags;
|
|
||||||
|
|
||||||
const webIdentityTokenFilePath = path.isAbsolute(webIdentityTokenFile) ?
|
|
||||||
webIdentityTokenFile :
|
|
||||||
path.join(process.env.GITHUB_WORKSPACE, webIdentityTokenFile);
|
|
||||||
|
|
||||||
if (!fs.existsSync(webIdentityTokenFilePath)) {
|
|
||||||
throw new Error(`Web identity token file does not exist: ${webIdentityTokenFilePath}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
assumeRoleRequest.WebIdentityToken = await fs.promises.readFile(webIdentityTokenFilePath, 'utf8');
|
|
||||||
assumeFunction = sts.assumeRoleWithWebIdentity.bind(sts);
|
|
||||||
} catch(error) {
|
|
||||||
throw new Error(`Web identity token file could not be read: ${error.message}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
return assumeFunction(assumeRoleRequest)
|
|
||||||
.promise()
|
|
||||||
.then(function (data) {
|
|
||||||
return {
|
|
||||||
accessKeyId: data.Credentials.AccessKeyId,
|
|
||||||
secretAccessKey: data.Credentials.SecretAccessKey,
|
|
||||||
sessionToken: data.Credentials.SessionToken,
|
|
||||||
};
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function sanitizeGithubActor(actor) {
|
|
||||||
// In some circumstances the actor may contain square brackets. For example, if they're a bot ('[bot]')
|
|
||||||
// Square brackets are not allowed in AWS session tags
|
|
||||||
return actor.replace(/\[|\]/g, SANITIZATION_CHARACTER)
|
|
||||||
}
|
|
||||||
|
|
||||||
function sanitizeGithubWorkflowName(name) {
|
|
||||||
// Workflow names can be almost any valid UTF-8 string, but tags are more restrictive.
|
|
||||||
// This replaces anything not conforming to the tag restrictions by inverting the regular expression.
|
|
||||||
// See the AWS documentation for constraint specifics https://docs.aws.amazon.com/STS/latest/APIReference/API_Tag.html.
|
|
||||||
const nameWithoutSpecialCharacters = name.replace(/[^\p{L}\p{Z}\p{N}_:/=+.-@-]/gu, SANITIZATION_CHARACTER);
|
|
||||||
const nameTruncated = nameWithoutSpecialCharacters.slice(0, MAX_TAG_VALUE_LENGTH)
|
|
||||||
return nameTruncated
|
|
||||||
}
|
|
||||||
|
|
||||||
function exportCredentials(params){
|
|
||||||
// Configure the AWS CLI and AWS SDKs using environment variables and set them as secrets.
|
|
||||||
// Setting the credentials as secrets masks them in Github Actions logs
|
|
||||||
const {accessKeyId, secretAccessKey, sessionToken} = params;
|
|
||||||
|
|
||||||
// AWS_ACCESS_KEY_ID:
|
|
||||||
// Specifies an AWS access key associated with an IAM user or role
|
|
||||||
core.setSecret(accessKeyId);
|
|
||||||
core.exportVariable('AWS_ACCESS_KEY_ID', accessKeyId);
|
|
||||||
|
|
||||||
// AWS_SECRET_ACCESS_KEY:
|
|
||||||
// Specifies the secret key associated with the access key. This is essentially the "password" for the access key.
|
|
||||||
core.setSecret(secretAccessKey);
|
|
||||||
core.exportVariable('AWS_SECRET_ACCESS_KEY', secretAccessKey);
|
|
||||||
|
|
||||||
// AWS_SESSION_TOKEN:
|
|
||||||
// Specifies the session token value that is required if you are using temporary security credentials.
|
|
||||||
if (sessionToken) {
|
|
||||||
core.setSecret(sessionToken);
|
|
||||||
core.exportVariable('AWS_SESSION_TOKEN', sessionToken);
|
|
||||||
} else if (process.env.AWS_SESSION_TOKEN) {
|
|
||||||
// clear session token from previous credentials action
|
|
||||||
core.exportVariable('AWS_SESSION_TOKEN', '');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function exportRegion(region) {
|
|
||||||
// AWS_DEFAULT_REGION and AWS_REGION:
|
|
||||||
// Specifies the AWS Region to send requests to
|
|
||||||
core.exportVariable('AWS_DEFAULT_REGION', region);
|
|
||||||
core.exportVariable('AWS_REGION', region);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function exportAccountId(maskAccountId, region) {
|
|
||||||
// Get the AWS account ID
|
|
||||||
const sts = getStsClient(region);
|
|
||||||
const identity = await sts.getCallerIdentity().promise();
|
|
||||||
const accountId = identity.Account;
|
|
||||||
if (!maskAccountId || maskAccountId.toLowerCase() == 'true') {
|
|
||||||
core.setSecret(accountId);
|
|
||||||
}
|
|
||||||
core.setOutput('aws-account-id', accountId);
|
|
||||||
return accountId;
|
|
||||||
}
|
|
||||||
|
|
||||||
function loadCredentials() {
|
|
||||||
// Force the SDK to re-resolve credentials with the default provider chain.
|
|
||||||
//
|
|
||||||
// This action typically sets credentials in the environment via environment variables.
|
|
||||||
// The SDK never refreshes those env-var-based credentials after initial load.
|
|
||||||
// In case there were already env-var creds set in the actions environment when this action
|
|
||||||
// loaded, this action needs to refresh the SDK creds after overwriting those environment variables.
|
|
||||||
//
|
|
||||||
// The credentials object needs to be entirely recreated (instead of simply refreshed),
|
|
||||||
// because the credential object type could change when this action writes env var creds.
|
|
||||||
// For example, the first load could return EC2 instance metadata credentials
|
|
||||||
// in a self-hosted runner, and the second load could return environment credentials
|
|
||||||
// from an assume-role call in this action.
|
|
||||||
aws.config.credentials = null;
|
|
||||||
|
|
||||||
return new Promise((resolve, reject) => {
|
|
||||||
aws.config.getCredentials((err) => {
|
|
||||||
if (err) {
|
|
||||||
reject(err);
|
|
||||||
}
|
|
||||||
resolve(aws.config.credentials);
|
|
||||||
})
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
async function validateCredentials(expectedAccessKeyId) {
|
|
||||||
let credentials;
|
|
||||||
try {
|
|
||||||
credentials = await loadCredentials();
|
|
||||||
|
|
||||||
if (!credentials.accessKeyId) {
|
|
||||||
throw new Error('Access key ID empty after loading credentials');
|
|
||||||
}
|
|
||||||
} catch (error) {
|
|
||||||
throw new Error(`Credentials could not be loaded, please check your action inputs: ${error.message}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
const actualAccessKeyId = credentials.accessKeyId;
|
|
||||||
|
|
||||||
if (expectedAccessKeyId && expectedAccessKeyId != actualAccessKeyId) {
|
|
||||||
throw new Error('Unexpected failure: Credentials loaded by the SDK do not match the access key ID configured by the action');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function getStsClient(region) {
|
|
||||||
return new aws.STS({
|
|
||||||
region,
|
|
||||||
stsRegionalEndpoints: 'regional',
|
|
||||||
customUserAgent: USER_AGENT
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
let defaultSleep = function (ms) {
|
|
||||||
return new Promise((resolve) => setTimeout(resolve, ms));
|
|
||||||
};
|
|
||||||
let sleep = defaultSleep;
|
|
||||||
|
|
||||||
// retryAndBackoff retries with exponential backoff the promise if the error isRetryable upto maxRetries time.
|
|
||||||
const retryAndBackoff = async (fn, isRetryable, retries = 0, maxRetries = 12, base = 50) => {
|
|
||||||
try {
|
|
||||||
return await fn();
|
|
||||||
} catch (err) {
|
|
||||||
if (!isRetryable) {
|
|
||||||
throw err;
|
|
||||||
}
|
|
||||||
// It's retryable, so sleep and retry.
|
|
||||||
await sleep(Math.random() * (Math.pow(2, retries) * base) );
|
|
||||||
retries += 1;
|
|
||||||
if (retries === maxRetries) {
|
|
||||||
throw err;
|
|
||||||
}
|
|
||||||
return await retryAndBackoff(fn, isRetryable, retries, maxRetries, base);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function configureProxy(proxyServer) {
|
|
||||||
const proxyFromEnv = process.env.HTTP_PROXY || process.env.http_proxy;
|
|
||||||
|
|
||||||
if (proxyFromEnv || proxyServer) {
|
|
||||||
let proxyToSet = null;
|
|
||||||
|
|
||||||
if (proxyServer){
|
|
||||||
console.log(`Setting proxy from actions input: ${proxyServer}`);
|
|
||||||
proxyToSet = proxyServer;
|
|
||||||
} else {
|
|
||||||
console.log(`Setting proxy from environment: ${proxyFromEnv}`);
|
|
||||||
proxyToSet = proxyFromEnv;
|
|
||||||
}
|
|
||||||
|
|
||||||
aws.config.update({
|
|
||||||
httpOptions: { agent: proxy(proxyToSet) }
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function run() {
|
|
||||||
try {
|
|
||||||
// Get inputs
|
|
||||||
const accessKeyId = core.getInput('aws-access-key-id', { required: false });
|
|
||||||
const audience = core.getInput('audience', { required: false });
|
|
||||||
const secretAccessKey = core.getInput('aws-secret-access-key', { required: false });
|
|
||||||
const region = core.getInput('aws-region', { required: true });
|
|
||||||
const sessionToken = core.getInput('aws-session-token', { required: false });
|
|
||||||
const maskAccountId = core.getInput('mask-aws-account-id', { required: false });
|
|
||||||
const roleToAssume = core.getInput('role-to-assume', {required: false});
|
|
||||||
const roleExternalId = core.getInput('role-external-id', { required: false });
|
|
||||||
let roleDurationSeconds = core.getInput('role-duration-seconds', {required: false})
|
|
||||||
|| (sessionToken && SESSION_ROLE_DURATION)
|
|
||||||
|| MAX_ACTION_RUNTIME;
|
|
||||||
const roleSessionName = core.getInput('role-session-name', { required: false }) || ROLE_SESSION_NAME;
|
|
||||||
const roleSkipSessionTaggingInput = core.getInput('role-skip-session-tagging', { required: false })|| 'false';
|
|
||||||
const roleSkipSessionTagging = roleSkipSessionTaggingInput.toLowerCase() === 'true';
|
|
||||||
const webIdentityTokenFile = core.getInput('web-identity-token-file', { required: false });
|
|
||||||
const proxyServer = core.getInput('http-proxy', { required: false });
|
|
||||||
|
|
||||||
if (!region.match(REGION_REGEX)) {
|
|
||||||
throw new Error(`Region is not valid: ${region}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
exportRegion(region);
|
|
||||||
|
|
||||||
// This wraps the logic for deciding if we should rely on the GH OIDC provider since we may need to reference
|
|
||||||
// the decision in a few differennt places. Consolidating it here makes the logic clearer elsewhere.
|
|
||||||
const useGitHubOIDCProvider = () => {
|
|
||||||
// The assumption here is that self-hosted runners won't be populating the `ACTIONS_ID_TOKEN_REQUEST_TOKEN`
|
|
||||||
// environment variable and they won't be providing a web idenity token file or access key either.
|
|
||||||
// V2 of the action might relax this a bit and create an explicit precedence for these so that customers
|
|
||||||
// can provide as much info as they want and we will follow the established credential loading precedence.
|
|
||||||
return roleToAssume && process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN && !accessKeyId && !webIdentityTokenFile
|
|
||||||
}
|
|
||||||
|
|
||||||
// Always export the source credentials and account ID.
|
|
||||||
// The STS client for calling AssumeRole pulls creds from the environment.
|
|
||||||
// Plus, in the assume role case, if the AssumeRole call fails, we want
|
|
||||||
// the source credentials and account ID to already be masked as secrets
|
|
||||||
// in any error messages.
|
|
||||||
if (accessKeyId) {
|
|
||||||
if (!secretAccessKey) {
|
|
||||||
throw new Error("'aws-secret-access-key' must be provided if 'aws-access-key-id' is provided");
|
|
||||||
}
|
|
||||||
|
|
||||||
exportCredentials({accessKeyId, secretAccessKey, sessionToken});
|
|
||||||
}
|
|
||||||
|
|
||||||
// Configures proxy
|
|
||||||
configureProxy(proxyServer);
|
|
||||||
|
|
||||||
// Attempt to load credentials from the GitHub OIDC provider.
|
|
||||||
// If a user provides an IAM Role Arn and DOESN'T provide an Access Key Id
|
|
||||||
// The only way to assume the role is via GitHub's OIDC provider.
|
|
||||||
let sourceAccountId;
|
|
||||||
let webIdentityToken;
|
|
||||||
if(useGitHubOIDCProvider()) {
|
|
||||||
webIdentityToken = await core.getIDToken(audience);
|
|
||||||
roleDurationSeconds = core.getInput('role-duration-seconds', {required: false}) || DEFAULT_ROLE_DURATION_FOR_OIDC_ROLES;
|
|
||||||
// We don't validate the credentials here because we don't have them yet when using OIDC.
|
|
||||||
} else {
|
|
||||||
// Regardless of whether any source credentials were provided as inputs,
|
|
||||||
// validate that the SDK can actually pick up credentials. This validates
|
|
||||||
// cases where this action is on a self-hosted runner that doesn't have credentials
|
|
||||||
// configured correctly, and cases where the user intended to provide input
|
|
||||||
// credentials but the secrets inputs resolved to empty strings.
|
|
||||||
await validateCredentials(accessKeyId);
|
|
||||||
|
|
||||||
sourceAccountId = await exportAccountId(maskAccountId, region);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Get role credentials if configured to do so
|
|
||||||
if (roleToAssume) {
|
|
||||||
const roleCredentials = await retryAndBackoff(
|
|
||||||
async () => { return await assumeRole({
|
|
||||||
sourceAccountId,
|
|
||||||
region,
|
|
||||||
roleToAssume,
|
|
||||||
roleExternalId,
|
|
||||||
roleDurationSeconds,
|
|
||||||
roleSessionName,
|
|
||||||
roleSkipSessionTagging,
|
|
||||||
webIdentityTokenFile,
|
|
||||||
webIdentityToken
|
|
||||||
}) }, true);
|
|
||||||
exportCredentials(roleCredentials);
|
|
||||||
// We need to validate the credentials in 2 of our use-cases
|
|
||||||
// First: self-hosted runners. If the GITHUB_ACTIONS environment variable
|
|
||||||
// is set to `true` then we are NOT in a self-hosted runner.
|
|
||||||
// Second: Customer provided credentials manually (IAM User keys stored in GH Secrets)
|
|
||||||
if (!process.env.GITHUB_ACTIONS || accessKeyId) {
|
|
||||||
await validateCredentials(roleCredentials.accessKeyId);
|
|
||||||
}
|
|
||||||
await exportAccountId(maskAccountId, region);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
catch (error) {
|
|
||||||
core.setFailed(error.message);
|
|
||||||
|
|
||||||
const showStackTrace = process.env.SHOW_STACK_TRACE;
|
|
||||||
|
|
||||||
if (showStackTrace === 'true') {
|
|
||||||
throw(error)
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
exports.withSleep = function (s) {
|
|
||||||
sleep = s;
|
|
||||||
};
|
|
||||||
exports.reset = function () {
|
|
||||||
sleep = defaultSleep;
|
|
||||||
};
|
|
||||||
|
|
||||||
exports.run = run
|
|
||||||
|
|
||||||
/* istanbul ignore next */
|
|
||||||
if (require.main === module) {
|
|
||||||
run();
|
|
||||||
}
|
|
||||||
-877
@@ -1,877 +0,0 @@
|
|||||||
const core = require('@actions/core');
|
|
||||||
const assert = require('assert');
|
|
||||||
const aws = require('aws-sdk');
|
|
||||||
const { run, withSleep, reset } = require('./index.js');
|
|
||||||
const proxy = require('https-proxy-agent');
|
|
||||||
|
|
||||||
jest.mock('@actions/core');
|
|
||||||
|
|
||||||
const FAKE_ACCESS_KEY_ID = 'MY-AWS-ACCESS-KEY-ID';
|
|
||||||
const FAKE_SECRET_ACCESS_KEY = 'MY-AWS-SECRET-ACCESS-KEY';
|
|
||||||
const FAKE_SESSION_TOKEN = 'MY-AWS-SESSION-TOKEN';
|
|
||||||
const FAKE_STS_ACCESS_KEY_ID = 'STS-AWS-ACCESS-KEY-ID';
|
|
||||||
const FAKE_STS_SECRET_ACCESS_KEY = 'STS-AWS-SECRET-ACCESS-KEY';
|
|
||||||
const FAKE_STS_SESSION_TOKEN = 'STS-AWS-SESSION-TOKEN';
|
|
||||||
const FAKE_REGION = 'fake-region-1';
|
|
||||||
const FAKE_ACCOUNT_ID = '123456789012';
|
|
||||||
const FAKE_ROLE_ACCOUNT_ID = '111111111111';
|
|
||||||
const ROLE_NAME = 'MY-ROLE';
|
|
||||||
const ROLE_ARN = 'arn:aws:iam::111111111111:role/MY-ROLE';
|
|
||||||
const ENVIRONMENT_VARIABLE_OVERRIDES = {
|
|
||||||
SHOW_STACK_TRACE: 'true',
|
|
||||||
GITHUB_REPOSITORY: 'MY-REPOSITORY-NAME',
|
|
||||||
GITHUB_WORKFLOW: 'MY-WORKFLOW-ID',
|
|
||||||
GITHUB_ACTION: 'MY-ACTION-NAME',
|
|
||||||
GITHUB_ACTOR: 'MY-USERNAME[bot]',
|
|
||||||
GITHUB_SHA: 'MY-COMMIT-ID',
|
|
||||||
GITHUB_REF: 'MY-BRANCH',
|
|
||||||
GITHUB_WORKSPACE: '/home/github'
|
|
||||||
};
|
|
||||||
const GITHUB_ACTOR_SANITIZED = 'MY-USERNAME_bot_'
|
|
||||||
|
|
||||||
function mockGetInput(requestResponse) {
|
|
||||||
return function (name, options) { // eslint-disable-line no-unused-vars
|
|
||||||
return requestResponse[name]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const CREDS_INPUTS = {
|
|
||||||
'aws-access-key-id': FAKE_ACCESS_KEY_ID,
|
|
||||||
'aws-secret-access-key': FAKE_SECRET_ACCESS_KEY
|
|
||||||
};
|
|
||||||
const DEFAULT_INPUTS = {
|
|
||||||
...CREDS_INPUTS,
|
|
||||||
'aws-session-token': FAKE_SESSION_TOKEN,
|
|
||||||
'aws-region': FAKE_REGION,
|
|
||||||
'mask-aws-account-id': 'TRUE'
|
|
||||||
};
|
|
||||||
const ASSUME_ROLE_INPUTS = {...CREDS_INPUTS, 'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION};
|
|
||||||
|
|
||||||
const mockStsCallerIdentity = jest.fn();
|
|
||||||
const mockStsAssumeRole = jest.fn();
|
|
||||||
const mockStsAssumeRoleWithWebIdentity = jest.fn();
|
|
||||||
|
|
||||||
jest.mock('aws-sdk', () => {
|
|
||||||
return {
|
|
||||||
config: {
|
|
||||||
getCredentials: jest.fn(),
|
|
||||||
update: jest.fn(),
|
|
||||||
},
|
|
||||||
STS: jest.fn(() => ({
|
|
||||||
getCallerIdentity: mockStsCallerIdentity,
|
|
||||||
assumeRole: mockStsAssumeRole,
|
|
||||||
assumeRoleWithWebIdentity: mockStsAssumeRoleWithWebIdentity
|
|
||||||
}))
|
|
||||||
};
|
|
||||||
});
|
|
||||||
|
|
||||||
jest.mock('fs', () => {
|
|
||||||
return {
|
|
||||||
promises: {
|
|
||||||
readFile: jest.fn(() => Promise.resolve('testpayload')),
|
|
||||||
},
|
|
||||||
existsSync: jest.fn(() => true)
|
|
||||||
};
|
|
||||||
});
|
|
||||||
|
|
||||||
|
|
||||||
jest.mock('axios', () => ({
|
|
||||||
get: jest.fn(() => Promise.resolve({ data: { value: "testtoken" }})),
|
|
||||||
}));
|
|
||||||
|
|
||||||
describe('Configure AWS Credentials', () => {
|
|
||||||
beforeEach(() => {
|
|
||||||
jest.resetModules();
|
|
||||||
process.env = { ...ENVIRONMENT_VARIABLE_OVERRIDES };
|
|
||||||
|
|
||||||
jest.clearAllMocks();
|
|
||||||
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(DEFAULT_INPUTS));
|
|
||||||
|
|
||||||
core.getIDToken = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(() => {
|
|
||||||
return "testtoken"
|
|
||||||
});
|
|
||||||
|
|
||||||
mockStsCallerIdentity.mockReset();
|
|
||||||
mockStsCallerIdentity
|
|
||||||
.mockReturnValueOnce({
|
|
||||||
promise() {
|
|
||||||
return Promise.resolve({ Account: FAKE_ACCOUNT_ID });
|
|
||||||
}
|
|
||||||
})
|
|
||||||
.mockReturnValueOnce({
|
|
||||||
promise() {
|
|
||||||
return Promise.resolve({ Account: FAKE_ROLE_ACCOUNT_ID });
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
aws.config.getCredentials.mockReset();
|
|
||||||
aws.config.getCredentials
|
|
||||||
.mockImplementationOnce(callback => {
|
|
||||||
if (!aws.config.credentials) {
|
|
||||||
aws.config.credentials = {
|
|
||||||
accessKeyId: FAKE_ACCESS_KEY_ID,
|
|
||||||
secretAccessKey: FAKE_SECRET_ACCESS_KEY
|
|
||||||
}
|
|
||||||
}
|
|
||||||
callback(null);
|
|
||||||
})
|
|
||||||
.mockImplementationOnce(callback => {
|
|
||||||
if (!aws.config.credentials) {
|
|
||||||
aws.config.credentials = {
|
|
||||||
accessKeyId: FAKE_STS_ACCESS_KEY_ID,
|
|
||||||
secretAccessKey: FAKE_STS_SECRET_ACCESS_KEY
|
|
||||||
}
|
|
||||||
}
|
|
||||||
callback(null);
|
|
||||||
});
|
|
||||||
|
|
||||||
aws.config.update.mockReset();
|
|
||||||
aws.config.update.mockImplementationOnce();
|
|
||||||
|
|
||||||
mockStsAssumeRole.mockImplementation(() => {
|
|
||||||
return {
|
|
||||||
promise() {
|
|
||||||
return Promise.resolve({
|
|
||||||
Credentials: {
|
|
||||||
AccessKeyId: FAKE_STS_ACCESS_KEY_ID,
|
|
||||||
SecretAccessKey: FAKE_STS_SECRET_ACCESS_KEY,
|
|
||||||
SessionToken: FAKE_STS_SESSION_TOKEN
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
mockStsAssumeRoleWithWebIdentity.mockImplementation(() => {
|
|
||||||
return {
|
|
||||||
promise() {
|
|
||||||
return Promise.resolve({
|
|
||||||
Credentials: {
|
|
||||||
AccessKeyId: FAKE_STS_ACCESS_KEY_ID,
|
|
||||||
SecretAccessKey: FAKE_STS_SECRET_ACCESS_KEY,
|
|
||||||
SessionToken: FAKE_STS_SESSION_TOKEN
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
withSleep(() => {
|
|
||||||
return Promise.resolve();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
afterEach(() => {
|
|
||||||
reset();
|
|
||||||
});
|
|
||||||
|
|
||||||
test('exports env vars', async () => {
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(5);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(4);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_ACCESS_KEY_ID', FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SECRET_ACCESS_KEY', FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', FAKE_SESSION_TOKEN);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_SESSION_TOKEN);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', FAKE_REGION);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', FAKE_REGION);
|
|
||||||
expect(core.setOutput).toHaveBeenCalledWith('aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCOUNT_ID);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('action fails when github env vars are not set', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
delete process.env.GITHUB_SHA;
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith('Missing required environment value. Are you running in GitHub Actions?');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('action does not require GITHUB_REF env var', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
delete process.env.GITHUB_REF;
|
|
||||||
|
|
||||||
await run();
|
|
||||||
});
|
|
||||||
|
|
||||||
test('hosted runners can pull creds from a self-hosted environment', async () => {
|
|
||||||
const mockInputs = {'aws-region': FAKE_REGION};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(2);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(1);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', FAKE_REGION);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', FAKE_REGION);
|
|
||||||
expect(core.setOutput).toHaveBeenCalledWith('aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCOUNT_ID);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('action with no accessible credentials fails', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
const mockInputs = {'aws-region': FAKE_REGION};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
aws.config.getCredentials.mockReset();
|
|
||||||
aws.config.getCredentials.mockImplementation(callback => {
|
|
||||||
callback(new Error('No credentials to load'));
|
|
||||||
});
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith("Credentials could not be loaded, please check your action inputs: No credentials to load");
|
|
||||||
});
|
|
||||||
|
|
||||||
test('action with empty credentials fails', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
const mockInputs = {'aws-region': FAKE_REGION};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
aws.config.getCredentials.mockReset();
|
|
||||||
aws.config.getCredentials.mockImplementation(callback => {
|
|
||||||
aws.config.credentials = {
|
|
||||||
accessKeyId: ''
|
|
||||||
}
|
|
||||||
callback(null);
|
|
||||||
});
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith("Credentials could not be loaded, please check your action inputs: Access key ID empty after loading credentials");
|
|
||||||
});
|
|
||||||
|
|
||||||
test('action fails when credentials are not set in the SDK correctly', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
aws.config.getCredentials.mockReset();
|
|
||||||
aws.config.getCredentials.mockImplementation(callback => {
|
|
||||||
aws.config.credentials = {
|
|
||||||
accessKeyId: FAKE_ACCESS_KEY_ID
|
|
||||||
}
|
|
||||||
callback(null);
|
|
||||||
});
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith("Unexpected failure: Credentials loaded by the SDK do not match the access key ID configured by the action");
|
|
||||||
});
|
|
||||||
|
|
||||||
test('session token is optional', async () => {
|
|
||||||
const mockInputs = {...CREDS_INPUTS, 'aws-region': 'eu-west-1'};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(4);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(3);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_ACCESS_KEY_ID', FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SECRET_ACCESS_KEY', FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', 'eu-west-1');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', 'eu-west-1');
|
|
||||||
expect(core.setOutput).toHaveBeenCalledWith('aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCOUNT_ID);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('existing env var creds are cleared', async () => {
|
|
||||||
const mockInputs = {...CREDS_INPUTS, 'aws-region': 'eu-west-1'};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
process.env.AWS_ACCESS_KEY_ID = 'foo';
|
|
||||||
process.env.AWS_SECRET_ACCESS_KEY = 'bar';
|
|
||||||
process.env.AWS_SESSION_TOKEN = 'helloworld';
|
|
||||||
aws.config.credentials = {
|
|
||||||
accessKeyId: 'foo',
|
|
||||||
secretAccessKey: 'bar',
|
|
||||||
sessionToken: 'helloworld'
|
|
||||||
};
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(5);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(3);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_ACCESS_KEY_ID', FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SECRET_ACCESS_KEY', FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', 'eu-west-1');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', 'eu-west-1');
|
|
||||||
expect(core.setOutput).toHaveBeenCalledWith('aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCOUNT_ID);
|
|
||||||
expect(aws.config.credentials.accessKeyId).toBe(FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(aws.config.credentials.secretAccessKey).toBe(FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(aws.config.credentials.sessionToken).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
test('validates region name', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
|
|
||||||
const mockInputs = {...CREDS_INPUTS, 'aws-region': '$AWS_REGION'};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith('Region is not valid: $AWS_REGION');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('throws error if access key id exists but missing secret access key', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
const inputsWIthoutSecretKey = {...ASSUME_ROLE_INPUTS}
|
|
||||||
inputsWIthoutSecretKey["aws-secret-access-key"] = undefined
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(inputsWIthoutSecretKey));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith("'aws-secret-access-key' must be provided if 'aws-access-key-id' is provided");
|
|
||||||
|
|
||||||
});
|
|
||||||
|
|
||||||
test('can opt out of masking account ID', async () => {
|
|
||||||
const mockInputs = {...CREDS_INPUTS, 'aws-region': 'us-east-1', 'mask-aws-account-id': 'false'};
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(mockInputs));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(0);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(4);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_ACCESS_KEY_ID', FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SECRET_ACCESS_KEY', FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledWith(FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_DEFAULT_REGION', 'us-east-1');
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_REGION', 'us-east-1');
|
|
||||||
expect(core.setOutput).toHaveBeenCalledWith('aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(2);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('error is caught by core.setFailed and caught', async () => {
|
|
||||||
process.env.SHOW_STACK_TRACE = 'false';
|
|
||||||
|
|
||||||
mockStsCallerIdentity.mockReset();
|
|
||||||
mockStsCallerIdentity.mockImplementation(() => {
|
|
||||||
throw new Error();
|
|
||||||
});
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(core.setFailed).toBeCalled();
|
|
||||||
});
|
|
||||||
|
|
||||||
test('error is caught by core.setFailed and passed', async () => {
|
|
||||||
|
|
||||||
mockStsCallerIdentity.mockReset();
|
|
||||||
mockStsCallerIdentity.mockImplementation(() => {
|
|
||||||
throw new Error();
|
|
||||||
});
|
|
||||||
|
|
||||||
await assert.rejects(() => run());
|
|
||||||
|
|
||||||
expect(core.setFailed).toBeCalled();
|
|
||||||
});
|
|
||||||
|
|
||||||
test('basic role assumption exports', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(1);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(7);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(7);
|
|
||||||
expect(core.setOutput).toHaveBeenCalledTimes(2);
|
|
||||||
|
|
||||||
// first the source credentials are exported and masked
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(1, FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(2, FAKE_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(3, FAKE_ACCOUNT_ID);
|
|
||||||
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(1, 'AWS_DEFAULT_REGION', FAKE_REGION);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(2, 'AWS_REGION', FAKE_REGION);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(3, 'AWS_ACCESS_KEY_ID', FAKE_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(4, 'AWS_SECRET_ACCESS_KEY', FAKE_SECRET_ACCESS_KEY);
|
|
||||||
|
|
||||||
expect(core.setOutput).toHaveBeenNthCalledWith(1, 'aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
|
|
||||||
// then the role credentials are exported and masked
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(4, FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(5, FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(6, FAKE_STS_SESSION_TOKEN);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(7, FAKE_ROLE_ACCOUNT_ID);
|
|
||||||
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(5, 'AWS_ACCESS_KEY_ID', FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(6, 'AWS_SECRET_ACCESS_KEY', FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(7, 'AWS_SESSION_TOKEN', FAKE_STS_SESSION_TOKEN);
|
|
||||||
|
|
||||||
expect(core.setOutput).toHaveBeenNthCalledWith(2, 'aws-account-id', FAKE_ROLE_ACCOUNT_ID);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('assume role can pull source credentials from self-hosted environment', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledTimes(1);
|
|
||||||
expect(core.exportVariable).toHaveBeenCalledTimes(5);
|
|
||||||
expect(core.setSecret).toHaveBeenCalledTimes(5);
|
|
||||||
expect(core.setOutput).toHaveBeenCalledTimes(2);
|
|
||||||
|
|
||||||
// first the source account is exported and masked
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(1, FAKE_ACCOUNT_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(1, 'AWS_DEFAULT_REGION', FAKE_REGION);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(2, 'AWS_REGION', FAKE_REGION);
|
|
||||||
expect(core.setOutput).toHaveBeenNthCalledWith(1, 'aws-account-id', FAKE_ACCOUNT_ID);
|
|
||||||
|
|
||||||
// then the role credentials are exported and masked
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(2, FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(3, FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(4, FAKE_STS_SESSION_TOKEN);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(5, FAKE_ROLE_ACCOUNT_ID);
|
|
||||||
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(3, 'AWS_ACCESS_KEY_ID', FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(4, 'AWS_SECRET_ACCESS_KEY', FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.exportVariable).toHaveBeenNthCalledWith(5, 'AWS_SESSION_TOKEN', FAKE_STS_SESSION_TOKEN);
|
|
||||||
|
|
||||||
expect(core.setOutput).toHaveBeenNthCalledWith(2, 'aws-account-id', FAKE_ROLE_ACCOUNT_ID);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role assumption tags', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role assumption duration provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'role-duration-seconds': 5}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 5,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role assumption session name provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'role-session-name': 'MySessionName'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'MySessionName',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('sets durationSeconds to one hour when session token provided and no duration is provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'aws-session-token': FAKE_SESSION_TOKEN}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('sets durationSeconds to one 6 hours no session token or duration is provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role name provided instead of ARN', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...CREDS_INPUTS, 'role-to-assume': ROLE_NAME, 'aws-region': FAKE_REGION}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: 'arn:aws:iam::123456789012:role/MY-ROLE',
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('web identity token file provided with absolute path', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION, 'web-identity-token-file': '/fake/token/file'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRoleWithWebIdentity).toHaveBeenCalledWith({
|
|
||||||
RoleArn: 'arn:aws:iam::111111111111:role/MY-ROLE',
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
WebIdentityToken: 'testpayload'
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('web identity token file provided with relative path', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION, 'web-identity-token-file': 'fake/token/file'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRoleWithWebIdentity).toHaveBeenCalledWith({
|
|
||||||
RoleArn: 'arn:aws:iam::111111111111:role/MY-ROLE',
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
WebIdentityToken: 'testpayload'
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('only role arn and region provided to use GH OIDC Token', async () => {
|
|
||||||
process.env.GITHUB_ACTIONS = 'true';
|
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'test-token';
|
|
||||||
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRoleWithWebIdentity).toHaveBeenCalledWith({
|
|
||||||
RoleArn: 'arn:aws:iam::111111111111:role/MY-ROLE',
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 3600,
|
|
||||||
WebIdentityToken: 'testtoken'
|
|
||||||
});
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(1, FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(2, FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(3, FAKE_STS_SESSION_TOKEN);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('GH OIDC With custom role duration', async () => {
|
|
||||||
const CUSTOM_ROLE_DURATION = 1234;
|
|
||||||
process.env.GITHUB_ACTIONS = 'true';
|
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'test-token';
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION, 'role-duration-seconds': CUSTOM_ROLE_DURATION}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRoleWithWebIdentity).toHaveBeenCalledWith({
|
|
||||||
RoleArn: 'arn:aws:iam::111111111111:role/MY-ROLE',
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: CUSTOM_ROLE_DURATION,
|
|
||||||
WebIdentityToken: 'testtoken'
|
|
||||||
});
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(1, FAKE_STS_ACCESS_KEY_ID);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(2, FAKE_STS_SECRET_ACCESS_KEY);
|
|
||||||
expect(core.setSecret).toHaveBeenNthCalledWith(3, FAKE_STS_SESSION_TOKEN);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role assumption fails after maximun trials using OIDC Provider', async () => {
|
|
||||||
process.env.GITHUB_ACTIONS = 'true';
|
|
||||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'test-token';
|
|
||||||
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({'role-to-assume': ROLE_ARN, 'aws-region': FAKE_REGION}));
|
|
||||||
|
|
||||||
mockStsAssumeRoleWithWebIdentity.mockReset();
|
|
||||||
mockStsAssumeRoleWithWebIdentity.mockImplementation(() => {
|
|
||||||
throw new Error();
|
|
||||||
});
|
|
||||||
|
|
||||||
await assert.rejects(() => run());
|
|
||||||
expect(mockStsAssumeRoleWithWebIdentity).toHaveBeenCalledTimes(12)
|
|
||||||
});
|
|
||||||
|
|
||||||
test('role external ID provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'role-external-id': 'abcdef'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
],
|
|
||||||
ExternalId: 'abcdef'
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('workflow name sanitized in role assumption tags', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
|
|
||||||
process.env = {...process.env, GITHUB_WORKFLOW: 'Workflow!"#$%&\'()*+, -./:;<=>?@[]^_`{|}~🙂💥🍌1yFvMOeD3ZHYsHrGjCceOboMYzBPo0CRNFdcsVRG6UgR3A912a8KfcBtEVvkAS7kRBq80umGff8mux5IN1y55HQWPNBNyaruuVr4islFXte4FDQZexGJRUSMyHQpxJ8OmZnET84oDmbvmIjgxI6IBrdihX9PHMapT4gQvRYnLqNiKb18rEMWDNoZRy51UPX5sWK2GKPipgKSO9kqLckZai9D2AN2RlWCxtMqChNtxuxjqeqhoQZo0oaq39sjcRZgAAAAAAA'};
|
|
||||||
|
|
||||||
const sanitizedWorkflowName = 'Workflow__________+_ -./:;<=>?@____________1yFvMOeD3ZHYsHrGjCceOboMYzBPo0CRNFdcsVRG6UgR3A912a8KfcBtEVvkAS7kRBq80umGff8mux5IN1y55HQWPNBNyaruuVr4islFXte4FDQZexGJRUSMyHQpxJ8OmZnET84oDmbvmIjgxI6IBrdihX9PHMapT4gQvRYnLqNiKb18rEMWDNoZRy51UPX5sWK2GKPipgKSO9kqLckZa'
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 6 * 3600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: sanitizedWorkflowName},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('skip tagging provided as true', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'role-skip-session-tagging': 'true'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 21600,
|
|
||||||
Tags: undefined
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('skip tagging provided as false', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS, 'role-skip-session-tagging': 'false'}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 21600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('skip tagging not provided', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput({...ASSUME_ROLE_INPUTS}));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
expect(mockStsAssumeRole).toHaveBeenCalledWith({
|
|
||||||
RoleArn: ROLE_ARN,
|
|
||||||
RoleSessionName: 'GitHubActions',
|
|
||||||
DurationSeconds: 21600,
|
|
||||||
Tags: [
|
|
||||||
{Key: 'GitHub', Value: 'Actions'},
|
|
||||||
{Key: 'Repository', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REPOSITORY},
|
|
||||||
{Key: 'Workflow', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_WORKFLOW},
|
|
||||||
{Key: 'Action', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_ACTION},
|
|
||||||
{Key: 'Actor', Value: GITHUB_ACTOR_SANITIZED},
|
|
||||||
{Key: 'Commit', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_SHA},
|
|
||||||
{Key: 'Branch', Value: ENVIRONMENT_VARIABLE_OVERRIDES.GITHUB_REF},
|
|
||||||
]
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
test('masks variables before exporting', async () => {
|
|
||||||
let maskedValues = [];
|
|
||||||
const publicFields = ['AWS_REGION', 'AWS_DEFAULT_REGION'];
|
|
||||||
core.setSecret.mockReset();
|
|
||||||
core.setSecret.mockImplementation((secret) => {
|
|
||||||
maskedValues.push(secret);
|
|
||||||
});
|
|
||||||
|
|
||||||
core.exportVariable.mockReset();
|
|
||||||
core.exportVariable.mockImplementation((name, value) => {
|
|
||||||
if (!maskedValues.includes(value) && !publicFields.includes(name)) {
|
|
||||||
throw new Error(value + " for variable " + name + " is not masked yet!");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
|
||||||
|
|
||||||
await run();
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('proxy settings', () => {
|
|
||||||
|
|
||||||
test('setting proxy with actions input', async () => {
|
|
||||||
const EXPECTED_PROXY = 'http://test.me'
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(
|
|
||||||
mockGetInput({ ...DEFAULT_INPUTS, 'http-proxy': EXPECTED_PROXY })
|
|
||||||
);
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(aws.config.update).toHaveBeenCalledTimes(1);
|
|
||||||
expect(aws.config.update).toHaveBeenCalledWith({
|
|
||||||
httpOptions: { agent: proxy(EXPECTED_PROXY) }
|
|
||||||
});
|
|
||||||
});
|
|
||||||
test('setting proxy from environment vars', async () => {
|
|
||||||
const EXPECTED_PROXY = 'http://test.me'
|
|
||||||
process.env.HTTP_PROXY = EXPECTED_PROXY;
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(
|
|
||||||
mockGetInput({ ...DEFAULT_INPUTS })
|
|
||||||
);
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(aws.config.update).toHaveBeenCalledTimes(1);
|
|
||||||
expect(aws.config.update).toHaveBeenCalledWith({
|
|
||||||
httpOptions: { agent: proxy(EXPECTED_PROXY) }
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
test('setting proxy - prefer action input', async () => {
|
|
||||||
const EXPECTED_PROXY = 'http://test.me'
|
|
||||||
const FALSE_PROXY = 'http://env.me'
|
|
||||||
process.env.HTTP_PROXY = FALSE_PROXY;
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(
|
|
||||||
mockGetInput({ ...DEFAULT_INPUTS, 'http-proxy': EXPECTED_PROXY })
|
|
||||||
);
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(aws.config.update).toHaveBeenCalledTimes(1);
|
|
||||||
expect(aws.config.update).toHaveBeenCalledWith({
|
|
||||||
httpOptions: { agent: proxy(EXPECTED_PROXY) }
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
test('ignoring proxy - without anything set', async () => {
|
|
||||||
core.getInput = jest
|
|
||||||
.fn()
|
|
||||||
.mockImplementation(
|
|
||||||
mockGetInput({ ...DEFAULT_INPUTS})
|
|
||||||
);
|
|
||||||
|
|
||||||
await run();
|
|
||||||
|
|
||||||
expect(aws.config.update).toHaveBeenCalledTimes(0);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
Generated
-4727
File diff suppressed because it is too large
Load Diff
@@ -1,38 +0,0 @@
|
|||||||
{
|
|
||||||
"name": "aws-actions-configure-aws-credentials",
|
|
||||||
"version": "2.0.0",
|
|
||||||
"description": "Configure AWS Credentials",
|
|
||||||
"main": "index.js",
|
|
||||||
"scripts": {
|
|
||||||
"lint": "eslint **.js",
|
|
||||||
"package": "ncc build index.js -o dist && ncc build cleanup.js -o dist/cleanup",
|
|
||||||
"test": "npm run lint && jest --coverage --verbose"
|
|
||||||
},
|
|
||||||
"repository": {
|
|
||||||
"type": "git",
|
|
||||||
"url": "git+https://github.com/aws-actions/configure-aws-credentials.git"
|
|
||||||
},
|
|
||||||
"keywords": [
|
|
||||||
"AWS",
|
|
||||||
"GitHub",
|
|
||||||
"Actions",
|
|
||||||
"JavaScript"
|
|
||||||
],
|
|
||||||
"author": "AWS",
|
|
||||||
"license": "MIT",
|
|
||||||
"bugs": {
|
|
||||||
"url": "https://github.com/aws-actions/configure-aws-credentials/issues"
|
|
||||||
},
|
|
||||||
"homepage": "https://github.com/aws-actions/configure-aws-credentials#readme",
|
|
||||||
"dependencies": {
|
|
||||||
"@actions/core": "^1.10.0",
|
|
||||||
"aws-sdk": "^2.1329.0",
|
|
||||||
"axios": "^1.3.4",
|
|
||||||
"https-proxy-agent": "^5.0.1"
|
|
||||||
},
|
|
||||||
"devDependencies": {
|
|
||||||
"@vercel/ncc": "^0.36.1",
|
|
||||||
"eslint": "^8.35.0",
|
|
||||||
"jest": "^29.4.3"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
Executable
+24
@@ -0,0 +1,24 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -ex
|
||||||
|
|
||||||
|
# Update the integ test action workflow file with the commit ID to test
|
||||||
|
sed -i "s|aws-actions/configure-aws-credentials@v1|aws-actions/configure-aws-credentials@$GIT_COMMIT_ID|g" test-workflow.yml
|
||||||
|
sed -i "s|BUILD_ID|$CODEBUILD_BUILD_ID|g" test-workflow.yml
|
||||||
|
|
||||||
|
mkdir -p .github/workflows
|
||||||
|
cp test-workflow.yml .github/workflows
|
||||||
|
git add .github/workflows
|
||||||
|
git commit -m "Test commit $GIT_COMMIT_ID"
|
||||||
|
|
||||||
|
# Trigger the action workflow
|
||||||
|
git push origin HEAD:integ-tests
|
||||||
|
|
||||||
|
# Validate that the action workflow succeeds
|
||||||
|
# Exit codes: success = 0; failure = 1; pending = 2; no status = 3
|
||||||
|
while hub ci-status; [ $? -ge 2 ]; do
|
||||||
|
echo "waiting for test workflow to complete..."
|
||||||
|
sleep 5
|
||||||
|
done
|
||||||
|
|
||||||
|
hub ci-status
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- integ-tests
|
||||||
|
|
||||||
|
name: Integration Test
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
name: Deploy
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Print current build ID
|
||||||
|
run: |
|
||||||
|
echo Integration test run: BUILD_ID
|
||||||
|
|
||||||
|
- name: Configure AWS credentials
|
||||||
|
uses: aws-actions/configure-aws-credentials@v1
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "user/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
|
|
||||||
|
- name: Configure AWS credentials from role
|
||||||
|
uses: aws-actions/configure-aws-credentials@v1
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
role-to-assume: github-actions-configure-aws-credentials-integ-tests
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: github-actions-integ-test
|
||||||
|
role-external-id: ${{ secrets.INTEG_TEST_ROLE_EXTERNAL_ID }}
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials from role
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "role/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
|
|
||||||
|
- name: Configure AWS credentials from role again
|
||||||
|
uses: aws-actions/configure-aws-credentials@v1
|
||||||
|
with:
|
||||||
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
|
aws-region: us-east-2
|
||||||
|
role-to-assume: github-actions-configure-aws-credentials-integ-tests
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: github-actions-integ-test
|
||||||
|
role-external-id: ${{ secrets.INTEG_TEST_ROLE_EXTERNAL_ID }}
|
||||||
|
|
||||||
|
- name: Test environment is configured with AWS credentials from role
|
||||||
|
run: |
|
||||||
|
aws sts get-caller-identity --query Arn | grep "role/github-actions-configure-aws-credentials-integ-tests" > /dev/null
|
||||||
Reference in New Issue
Block a user