mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-09-01 05:45:06 +09:00
Compare commits
35 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 8c3f20df09 | |||
| 50ac8dd1e1 | |||
| a2593d09d1 | |||
| 7a8dec84bd | |||
| 2b89f8a0da | |||
| 6488aec6e7 | |||
| 856a411d27 | |||
| 7e7ee94419 | |||
| 8ad39aa824 | |||
| 2014030530 | |||
| 3aeb7ba662 | |||
| 3994f1aeae | |||
| a3412312b9 | |||
| ef2571b57d | |||
| 8e373defe9 | |||
| 9555344752 | |||
| 72f2c7b9a3 | |||
| b0cb02aa90 | |||
| 7bac5f98a7 | |||
| 922470e4ee | |||
| d3c2317d0a | |||
| f0ede74cf3 | |||
| 8afcd6259e | |||
| 84a8fd5e77 | |||
| d78f55b1db | |||
| 6c962b9fd3 | |||
| 14b6c355ca | |||
| 22617f9706 | |||
| 622237c36a | |||
| 014a5f9adc | |||
| 44cffa5fa8 | |||
| 19f0360930 | |||
| fd194eccd1 | |||
| 7f32242eff | |||
| 7e430f7278 |
@@ -0,0 +1,51 @@
|
|||||||
|
name: "Close Stale Issues"
|
||||||
|
|
||||||
|
# Controls when the action will run.
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 */4 * * *"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
cleanup:
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Stale issue job
|
||||||
|
steps:
|
||||||
|
- uses: aws-actions/stale-issue-cleanup@v5
|
||||||
|
with:
|
||||||
|
# Setting messages to an empty string will cause the automation to skip
|
||||||
|
# that category
|
||||||
|
ancient-issue-message: This issue has not received any attention in 1 year. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
stale-issue-message: This issue has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
stale-pr-message: This PR has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
|
||||||
|
# These labels are required
|
||||||
|
stale-issue-label: closing-soon
|
||||||
|
exempt-issue-labels: no-autoclose
|
||||||
|
stale-pr-label: closing-soon
|
||||||
|
exempt-pr-labels: no-autoclose
|
||||||
|
response-requested-label: response-requested
|
||||||
|
|
||||||
|
# Don't set closed-for-staleness label to skip closing very old issues
|
||||||
|
# regardless of label
|
||||||
|
closed-for-staleness-label: closed-for-staleness
|
||||||
|
|
||||||
|
# Issue timing
|
||||||
|
days-before-stale: 5
|
||||||
|
days-before-close: 2
|
||||||
|
days-before-ancient: 36500
|
||||||
|
|
||||||
|
# If you don't want to mark a issue as being ancient based on a
|
||||||
|
# threshold of "upvotes", you can set this here. An "upvote" is
|
||||||
|
# the total number of +1, heart, hooray, and rocket reactions
|
||||||
|
# on an issue.
|
||||||
|
minimum-upvotes-to-exempt: 5
|
||||||
|
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
loglevel: DEBUG
|
||||||
|
# Set dry-run to true to not perform label or close actions.
|
||||||
|
dry-run: false
|
||||||
@@ -13,7 +13,5 @@ jobs:
|
|||||||
# These inputs are both required
|
# These inputs are both required
|
||||||
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
||||||
message: |
|
message: |
|
||||||
** Note **
|
|
||||||
Comments on closed issues are hard for our team to see.
|
Comments on closed issues are hard for our team to see.
|
||||||
If you need more assistance, please either tag a team member or open a new issue that references this one.
|
If you need more assistance, please either tag a team member or open a new issue that references this one.
|
||||||
If you wish to keep having a conversation with other community members under this issue feel free to do so.
|
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ on:
|
|||||||
- main
|
- main
|
||||||
paths-ignore:
|
paths-ignore:
|
||||||
- 'dist/**'
|
- 'dist/**'
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
package:
|
package:
|
||||||
@@ -27,10 +28,10 @@ jobs:
|
|||||||
npm test
|
npm test
|
||||||
npm run package
|
npm run package
|
||||||
- name: Configure AWS credentials
|
- name: Configure AWS credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-west-2
|
aws-region: us-west-2
|
||||||
role-to-assume: ${{ secrets.SECRETS_AWS_ROLE_TO_ASSUME }}
|
role-to-assume: ${{ secrets.SECRETS_AWS_PACKAGING_ROLE_TO_ASSUME }}
|
||||||
role-duration-seconds: 900
|
role-duration-seconds: 900
|
||||||
role-session-name: SecretsManagerFetch
|
role-session-name: SecretsManagerFetch
|
||||||
- name: Get bot user token
|
- name: Get bot user token
|
||||||
@@ -38,7 +39,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
parse-json-secrets: true
|
parse-json-secrets: true
|
||||||
secret-ids: |
|
secret-ids: |
|
||||||
OSDS,arn:aws:secretsmanager:us-west-2:294535624312:secret:github-aws-sdk-osds-automation-ZHNalp
|
OSDS,arn:aws:secretsmanager:us-west-2:206735643321:secret:github-aws-sdk-osds-automation-gebs9n
|
||||||
- name: Commit
|
- name: Commit
|
||||||
run: |
|
run: |
|
||||||
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
name: Run tests
|
name: Run Integ tests
|
||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -12,7 +12,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run OIDC integ tests
|
name: Run OIDC integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -27,12 +26,37 @@ jobs:
|
|||||||
role-duration-seconds: 900
|
role-duration-seconds: 900
|
||||||
role-session-name: IntegOidcAssumeRole
|
role-session-name: IntegOidcAssumeRole
|
||||||
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
||||||
|
integ-oidc-env:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
id-token: write
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
|
name: Run OIDC integ tests with existing invalid env vars
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
env:
|
||||||
|
AWS_ACCESS_KEY_ID: dummyaccesskeyid
|
||||||
|
AWS_SECRET_ACCESS_KEY: dummysecretkey
|
||||||
|
AWS_SESSION_TOKEN: dummytoken
|
||||||
|
timeout-minutes: 30
|
||||||
|
steps:
|
||||||
|
- name: "Checkout repository"
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
- name: Integ test for OIDC
|
||||||
|
uses: ./
|
||||||
|
with:
|
||||||
|
aws-region: us-west-2
|
||||||
|
role-to-assume: ${{ secrets.SECRETS_OIDC_AWS_ROLE_TO_ASSUME }}
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: IntegOidcAssumeRole
|
||||||
|
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
||||||
integ-access-keys:
|
integ-access-keys:
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run access key integ tests
|
name: Run access key integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -53,7 +77,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run access key from env integ tests
|
name: Run access key from env integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -75,7 +98,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run IAM User integ tests
|
name: Run IAM User integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
|
|||||||
@@ -9,7 +9,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [windows-latest, ubuntu-latest, macos-latest]
|
os: [windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run unit tests
|
name: Run unit tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
@@ -19,7 +18,7 @@ jobs:
|
|||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v3
|
uses: actions/setup-node@v3
|
||||||
with:
|
with:
|
||||||
node-version: ${{ matrix.node }}
|
node-version: 20
|
||||||
- name: "Install dependencies"
|
- name: "Install dependencies"
|
||||||
uses: bahmutov/npm-install@v1
|
uses: bahmutov/npm-install@v1
|
||||||
- name: "Run tests"
|
- name: "Run tests"
|
||||||
@@ -34,7 +33,7 @@ jobs:
|
|||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v3
|
uses: actions/setup-node@v3
|
||||||
with:
|
with:
|
||||||
node-version: 16
|
node-version: 20
|
||||||
- name: "Install dependencies"
|
- name: "Install dependencies"
|
||||||
uses: bahmutov/npm-install@v1
|
uses: bahmutov/npm-install@v1
|
||||||
- name: "Lint code"
|
- name: "Lint code"
|
||||||
|
|||||||
+30
-4
@@ -1,8 +1,18 @@
|
|||||||
queue_rules:
|
queue_rules:
|
||||||
- name: default
|
- name: default
|
||||||
conditions:
|
conditions:
|
||||||
# Conditions to get out of the queue (= merged)
|
# Conditions to merge a queued PR
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest, 14)
|
||||||
|
- check-success=Run unit tests (windows-latest, 16)
|
||||||
|
- check-success=Run unit tests (windows-latest, 18)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 14)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 16)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 18)
|
||||||
|
- check-success=Run unit tests (macos-latest, 14)
|
||||||
|
- check-success=Run unit tests (macos-latest, 16)
|
||||||
|
- check-success=Run unit tests (macos-latest, 18)
|
||||||
|
- "#approved-reviews-by>=1"
|
||||||
|
- -approved-reviews-by~=author
|
||||||
|
|
||||||
pull_request_rules:
|
pull_request_rules:
|
||||||
- name: Automatically merge on CI success and review approval
|
- name: Automatically merge on CI success and review approval
|
||||||
@@ -10,7 +20,15 @@ pull_request_rules:
|
|||||||
- base~=main|integ-tests
|
- base~=main|integ-tests
|
||||||
- "#approved-reviews-by>=1"
|
- "#approved-reviews-by>=1"
|
||||||
- -approved-reviews-by~=author
|
- -approved-reviews-by~=author
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest, 14)
|
||||||
|
- check-success=Run unit tests (windows-latest, 16)
|
||||||
|
- check-success=Run unit tests (windows-latest, 18)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 14)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 16)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 18)
|
||||||
|
- check-success=Run unit tests (macos-latest, 14)
|
||||||
|
- check-success=Run unit tests (macos-latest, 16)
|
||||||
|
- check-success=Run unit tests (macos-latest, 18)
|
||||||
- label!=work-in-progress
|
- label!=work-in-progress
|
||||||
- -title~=(WIP|wip)
|
- -title~=(WIP|wip)
|
||||||
- -merged
|
- -merged
|
||||||
@@ -25,7 +43,15 @@ pull_request_rules:
|
|||||||
conditions:
|
conditions:
|
||||||
- base~=main
|
- base~=main
|
||||||
- author=dependabot[bot]
|
- author=dependabot[bot]
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest, 14)
|
||||||
|
- check-success=Run unit tests (windows-latest, 16)
|
||||||
|
- check-success=Run unit tests (windows-latest, 18)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 14)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 16)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest, 18)
|
||||||
|
- check-success=Run unit tests (macos-latest, 14)
|
||||||
|
- check-success=Run unit tests (macos-latest, 16)
|
||||||
|
- check-success=Run unit tests (macos-latest, 18)
|
||||||
- -title~=(WIP|wip)
|
- -title~=(WIP|wip)
|
||||||
- -label~=(blocked|do-not-merge)
|
- -label~=(blocked|do-not-merge)
|
||||||
- -merged
|
- -merged
|
||||||
|
|||||||
@@ -2,6 +2,15 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
||||||
|
|
||||||
|
## [4.0.0](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.2...v4.0.0) (2023-09-11)
|
||||||
|
|
||||||
|
* Upgraded runtime to `node20` from `node16`
|
||||||
|
|
||||||
|
## [3.0.2](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.1...v3.0.2) (2023-09-07)
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
* fixes #817 #819: validation logic throwing unwanted errors [d78f55b](https://github.com/aws-actions/configure-aws-credentials/commit/d78f55b1db65186cb251a8504ae9527af06fc5fd)
|
||||||
|
|
||||||
## [3.0.1](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.0...v3.0.1) (2023-08-24)
|
## [3.0.1](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.0...v3.0.1) (2023-08-24)
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
|
|||||||
@@ -7,7 +7,15 @@ calls.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
### News
|
### Recent News
|
||||||
|
|
||||||
|
#### v4 Announcement (9/11/23)
|
||||||
|
|
||||||
|
We have just released `v4` of Configure AWS Credentials. The only thing that
|
||||||
|
changed from `v3` is that the action now runs on `node20` instead of `node16`.
|
||||||
|
You can still see the `v3` announcement below, as it is still recent.
|
||||||
|
|
||||||
|
#### v3 Announcement (8/23/23)
|
||||||
|
|
||||||
We have recently released `v3` of Configure AWS Credentials! With this new
|
We have recently released `v3` of Configure AWS Credentials! With this new
|
||||||
release we have migrated the code to TypeScript, and have also migrated away
|
release we have migrated the code to TypeScript, and have also migrated away
|
||||||
@@ -24,7 +32,7 @@ changes should be backwards compatible with your existing workflows.
|
|||||||
_all_ use cases. This is changed from 6 hours in `v2`. You can adjust this value
|
_all_ use cases. This is changed from 6 hours in `v2`. You can adjust this value
|
||||||
with the `role-duration-seconds` input.
|
with the `role-duration-seconds` input.
|
||||||
- By default, your account ID will not be masked in workflow logs. This was
|
- By default, your account ID will not be masked in workflow logs. This was
|
||||||
changed from being masked by default in the previous version. AWS does consider
|
changed from being masked by default in the previous version. AWS does not consider
|
||||||
account IDs as sensitive information, so this change reflects that stance. You
|
account IDs as sensitive information, so this change reflects that stance. You
|
||||||
can revert to the old default and mask your account ID in workflow logs by
|
can revert to the old default and mask your account ID in workflow logs by
|
||||||
setting the `mask-aws-account-id` input to `true`.
|
setting the `mask-aws-account-id` input to `true`.
|
||||||
@@ -46,7 +54,7 @@ variables are interfering with the action. You can enable this by setting the
|
|||||||
**Bug fixes**
|
**Bug fixes**
|
||||||
|
|
||||||
You can find a list of bugs that have been fixed in v3 in the
|
You can find a list of bugs that have been fixed in v3 in the
|
||||||
[changelog](./changelog.md).
|
[changelog](./CHANGELOG.md).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -82,7 +90,7 @@ To do that, you would add the following step to your workflow:
|
|||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
@@ -111,7 +119,7 @@ jobs:
|
|||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v3
|
||||||
- name: Configure AWS credentials from Test account
|
- name: Configure AWS credentials from Test account
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::111111111111:role/my-github-actions-role-test
|
role-to-assume: arn:aws:iam::111111111111:role/my-github-actions-role-test
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
@@ -119,7 +127,7 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
aws s3 sync . s3://my-s3-test-website-bucket
|
aws s3 sync . s3://my-s3-test-website-bucket
|
||||||
- name: Configure AWS credentials from Production account
|
- name: Configure AWS credentials from Production account
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::222222222222:role/my-github-actions-role-prod
|
role-to-assume: arn:aws:iam::222222222222:role/my-github-actions-role-prod
|
||||||
aws-region: us-west-2
|
aws-region: us-west-2
|
||||||
@@ -209,7 +217,7 @@ within the Action. See [issue 419](https://github.com/aws-actions/configure-aws-
|
|||||||
You can skip this session tagging by providing
|
You can skip this session tagging by providing
|
||||||
`role-skip-session-tagging` as true in the action's inputs:
|
`role-skip-session-tagging` as true in the action's inputs:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-skip-session-tagging: true
|
role-skip-session-tagging: true
|
||||||
```
|
```
|
||||||
@@ -220,13 +228,13 @@ You can skip this session tagging by providing
|
|||||||
An IAM policy in stringified JSON format that you want to use as an inline session policy.
|
An IAM policy in stringified JSON format that you want to use as an inline session policy.
|
||||||
Depending on preferences, the JSON could be written on a single line like this:
|
Depending on preferences, the JSON could be written on a single line like this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
|
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
|
||||||
```
|
```
|
||||||
Or we can have a nicely formatted JSON as well:
|
Or we can have a nicely formatted JSON as well:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
inline-session-policy: >-
|
inline-session-policy: >-
|
||||||
{
|
{
|
||||||
@@ -246,13 +254,13 @@ Or we can have a nicely formatted JSON as well:
|
|||||||
The Amazon Resource Names (ARNs) of the IAM managed policies that you want to use as managed session policies.
|
The Amazon Resource Names (ARNs) of the IAM managed policies that you want to use as managed session policies.
|
||||||
The policies must exist in the same account as the role. You can pass a single managed policy like this:
|
The policies must exist in the same account as the role. You can pass a single managed policy like this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
||||||
```
|
```
|
||||||
And we can pass multiple managed policies likes this:
|
And we can pass multiple managed policies likes this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
managed-session-policies: |
|
managed-session-policies: |
|
||||||
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
||||||
@@ -291,11 +299,11 @@ We recommend using [GitHub's OIDC provider](https://docs.github.com/en/actions/d
|
|||||||
|
|
||||||
### Audience
|
### Audience
|
||||||
|
|
||||||
When the JWT is created, an audience needs to be specified. By default, the audience is `sts.amazon.com` and this will work for most cases. Changing the default audience may be necessary when using non-default AWS partitions. You can specify the audience through the `audience` input:
|
When the JWT is created, an audience needs to be specified. By default, the audience is `sts.amazonaws.com` and this will work for most cases. Changing the default audience may be necessary when using non-default AWS partitions. You can specify the audience through the `audience` input:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials for China region audience
|
- name: Configure AWS Credentials for China region audience
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
audience: sts.amazonaws.com.cn
|
audience: sts.amazonaws.com.cn
|
||||||
aws-region: us-east-3
|
aws-region: us-east-3
|
||||||
@@ -407,7 +415,7 @@ You can use this action to simply configure the region and account ID in the
|
|||||||
environment, and then use the runner's credentials for all AWS API calls made by
|
environment, and then use the runner's credentials for all AWS API calls made by
|
||||||
your Actions workflow:
|
your Actions workflow:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
```
|
```
|
||||||
@@ -417,7 +425,7 @@ APIs called by your Actions workflow.
|
|||||||
Or, you can use this action to assume a role, and then use the role credentials
|
Or, you can use this action to assume a role, and then use the role credentials
|
||||||
for all AWS API calls made by your Actions workflow:
|
for all AWS API calls made by your Actions workflow:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: my-github-actions-role
|
role-to-assume: my-github-actions-role
|
||||||
@@ -440,7 +448,7 @@ environment.
|
|||||||
|
|
||||||
Manually configured proxy:
|
Manually configured proxy:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: my-github-actions-role
|
role-to-assume: my-github-actions-role
|
||||||
@@ -470,7 +478,7 @@ should include the AWS CLI by default.
|
|||||||
### AssumeRoleWithWebIdentity (recommended)
|
### AssumeRoleWithWebIdentity (recommended)
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
@@ -481,13 +489,13 @@ In this example, the Action will load the OIDC token from the GitHub-provided en
|
|||||||
### AssumeRole with role previously assumed by action in same workflow
|
### AssumeRole with role previously assumed by action in same workflow
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
role-session-name: MySessionName
|
role-session-name: MySessionName
|
||||||
- name: Configure other AWS Credentials
|
- name: Configure other AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
|
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
|
||||||
@@ -499,7 +507,7 @@ In this two-step example, the first step will use OIDC to assume the role `arn:a
|
|||||||
### AssumeRole with static IAM credentials in repository secrets
|
### AssumeRole with static IAM credentials in repository secrets
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
@@ -515,7 +523,7 @@ In this example, the secret `AWS_ROLE_TO_ASSUME` contains a string like `arn:aws
|
|||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials 1
|
- name: Configure AWS Credentials 1
|
||||||
id: creds
|
id: creds
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
@@ -524,7 +532,7 @@ In this example, the secret `AWS_ROLE_TO_ASSUME` contains a string like `arn:aws
|
|||||||
run: |
|
run: |
|
||||||
aws sts get-caller-identity
|
aws sts get-caller-identity
|
||||||
- name: Configure AWS Credentials 2
|
- name: Configure AWS Credentials 2
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
|
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
|
||||||
|
|||||||
-204
@@ -3307,210 +3307,6 @@ Apache-2.0
|
|||||||
limitations under the License.
|
limitations under the License.
|
||||||
|
|
||||||
|
|
||||||
@aws-sdk/node-http-handler
|
|
||||||
Apache-2.0
|
|
||||||
Apache License
|
|
||||||
Version 2.0, January 2004
|
|
||||||
http://www.apache.org/licenses/
|
|
||||||
|
|
||||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
|
||||||
|
|
||||||
1. Definitions.
|
|
||||||
|
|
||||||
"License" shall mean the terms and conditions for use, reproduction,
|
|
||||||
and distribution as defined by Sections 1 through 9 of this document.
|
|
||||||
|
|
||||||
"Licensor" shall mean the copyright owner or entity authorized by
|
|
||||||
the copyright owner that is granting the License.
|
|
||||||
|
|
||||||
"Legal Entity" shall mean the union of the acting entity and all
|
|
||||||
other entities that control, are controlled by, or are under common
|
|
||||||
control with that entity. For the purposes of this definition,
|
|
||||||
"control" means (i) the power, direct or indirect, to cause the
|
|
||||||
direction or management of such entity, whether by contract or
|
|
||||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
|
||||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
|
||||||
|
|
||||||
"You" (or "Your") shall mean an individual or Legal Entity
|
|
||||||
exercising permissions granted by this License.
|
|
||||||
|
|
||||||
"Source" form shall mean the preferred form for making modifications,
|
|
||||||
including but not limited to software source code, documentation
|
|
||||||
source, and configuration files.
|
|
||||||
|
|
||||||
"Object" form shall mean any form resulting from mechanical
|
|
||||||
transformation or translation of a Source form, including but
|
|
||||||
not limited to compiled object code, generated documentation,
|
|
||||||
and conversions to other media types.
|
|
||||||
|
|
||||||
"Work" shall mean the work of authorship, whether in Source or
|
|
||||||
Object form, made available under the License, as indicated by a
|
|
||||||
copyright notice that is included in or attached to the work
|
|
||||||
(an example is provided in the Appendix below).
|
|
||||||
|
|
||||||
"Derivative Works" shall mean any work, whether in Source or Object
|
|
||||||
form, that is based on (or derived from) the Work and for which the
|
|
||||||
editorial revisions, annotations, elaborations, or other modifications
|
|
||||||
represent, as a whole, an original work of authorship. For the purposes
|
|
||||||
of this License, Derivative Works shall not include works that remain
|
|
||||||
separable from, or merely link (or bind by name) to the interfaces of,
|
|
||||||
the Work and Derivative Works thereof.
|
|
||||||
|
|
||||||
"Contribution" shall mean any work of authorship, including
|
|
||||||
the original version of the Work and any modifications or additions
|
|
||||||
to that Work or Derivative Works thereof, that is intentionally
|
|
||||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
|
||||||
or by an individual or Legal Entity authorized to submit on behalf of
|
|
||||||
the copyright owner. For the purposes of this definition, "submitted"
|
|
||||||
means any form of electronic, verbal, or written communication sent
|
|
||||||
to the Licensor or its representatives, including but not limited to
|
|
||||||
communication on electronic mailing lists, source code control systems,
|
|
||||||
and issue tracking systems that are managed by, or on behalf of, the
|
|
||||||
Licensor for the purpose of discussing and improving the Work, but
|
|
||||||
excluding communication that is conspicuously marked or otherwise
|
|
||||||
designated in writing by the copyright owner as "Not a Contribution."
|
|
||||||
|
|
||||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
|
||||||
on behalf of whom a Contribution has been received by Licensor and
|
|
||||||
subsequently incorporated within the Work.
|
|
||||||
|
|
||||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
copyright license to reproduce, prepare Derivative Works of,
|
|
||||||
publicly display, publicly perform, sublicense, and distribute the
|
|
||||||
Work and such Derivative Works in Source or Object form.
|
|
||||||
|
|
||||||
3. Grant of Patent License. Subject to the terms and conditions of
|
|
||||||
this License, each Contributor hereby grants to You a perpetual,
|
|
||||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
|
||||||
(except as stated in this section) patent license to make, have made,
|
|
||||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
|
||||||
where such license applies only to those patent claims licensable
|
|
||||||
by such Contributor that are necessarily infringed by their
|
|
||||||
Contribution(s) alone or by combination of their Contribution(s)
|
|
||||||
with the Work to which such Contribution(s) was submitted. If You
|
|
||||||
institute patent litigation against any entity (including a
|
|
||||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
|
||||||
or a Contribution incorporated within the Work constitutes direct
|
|
||||||
or contributory patent infringement, then any patent licenses
|
|
||||||
granted to You under this License for that Work shall terminate
|
|
||||||
as of the date such litigation is filed.
|
|
||||||
|
|
||||||
4. Redistribution. You may reproduce and distribute copies of the
|
|
||||||
Work or Derivative Works thereof in any medium, with or without
|
|
||||||
modifications, and in Source or Object form, provided that You
|
|
||||||
meet the following conditions:
|
|
||||||
|
|
||||||
(a) You must give any other recipients of the Work or
|
|
||||||
Derivative Works a copy of this License; and
|
|
||||||
|
|
||||||
(b) You must cause any modified files to carry prominent notices
|
|
||||||
stating that You changed the files; and
|
|
||||||
|
|
||||||
(c) You must retain, in the Source form of any Derivative Works
|
|
||||||
that You distribute, all copyright, patent, trademark, and
|
|
||||||
attribution notices from the Source form of the Work,
|
|
||||||
excluding those notices that do not pertain to any part of
|
|
||||||
the Derivative Works; and
|
|
||||||
|
|
||||||
(d) If the Work includes a "NOTICE" text file as part of its
|
|
||||||
distribution, then any Derivative Works that You distribute must
|
|
||||||
include a readable copy of the attribution notices contained
|
|
||||||
within such NOTICE file, excluding those notices that do not
|
|
||||||
pertain to any part of the Derivative Works, in at least one
|
|
||||||
of the following places: within a NOTICE text file distributed
|
|
||||||
as part of the Derivative Works; within the Source form or
|
|
||||||
documentation, if provided along with the Derivative Works; or,
|
|
||||||
within a display generated by the Derivative Works, if and
|
|
||||||
wherever such third-party notices normally appear. The contents
|
|
||||||
of the NOTICE file are for informational purposes only and
|
|
||||||
do not modify the License. You may add Your own attribution
|
|
||||||
notices within Derivative Works that You distribute, alongside
|
|
||||||
or as an addendum to the NOTICE text from the Work, provided
|
|
||||||
that such additional attribution notices cannot be construed
|
|
||||||
as modifying the License.
|
|
||||||
|
|
||||||
You may add Your own copyright statement to Your modifications and
|
|
||||||
may provide additional or different license terms and conditions
|
|
||||||
for use, reproduction, or distribution of Your modifications, or
|
|
||||||
for any such Derivative Works as a whole, provided Your use,
|
|
||||||
reproduction, and distribution of the Work otherwise complies with
|
|
||||||
the conditions stated in this License.
|
|
||||||
|
|
||||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
|
||||||
any Contribution intentionally submitted for inclusion in the Work
|
|
||||||
by You to the Licensor shall be under the terms and conditions of
|
|
||||||
this License, without any additional terms or conditions.
|
|
||||||
Notwithstanding the above, nothing herein shall supersede or modify
|
|
||||||
the terms of any separate license agreement you may have executed
|
|
||||||
with Licensor regarding such Contributions.
|
|
||||||
|
|
||||||
6. Trademarks. This License does not grant permission to use the trade
|
|
||||||
names, trademarks, service marks, or product names of the Licensor,
|
|
||||||
except as required for reasonable and customary use in describing the
|
|
||||||
origin of the Work and reproducing the content of the NOTICE file.
|
|
||||||
|
|
||||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
|
||||||
agreed to in writing, Licensor provides the Work (and each
|
|
||||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
|
||||||
implied, including, without limitation, any warranties or conditions
|
|
||||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
|
||||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
|
||||||
appropriateness of using or redistributing the Work and assume any
|
|
||||||
risks associated with Your exercise of permissions under this License.
|
|
||||||
|
|
||||||
8. Limitation of Liability. In no event and under no legal theory,
|
|
||||||
whether in tort (including negligence), contract, or otherwise,
|
|
||||||
unless required by applicable law (such as deliberate and grossly
|
|
||||||
negligent acts) or agreed to in writing, shall any Contributor be
|
|
||||||
liable to You for damages, including any direct, indirect, special,
|
|
||||||
incidental, or consequential damages of any character arising as a
|
|
||||||
result of this License or out of the use or inability to use the
|
|
||||||
Work (including but not limited to damages for loss of goodwill,
|
|
||||||
work stoppage, computer failure or malfunction, or any and all
|
|
||||||
other commercial damages or losses), even if such Contributor
|
|
||||||
has been advised of the possibility of such damages.
|
|
||||||
|
|
||||||
9. Accepting Warranty or Additional Liability. While redistributing
|
|
||||||
the Work or Derivative Works thereof, You may choose to offer,
|
|
||||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
|
||||||
or other liability obligations and/or rights consistent with this
|
|
||||||
License. However, in accepting such obligations, You may act only
|
|
||||||
on Your own behalf and on Your sole responsibility, not on behalf
|
|
||||||
of any other Contributor, and only if You agree to indemnify,
|
|
||||||
defend, and hold each Contributor harmless for any liability
|
|
||||||
incurred by, or claims asserted against, such Contributor by reason
|
|
||||||
of your accepting any such warranty or additional liability.
|
|
||||||
|
|
||||||
END OF TERMS AND CONDITIONS
|
|
||||||
|
|
||||||
APPENDIX: How to apply the Apache License to your work.
|
|
||||||
|
|
||||||
To apply the Apache License to your work, attach the following
|
|
||||||
boilerplate notice, with the fields enclosed by brackets "{}"
|
|
||||||
replaced with your own identifying information. (Don't include
|
|
||||||
the brackets!) The text should be enclosed in the appropriate
|
|
||||||
comment syntax for the file format. We also recommend that a
|
|
||||||
file or class name and description of purpose be included on the
|
|
||||||
same "printed page" as the copyright notice for easier
|
|
||||||
identification within third-party archives.
|
|
||||||
|
|
||||||
Copyright 2018-2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
|
|
||||||
@aws-sdk/token-providers
|
@aws-sdk/token-providers
|
||||||
Apache-2.0
|
Apache-2.0
|
||||||
Apache License
|
Apache License
|
||||||
|
|||||||
+1
-1
@@ -2,7 +2,7 @@
|
|||||||
name: '"Configure AWS Credentials" Action for GitHub Actions'
|
name: '"Configure AWS Credentials" Action for GitHub Actions'
|
||||||
description: Configures AWS credentials for use in subsequent steps in a GitHub Action workflow
|
description: Configures AWS credentials for use in subsequent steps in a GitHub Action workflow
|
||||||
runs:
|
runs:
|
||||||
using: node16
|
using: node20
|
||||||
main: dist/index.js
|
main: dist/index.js
|
||||||
post: dist/cleanup/index.js
|
post: dist/cleanup/index.js
|
||||||
branding:
|
branding:
|
||||||
|
|||||||
+1514
-1343
File diff suppressed because it is too large
Load Diff
+199
-1491
File diff suppressed because it is too large
Load Diff
@@ -20,7 +20,7 @@ jobs:
|
|||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v3
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
## the following creates an ARN based on the values entered into github secrets
|
## the following creates an ARN based on the values entered into github secrets
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# federated-setup
|
# federated-setup
|
||||||
|
|
||||||
## [github-action-oidc-federation](./github-actions-odic-federation.yml)
|
## [github-action-oidc-federation](./github-actions-oidc-federation.yml)
|
||||||
|
|
||||||
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account.
|
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account.
|
||||||
|
|
||||||
|
|||||||
Generated
+2095
-1897
File diff suppressed because it is too large
Load Diff
+17
-17
@@ -14,34 +14,34 @@
|
|||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@aws-sdk/credential-provider-env": "^3.186.0",
|
"@aws-sdk/credential-provider-env": "^3.186.0",
|
||||||
"@aws-sdk/property-provider": "^3.188.0",
|
"@smithy/property-provider": "^2.0.6",
|
||||||
"@jest/globals": "^29.1.2",
|
"@jest/globals": "^29.6.4",
|
||||||
"@types/jest": "^29.1.2",
|
"@types/jest": "^29.5.4",
|
||||||
"@types/node": "^14",
|
"@types/node": "^20",
|
||||||
"@typescript-eslint/eslint-plugin": "^5",
|
"@typescript-eslint/eslint-plugin": "<=5.62.0",
|
||||||
"@typescript-eslint/parser": "^5",
|
"@typescript-eslint/parser": "<=5.62.0",
|
||||||
"@vercel/ncc": "^0.34.0",
|
"@vercel/ncc": "^0.38.0",
|
||||||
"aws-sdk-client-mock": "^2.0.0",
|
"aws-sdk-client-mock": "^3.0.0",
|
||||||
"copyfiles": "^2.4.1",
|
"copyfiles": "^2.4.1",
|
||||||
"del-cli": "^5.0.0",
|
"del-cli": "^5.1.0",
|
||||||
"eslint": "^8",
|
"eslint": "^8",
|
||||||
"eslint-config-prettier": "^8.5.0",
|
"eslint-config-prettier": "^9.0.0",
|
||||||
"eslint-import-resolver-node": "^0.3.6",
|
"eslint-import-resolver-node": "^0.3.6",
|
||||||
"eslint-import-resolver-typescript": "^3.5.1",
|
"eslint-import-resolver-typescript": "^3.5.1",
|
||||||
"eslint-plugin-import": "^2.26.0",
|
"eslint-plugin-import": "^2.28.1",
|
||||||
"eslint-plugin-prettier": "^4.2.1",
|
"eslint-plugin-prettier": "^5.0.0",
|
||||||
"jest": "^29.1.2",
|
"jest": "^29.6.4",
|
||||||
"jest-junit": "^13",
|
"jest-junit": "^16",
|
||||||
"json-schema": "^0.4.0",
|
"json-schema": "^0.4.0",
|
||||||
"prettier": "^2.7.1",
|
"prettier": "^3.0.3",
|
||||||
"standard-version": "^9",
|
"standard-version": "^9",
|
||||||
"ts-jest": "^29.0.3",
|
"ts-jest": "^29.0.3",
|
||||||
"typescript": "^4.8.4"
|
"typescript": "^5.2.2"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.0",
|
"@actions/core": "^1.10.0",
|
||||||
"@aws-sdk/client-sts": "^3",
|
"@aws-sdk/client-sts": "^3",
|
||||||
"@aws-sdk/node-http-handler": "^3",
|
"@smithy/node-http-handler": "^2.0.0",
|
||||||
"https-proxy-agent": "^5.0.0"
|
"https-proxy-agent": "^5.0.0"
|
||||||
},
|
},
|
||||||
"keywords": [
|
"keywords": [
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { info } from '@actions/core';
|
import { info } from '@actions/core';
|
||||||
import { STSClient } from '@aws-sdk/client-sts';
|
import { STSClient } from '@aws-sdk/client-sts';
|
||||||
import { NodeHttpHandler } from '@aws-sdk/node-http-handler';
|
import { NodeHttpHandler } from '@smithy/node-http-handler';
|
||||||
import { HttpsProxyAgent } from 'https-proxy-agent';
|
import { HttpsProxyAgent } from 'https-proxy-agent';
|
||||||
import { errorMessage } from './helpers';
|
import { errorMessage } from './helpers';
|
||||||
|
|
||||||
|
|||||||
+5
-7
@@ -128,15 +128,13 @@ export async function run() {
|
|||||||
// the source credentials to already be masked as secrets
|
// the source credentials to already be masked as secrets
|
||||||
// in any error messages.
|
// in any error messages.
|
||||||
exportCredentials({ AccessKeyId, SecretAccessKey, SessionToken });
|
exportCredentials({ AccessKeyId, SecretAccessKey, SessionToken });
|
||||||
} else if (
|
} else if (!webIdentityTokenFile && !roleChaining) {
|
||||||
!webIdentityTokenFile &&
|
// Proceed only if credentials can be picked up
|
||||||
!roleChaining &&
|
await credentialsClient.validateCredentials();
|
||||||
!(process.env['AWS_ACCESS_KEY_ID'] && process.env['AWS_SECRET_ACCESS_KEY'])
|
sourceAccountId = await exportAccountId(credentialsClient, maskAccountId);
|
||||||
) {
|
|
||||||
throw new Error('Could not determine how to assume credentials. Please check your inputs and try again.');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (AccessKeyId || roleChaining || (process.env['AWS_ACCESS_KEY_ID'] && process.env['AWS_SECRET_ACCESS_KEY'])) {
|
if (AccessKeyId || roleChaining) {
|
||||||
// Validate that the SDK can actually pick up credentials.
|
// Validate that the SDK can actually pick up credentials.
|
||||||
// This validates cases where this action is using existing environment credentials,
|
// This validates cases where this action is using existing environment credentials,
|
||||||
// and cases where the user intended to provide input credentials but the secrets inputs resolved to empty strings.
|
// and cases where the user intended to provide input credentials but the secrets inputs resolved to empty strings.
|
||||||
|
|||||||
+7
-4
@@ -6,7 +6,7 @@ import {
|
|||||||
STSClient,
|
STSClient,
|
||||||
} from '@aws-sdk/client-sts';
|
} from '@aws-sdk/client-sts';
|
||||||
import { fromEnv } from '@aws-sdk/credential-provider-env';
|
import { fromEnv } from '@aws-sdk/credential-provider-env';
|
||||||
import { CredentialsProviderError } from '@aws-sdk/property-provider';
|
import { CredentialsProviderError } from '@smithy/property-provider';
|
||||||
import { mockClient } from 'aws-sdk-client-mock';
|
import { mockClient } from 'aws-sdk-client-mock';
|
||||||
import { withsleep, reset } from '../src/helpers';
|
import { withsleep, reset } from '../src/helpers';
|
||||||
import { run } from '../src/index';
|
import { run } from '../src/index';
|
||||||
@@ -202,7 +202,7 @@ describe('Configure AWS Credentials', () => {
|
|||||||
await run();
|
await run();
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: Could not load credentials from any providers'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -217,7 +217,7 @@ describe('Configure AWS Credentials', () => {
|
|||||||
await run();
|
await run();
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: Access key ID empty after loading credentials'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -508,6 +508,8 @@ describe('Configure AWS Credentials', () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
test('GH OIDC check fails if token is not set', async () => {
|
test('GH OIDC check fails if token is not set', async () => {
|
||||||
|
(fromEnv as jest.Mock).mockReset();
|
||||||
|
process.env['ACTIONS_ID_TOKEN_REQUEST_TOKEN'] = undefined;
|
||||||
process.env['GITHUB_ACTIONS'] = 'true';
|
process.env['GITHUB_ACTIONS'] = 'true';
|
||||||
jest.spyOn(core, 'getInput').mockImplementation(
|
jest.spyOn(core, 'getInput').mockImplementation(
|
||||||
mockGetInput({
|
mockGetInput({
|
||||||
@@ -523,11 +525,12 @@ describe('Configure AWS Credentials', () => {
|
|||||||
' If you are not trying to authenticate with OIDC and the action is working successfully, you can ignore this message.'
|
' If you are not trying to authenticate with OIDC and the action is working successfully, you can ignore this message.'
|
||||||
);
|
);
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: provider is not a function'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test('Assume role with existing credentials if nothing else set', async () => {
|
test('Assume role with existing credentials if nothing else set', async () => {
|
||||||
|
process.env['ACTIONS_ID_TOKEN_REQUEST_TOKEN'] = undefined;
|
||||||
process.env['AWS_ACCESS_KEY_ID'] = FAKE_ACCESS_KEY_ID;
|
process.env['AWS_ACCESS_KEY_ID'] = FAKE_ACCESS_KEY_ID;
|
||||||
process.env['AWS_SECRET_ACCESS_KEY'] = FAKE_SECRET_ACCESS_KEY;
|
process.env['AWS_SECRET_ACCESS_KEY'] = FAKE_SECRET_ACCESS_KEY;
|
||||||
jest.spyOn(core, 'getInput').mockImplementation(
|
jest.spyOn(core, 'getInput').mockImplementation(
|
||||||
|
|||||||
Reference in New Issue
Block a user