mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-09-02 05:55:10 +09:00
Compare commits
64 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 010d0da01d | |||
| b48e2ee5c6 | |||
| 183b94a269 | |||
| 1d4ae371e5 | |||
| 6a430ce1a4 | |||
| 8402193770 | |||
| f31c158843 | |||
| 164817a8f8 | |||
| e2c335e163 | |||
| a1a09b7ff2 | |||
| 53bf02c02f | |||
| 6960539309 | |||
| 83ceb16ee1 | |||
| 5cb52d02e4 | |||
| fbaaea8490 | |||
| 0d9b446851 | |||
| 51e898662e | |||
| dc894b4148 | |||
| 4f8ea089cf | |||
| ff5c452440 | |||
| 96cd64d434 | |||
| 3d11655d76 | |||
| e50f96d7c7 | |||
| 8025ae060f | |||
| bc2200e43c | |||
| 155b315cee | |||
| 59d2ad0a59 | |||
| 1067f72d75 | |||
| 393929845e | |||
| 8c3f20df09 | |||
| 50ac8dd1e1 | |||
| a2593d09d1 | |||
| 7a8dec84bd | |||
| 2b89f8a0da | |||
| 6488aec6e7 | |||
| 856a411d27 | |||
| 7e7ee94419 | |||
| 8ad39aa824 | |||
| 2014030530 | |||
| 3aeb7ba662 | |||
| 3994f1aeae | |||
| a3412312b9 | |||
| ef2571b57d | |||
| 8e373defe9 | |||
| 9555344752 | |||
| 72f2c7b9a3 | |||
| b0cb02aa90 | |||
| 7bac5f98a7 | |||
| 922470e4ee | |||
| d3c2317d0a | |||
| f0ede74cf3 | |||
| 8afcd6259e | |||
| 84a8fd5e77 | |||
| d78f55b1db | |||
| 6c962b9fd3 | |||
| 14b6c355ca | |||
| 22617f9706 | |||
| 622237c36a | |||
| 014a5f9adc | |||
| 44cffa5fa8 | |||
| 19f0360930 | |||
| fd194eccd1 | |||
| 7f32242eff | |||
| 7e430f7278 |
@@ -0,0 +1,51 @@
|
|||||||
|
name: "Close Stale Issues"
|
||||||
|
|
||||||
|
# Controls when the action will run.
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 */4 * * *"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
cleanup:
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Stale issue job
|
||||||
|
steps:
|
||||||
|
- uses: aws-actions/stale-issue-cleanup@v5
|
||||||
|
with:
|
||||||
|
# Setting messages to an empty string will cause the automation to skip
|
||||||
|
# that category
|
||||||
|
ancient-issue-message: This issue has not received any attention in 1 year. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
stale-issue-message: This issue has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
stale-pr-message: This PR has not received a response in a while. If you want to keep this issue open, please leave a comment below and auto-close will be canceled.
|
||||||
|
|
||||||
|
# These labels are required
|
||||||
|
stale-issue-label: closing-soon
|
||||||
|
exempt-issue-labels: no-autoclose
|
||||||
|
stale-pr-label: closing-soon
|
||||||
|
exempt-pr-labels: no-autoclose
|
||||||
|
response-requested-label: response-requested
|
||||||
|
|
||||||
|
# Don't set closed-for-staleness label to skip closing very old issues
|
||||||
|
# regardless of label
|
||||||
|
closed-for-staleness-label: closed-for-staleness
|
||||||
|
|
||||||
|
# Issue timing
|
||||||
|
days-before-stale: 5
|
||||||
|
days-before-close: 2
|
||||||
|
days-before-ancient: 36500
|
||||||
|
|
||||||
|
# If you don't want to mark a issue as being ancient based on a
|
||||||
|
# threshold of "upvotes", you can set this here. An "upvote" is
|
||||||
|
# the total number of +1, heart, hooray, and rocket reactions
|
||||||
|
# on an issue.
|
||||||
|
minimum-upvotes-to-exempt: 5
|
||||||
|
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
loglevel: DEBUG
|
||||||
|
# Set dry-run to true to not perform label or close actions.
|
||||||
|
dry-run: false
|
||||||
@@ -13,7 +13,5 @@ jobs:
|
|||||||
# These inputs are both required
|
# These inputs are both required
|
||||||
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
||||||
message: |
|
message: |
|
||||||
** Note **
|
|
||||||
Comments on closed issues are hard for our team to see.
|
Comments on closed issues are hard for our team to see.
|
||||||
If you need more assistance, please either tag a team member or open a new issue that references this one.
|
If you need more assistance, please either tag a team member or open a new issue that references this one.
|
||||||
If you wish to keep having a conversation with other community members under this issue feel free to do so.
|
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ on:
|
|||||||
- main
|
- main
|
||||||
paths-ignore:
|
paths-ignore:
|
||||||
- 'dist/**'
|
- 'dist/**'
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
package:
|
package:
|
||||||
@@ -27,10 +28,10 @@ jobs:
|
|||||||
npm test
|
npm test
|
||||||
npm run package
|
npm run package
|
||||||
- name: Configure AWS credentials
|
- name: Configure AWS credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-west-2
|
aws-region: us-west-2
|
||||||
role-to-assume: ${{ secrets.SECRETS_AWS_ROLE_TO_ASSUME }}
|
role-to-assume: ${{ secrets.SECRETS_AWS_PACKAGING_ROLE_TO_ASSUME }}
|
||||||
role-duration-seconds: 900
|
role-duration-seconds: 900
|
||||||
role-session-name: SecretsManagerFetch
|
role-session-name: SecretsManagerFetch
|
||||||
- name: Get bot user token
|
- name: Get bot user token
|
||||||
@@ -38,7 +39,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
parse-json-secrets: true
|
parse-json-secrets: true
|
||||||
secret-ids: |
|
secret-ids: |
|
||||||
OSDS,arn:aws:secretsmanager:us-west-2:294535624312:secret:github-aws-sdk-osds-automation-ZHNalp
|
OSDS,arn:aws:secretsmanager:us-west-2:206735643321:secret:github-aws-sdk-osds-automation-gebs9n
|
||||||
- name: Commit
|
- name: Commit
|
||||||
run: |
|
run: |
|
||||||
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
echo "::add-mask::${{ env.OSDS_ACCESS_TOKEN }}"
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
name: Run tests
|
name: Run Integ tests
|
||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
@@ -12,7 +12,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run OIDC integ tests
|
name: Run OIDC integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -27,12 +26,37 @@ jobs:
|
|||||||
role-duration-seconds: 900
|
role-duration-seconds: 900
|
||||||
role-session-name: IntegOidcAssumeRole
|
role-session-name: IntegOidcAssumeRole
|
||||||
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
||||||
|
integ-oidc-env:
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
id-token: write
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
|
name: Run OIDC integ tests with existing invalid env vars
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
env:
|
||||||
|
AWS_ACCESS_KEY_ID: dummyaccesskeyid
|
||||||
|
AWS_SECRET_ACCESS_KEY: dummysecretkey
|
||||||
|
AWS_SESSION_TOKEN: dummytoken
|
||||||
|
timeout-minutes: 30
|
||||||
|
steps:
|
||||||
|
- name: "Checkout repository"
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
- name: Integ test for OIDC
|
||||||
|
uses: ./
|
||||||
|
with:
|
||||||
|
aws-region: us-west-2
|
||||||
|
role-to-assume: ${{ secrets.SECRETS_OIDC_AWS_ROLE_TO_ASSUME }}
|
||||||
|
role-duration-seconds: 900
|
||||||
|
role-session-name: IntegOidcAssumeRole
|
||||||
|
role-external-id: ${{ secrets.SECRETS_OIDC_AWS_ROLE_EXTERNAL_ID }}
|
||||||
integ-access-keys:
|
integ-access-keys:
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run access key integ tests
|
name: Run access key integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -53,7 +77,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run access key from env integ tests
|
name: Run access key from env integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
@@ -75,7 +98,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
os: [[self-hosted, linux-fargate], windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run IAM User integ tests
|
name: Run IAM User integ tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
|
|||||||
@@ -9,7 +9,6 @@ jobs:
|
|||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: [windows-latest, ubuntu-latest, macos-latest]
|
os: [windows-latest, ubuntu-latest, macos-latest]
|
||||||
node: [14, 16, 18]
|
|
||||||
name: Run unit tests
|
name: Run unit tests
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
@@ -19,7 +18,7 @@ jobs:
|
|||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v3
|
uses: actions/setup-node@v3
|
||||||
with:
|
with:
|
||||||
node-version: ${{ matrix.node }}
|
node-version: 20
|
||||||
- name: "Install dependencies"
|
- name: "Install dependencies"
|
||||||
uses: bahmutov/npm-install@v1
|
uses: bahmutov/npm-install@v1
|
||||||
- name: "Run tests"
|
- name: "Run tests"
|
||||||
@@ -34,7 +33,7 @@ jobs:
|
|||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v3
|
uses: actions/setup-node@v3
|
||||||
with:
|
with:
|
||||||
node-version: 16
|
node-version: 20
|
||||||
- name: "Install dependencies"
|
- name: "Install dependencies"
|
||||||
uses: bahmutov/npm-install@v1
|
uses: bahmutov/npm-install@v1
|
||||||
- name: "Lint code"
|
- name: "Lint code"
|
||||||
|
|||||||
+12
-4
@@ -1,8 +1,12 @@
|
|||||||
queue_rules:
|
queue_rules:
|
||||||
- name: default
|
- name: default
|
||||||
conditions:
|
conditions:
|
||||||
# Conditions to get out of the queue (= merged)
|
# Conditions to merge a queued PR
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest)
|
||||||
|
- check-success=Run unit tests (macos-latest)
|
||||||
|
- "#approved-reviews-by>=1"
|
||||||
|
- -approved-reviews-by~=author
|
||||||
|
|
||||||
pull_request_rules:
|
pull_request_rules:
|
||||||
- name: Automatically merge on CI success and review approval
|
- name: Automatically merge on CI success and review approval
|
||||||
@@ -10,7 +14,9 @@ pull_request_rules:
|
|||||||
- base~=main|integ-tests
|
- base~=main|integ-tests
|
||||||
- "#approved-reviews-by>=1"
|
- "#approved-reviews-by>=1"
|
||||||
- -approved-reviews-by~=author
|
- -approved-reviews-by~=author
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest)
|
||||||
|
- check-success=Run unit tests (macos-latest)
|
||||||
- label!=work-in-progress
|
- label!=work-in-progress
|
||||||
- -title~=(WIP|wip)
|
- -title~=(WIP|wip)
|
||||||
- -merged
|
- -merged
|
||||||
@@ -25,7 +31,9 @@ pull_request_rules:
|
|||||||
conditions:
|
conditions:
|
||||||
- base~=main
|
- base~=main
|
||||||
- author=dependabot[bot]
|
- author=dependabot[bot]
|
||||||
- status-success=Run Unit Tests
|
- check-success=Run unit tests (windows-latest)
|
||||||
|
- check-success=Run unit tests (ubuntu-latest)
|
||||||
|
- check-success=Run unit tests (macos-latest)
|
||||||
- -title~=(WIP|wip)
|
- -title~=(WIP|wip)
|
||||||
- -label~=(blocked|do-not-merge)
|
- -label~=(blocked|do-not-merge)
|
||||||
- -merged
|
- -merged
|
||||||
|
|||||||
@@ -2,6 +2,20 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
|
||||||
|
|
||||||
|
## [4.0.1](https://github.com/aws-actions/configure-aws-credentials/compare/v4.0.0...v4.0.1) (2023-10-03)
|
||||||
|
|
||||||
|
### Documentation
|
||||||
|
* Throw a warning when customers use long-term credentials.
|
||||||
|
|
||||||
|
## [4.0.0](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.2...v4.0.0) (2023-09-11)
|
||||||
|
|
||||||
|
* Upgraded runtime to `node20` from `node16`
|
||||||
|
|
||||||
|
## [3.0.2](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.1...v3.0.2) (2023-09-07)
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
* fixes #817 #819: validation logic throwing unwanted errors [d78f55b](https://github.com/aws-actions/configure-aws-credentials/commit/d78f55b1db65186cb251a8504ae9527af06fc5fd)
|
||||||
|
|
||||||
## [3.0.1](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.0...v3.0.1) (2023-08-24)
|
## [3.0.1](https://github.com/aws-actions/configure-aws-credentials/compare/v3.0.0...v3.0.1) (2023-08-24)
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
|
|||||||
@@ -7,7 +7,23 @@ calls.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
### News
|
### Recent News
|
||||||
|
|
||||||
|
#### Long-term credentials warning (10/3/23)
|
||||||
|
|
||||||
|
We have added a warning when using long-term credentials to access AWS
|
||||||
|
(IAM access keys and secret keys). Using long-term credentials requires you
|
||||||
|
to create IAM users and properly secure the access keys to prevent their disclosure.
|
||||||
|
A better approach is to use [GitHub's support for OpenID Connect](#OIDC) to authenticate
|
||||||
|
using an IAM role to generate temporary security credentials.
|
||||||
|
|
||||||
|
#### v4 Announcement (9/11/23)
|
||||||
|
|
||||||
|
We have just released `v4` of Configure AWS Credentials. The only thing that
|
||||||
|
changed from `v3` is that the action now runs on `node20` instead of `node16`.
|
||||||
|
You can still see the `v3` announcement below, as it is still recent.
|
||||||
|
|
||||||
|
#### v3 Announcement (8/23/23)
|
||||||
|
|
||||||
We have recently released `v3` of Configure AWS Credentials! With this new
|
We have recently released `v3` of Configure AWS Credentials! With this new
|
||||||
release we have migrated the code to TypeScript, and have also migrated away
|
release we have migrated the code to TypeScript, and have also migrated away
|
||||||
@@ -24,7 +40,7 @@ changes should be backwards compatible with your existing workflows.
|
|||||||
_all_ use cases. This is changed from 6 hours in `v2`. You can adjust this value
|
_all_ use cases. This is changed from 6 hours in `v2`. You can adjust this value
|
||||||
with the `role-duration-seconds` input.
|
with the `role-duration-seconds` input.
|
||||||
- By default, your account ID will not be masked in workflow logs. This was
|
- By default, your account ID will not be masked in workflow logs. This was
|
||||||
changed from being masked by default in the previous version. AWS does consider
|
changed from being masked by default in the previous version. AWS does not consider
|
||||||
account IDs as sensitive information, so this change reflects that stance. You
|
account IDs as sensitive information, so this change reflects that stance. You
|
||||||
can revert to the old default and mask your account ID in workflow logs by
|
can revert to the old default and mask your account ID in workflow logs by
|
||||||
setting the `mask-aws-account-id` input to `true`.
|
setting the `mask-aws-account-id` input to `true`.
|
||||||
@@ -46,7 +62,7 @@ variables are interfering with the action. You can enable this by setting the
|
|||||||
**Bug fixes**
|
**Bug fixes**
|
||||||
|
|
||||||
You can find a list of bugs that have been fixed in v3 in the
|
You can find a list of bugs that have been fixed in v3 in the
|
||||||
[changelog](./changelog.md).
|
[changelog](./CHANGELOG.md).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -82,7 +98,7 @@ To do that, you would add the following step to your workflow:
|
|||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
@@ -111,7 +127,7 @@ jobs:
|
|||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v3
|
||||||
- name: Configure AWS credentials from Test account
|
- name: Configure AWS credentials from Test account
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::111111111111:role/my-github-actions-role-test
|
role-to-assume: arn:aws:iam::111111111111:role/my-github-actions-role-test
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
@@ -119,7 +135,7 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
aws s3 sync . s3://my-s3-test-website-bucket
|
aws s3 sync . s3://my-s3-test-website-bucket
|
||||||
- name: Configure AWS credentials from Production account
|
- name: Configure AWS credentials from Production account
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-to-assume: arn:aws:iam::222222222222:role/my-github-actions-role-prod
|
role-to-assume: arn:aws:iam::222222222222:role/my-github-actions-role-prod
|
||||||
aws-region: us-west-2
|
aws-region: us-west-2
|
||||||
@@ -209,7 +225,7 @@ within the Action. See [issue 419](https://github.com/aws-actions/configure-aws-
|
|||||||
You can skip this session tagging by providing
|
You can skip this session tagging by providing
|
||||||
`role-skip-session-tagging` as true in the action's inputs:
|
`role-skip-session-tagging` as true in the action's inputs:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
role-skip-session-tagging: true
|
role-skip-session-tagging: true
|
||||||
```
|
```
|
||||||
@@ -220,13 +236,13 @@ You can skip this session tagging by providing
|
|||||||
An IAM policy in stringified JSON format that you want to use as an inline session policy.
|
An IAM policy in stringified JSON format that you want to use as an inline session policy.
|
||||||
Depending on preferences, the JSON could be written on a single line like this:
|
Depending on preferences, the JSON could be written on a single line like this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
|
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
|
||||||
```
|
```
|
||||||
Or we can have a nicely formatted JSON as well:
|
Or we can have a nicely formatted JSON as well:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
inline-session-policy: >-
|
inline-session-policy: >-
|
||||||
{
|
{
|
||||||
@@ -246,13 +262,13 @@ Or we can have a nicely formatted JSON as well:
|
|||||||
The Amazon Resource Names (ARNs) of the IAM managed policies that you want to use as managed session policies.
|
The Amazon Resource Names (ARNs) of the IAM managed policies that you want to use as managed session policies.
|
||||||
The policies must exist in the same account as the role. You can pass a single managed policy like this:
|
The policies must exist in the same account as the role. You can pass a single managed policy like this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
||||||
```
|
```
|
||||||
And we can pass multiple managed policies likes this:
|
And we can pass multiple managed policies likes this:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
managed-session-policies: |
|
managed-session-policies: |
|
||||||
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
|
||||||
@@ -291,11 +307,11 @@ We recommend using [GitHub's OIDC provider](https://docs.github.com/en/actions/d
|
|||||||
|
|
||||||
### Audience
|
### Audience
|
||||||
|
|
||||||
When the JWT is created, an audience needs to be specified. By default, the audience is `sts.amazon.com` and this will work for most cases. Changing the default audience may be necessary when using non-default AWS partitions. You can specify the audience through the `audience` input:
|
When the JWT is created, an audience needs to be specified. By default, the audience is `sts.amazonaws.com` and this will work for most cases. Changing the default audience may be necessary when using non-default AWS partitions. You can specify the audience through the `audience` input:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials for China region audience
|
- name: Configure AWS Credentials for China region audience
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
audience: sts.amazonaws.com.cn
|
audience: sts.amazonaws.com.cn
|
||||||
aws-region: us-east-3
|
aws-region: us-east-3
|
||||||
@@ -407,7 +423,7 @@ You can use this action to simply configure the region and account ID in the
|
|||||||
environment, and then use the runner's credentials for all AWS API calls made by
|
environment, and then use the runner's credentials for all AWS API calls made by
|
||||||
your Actions workflow:
|
your Actions workflow:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
```
|
```
|
||||||
@@ -417,7 +433,7 @@ APIs called by your Actions workflow.
|
|||||||
Or, you can use this action to assume a role, and then use the role credentials
|
Or, you can use this action to assume a role, and then use the role credentials
|
||||||
for all AWS API calls made by your Actions workflow:
|
for all AWS API calls made by your Actions workflow:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: my-github-actions-role
|
role-to-assume: my-github-actions-role
|
||||||
@@ -440,7 +456,7 @@ environment.
|
|||||||
|
|
||||||
Manually configured proxy:
|
Manually configured proxy:
|
||||||
```yaml
|
```yaml
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: my-github-actions-role
|
role-to-assume: my-github-actions-role
|
||||||
@@ -470,7 +486,7 @@ should include the AWS CLI by default.
|
|||||||
### AssumeRoleWithWebIdentity (recommended)
|
### AssumeRoleWithWebIdentity (recommended)
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
@@ -481,13 +497,13 @@ In this example, the Action will load the OIDC token from the GitHub-provided en
|
|||||||
### AssumeRole with role previously assumed by action in same workflow
|
### AssumeRole with role previously assumed by action in same workflow
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
role-session-name: MySessionName
|
role-session-name: MySessionName
|
||||||
- name: Configure other AWS Credentials
|
- name: Configure other AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
|
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
|
||||||
@@ -499,7 +515,7 @@ In this two-step example, the first step will use OIDC to assume the role `arn:a
|
|||||||
### AssumeRole with static IAM credentials in repository secrets
|
### AssumeRole with static IAM credentials in repository secrets
|
||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
||||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||||
@@ -515,7 +531,7 @@ In this example, the secret `AWS_ROLE_TO_ASSUME` contains a string like `arn:aws
|
|||||||
```yaml
|
```yaml
|
||||||
- name: Configure AWS Credentials 1
|
- name: Configure AWS Credentials 1
|
||||||
id: creds
|
id: creds
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
|
||||||
@@ -524,7 +540,7 @@ In this example, the secret `AWS_ROLE_TO_ASSUME` contains a string like `arn:aws
|
|||||||
run: |
|
run: |
|
||||||
aws sts get-caller-identity
|
aws sts get-caller-identity
|
||||||
- name: Configure AWS Credentials 2
|
- name: Configure AWS Credentials 2
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-2
|
aws-region: us-east-2
|
||||||
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
|
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
|
||||||
|
|||||||
+1
-1
@@ -3307,7 +3307,7 @@ Apache-2.0
|
|||||||
limitations under the License.
|
limitations under the License.
|
||||||
|
|
||||||
|
|
||||||
@aws-sdk/node-http-handler
|
@aws-sdk/region-config-resolver
|
||||||
Apache-2.0
|
Apache-2.0
|
||||||
Apache License
|
Apache License
|
||||||
Version 2.0, January 2004
|
Version 2.0, January 2004
|
||||||
|
|||||||
+1
-1
@@ -2,7 +2,7 @@
|
|||||||
name: '"Configure AWS Credentials" Action for GitHub Actions'
|
name: '"Configure AWS Credentials" Action for GitHub Actions'
|
||||||
description: Configures AWS credentials for use in subsequent steps in a GitHub Action workflow
|
description: Configures AWS credentials for use in subsequent steps in a GitHub Action workflow
|
||||||
runs:
|
runs:
|
||||||
using: node16
|
using: node20
|
||||||
main: dist/index.js
|
main: dist/index.js
|
||||||
post: dist/cleanup/index.js
|
post: dist/cleanup/index.js
|
||||||
branding:
|
branding:
|
||||||
|
|||||||
+1975
-1383
File diff suppressed because it is too large
Load Diff
+583
-1450
File diff suppressed because it is too large
Load Diff
@@ -20,7 +20,7 @@ jobs:
|
|||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v3
|
||||||
- name: Configure AWS Credentials
|
- name: Configure AWS Credentials
|
||||||
uses: aws-actions/configure-aws-credentials@v3
|
uses: aws-actions/configure-aws-credentials@v4
|
||||||
with:
|
with:
|
||||||
aws-region: us-east-1
|
aws-region: us-east-1
|
||||||
## the following creates an ARN based on the values entered into github secrets
|
## the following creates an ARN based on the values entered into github secrets
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# federated-setup
|
# federated-setup
|
||||||
|
|
||||||
## [github-action-oidc-federation](./github-actions-odic-federation.yml)
|
## [github-action-oidc-federation](./github-actions-oidc-federation.yml)
|
||||||
|
|
||||||
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account.
|
Setup of the OIDC federation between your GitHub Organization/repository and your AWS account.
|
||||||
|
|
||||||
|
|||||||
Generated
+2196
-1913
File diff suppressed because it is too large
Load Diff
+19
-19
@@ -14,34 +14,34 @@
|
|||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@aws-sdk/credential-provider-env": "^3.186.0",
|
"@aws-sdk/credential-provider-env": "^3.186.0",
|
||||||
"@aws-sdk/property-provider": "^3.188.0",
|
"@smithy/property-provider": "^2.0.11",
|
||||||
"@jest/globals": "^29.1.2",
|
"@jest/globals": "^29.7.0",
|
||||||
"@types/jest": "^29.1.2",
|
"@types/jest": "^29.5.5",
|
||||||
"@types/node": "^14",
|
"@types/node": "^20",
|
||||||
"@typescript-eslint/eslint-plugin": "^5",
|
"@typescript-eslint/eslint-plugin": "<=5.62.0",
|
||||||
"@typescript-eslint/parser": "^5",
|
"@typescript-eslint/parser": "<=5.62.0",
|
||||||
"@vercel/ncc": "^0.34.0",
|
"@vercel/ncc": "^0.38.0",
|
||||||
"aws-sdk-client-mock": "^2.0.0",
|
"aws-sdk-client-mock": "^3.0.0",
|
||||||
"copyfiles": "^2.4.1",
|
"copyfiles": "^2.4.1",
|
||||||
"del-cli": "^5.0.0",
|
"del-cli": "^5.1.0",
|
||||||
"eslint": "^8",
|
"eslint": "^8",
|
||||||
"eslint-config-prettier": "^8.5.0",
|
"eslint-config-prettier": "^9.0.0",
|
||||||
"eslint-import-resolver-node": "^0.3.6",
|
"eslint-import-resolver-node": "^0.3.6",
|
||||||
"eslint-import-resolver-typescript": "^3.5.1",
|
"eslint-import-resolver-typescript": "^3.6.1",
|
||||||
"eslint-plugin-import": "^2.26.0",
|
"eslint-plugin-import": "^2.28.1",
|
||||||
"eslint-plugin-prettier": "^4.2.1",
|
"eslint-plugin-prettier": "^5.0.0",
|
||||||
"jest": "^29.1.2",
|
"jest": "^29.7.0",
|
||||||
"jest-junit": "^13",
|
"jest-junit": "^16",
|
||||||
"json-schema": "^0.4.0",
|
"json-schema": "^0.4.0",
|
||||||
"prettier": "^2.7.1",
|
"prettier": "^3.0.3",
|
||||||
"standard-version": "^9",
|
"standard-version": "^9",
|
||||||
"ts-jest": "^29.0.3",
|
"ts-jest": "^29.0.3",
|
||||||
"typescript": "^4.8.4"
|
"typescript": "^5.2.2"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.0",
|
"@actions/core": "^1.10.1",
|
||||||
"@aws-sdk/client-sts": "^3",
|
"@aws-sdk/client-sts": "^3",
|
||||||
"@aws-sdk/node-http-handler": "^3",
|
"@smithy/node-http-handler": "^2.1.6",
|
||||||
"https-proxy-agent": "^5.0.0"
|
"https-proxy-agent": "^5.0.0"
|
||||||
},
|
},
|
||||||
"keywords": [
|
"keywords": [
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { info } from '@actions/core';
|
import { info } from '@actions/core';
|
||||||
import { STSClient } from '@aws-sdk/client-sts';
|
import { STSClient } from '@aws-sdk/client-sts';
|
||||||
import { NodeHttpHandler } from '@aws-sdk/node-http-handler';
|
import { NodeHttpHandler } from '@smithy/node-http-handler';
|
||||||
import { HttpsProxyAgent } from 'https-proxy-agent';
|
import { HttpsProxyAgent } from 'https-proxy-agent';
|
||||||
import { errorMessage } from './helpers';
|
import { errorMessage } from './helpers';
|
||||||
|
|
||||||
|
|||||||
@@ -56,6 +56,12 @@ async function assumeRoleWithWebIdentityTokenFile(
|
|||||||
|
|
||||||
async function assumeRoleWithCredentials(params: AssumeRoleCommandInput, client: STSClient) {
|
async function assumeRoleWithCredentials(params: AssumeRoleCommandInput, client: STSClient) {
|
||||||
core.info('Assuming role with user credentials');
|
core.info('Assuming role with user credentials');
|
||||||
|
if (!process.env['AWS_SESSION_TOKEN']) {
|
||||||
|
core.warning(
|
||||||
|
'To avoid using long-term AWS credentials, please update your workflows to authenticate using OpenID Connect.' +
|
||||||
|
' See https://s12d.com/gha-oidc-aws for more information.'
|
||||||
|
);
|
||||||
|
}
|
||||||
try {
|
try {
|
||||||
const creds = await client.send(new AssumeRoleCommand({ ...params }));
|
const creds = await client.send(new AssumeRoleCommand({ ...params }));
|
||||||
return creds;
|
return creds;
|
||||||
|
|||||||
+5
-7
@@ -128,15 +128,13 @@ export async function run() {
|
|||||||
// the source credentials to already be masked as secrets
|
// the source credentials to already be masked as secrets
|
||||||
// in any error messages.
|
// in any error messages.
|
||||||
exportCredentials({ AccessKeyId, SecretAccessKey, SessionToken });
|
exportCredentials({ AccessKeyId, SecretAccessKey, SessionToken });
|
||||||
} else if (
|
} else if (!webIdentityTokenFile && !roleChaining) {
|
||||||
!webIdentityTokenFile &&
|
// Proceed only if credentials can be picked up
|
||||||
!roleChaining &&
|
await credentialsClient.validateCredentials();
|
||||||
!(process.env['AWS_ACCESS_KEY_ID'] && process.env['AWS_SECRET_ACCESS_KEY'])
|
sourceAccountId = await exportAccountId(credentialsClient, maskAccountId);
|
||||||
) {
|
|
||||||
throw new Error('Could not determine how to assume credentials. Please check your inputs and try again.');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (AccessKeyId || roleChaining || (process.env['AWS_ACCESS_KEY_ID'] && process.env['AWS_SECRET_ACCESS_KEY'])) {
|
if (AccessKeyId || roleChaining) {
|
||||||
// Validate that the SDK can actually pick up credentials.
|
// Validate that the SDK can actually pick up credentials.
|
||||||
// This validates cases where this action is using existing environment credentials,
|
// This validates cases where this action is using existing environment credentials,
|
||||||
// and cases where the user intended to provide input credentials but the secrets inputs resolved to empty strings.
|
// and cases where the user intended to provide input credentials but the secrets inputs resolved to empty strings.
|
||||||
|
|||||||
+29
-4
@@ -6,7 +6,7 @@ import {
|
|||||||
STSClient,
|
STSClient,
|
||||||
} from '@aws-sdk/client-sts';
|
} from '@aws-sdk/client-sts';
|
||||||
import { fromEnv } from '@aws-sdk/credential-provider-env';
|
import { fromEnv } from '@aws-sdk/credential-provider-env';
|
||||||
import { CredentialsProviderError } from '@aws-sdk/property-provider';
|
import { CredentialsProviderError } from '@smithy/property-provider';
|
||||||
import { mockClient } from 'aws-sdk-client-mock';
|
import { mockClient } from 'aws-sdk-client-mock';
|
||||||
import { withsleep, reset } from '../src/helpers';
|
import { withsleep, reset } from '../src/helpers';
|
||||||
import { run } from '../src/index';
|
import { run } from '../src/index';
|
||||||
@@ -105,6 +105,9 @@ describe('Configure AWS Credentials', () => {
|
|||||||
jest.spyOn(core, 'info').mockImplementation((string) => {
|
jest.spyOn(core, 'info').mockImplementation((string) => {
|
||||||
return string;
|
return string;
|
||||||
});
|
});
|
||||||
|
jest.spyOn(core, 'warning').mockImplementation((string) => {
|
||||||
|
return string;
|
||||||
|
});
|
||||||
(fromEnv as jest.Mock)
|
(fromEnv as jest.Mock)
|
||||||
.mockImplementationOnce(() => () => ({
|
.mockImplementationOnce(() => () => ({
|
||||||
accessKeyId: FAKE_ACCESS_KEY_ID,
|
accessKeyId: FAKE_ACCESS_KEY_ID,
|
||||||
@@ -202,7 +205,7 @@ describe('Configure AWS Credentials', () => {
|
|||||||
await run();
|
await run();
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: Could not load credentials from any providers'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -217,7 +220,7 @@ describe('Configure AWS Credentials', () => {
|
|||||||
await run();
|
await run();
|
||||||
|
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: Access key ID empty after loading credentials'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -508,6 +511,8 @@ describe('Configure AWS Credentials', () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
test('GH OIDC check fails if token is not set', async () => {
|
test('GH OIDC check fails if token is not set', async () => {
|
||||||
|
(fromEnv as jest.Mock).mockReset();
|
||||||
|
process.env['ACTIONS_ID_TOKEN_REQUEST_TOKEN'] = undefined;
|
||||||
process.env['GITHUB_ACTIONS'] = 'true';
|
process.env['GITHUB_ACTIONS'] = 'true';
|
||||||
jest.spyOn(core, 'getInput').mockImplementation(
|
jest.spyOn(core, 'getInput').mockImplementation(
|
||||||
mockGetInput({
|
mockGetInput({
|
||||||
@@ -523,11 +528,12 @@ describe('Configure AWS Credentials', () => {
|
|||||||
' If you are not trying to authenticate with OIDC and the action is working successfully, you can ignore this message.'
|
' If you are not trying to authenticate with OIDC and the action is working successfully, you can ignore this message.'
|
||||||
);
|
);
|
||||||
expect(core.setFailed).toHaveBeenCalledWith(
|
expect(core.setFailed).toHaveBeenCalledWith(
|
||||||
'Could not determine how to assume credentials. Please check your inputs and try again.'
|
'Credentials could not be loaded, please check your action inputs: provider is not a function'
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test('Assume role with existing credentials if nothing else set', async () => {
|
test('Assume role with existing credentials if nothing else set', async () => {
|
||||||
|
process.env['ACTIONS_ID_TOKEN_REQUEST_TOKEN'] = undefined;
|
||||||
process.env['AWS_ACCESS_KEY_ID'] = FAKE_ACCESS_KEY_ID;
|
process.env['AWS_ACCESS_KEY_ID'] = FAKE_ACCESS_KEY_ID;
|
||||||
process.env['AWS_SECRET_ACCESS_KEY'] = FAKE_SECRET_ACCESS_KEY;
|
process.env['AWS_SECRET_ACCESS_KEY'] = FAKE_SECRET_ACCESS_KEY;
|
||||||
jest.spyOn(core, 'getInput').mockImplementation(
|
jest.spyOn(core, 'getInput').mockImplementation(
|
||||||
@@ -865,4 +871,23 @@ describe('Configure AWS Credentials', () => {
|
|||||||
|
|
||||||
expect(core.setOutput).toHaveBeenCalledTimes(4);
|
expect(core.setOutput).toHaveBeenCalledTimes(4);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test('prints warning for access key usage and no session token', async () => {
|
||||||
|
jest.spyOn(core, 'getInput').mockImplementation(mockGetInput(ASSUME_ROLE_INPUTS));
|
||||||
|
|
||||||
|
await run();
|
||||||
|
|
||||||
|
expect(core.warning).toHaveBeenCalledWith(
|
||||||
|
'To avoid using long-term AWS credentials, please update your workflows to authenticate using OpenID Connect.' +
|
||||||
|
' See https://s12d.com/gha-oidc-aws for more information.'
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('skips warning for access key usage with session token', async () => {
|
||||||
|
jest.spyOn(core, 'getInput').mockImplementation(mockGetInput(DEFAULT_INPUTS));
|
||||||
|
|
||||||
|
await run();
|
||||||
|
|
||||||
|
expect(core.warning).toHaveBeenCalledTimes(0);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user