SShortSingh.
Back to feed

GitHub Actions OIDC Lets Teams Drop Long-Lived AWS Access Keys for Good

0
·1 views

Security-conscious teams can replace static AWS access keys stored in GitHub Actions secrets with short-lived credentials using OpenID Connect (OIDC) federation. GitHub's token service presents a signed JWT to AWS, which trusts it via a configured identity provider rather than a shared secret, with AWS STS then issuing temporary credentials lasting up to one hour by default. A single OIDC provider resource needs to be created only once per AWS account in IAM, pointing to token.actions.githubusercontent.com, and can be shared across all repositories and workflows in that account. The IAM role's trust policy must be tightly scoped using the token's sub claim to a specific repository, branch, and environment to prevent unauthorized roles from being assumed by other workflows. Wildcarding the sub condition — such as allowing any repo in an organization — is flagged as a critical misconfiguration that undermines the security model entirely.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

n8n Workflow Uses Threat Scores and Four Branches to Filter Signup Fraud

A tutorial published on DEV Community outlines a more reliable signup fraud detection workflow built in n8n, replacing simple VPN boolean checks with a 0–100 threat score system. The workflow uses a webhook, a single IP lookup node, an override check, and a Switch node with four output branches covering allow, review, friction, and block actions. Three common failure cases are highlighted: corporate gateways like Zscaler that share IPs across entire workforces, privacy relays such as iCloud Private Relay that do not trigger standard VPN flags, and residential proxies that may evade datacenter-only checks. The IP lookup returns 28 security fields, including proxy and VPN confidence scores, which allow more nuanced routing decisions than a single flag permits. Each security lookup costs 2 credits, meaning a 150,000-credit monthly plan can cover up to 75,000 scored signups, and the author estimates build time at under one hour.

0
ProgrammingDEV Community ·

How to Inspect SSL Certificates and CSRs Safely Without Exposing Internal Data

During a Kubernetes cluster migration, a misconfigured Certificate Signing Request missing wildcard Subject Alternative Names triggered a browser certificate error, highlighting a common operational pitfall. To diagnose such issues, many engineers paste CSRs or certificates into online decoder tools, which poses a significant security risk. Internal certificates often contain sensitive metadata such as hostnames, infrastructure endpoints, and private keys that can be logged or stored by third-party servers. X.509 certificates are ASN.1 data structures encoded in DER binary format and wrapped as PEM files, meaning they can be parsed locally without relying on remote tools. Understanding the underlying Tag-Length-Value structure of these certificates enables developers to inspect them safely in-house, avoiding exposure of internal network topology to unknown parties.

0
ProgrammingDEV Community ·

Five Security Gaps Putting Small Business Remote Workers at Risk

Small businesses running remote or hybrid work arrangements often leave company data exposed through weak passwords, unpatched devices, and untested backups, according to a security guide aimed at non-specialist IT staff. The most impactful first step recommended is enabling multi-factor authentication on business email, since email access can unlock nearly every other account. Phishing risks are heightened for remote workers who lack nearby colleagues to cross-check suspicious messages, making written verification policies for financial requests essential. Businesses should follow the 3-2-1 backup rule and regularly test restores, rather than assuming backups are functional. In New Mexico specifically, the state's Data Breach Notification Act requires businesses holding residents' personal data to maintain reasonable security and notify affected individuals after a breach.

GitHub Actions OIDC Lets Teams Drop Long-Lived AWS Access Keys for Good · ShortSingh