GitHub Actions OIDC Lets Teams Drop Long-Lived AWS Access Keys for Good
Security-conscious teams can replace static AWS access keys stored in GitHub Actions secrets with short-lived credentials using OpenID Connect (OIDC) federation. GitHub's token service presents a signed JWT to AWS, which trusts it via a configured identity provider rather than a shared secret, with AWS STS then issuing temporary credentials lasting up to one hour by default. A single OIDC provider resource needs to be created only once per AWS account in IAM, pointing to token.actions.githubusercontent.com, and can be shared across all repositories and workflows in that account. The IAM role's trust policy must be tightly scoped using the token's sub claim to a specific repository, branch, and environment to prevent unauthorized roles from being assumed by other workflows. Wildcarding the sub condition — such as allowing any repo in an organization — is flagged as a critical misconfiguration that undermines the security model entirely.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in