File tree 2 files changed +12
-8
lines changed
2 files changed +12
-8
lines changed Original file line number Diff line number Diff line change 11
11
env :
12
12
TF_STATE_BUCKET : " stackgen-meetup-terraform-state"
13
13
AWS_REGION : " us-west-2"
14
- STATIC_ASSETS_BUCKET : " stackgen-meetup-static-assets"
15
14
16
15
jobs :
17
16
apply-appstack :
@@ -27,15 +26,15 @@ jobs:
27
26
- name : Configure AWS credentials
28
27
uses : aws-actions/configure-aws-credentials@v4
29
28
with :
30
- aws-access-key-id : ${{ secrets.AWS_ACCESS_KEY_ID }}
31
- aws-secret-access-key : ${{ secrets.AWS_SECRET_ACCESS_KEY }}
32
- aws-session-token : ${{ secrets.AWS_SESSION_TOKEN }}
29
+ # aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
30
+ # aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
31
+ # aws-session-token: ${{ secrets.AWS_SESSION_TOKEN }}
33
32
aws-region : ${{ env.AWS_REGION }}
33
+ role-to-assume : arn:aws:iam::222634395437:role/sep-24-meetup-oidc-github
34
34
35
35
- name : Apply TF Changes
36
36
uses : ./.github/workflows/apply
37
37
with :
38
38
tf_state_bucket : ${{ env.TF_STATE_BUCKET }}
39
39
tf_state_key : ${{ github.repository }}/terraform.tfstate
40
40
aws_region : ${{ env.AWS_REGION }}
41
- static_assets_bucket : ${{ env.STATIC_ASSETS_BUCKET }}
Original file line number Diff line number Diff line change 14
14
15
15
jobs :
16
16
plan :
17
+ permissions :
18
+ id-token : write
19
+ contents : read
20
+ pull-requests : write
17
21
runs-on : ubuntu-latest
18
22
steps :
19
23
- name : Checkout repository
@@ -25,10 +29,11 @@ jobs:
25
29
- name : Configure AWS credentials
26
30
uses : aws-actions/configure-aws-credentials@v4
27
31
with :
28
- aws-access-key-id : ${{ secrets.AWS_ACCESS_KEY_ID }}
29
- aws-secret-access-key : ${{ secrets.AWS_SECRET_ACCESS_KEY }}
30
- aws-session-token : ${{ secrets.AWS_SESSION_TOKEN }}
32
+ # aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
33
+ # aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
34
+ # aws-session-token: ${{ secrets.AWS_SESSION_TOKEN }}
31
35
aws-region : ${{ env.AWS_REGION }}
36
+ role-to-assume : arn:aws:iam::222634395437:role/sep-24-meetup-oidc-github
32
37
33
38
- name : Create backend.tf
34
39
run : |
You can’t perform that action at this time.
0 commit comments