From 1f69a5f9c915c41101b6f1480e703b2a0b3d75a3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tarik=20Demirovi=C4=87?= Date: Tue, 7 May 2024 15:00:42 +0200 Subject: [PATCH 1/2] Update generalized-deploy.yaml to use IAM role --- .github/workflows/generalized-deploy.yaml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/.github/workflows/generalized-deploy.yaml b/.github/workflows/generalized-deploy.yaml index 2db93a31..e41a2e6f 100644 --- a/.github/workflows/generalized-deploy.yaml +++ b/.github/workflows/generalized-deploy.yaml @@ -16,9 +16,7 @@ jobs: - name: Configure AWS Credentials uses: aws-actions/configure-aws-credentials@v1 with: - aws-access-key-id: ${{ secrets.GDBP_AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.GDBP_AWS_SECRET_ACCESS_KEY }} + role-to-assume: ${{ secrets.GDBP_AWS_IAM_ROLE_ARN }} aws-region: us-west-2 - commit: ${{ github.sha }} - name: Challenge Bypass Server Deployments - uses: brave-intl/general-docker-build-pipeline-action@v1.0.9 \ No newline at end of file + uses: brave-intl/general-docker-build-pipeline-action@v1.0.9 From 2f6c8365348bd380bfe569dec0e49387f1e6d740 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tarik=20Demirovi=C4=87?= Date: Tue, 7 May 2024 15:01:24 +0200 Subject: [PATCH 2/2] Update generalized-deploy.yaml --- .github/workflows/generalized-deploy.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/generalized-deploy.yaml b/.github/workflows/generalized-deploy.yaml index e41a2e6f..d40f6c70 100644 --- a/.github/workflows/generalized-deploy.yaml +++ b/.github/workflows/generalized-deploy.yaml @@ -10,6 +10,9 @@ jobs: push: name: Invoke Challenge By Pass Docker Build Pipeline runs-on: ubuntu-latest + permissions: + id-token: write + contents: read steps: - name: Checkout uses: actions/checkout@v2