Q: Your GitHub Actions pipeline uses a long-lived AWS Access Key to deploy securely to EKS. The security team mandates that no static long-lived keys can ever be stored in GitHub Secrets due to exfiltration risks. How do you deploy natively without keys?
You must implement OpenID Connect (OIDC) identity federation.
#CI/CD #Additional CI/CD Scenarios #L2 #DevOps #Automation #Pipelines
🎙️ Candidate Opening & Architectural Context
""When developers encounter this build or release bottleneck, my first goal is unblocking velocity safely. The interviewer is testing: OpenID Connect (OIDC) federation.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
You must implement OpenID Connect (OIDC) identity federation.
- In AWS IAM, you natively register GitHub Actions as an authorized OIDC Identity Provider (IdP).
- You create an IAM Role that explicitly trusts this IdP, attaching a Condition specifying that only your specific GitHub repository (
repo:my-org/my-app:*) is allowed to assume it. - In the GitHub Actions YAML, use
aws-actions/configure-aws-credentialsand simply provide the IAM Role ARN.
2️⃣
Remediation & Permanent Safeguards
GitHub dynamically requests a short-lived cryptographic JWT token, presents it natively to AWS STS, and receives temporary session credentials valid exclusively for the exact duration of the execution. There are zero static secrets to rotate or steal.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: In AWS IAM, you natively register GitHub Actions as an authorized OIDC Identity Provider (IdP).."
⚡ 60-Second Elevator Pitch Talking Points
- In AWS IAM, you natively register GitHub Actions as an authorized OIDC Identity Provider (IdP).
- You create an IAM Role that explicitly trusts this IdP, attaching a Condition specifying that onl...
- In the GitHub Actions YAML, use aws-actions/configure-aws-credentials and simply provide the IAM ...
Advertisement