⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All CI/CD & GitOps Interview Questions Scenario 139 of 176 in CI/CD & GitOps
Senior DevOps / SRE CI/CD Cloud Security & Identity Federation Security Hardening

Q: Your engineering org has 200 GitHub repositories deploying infrastructure to AWS. Storing static AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY in GitHub repository secrets exposes severe risks of credential theft and token leaks. How do you completely eliminate static cloud credentials in GitHub Actions using OpenID Connect (OIDC) and AWS IAM role assumption?

Engineering a zero-static-credential deployment pipeline from GitHub Actions to AWS utilizing OpenID Connect (OIDC) identity federation, dynamic STS token generation, and repository-scoped trust policies.

#CI/CD #GitHub Actions #OIDC #AWS #IAM #Security #Zero Trust
🎙️ Candidate Opening & Architectural Context
"Static AWS credentials stored in GitHub repository secrets are a massive attack vector—they never expire, lack contextual guardrails, and are frequently leaked in workflow logs. We migrated our entire organization to GitHub Actions OIDC identity federation with AWS IAM."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Create GitHub OIDC Identity Provider in AWS IAM

Establish cryptographic trust between AWS and GitHub Actions:

  • IAM OIDC Provider: Created OpenID Connect provider in AWS: URL https://token.actions.githubusercontent.com, Audience sts.amazonaws.com.
  • Thumbprint Validation: Registered GitHub's public certificate thumbprint (6938fd4d98bab03faadb97b34396831e3780aea1).
Pro Tip: The OIDC Identity Provider allows AWS STS to cryptographically verify JSON Web Tokens (JWT) signed by GitHub.
2️⃣

Configure Scoped AWS IAM Role Trust Policy

Restrict role assumption strictly to specific repositories and branches:

  • Trust Policy JSON: Configured Principal: { Federated: 'arn:aws:iam::ACCOUNT:oidc-provider/token.actions.githubusercontent.com' } with Action: 'sts:AssumeRoleWithWebIdentity'.
  • Condition Keys: Enforced strict boundary: Condition: { StringEquals: { 'token.actions.githubusercontent.com:aud': 'sts.amazonaws.com' }, StringLike: { 'token.actions.githubusercontent.com:sub': 'repo:my-org/payment-service:ref:refs/heads/main' } }.
Pro Tip: Strictly validating the 'sub' (subject) claim ensures that other GitHub users or pull requests from unauthorized branches cannot assume your production AWS role.
Advertisement
3️⃣

Configure GitHub Actions Workflow Permissions & Assume Role Step

Equip the workflow to request OIDC tokens and assume the IAM role:

  • Workflow Permissions: Declared top-level permissions: permissions: { id-token: write, contents: read }.
  • AWS Auth Action: Integrated official action: uses: aws-actions/configure-aws-credentials@v4 with: { role-to-assume: 'arn:aws:iam::ACCOUNT:role/github-deploy-role', aws-region: 'us-east-1' }.
Pro Tip: Setting permissions: id-token: write authorizes GitHub's OIDC provider to mint a unique, short-lived JWT for the running job.
4️⃣

Verify Ephemeral Token Generation & Delete Legacy Static Secrets

Confirm successful deployment and purge static IAM access keys:

  • Token Exchange: Workflow automatically exchanges the GitHub JWT for temporary 1-hour AWS STS session credentials.
  • Purge Static Secrets: Deleted all AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY entries from GitHub repository and organization secrets.
  • Security Posture: Completely eliminated credential leak vectors with zero ongoing credential rotation overhead.
Pro Tip: Temporary STS credentials expire automatically after the workflow job completes, leaving zero residue for attackers.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"GitHub Actions OIDC federation replaces dangerous static AWS access keys with short-lived STS credentials, enforced by repository-scoped IAM trust conditions and zero stored secrets."
⚡ 60-Second Elevator Pitch Talking Points
  • Create an OIDC Identity Provider in AWS IAM trusting token.actions.githubusercontent.com.
  • Define an IAM role with trust conditions validating the exact GitHub repository and branch.
  • Configure GitHub Actions with permissions: id-token: write and aws-actions/configure-aws-credentials.
  • Delete all static AWS access keys from GitHub secrets permanently.
Advertisement
Want more CI/CD & GitOps scenarios?
Explore our complete collection of scenario-based CI/CD & GitOps interview runbooks.
Browse All CI/CD & GitOps Questions →