Q: Your engineering org has 200 GitHub repositories deploying infrastructure to AWS. Storing static AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY in GitHub repository secrets exposes severe risks of credential theft and token leaks. How do you completely eliminate static cloud credentials in GitHub Actions using OpenID Connect (OIDC) and AWS IAM role assumption?
Engineering a zero-static-credential deployment pipeline from GitHub Actions to AWS utilizing OpenID Connect (OIDC) identity federation, dynamic STS token generation, and repository-scoped trust policies.
Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Create GitHub OIDC Identity Provider in AWS IAM
Establish cryptographic trust between AWS and GitHub Actions:
- IAM OIDC Provider: Created OpenID Connect provider in AWS: URL
https://token.actions.githubusercontent.com, Audiencests.amazonaws.com. - Thumbprint Validation: Registered GitHub's public certificate thumbprint (
6938fd4d98bab03faadb97b34396831e3780aea1).
Configure Scoped AWS IAM Role Trust Policy
Restrict role assumption strictly to specific repositories and branches:
- Trust Policy JSON: Configured
Principal: { Federated: 'arn:aws:iam::ACCOUNT:oidc-provider/token.actions.githubusercontent.com' }withAction: 'sts:AssumeRoleWithWebIdentity'. - Condition Keys: Enforced strict boundary:
Condition: { StringEquals: { 'token.actions.githubusercontent.com:aud': 'sts.amazonaws.com' }, StringLike: { 'token.actions.githubusercontent.com:sub': 'repo:my-org/payment-service:ref:refs/heads/main' } }.
Configure GitHub Actions Workflow Permissions & Assume Role Step
Equip the workflow to request OIDC tokens and assume the IAM role:
- Workflow Permissions: Declared top-level permissions:
permissions: { id-token: write, contents: read }. - AWS Auth Action: Integrated official action:
uses: aws-actions/configure-aws-credentials@v4 with: { role-to-assume: 'arn:aws:iam::ACCOUNT:role/github-deploy-role', aws-region: 'us-east-1' }.
Verify Ephemeral Token Generation & Delete Legacy Static Secrets
Confirm successful deployment and purge static IAM access keys:
- Token Exchange: Workflow automatically exchanges the GitHub JWT for temporary 1-hour AWS STS session credentials.
- Purge Static Secrets: Deleted all AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY entries from GitHub repository and organization secrets.
- Security Posture: Completely eliminated credential leak vectors with zero ongoing credential rotation overhead.
- Create an OIDC Identity Provider in AWS IAM trusting token.actions.githubusercontent.com.
- Define an IAM role with trust conditions validating the exact GitHub repository and branch.
- Configure GitHub Actions with permissions: id-token: write and aws-actions/configure-aws-credentials.
- Delete all static AWS access keys from GitHub secrets permanently.