Q: You use GitHub Actions to deploy to AWS. Currently, you store long-lived AWS IAM Access Keys as GitHub Repository Secrets. Why is this an anti-pattern, and what is the modern, secure alternative?
Storing long-lived static credentials in a third-party CI/CD platform is an anti-pattern because if the platform is compromised (or a dev...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
Storing long-lived static credentials in a third-party CI/CD platform is an anti-pattern because if the platform is compromised (or a developer accidentally dumps the environment variables in a CI log), the keys are permanently exposed until manually revoked. The modern, secure alternative is OIDC (OpenID Connect) Federation. Instead of storing static keys, you configure an OIDC Identity Provider in AWS that trusts GitHub's token authority. In the GitHub Action, the pipeline requests a short-lived OIDC JSON Web Token from GitHub, cryptographically proving it represents a specific repository and branch. The pipeline sends this JWT to AWS STS via AssumeRoleWithWebIdentity. AWS validates the token signature and returns short-lived, temporary session credentials valid only for the duration of the deployment. Zero permanent secrets are stored anywhere.
- Immediate Triage: Storing long-lived static credentials in a third-party CI/CD platform is an anti-pattern becaus
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.