AWS federation comes to GitHub Actions
awsteele.com
awsteele.com
[1]. https://twitter.com/micahhausler/status/1431350884810821637
[1] https://mobile.twitter.com/__steele/status/14379684517173944...
I can recommend checking out his trackiam project too: https://github.com/glassechidna/trackiam
On a side note, are similar things (Assume an IAM role with federation instead of keys) possible at other platforms? Azure Devops perhaps?
https://aws.amazon.com/blogs/opensource/introducing-fine-gra...
In addition, you can just assign IAM roles to the runner EC2 instances themselves, placing ALL of the authentication and authorization in AWS rather than in GitLab. Then the runner will only be able to access the things that you allow through its IAM policy.
Another approach is placing a GitLab runner within AWS and assigning it an IAM role directly. While this isn't as flexible, it is also not as complex to debug why a specific user can't build or deploy a job when another can.
In this scheme, there is potentially a runner per-dev team that has the same exact IAM profile as the dev team.
This can be done using KIAM for EKS runners, or if you are doing docker runners, you can use the "GitLab HA Scaling Runner Vending Machine for AWS EC2 ASG" here: https://gitlab.com/guided-explorations/aws/gitlab-runner-aut...
That last automation is designed to be self-service and can be setup in AWS Service Manager for teams to self-deploy their runners.
The many other benefits to the "GitLab HA Scaling Runner Vending Machine for AWS EC2 ASG" automation are enumerated here: https://gitlab.com/guided-explorations/aws/gitlab-runner-aut...
I'm interested in his teaser comment at the end; here's more about role session tags: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-... So it is looking like he might want to extract some values from the github provided JWT and use that to request more narrowly defined permissions?
Finally, I'm surprised no "JWT is awful and insecure" folks have posted yet, though.
[1]: https://docs.github.com/en/actions/reference/authentication-...
This looks like a great feature to help keep long-lived AWS secrets out of my builds entirely.
If you use Jenkins but want to play with GitHub Actions, my library allows that, plus some other cool things. https://github.com/DontShaveTheYak/jenkins-std-lib
https://support.atlassian.com/bitbucket-cloud/docs/deploy-on...