Skip to content

Commit

Permalink
Merge pull request #817 from makerdao/TECH-3250-set-role
Browse files Browse the repository at this point in the history
Use AWS role
  • Loading branch information
jeannettemcd authored Jun 14, 2024
2 parents eabe962 + 277e628 commit 5cadc8a
Show file tree
Hide file tree
Showing 4 changed files with 24 additions and 8 deletions.
8 changes: 6 additions & 2 deletions .github/workflows/angular-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ on:
- ".github/workflows/angular-dev.yml"
- "helm/staging/frontend*"

permissions:
id-token: write
contents: read

jobs:
build:
runs-on: ubuntu-latest
Expand All @@ -25,8 +29,8 @@ jobs:
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.STAGING_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.STAGING_AWS_SECRET_ACCESS_KEY }}
role-to-assume: ${{ secrets.GA_OIDC_EKS_STAGING }}
role-session-name: AngularDevMips
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/angular-prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ on:
- ".github/workflows/angular-prod.yml"
- "helm/prod/frontend*"

permissions:
id-token: write
contents: read

jobs:
build:
runs-on: ubuntu-latest
Expand All @@ -25,8 +29,8 @@ jobs:
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.PROD_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.PROD_AWS_SECRET_ACCESS_KEY }}
role-to-assume: ${{ secrets.GA_OIDC_EKS_PROD }}
role-session-name: AngularProdMips
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/node.js-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ on:
- ".github/workflows/node.js-dev.yml"
- "helm/staging/backend*"

permissions:
id-token: write
contents: read

jobs:
build-deploy:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -39,8 +43,8 @@ jobs:
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.STAGING_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.STAGING_AWS_SECRET_ACCESS_KEY }}
role-to-assume: ${{ secrets.GA_OIDC_EKS_STAGING }}
role-session-name: NodeDevMips
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/node.js-prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ on:
- ".github/workflows/node.js-prod.yml"
- "helm/prod/backend*"

permissions:
id-token: write
contents: read

jobs:
build-deploy:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -39,8 +43,8 @@ jobs:
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.PROD_AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.PROD_AWS_SECRET_ACCESS_KEY }}
role-to-assume: ${{ secrets.GA_OIDC_EKS_PROD }}
role-session-name: NodeProdMips
aws-region: ${{ env.REGION }}

- name: Login to AWS ECR
Expand Down

0 comments on commit 5cadc8a

Please sign in to comment.