Update OIDC roles to use session tokens #337
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Rolling out using OIDC session tokens in all buildkite pipelines that assume IAM roles.
Context
Notably rolls out https://github.com/buildkite/terraform-modules/pull/60 in alignment with our incident 486 findings.
This moves everyone away from the glob matching sub claims and over to session tokens, from https://github.com/buildkite/terraform-modules/pull/56
The IAM role trust policies are being updated in buildkite-dev account in PR: https://github.com/buildkite/aws-buildkite-dev/pull/468 - this will need to be merged and applied before any of these pipeline.yml changes work.
Changes
Update plugin version to one that supports session tags, and add session tag requirements to it.
Testing
Once the IAM change is merged and applied, I'll retry the build and ensure it is GREEN before merging. This has worked in other pipelines.