Skip to content

Conversation

d4l3k
Copy link
Member

@d4l3k d4l3k commented Oct 14, 2021

Test plan:

@d4l3k d4l3k marked this pull request as draft October 14, 2021 21:42
@d4l3k d4l3k changed the title CI: use OIDC CI: use OIDC (pr) Oct 14, 2021
@d4l3k d4l3k closed this Oct 14, 2021
@d4l3k d4l3k mentioned this pull request Oct 14, 2021
facebook-github-bot pushed a commit that referenced this pull request Oct 15, 2021
Summary:
This switches our integration tests to use the GitHub OpenID Connect credentials provider instead of using hard coded AWS session tokens. This will issue tokens that last for 1 hour so should be a lot more secure (and trackable) than before.

https://awsteele.com/blog/2021/09/15/aws-federation-comes-to-github-actions.html

Pull Request resolved: #256

Test Plan:
CI

created PR from external repo to verify they can't generate tokens #257

Reviewed By: kiukchung

Differential Revision: D31674489

Pulled By: d4l3k

fbshipit-source-id: 5936c64794816eb9fafe76899af44e2f865c64df
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant