-
Notifications
You must be signed in to change notification settings - Fork 526
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(ci): aws runner: switch to OIDC-based assuming role #2081
Conversation
Codecov Report
@@ Coverage Diff @@
## main #2081 +/- ##
==========================================
+ Coverage 70.93% 71.04% +0.10%
==========================================
Files 633 635 +2
Lines 81126 81633 +507
==========================================
+ Hits 57548 57993 +445
- Misses 23578 23640 +62
Flags with carried forward coverage won't be shown. Click here to find out more.
📣 Codecov can now indicate which changes are the most critical in Pull Requests. Learn more |
Unluckily, this approach still does not works for pull request from forked repos (the community developers). 😇 Here is the reason:
It’s possible to send write tokens to workflows from pull requests - allows pull requests from forks to use a |
Let's wait for switching to a new CI pipeline, or simply still go with the pull-and-push way. |
Agree. I think we can keep using the manual pull-and-push way mentioned in CONTRIBUTING.md, until switching to new CI pipeline later. |
What's changed and what's your intention?
After this PR, EC2 for CI workflow will be created in the following way, which is recommended by AWS officially.
After that, the community developer should be able to run CI easily. I'll test this later.
References:
Checklist
N/A
Refer to a related PR or issue link (optional)
closes #1339