Skip to content

Commit fcbb90c

Browse files
authored
[Refactor] AWS IAM Role로 접근 (#283)
* refactor: AWS IAM Role로 접근 * refactor: OIDC 공급자에게 JWT ID 토큰 요청하도록 권한 설정
1 parent a7d2b44 commit fcbb90c

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

.github/workflows/docker-build-develop.yaml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -77,6 +77,9 @@ jobs:
7777
group: deploy
7878
cancel-in-progress: true # 기존 실행 중인 워크플로우는 취소, 새 커밋 기준으로 실행
7979

80+
permissions:
81+
id-token: write
82+
8083
steps:
8184
- name: GitHub Actions Runner의 Public IP 가져오기
8285
run : |
@@ -85,8 +88,7 @@ jobs:
8588
- name: AWS credentials 설정
8689
uses: aws-actions/configure-aws-credentials@v4
8790
with:
88-
aws-access-key-id: ${{ secrets.AWS_IAM_ACCESS_KEY_ID }}
89-
aws-secret-access-key: ${{ secrets.AWS_IAM_SECRET_ACCESS_KEY }}
91+
role-to-assume: ${{ secrets.AWS_IAM_ROLE }}
9092
aws-region: ${{ secrets.AWS_REGION }}
9193

9294
- name: GitHub Actions IP를 인바운드 룰에 임시 추가

0 commit comments

Comments
 (0)