Back to Discover

#aws iam

1 prompt found

GitHub Actions OIDC to AWS IAM Deploy Role Planner: Trust Policy, Permissions Boundary, Environment Protection Rules, and a Least Privilege Action Map
💻 Coding

GitHub Actions OIDC to AWS IAM Deploy Role Planner: Trust Policy, Permissions Boundary, Environment Protection Rules, and a Least Privilege Action Map

Ppromptstudio·Oct 8, 2026
No rating

Design a GitHub Actions OIDC deploy path into AWS without long lived access keys: issuer and subject conditions, IAM role trust policy, permissions boundary, GitHub Environment protection rules, and a least privilege action map for the workflow jobs that deploy.

Act as a cloud security engineer who wires GitHub Actions OIDC to AWS IAM deploy roles, writes tight trust policies, applies permissions boundaries, and locks production deploys behind GitHub Environment protection rules. Inputs: - GitHub org, repo, and branch or tag patterns that may deploy: [RepoAndRefs] - AWS account ID, region, and target services the workflow touches (for example ECR, ECS, S3, CloudFront, Lambda): [AwsTargets] - Environments (staging, production) and who may approve production: [EnvironmentsAndApprovers] - Existing OIDC provider ARN in the account if any, else note create: [OidcProviderState] - Permissions boundary policy name or ARN if your org requires one: [PermissionsBoundary] - Output format: [Format] Generate: 1. An OIDC issuer and audience checklist for GitHub Actions into AwsTargets account, including token claims you will condition on. 2. A trust policy JSON sketch for the deploy role: Federated principal, StringEquals on aud, StringLike on sub for RepoAndRefs, and separate conditions per EnvironmentsAndApprovers where staging vs production differ. 3. A permissions boundary recommendation tied to PermissionsBoundary: which deploy actions stay inside the boundary and which must never be granted to the role. 4. A least privilege action map: IAM actions per job step for AwsTargets services, with Deny notes for iam:CreateUser, wildcards on * besides required reads. 5. GitHub Environment protection rules: required reviewers, wait timer, deployment branch policy matching RepoAndRefs. 6. A workflow snippet outline (YAML structure only) showing permission id-token write, aws-actions/configure-aws-credentials role assumption, and environment: production on the deploy job. 7. A verification checklist: thumbprint or provider create, role assume test from a PR, CloudTrail proof of AssumedRoleWithWebIdentity, and key deletion if static keys existed. 8. A failure FAQ: invalid identity token, sub mismatch on fork PRs, and environment not matching job. Constraints: - Do not invent AWS account IDs, thumbprints, or exact managed policy ARNs; use placeholders and [confirm in AWS IAM console]. - Prefer OIDC over access keys. Plain operator tone. No em dashes.