{"repo":"unfunco/terraform-aws-oidc-github","free":true,"listed":false,"github":"https://github.com/unfunco/terraform-aws-oidc-github","clone":"git clone https://github.com/unfunco/terraform-aws-oidc-github.git","description":"Terraform module to configure GitHub Actions as an OpenID Connect (OIDC) identity provider in AWS.","language":"HCL","stars":117,"topics":["terraform","aws","github","github-actions","oidc","federated-identity","openid-connect","terraform-module","security","amazon-web-services"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"AWS GitHub Actions OIDC Terraform Module Terraform module to configure GitHub Actions as an OpenID Connect (OIDC) identity provider in AWS, allowing GitHub Actions to obtain short-lived credentials by assuming IAM roles directly, and enabling secure authentication between GitHub Actions workflows and AWS resources. 🔨 Getting started Requirements - [Terraform] 1.0+ Installation and usage The following snippet shows the minimum required configuration to create a working OIDC connection between GitHub Actions and AWS. By default, bare github subjects entries are expanded to the ref:refs/heads/main subject. You can set default subject to a different value such as ref:refs/heads/master , pull request , or , but is broader than most projects need. Each github subjects entry can also include an explicit GitHub OIDC subject suffix. That means pull requests do not require default subject = \" \" , and can be allowed explicitly alongside the default branch: To attach additional AWS managed policies to the IAM role, provide the policy name or path after policy/ and the module will generate the correct ARN for the active AWS partition: The following demonstrates how to use GitHub Actions once the Terraform module has been applied to your AWS account. The action receives a JSON Web Token (JWT) from the GitHub OIDC provider and then requests an access token from AWS. Enterprise Cloud Organisations using GitHub Enterprise Cloud can further improve their security posture by setting the enterp","default_branch":null,"files":null,"tree":[],"storefront":"/r/unfunco","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/unfunco/terraform-aws-oidc-github/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}