You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions PR任务如何获取AWS角色?sub值应设为多少?

PR事件触发GitHub Actions获取AWS角色的sub配置

当PR事件触发GitHub Actions任务时,对应的token.actions.githubusercontent.com:sub值格式为:
repo:<myorg>/<myrepo>:pull_request

你需要修改AWS角色的信任策略,将PR对应的sub值加入到StringLike规则中,同时保留原有分支任务的配置,修改后的策略示例如下:

"Condition": {
    "StringEquals": {
        "token.actions.githubusercontent.com:aud": "sts.amazonaws.com"
    },
    "StringLike": {
        "token.actions.githubusercontent.com:sub": [
            "repo:<myorg>/<myrepo>:ref:refs/*",
            "repo:<myorg>/<myrepo>:pull_request"
        ]
    }
}

补充说明

  • 如果你的仓库需要接受来自fork仓库的PR并允许其获取AWS角色,对应的sub值为repo:<fork-org>/<fork-repo>:pull_request,可以将该值添加到sub列表中(不建议使用过于宽泛的通配符,避免权限泄露)。
  • PR事件(包括打开、同步、更新PR)触发的任务,sub固定为上述格式,不会包含具体的refs路径。

内容的提问来源于stack exchange,提问作者totooooo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 04:27:03