GitHub Actions PR任务如何获取AWS角色?sub值应设为多少?
PR事件触发GitHub Actions获取AWS角色的sub配置
当PR事件触发GitHub Actions任务时,对应的token.actions.githubusercontent.com:sub值格式为:repo:<myorg>/<myrepo>:pull_request
你需要修改AWS角色的信任策略,将PR对应的sub值加入到StringLike规则中,同时保留原有分支任务的配置,修改后的策略示例如下:
"Condition": { "StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" }, "StringLike": { "token.actions.githubusercontent.com:sub": [ "repo:<myorg>/<myrepo>:ref:refs/*", "repo:<myorg>/<myrepo>:pull_request" ] } }
补充说明
- 如果你的仓库需要接受来自fork仓库的PR并允许其获取AWS角色,对应的sub值为
repo:<fork-org>/<fork-repo>:pull_request,可以将该值添加到sub列表中(不建议使用过于宽泛的通配符,避免权限泄露)。 - PR事件(包括打开、同步、更新PR)触发的任务,sub固定为上述格式,不会包含具体的refs路径。
内容的提问来源于stack exchange,提问作者totooooo
相关产品推荐
相关产品推荐

