AWS STS Get-Caller-Identity v4.0.2明文凭证暴露,如何在新版本隐藏?
问题描述
我在GitHub Actions中结合AWS、Terraform使用aws sts get-caller-identity工具做角色验证,步骤配置如下:
- name: Validate Identity with AWS run: aws sts get-caller-identity
当前遇到的问题是,该步骤输出未自动隐藏敏感凭证(如AWS账号ID),直接显示真实信息,存在泄露风险。正常的安全输出示例应为:
{ "UserId": "removed_for_question:removed_for_question", "Account": "***", "Arn": "arn:aws:sts::***:removed_for_question" }
经排查,问题源于configure-aws-credentials的版本差异:旧版本v1.7.0可自动隐藏敏感内容,但升级到v4.0.2后此功能失效。两个版本的配置分别如下:
旧版本v1.7.0配置:
- name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v1.7.0 with: role-to-assume: ${{ secrets.AWS_ROLE }} role-session-name: removed_for_question aws-region: ${{ secrets.AWS_REGION }}
新版本v4.0.2配置:
- name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v4.0.2 with: role-to-assume: ${{ secrets.AWS_ROLE }} role-session-name: removed_for_question aws-region: ${{ secrets.AWS_REGION }}
需要在不回退旧版本的前提下实现凭证隐藏。
解决方法
方法1:手动添加GitHub Actions输出掩码
通过GitHub Actions的::add-mask::命令,将AWS账号ID标记为敏感内容,系统会自动在输出中替换为***。
如果已将账号ID存在GitHub Secrets中,可直接配置:
- name: Mask AWS Account ID run: echo "::add-mask::${AWS_ACCOUNT_ID}" env: AWS_ACCOUNT_ID: ${{ secrets.AWS_ACCOUNT_ID }} - name: Validate Identity with AWS run: aws sts get-caller-identity
若未提前存储账号ID,可先获取再掩码:
- name: Get and Mask AWS Account ID run: | ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text) echo "::add-mask::${ACCOUNT_ID}" - name: Validate Identity with AWS run: aws sts get-caller-identity
方法2:过滤AWS CLI输出,替换敏感字段
直接修改aws sts get-caller-identity的输出内容,用脚本替换敏感部分:
- name: Validate Identity with AWS run: | RESPONSE=$(aws sts get-caller-identity) # 替换Account字段值为*** RESPONSE=$(echo "$RESPONSE" | sed 's/"Account": "[0-9]*"/"Account": "***"/') # 替换Arn中的账号ID部分为*** RESPONSE=$(echo "$RESPONSE" | sed 's/arn:aws:sts::[0-9]*:/arn:aws:sts::***:/') echo "$RESPONSE"
也可以只输出需要验证的非敏感内容,比如只检查角色名称:
- name: Validate Identity with AWS run: aws sts get-caller-identity --query Arn --output text | grep "your-target-role-name"
方法3:启用configure-aws-credentials的内置掩码功能
v4.x版本的configure-aws-credentials支持通过mask-aws-account-id参数开启账号ID自动掩码,只需在配置中添加该参数:
- name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@v4.0.2 with: role-to-assume: ${{ secrets.AWS_ROLE }} role-session-name: removed_for_question aws-region: ${{ secrets.AWS_REGION }} mask-aws-account-id: true
内容的提问来源于stack exchange,提问作者ccohen
相关产品推荐
相关产品推荐

