Files
miti99bot/aws/iam-github-oidc-trust.json
T
tiennm99 fb553cfe93 docs(aws): bootstrap + ops cheatsheets
- aws/README.md: one-time AWS account setup (account ID, IAM, OIDC)
- aws/iam-github-oidc-trust.json: GitHub OIDC trust policy template
- docs/deploy-aws.md: steady-state deployment operations guide
2026-05-10 02:29:52 +07:00

25 lines
699 B
JSON

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::REPLACE_WITH_AWS_ACCOUNT_ID:oidc-provider/token.actions.githubusercontent.com"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"token.actions.githubusercontent.com:aud": "sts.amazonaws.com"
},
"StringLike": {
"token.actions.githubusercontent.com:sub": [
"repo:tiennm99/miti99bot-go:ref:refs/heads/main",
"repo:tiennm99/miti99bot-go:ref:refs/heads/dev",
"repo:tiennm99/miti99bot-go:pull_request"
]
}
}
}
]
}