GitHub Actions OIDC 到 AWS 安全部署配置工作流示例name: deploy on: { push: { branches: [ main ] } } permissions: id-token: write contents: read jobs: deploy: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: aws-actions/configure-aws-credentials@v4 with: role-to-assume: arn:aws:iam::123456789012:role/GitHubOIDCRole aws-region: us-east-1 - run: aws s3 sync dist s3://my-bucket --delete 角色信任策略要点允许来自 GitHub 的 OIDC 身份并限定仓库与分支条件总结通过 OIDC 与短期令牌实现无密钥部署,降低凭证泄露风险并提升合规性。

发表评论 取消回复