Authenticating GitHub Actions to AWS Without Access Keys
Learn how to use OpenID Connect (OIDC) for GitHub Actions to obtain short-lived AWS credentials securely without key rotation.

Stock photo for illustration only, not from the actual event
- Authenticate GitHub Actions to AWS using OIDC without static access keys
- Configure the Identity Provider once per AWS account
- Control access using Trust Policies specifying allowed repositories and branches
- Workflows receive temporary credentials that expire automatically after the run
While working with GitHub Actions, developers can utilize OpenID Connect (OIDC) to authenticate directly to AWS. This approach allows workflows to acquire short-lived AWS credentials dynamically for each individual run, completely eliminating the need to store long-lived static access keys.
This method significantly improves security by removing the burden of rotating or managing persistent credentials that carry long-term risks. To get started in the AWS Console, navigate to IAM, select Identity providers, and add a new provider.
- This setup needs to be performed only once per AWS account
- Every role utilized by your workflows can share this single provider
- Navigate to IAM, select Roles, and click Create role
- Choose Web identity and select the newly created provider with the sts.amazonaws.com audience

Stock photo for illustration only, not from the actual event
Next, the trust policy controls precisely which GitHub repository and branch are permitted to assume this role. The policy structure must explicitly define these boundaries, accompanied by an attached permission policy limited strictly to the required actions, such as listing and uploading files to a single S3 bucket.
Adopting OIDC for cloud authentication represents a modern security best practice that eliminates hardcoded secrets in source control. By issuing ultra-short-lived tokens, organizations drastically minimize the attack surface, ensuring that even if credentials are intercepted, they quickly become invalid.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment