Files
Dave HortonandClaude Opus 5 a6663198da ci: authenticate to AWS via GitHub OIDC using the role_arn credential path (#1582)
This repo is public and held a long-lived AWS access key as repository secrets
(set 2023-11-22). It is replaced with short-lived credentials from the GitHub OIDC
provider; no AWS key and no account id remain in the repo.

create-test-db.js wrote {access_key_id, secret_access_key, aws_region} into the test
database as the aws speech credential, which sends speech-utils' getAwsAuthToken down
its access-key branch and calls GetSessionToken -- rejected by AWS for session
credentials. The role_arn branch calls AssumeRole instead, which accepts them, and is
already plumbed through db-utils.js, call-session.js and stt-task.js. The pinned
speech-utils 0.2.30 already supports it, so no dependency change is needed.

Fork pull requests receive neither secrets nor an OIDC token, so the credentials step
is guarded by a condition; the AWS tests then skip for forks exactly as they do today.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-26 13:53:14 -04:00
..
2025-06-28 15:01:09 -04:00
2025-06-28 15:01:09 -04:00
2023-06-03 08:16:05 -04:00
2020-01-07 10:34:03 -05:00
2023-12-28 14:59:59 -05:00
2023-06-03 09:09:49 -04:00
2023-06-09 14:54:53 -04:00
2023-06-03 08:16:05 -04:00
2023-02-06 08:06:41 -05:00