Skip to content

Where should OIDC role ARN be stored? #695

Answered by peterwoodworth
niyatim23 asked this question in Q&A
Discussion options

You must be logged in to vote

Hey @niyatim23,

I'm not a security expert - so please contact the right internal teams for the best possible guidance here.

For my relatively uninformed answer compared to what you might get from dedicated internal teams (please take this with a grain of salt) - in theory the role arn can be public with no security concerns. With a secure trust policy on the OIDC role you should be completely safe from any actors being able to somehow obtain a valid token.

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by niyatim23
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants