Skip to content

switch aws creds to role-based #6

switch aws creds to role-based

switch aws creds to role-based #6

Workflow file for this run

name: (DEV) Build and deploy all images
on:
push:
branches:
- 'master'
permissions:
id-token: write
contents: read
jobs:
build:
name: Build Images
runs-on: ubuntu-latest
strategy:
matrix:
include:
- repository: RATE_ORACLE
dockerfile: rate-oracle.dockerfile
- repository: CRDAO_API
dockerfile: api.dockerfile
- repository: CRDAO_HANDLER
dockerfile: handler.dockerfile
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ACCESS_ROLE_DEV }}
role-session-name: GitHub_to_AWS_via_FederatedOIDC
aws-region: ${{ secrets.AWS_REGION }}
- name: Login to Amazon ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@v2
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: |
${{ steps.login-ecr.outputs.registry }}/${{ secrets[format('ECR_REPOSITORY_{0}', matrix.repository)] }}
tags: |
type=sha
type=raw,value=latest
- name: Build and push up
uses: docker/build-push-action@v5
with:
file: infra/docker/${{ matrix.dockerfile }}
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}