Skip to content

Commit 14924e2

Browse files
umair-ablyclaude
andcommitted
Add temporary OIDC claims debug workflow
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1 parent becd92c commit 14924e2

1 file changed

Lines changed: 36 additions & 0 deletions

File tree

‎.github/workflows/oidc-debug.yml‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
name: OIDC Debug
2+
3+
# Temporary diagnostic for the post-rename sts:AssumeRoleWithWebIdentity denial.
4+
# Prints the decoded OIDC claims (never the token itself) and attempts to assume
5+
# the new sdk-builds role with the current credentials action.
6+
7+
on:
8+
push:
9+
branches: [debug/oidc-claims]
10+
11+
permissions: {}
12+
13+
jobs:
14+
claims:
15+
runs-on: ubuntu-latest
16+
permissions:
17+
id-token: write
18+
steps:
19+
- name: Print OIDC claims (claims only, no token material)
20+
uses: actions/github-script@v7
21+
with:
22+
script: |
23+
const token = await core.getIDToken('sts.amazonaws.com');
24+
const payload = JSON.parse(Buffer.from(token.split('.')[1], 'base64url').toString());
25+
const { iss, sub, aud, repository, repository_owner, repository_id, ref, event_name } = payload;
26+
console.log(JSON.stringify({ iss, sub, aud, repository, repository_owner, repository_id, ref, event_name }, null, 2));
27+
28+
- name: Assume new sdk-builds role (configure-aws-credentials v4)
29+
uses: aws-actions/configure-aws-credentials@v4
30+
with:
31+
aws-region: eu-west-2
32+
role-to-assume: arn:aws:iam::${{ secrets.ABLY_AWS_ACCOUNT_ID_SDK }}:role/ably-sdk-builds-ably-pubsub-ruby
33+
role-session-name: oidc-debug
34+
35+
- name: Confirm assumed identity
36+
run: aws sts get-caller-identity

0 commit comments

Comments
 (0)