Skip to content

Commit da33050

Browse files
authored
Merge pull request #3050 from aws-observability/update-cn-release-to-use-role
assume role using OIDC instead of long-term creds
2 parents 2a9454e + e9ebb37 commit da33050

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

.github/workflows/ssm-release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -263,8 +263,8 @@ jobs:
263263
- name: Configure AWS Credentials for CN regions
264264
uses: aws-actions/configure-aws-credentials@v4
265265
with:
266-
aws-access-key-id: ${{ secrets.RELEASE_CN_KEY_ID }}
267-
aws-secret-access-key: ${{ secrets.RELEASE_CN_SECRET }}
266+
role-to-assume: ${{ secrets.COLLECTOR_PROD_RELEASE_CN_ROLE_ARN }}
267+
audience: sts.amazonaws.com.cn
268268
aws-region: cn-north-1
269269

270270
- name: Copy SSM package to S3 in CN regions

0 commit comments

Comments
 (0)