Skip to content

Commit 51e6095

Browse files
committed
properly accessing secrets
1 parent 4a4ba1b commit 51e6095

File tree

2 files changed

+13
-5
lines changed

2 files changed

+13
-5
lines changed

.github/workflows/deploy.yml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
secrets:
1212
aws-assume-role:
1313
required: true
14+
aws-access-key-id:
15+
required: true
16+
aws-secret-access-key:
17+
required: true
1418

1519
env:
1620
aws-session-name: shc-reader-github-deploy
@@ -31,8 +35,8 @@ jobs:
3135
- name: 'Configure AWS Role'
3236
uses: aws-actions/configure-aws-credentials@v1
3337
with:
34-
aws-access-key-id: ${{ secrets.TERRAFORM_AWS_ACCESS_KEY_ID }}
35-
aws-secret-access-key: ${{ secrets.TERRAFORM_AWS_SECRET_ACCESS_KEY }}
38+
aws-access-key-id: ${{ secrets.aws-access-key-id }}
39+
aws-secret-access-key: ${{ secrets.aws-secret-access-key }}
3640
aws-region: ${{ inputs.aws-region }}
3741
role-to-assume: ${{ secrets.aws-assume-role }}
3842
role-duration-seconds: 1200

.github/workflows/setup.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,16 @@ jobs:
1414
s3-bucket-name: ips-viewer-app
1515
secrets:
1616
aws-assume-role: "${{ secrets.GH_AWS_SERVICE_ROLE_DEV }}"
17+
aws-access-key-id: "${{ secrets.TERRAFORM_AWS_ACCESS_KEY_ID }}"
18+
aws-secret-access-key: "${{ secrets.TERRAFORM_AWS_SECRET_ACCESS_KEY }}"
1719
deploy-prod:
1820
if: contains(github.ref, 'prod')
19-
name: 'Call dev deployment workflow'
21+
name: 'Call prod deployment workflow'
2022
uses: ./.github/workflows/deploy.yml
2123
with:
2224
aws-region: us-east-1
23-
s3-bucket-name: ips-viewer-app
25+
s3-bucket-name: ips-viewer-app-prod
2426
secrets:
25-
aws-assume-role: ${{ secrets.GH_AWS_SERVICE_ROLE_PROD }}
27+
aws-assume-role: "${{ secrets.GH_AWS_SERVICE_ROLE_PROD }}"
28+
aws-access-key-id: "${{ secrets.TERRAFORM_AWS_ACCESS_KEY_ID }}"
29+
aws-secret-access-key: "${{ secrets.TERRAFORM_AWS_SECRET_ACCESS_KEY }}"

0 commit comments

Comments
 (0)