AWS Github Oidc Scoped Role

OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM. Covers the non-obvious `job_workflow_ref` condition (vs just `sub` for repo+branch), the Bedrock inference profile ARN patterns, required `aws-marketplace` permissions alongside Bedrock, and the ReadOnlyAccess + explicit Deny pattern for AI agent roles. Use when wiring GitHub Actions to AWS via OIDC.

mizchi cc43e84 2 files · 7.7 KB Updated

File contents

mizchi/skills/tree/main/aws/github-oidc-scoped-role commit cc43e84a9d

Frequently asked questions

npx skillmds@latest add mizchi/aws-github-oidc-scoped-role