Skip to content

Commit

Permalink
Chore: update AWS action (safe-global#3658)
Browse files Browse the repository at this point in the history
* Chore: update AWS action

* Add permissions

* Move permissions to the job

* Move permissions higher
  • Loading branch information
katspaugh authored May 6, 2024
1 parent afa8d22 commit f6108fe
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 8 deletions.
8 changes: 4 additions & 4 deletions .github/workflows/deploy-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ jobs:
runs-on: ubuntu-latest
permissions:
pull-requests: write
id-token: write

name: Deploy to dev/staging

Expand Down Expand Up @@ -45,11 +46,10 @@ jobs:
- uses: ./.github/workflows/build-storybook

- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v1
uses: aws-actions/configure-aws-credentials@v3
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ secrets.AWS_DEFAULT_REGION }}
role-to-assume: ${{ secrets.AWS_ROLE }}
aws-region: ${{ secrets.AWS_REGION }}

# Staging
- name: Deploy to the staging S3
Expand Down
10 changes: 6 additions & 4 deletions .github/workflows/deploy-production.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:

jobs:
release:
permissions:
id-token: write

runs-on: ubuntu-latest
name: Deploy release
env:
Expand Down Expand Up @@ -47,11 +50,10 @@ jobs:
GITHUB_TOKEN: ${{ github.token }}

- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v1
uses: aws-actions/configure-aws-credentials@v3
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ secrets.AWS_DEFAULT_REGION }}
role-to-assume: ${{ secrets.AWS_ROLE }}
aws-region: ${{ secrets.AWS_REGION }}

# Script to upload release files
- name: 'Upload release build files for production'
Expand Down

0 comments on commit f6108fe

Please sign in to comment.