🔥 3-day streak
GitHub Actions (GH-200)90 / 142
Question 90 of 142
Your team currently stores a long-lived AWS access key and secret in repository secrets to let a deployment workflow push artifacts to an S3 bucket. Security wants to eliminate stored cloud credentials entirely by using OpenID Connect (OIDC) federation with AWS IAM. Which combination of changes correctly configures the workflow to obtain short-lived AWS credentials via OIDC?
Reviewed for accuracy · Report an issueNext question