alphagov / govuk-infrastructure

Terraform turnup automation for the EKS Kubernetes clusters that host GOV.UK. See https://github.com/alphagov/govuk-helm-charts for application config.
MIT License
138 stars 24 forks source link

Revert suspected-broken attempt to fix GitHub->ECR IAM authz. #1352

Closed sengi closed 2 months ago

sengi commented 2 months ago

Reverts #1350, #1351, #1353.

Suspect those changes are why GitHub deploy.yml actions started failing like this:

Run aws-actions/configure-aws-credentials@v4
  with:
    role-to-assume: arn:aws:iam::17[2](https://github.com/alphagov/maslow/actions/runs/9601582713/job/26480461933#step:4:2)025368201:role/github_action_ecr_push
    aws-region: eu-west-1
    role-session-name: ecr-push
    audience: sts.amazonaws.com
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Assuming role with OIDC
Error: Could not assume role with OIDC: Not authorized to perform sts:AssumeRoleWithWebIdentity