Configuring OIDC Trust for AWS

Not run here: this subsection needs an AWS 24 account, and AWS CloudFormation uses LocalStack 63,725 instead. AWS needs two things from its documentation: an IAM OIDC identity provider for token.actions.githubusercontent.com with the audience sts.amazonaws.com (created once per account in the IAM console, or with aws iam create-open-id-connect-provider), and a role whose trust policy accepts only BookNest's tokens:

Trust policy of a BookNest deployment role (not run here)JSON
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {
      "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com"
    },
    "Action": "sts:AssumeRoleWithWebIdentity",
    "Condition": {
      "StringEquals": {
        "token.actions.githubusercontent.com:aud": "sts.amazonaws.com",
        "token.actions.githubusercontent.com:sub":
          "repo:binarybehemoth@15277380/booknest@1387250434:environment:production"
      }
    }
  }]
}

The sub condition is the security boundary. Pinning it to the production environment means only jobs that passed that environment's reviewers and branch rules (Secrets and Environments) can assume the role. IAM refuses a trust policy for GitHub 29 's provider whose sub is missing or only a wildcard, because repo:* would let any repository on GitHub in; StringLike with repo:binarybehemoth@15277380/booknest@1387250434:* would admit every branch and environment of this one repository. In the production job, aws-actions/configure-aws-credentials@v6 (6.3.0, September 2026), given role-to-assume and aws-region, calls AssumeRoleWithWebIdentity and exports temporary keys, valid for an hour by default, to later steps. No AWS secret is stored in GitHub at all.