-

Your workflow has
id-token: write. The role ARN is right. The trust policy looks exactly like the one in every tutorial. Andaws-actions/configure-aws-credentialsstill tells you to get lost:Not authorized to perform sts:AssumeRoleWithWebIdentityNothing changed on the AWS side. Nothing changed in the workflow. So what broke?
The thing that changed was GitHub
GitHub now issues immutable OIDC subject claims for some repositories — new repos created after the rollout, plus repos that opted in, were renamed, or were transferred. The
subclaim quietly grew a pair of numeric IDs: -
Creating the Pipeline Execution Role
To deploy your Hugo site to AWS S3 using GitHub Actions OIDC, you’ll need to set up a specific IAM role. Here’s a step-by-step guide to creating and configuring this role.
Step 1: Configure the OIDC Provider
First, you need to create an OIDC provider in AWS IAM if you haven’t already:
- Navigate to the AWS IAM Console
- Go to Identity Providers
- Click “Add Provider”
- Select “OpenID Connect”
- For the Provider URL, enter:
https://token.actions.githubusercontent.com - For the Audience, enter:
sts.amazonaws.com - Click “Add provider”
Step 2: Create the IAM Role
- Go to IAM Roles in the AWS Console
- Click “Create Role”
- Select “Web Identity”
- Choose the GitHub OIDC provider you just created
- For the Audience, select
sts.amazonaws.com - Add the following trust relationship:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::<YOUR-AWS-ACCOUNT-ID>:oidc-provider/token.actions.githubusercontent.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" }, "StringLike": { "token.actions.githubusercontent.com:sub": "repo:<GITHUB-USERNAME>/<REPOSITORY-NAME>:*" } } } ] }Replace:
-
Looking to automate your Hugo website deployments to AWS S3? The
hugo-to-s3-action-oidcGitHub Action makes this process seamless by handling both the build and deployment in a single step, all while using secure OIDC authentication.Prerequisites
Before you begin, ensure you have:
- A Hugo website in a GitHub repository
- An AWS S3 bucket set up for static website hosting
- AWS configured with GitHub OIDC authentication
- Appropriate IAM roles and permissions
For detailed instructions on setting up OIDC in AWS, refer to the official GitHub documentation.