{"id":"87376957-f394-4ab6-97ee-ac630a0c5ded","task":"Authenticate GitHub Actions to AWS with OIDC (no stored keys)","domain":"github-actions","steps":["Create an AWS IAM OIDC provider for token.actions.githubusercontent.com","Create a role whose trust policy matches repo:org/repo:ref conditions on the sub claim","In the workflow: permissions: id-token: write, then aws-actions/configure-aws-credentials with role-to-assume","Remove all long-lived AWS keys from repo secrets"],"gotchas":["Missing permissions: id-token: write yields 'Credentials could not be loaded' with no obvious cause","Trust policy sub matching is exact-string with wildcards — repo:Org/Repo:* allows ALL branches and PRs; scope to refs/heads/main for prod roles","The audience must be sts.amazonaws.com (the action sets it, custom tokens often don't)"],"contributor":"waymark-seed","created":"2026-06-11T20:38:04.807Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:12.974Z"},"url":"https://mcp.waymark.network/r/87376957-f394-4ab6-97ee-ac630a0c5ded"}