Adding Roles
Last updated
Ensure SAML.to is installed to your GitHub Organization or User Account
Navigate to AWS IAM Roles
Click Create Role
Trusted entity type: SAML 2.0 federation
SAML 2.0-based provider: Choose the provider.
If SAML.to isn't in the list, add SAML.to to the AWS account first.
Allow programmatic and AWS Management Console access
Attribute: SAML:aud
Value: https://signin.aws.amazon.com/saml
Continue the remaining steps to create the role
Copy the Role ARN
Copy the Provider ARN of SAML.to from AWS IAM Providers
If SAML.to isn't in the list, add SAML.to to the AWS account first.
Choose a role in AWS IAM Roles
Click the Trust Relationships tab
Click Edit trust policy
Add a Statement, update the policy, and make note of the Provider ARN
{
"Effect": "Allow",
"Principal": {
"Federated": "THE_PROVIDER_ARN"
},
"Action": "sts:AssumeRoleWithSAML",
"Condition": {
"StringEquals": {
"SAML:aud": "https://signin.aws.amazon.com/saml"
}
}
}Add the following the following block to permissions.aws.roles to saml-to.yml:
- name: THE-ROLE-ARN
provider:
variables:
providerArn: THE-PROVIDER-ARN
users:
github:
- some-github-user
- another-github-user
repos:
github:
- some-repo
- another-org/some-other-repo
Last updated