1
0
mirror of synced 2026-01-06 06:02:35 -05:00
Commit Graph

77 Commits

Author SHA1 Message Date
Chris Patterson
35dc4ada2b Removing ForAllValues operator from IAM example
The ForAllValues operator is used. It should be removed, since it applies only to multi-valued condition keys. In this case, the GH “tokens.action.githubusercontent.com:aud/sub” condition keys only have a single value. This will indicate IAM policy warnings to the customer in AWS’s Access Analyzer service since this is incorrect.
2022-05-31 09:30:50 -04:00
Janice
851c46d131 Merge branch 'main' into patch-2 2022-05-19 03:59:05 -07:00
Sophie
886bef2b01 Merge branch 'main' into sophietheking-vscode 2022-05-18 11:16:14 +02:00
Jan Brasna
df102201d4 Fix choosing a runner wording 2022-05-13 02:55:36 +02:00
Matt Pollard
dedbaa7831 GitHub Enterprise Server 3.5 release candidate (#26792) 2022-05-10 18:30:14 +02:00
hubwriter
2a75738469 Merge branch 'main' into sophietheking-vscode 2022-05-10 13:20:55 +02:00
Chris Patterson
d4bb0351f5 Minor change to IAM Policy example
The ForAllValues operator is used. It should be removed, since it applies only to multi-valued condition keys. In this case, the GH “tokens.action.githubusercontent.com:aud/sub” condition keys only have a single value. This will indicate IAM policy warnings to the customer in AWS’s Access Analyzer service since this is incorrect.
2022-04-26 16:58:00 -04:00
Sophie
f0036a724f Merge branch 'main' into sophietheking-vscode 2022-04-21 09:27:35 +02:00
Sophie
ac4c64b683 Merge branch 'main' into sophie-6156-content 2022-04-13 09:14:13 +02:00
Sophie
2a4185cd57 Added variable and consistent use of Visual Studio Code and VS Code 2022-04-12 15:58:44 +02:00
Laura Coursen
35e1d3a68b Add more links to the GHEC trial (#26587) 2022-04-07 09:48:41 -05:00
Matt Pollard
30f2b92798 Merge branch 'main' into sophie-6156-content 2022-04-06 13:53:40 +02:00
Lucas Costi
b49c768777 Version actions for GHES, use reusables (#26004)
Co-authored-by: Kevin Heis <heiskr@users.noreply.github.com>
Co-authored-by: Sarah Edwards <skedwards88@github.com>
2022-04-01 09:36:17 +10:00
Sophie
18edb677c9 Merge branch 'main' into sophie-6156-content 2022-03-17 09:25:19 +01:00
Sophie
74ba23bec7 Change instances of user account to personal account in content 2022-03-16 15:18:37 +01:00
Sarah Edwards
a61ebaa066 point to deployment guidance (#26129) 2022-03-14 15:53:24 +00:00
Lucas Costi
bbe65a24fd Fix deployment category index page versions (#26088) 2022-03-11 09:22:24 +10:00
Martin Lopes
f6ba189334 Update about-security-hardening-with-openid-connect.md (#25825) 2022-03-04 08:31:53 +00:00
Jonathan Tamsut
d04e4046ae bump version for upload-artifact and download-artifact code snippets (#25782) 2022-03-04 10:17:09 +10:00
Robert Sese
79c48070c4 Deprecate 3.0 (#25646)
* Deprecate 3.0

* 3.0 deprecation: remove 3.0 markup (#25647)

* Remove liquid conditionals and content for 3.0 deprecation

* Remove manually, no longer versioned in a supported version

* Remove translations manually, no longer versioned in a supported version

* Remove 'if', now in all supported versions

* Remove dangling 'elseif', now in all supported versions

* Remove dangling 'elseif' and 3.0 screenshot reference, now in all supported versions

* Nudge to latest supported GHES version

* Nudge to latest supported release GHES version

* Bump all the version for the liquid tests

* Bump first deprecated version for linting tests

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Prefer double quotes

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Remove extra newline

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Remove extra newline

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Remove extra newline

Co-authored-by: Laura Coursen <lecoursen@github.com>

* One reusable per line

Co-authored-by: Laura Coursen <lecoursen@github.com>

* One reusable per line

Co-authored-by: Laura Coursen <lecoursen@github.com>

* One reusable per line

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Stray whitespace ✂️

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Version check not needed anymore

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Just 'ghes' since we're deprecating 3.0

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Don't depend on hardcoded versions

Co-authored-by: Laura Coursen <lecoursen@github.com>

* Remove static files for 3.0 deprecation (#25649)

Co-authored-by: Laura Coursen <lecoursen@github.com>
2022-03-03 13:08:24 -06:00
Sophie
50c0b2d0b0 Removed duplicate actions reusable folder 2022-02-25 15:51:14 +01:00
Martin Lopes
d8011df177 Added explanation of subject claim metadata concatenation (#25365)
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
2022-02-17 05:01:48 +00:00
Martin Lopes
54f89a7868 Merge branch 'main' into patch-2 2022-02-16 12:00:27 +10:00
Vanessa
4b8b75e337 GitHub Enterprise Server 3.4 release candidate (#24754)
Co-authored-by: Laura Coursen <lecoursen@github.com>
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
Co-authored-by: Vanessa <vgrl@github.com>
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
Co-authored-by: Lars Schneider <larsxschneider@github.com>
Co-authored-by: Jared Murrell <primetheus@github.com>
Co-authored-by: Jules Parker <19994093+jules-p@users.noreply.github.com>
Co-authored-by: Docubot <67483024+docubot@users.noreply.github.com>
Co-authored-by: Martin Lopes <martin389@github.com>
Co-authored-by: Laura Coursen <lecoursen@github.com>
Co-authored-by: Sarita Iyer <saritai@github.com>
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com>
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
Co-authored-by: hubwriter <hubwriter@github.com>
Co-authored-by: Steve Guntrip <stevecat@github.com>
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
Co-authored-by: Lars Schneider <larsxschneider@github.com>
Co-authored-by: Jared Murrell <primetheus@github.com>
Co-authored-by: github-openapi-bot <69533958+github-openapi-bot@users.noreply.github.com>
Co-authored-by: github-openapi-bot <github-openapi-bot@users.noreply.github.com>
2022-02-15 13:40:37 -05:00
Martin Lopes
ef18efca0b Merge branch 'main' into patch-2 2022-02-15 10:07:05 +10:00
Ramya Parimi
5be744cf8c Merge branch 'main' into patch-2 2022-02-11 11:11:12 -06:00
Martin Lopes
8c726d5e6d Merge branch 'main' into patch-2 2022-02-08 14:42:58 +10:00
Martin Lopes
560193fc74 OIDC - Adding permissions settings (#14998)
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
2022-02-04 00:41:25 +00:00
Martin Lopes
a5dc19c27c Merge branch 'main' into patch-2 2022-02-03 17:35:53 +10:00
Martin Lopes
6e37adac33 Update the OIDC docs (#24828) 2022-02-01 12:07:34 +10:00
Ramya Parimi
e442894d8f Fixing Vale errors in source round 2 (#24393)
* edited reprovision sentence

* vale errors

* fix vale errors

* vale errors

* revert change

* Update content/actions/automating-builds-and-tests/building-and-testing-nodejs.md

Co-authored-by: Vanessa <vgrl@github.com>

* Update content/actions/deployment/deploying-to-your-cloud-provider/deploying-to-google-kubernetes-engine.md

Co-authored-by: Vanessa <vgrl@github.com>

* Update content/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-hashicorp-vault.md

Co-authored-by: Vanessa <vgrl@github.com>

* Update content/organizations/managing-saml-single-sign-on-for-your-organization/managing-team-synchronization-for-your-organization.md

Co-authored-by: Vanessa <vgrl@github.com>

Co-authored-by: Vanessa <vgrl@github.com>
2022-01-24 20:19:41 +00:00
Sarah Edwards
f8e8045bd6 fix indentation (#24414) 2022-01-20 14:05:00 +00:00
Ramya Parimi
41d30aac6a Merge branch 'main' into patch-2 2022-01-14 07:26:36 -06:00
Sarah Edwards
abb2c01e43 Update events that trigger workflows docs (#23954)
Co-authored-by: Jacob Wallraff <thyeggman@github.com>
Co-authored-by: hubwriter <hubwriter@github.com>
2022-01-13 15:12:16 -08:00
Mark Adamson
f8d0cdc51d Fix another typo 2022-01-13 22:36:05 +00:00
Mark Adamson
f745799fa2 Fix typo 'was' vs. 'has' 2022-01-13 22:20:17 +00:00
Tingluo Huang
ec48267807 Suggest customers to use actions/checkout@v2 (#23978)
Co-authored-by: Sarah Edwards <skedwards88@github.com>
2022-01-04 15:33:05 +00:00
hubwriter
0651660f33 Change "workflow templates" to "starter workflows" (#23823)
Co-authored-by: skedwards88 <skedwards88@github.com>
2021-12-21 18:15:54 +00:00
William Tisäter
d7d0b05255 Correctly assign IAM policy bindings
gcloud projects add-iam-policy-binding only take on role per command.
2021-12-21 09:58:23 +01:00
Sarah Edwards
ea861e22ad update frontmatter to reflect reorg (#23829) 2021-12-17 17:55:35 +00:00
Sarah Edwards
2bbbea6058 [Do not merge until starter template PRs merge] Add more Azure starter template guides (#22832)
Co-authored-by: Mike Surowiec <mikesurowiec@users.noreply.github.com>
Co-authored-by: Francis <15894826+francisfuzz@users.noreply.github.com>
Co-authored-by: Tom Gamble <thomasgamble2@gmail.com>
Co-authored-by: Jason Freeberg <jafreebe@microsoft.com>
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
Co-authored-by: Simona Cotin <simona.cotin@microsoft.com>
2021-12-17 08:56:09 -08:00
Rachael Sewell
daafb8cb9d break up large rest pages (#23652) 2021-12-14 20:39:25 +00:00
Matt Pollard
b3e1ff4e89 Update documentation for GitHub AE's December 2021 release (#23405) 2021-12-07 10:36:37 +01:00
Ethan Palm
fcb733492f [GHEC version] Version content about GitHub Actions (#23257)
* Remove extra liquid tags

Reusable contains the same tags that it is wrapped in

* update Using environments for deployment article

* Version Releasing and maintaining actions

* Version Adding self-hosted runners

* Version Removing self-hosted runners

* Version reusables

* Version Managing access to self hosted runners using groups

* Update Adding selfhosted runners

* Update Managing access to selfhosted runners using groups

* Remove enterprise from fpt version

* Update Removing selfhosted runners

* Update reusables
2021-12-03 18:35:59 +00:00
Ari Pollak
ba382b2039 Tweak AWS OIDC instructions (#11621)
* Tweak AWS OIDC instructions

* Only contents: read is necessary
* Remove :aud filter because it's set to "sts.amazonaws.com" when using aws-actions/configure-aws-credentials

* Update to be valid JSON, and actually remove :aud

Co-authored-by: hubwriter <hubwriter@github.com>
2021-11-30 10:34:18 +00:00
KeisukeYamashita
c8218d51b5 Fix list services command in GCP OpenID connect doc (#11506) 2021-11-30 09:27:27 +00:00
Felicity Chapman
8febf7251d Add raw tags around YAML example (#12447) 2021-11-29 11:58:19 +00:00
hubwriter
dc9dab0032 [GA date TBD] Update reusable workflows docs for GA (#22795)
* Update reusable workflows docs

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* Update content/actions/learn-github-actions/reusing-workflows.md

* Update content/actions/learn-github-actions/reusing-workflows.md

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Martin Lopes <martin389@github.com>

* Apply review suggestion from Lucas

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Martin Lopes <martin389@github.com>

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Martin Lopes <martin389@github.com>

* Update content/actions/learn-github-actions/reusing-workflows.md

Co-authored-by: Martin Lopes <martin389@github.com>

* Add information about use of runners

As per review comment from Ajay Krishna Nalisetty

* Update content/actions/learn-github-actions/workflow-syntax-for-github-actions.md

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* Update content/actions/learn-github-actions/workflow-syntax-for-github-actions.md

* Fix version as per Lucas's review comment

* Explain using environment secrets

* Add workflow diagram

* Move explanation of diagram above it

* Slight change to job_workflow-ref description

Include the syntax of the response data, as per
https://github.slack.com/archives/C01SMLA6MNY/p1637731982336700

* Clarify difference between repo and job_workflow_ref

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
Co-authored-by: Martin Lopes <martin389@github.com>
Co-authored-by: Octomerger Bot <63058869+Octomerger@users.noreply.github.com>
2021-11-24 14:26:50 +00:00
Conrad Tötterman
7002fa0ca9 combine best of two worlds 2021-11-19 18:33:58 +02:00
Conrad Tötterman
b092ab95b9 Remove aud from example and ForAllValues
I've tested a wide variety of cases and compared to Cloudtrail Events.

only `sub` is currently sent to and compared in AWS open-id connector for GitHub.
`aud` will *always* be sts.amazonaws.com

So, the IAM trust relationship policy (GitHub OIDC -> AWS) for the role-to-be-assumed should perform conditional checks on `sub` which contains this information:

`"token.actions.githubusercontent.com:sub": "repo:organization-name/repository-name:ref:refs/heads/branch-name"`

If the conditional StringLike is used, wildcard can be used for `branch-name`

There might be other things to touch up on in this README.md to reflect this information
2021-11-19 18:08:23 +02:00