5 ms·
Show HN: Stop Putting AWS Credentials in GitHub Secrets
Greetings!
I've created a GitHub action that works that allows GitHub Actions to exchange a GitHub token for AWS Access Credentials.
I've cultivated a few examples of it in action:
https://github.com/saml-to/aws-assume-role-action-examples https://github.com/saml-to/aws-assume-role-action-examples
I've always found management of AWS Credentials has been a pain. So this setting up this Action works like this:
1) A SAML Identity Provider is created in AWS
2) A Role in AWS is set up to trust that Identity Provider
3) A config file is added to the repository indicating which role can be assumed
4) The GitHub Action exchanges the Repo Secret for AWS Credentials using the SAML.to backend for the exchange
Let me know what you think! I'm Happy to take questions and comments here or on Gitter:
https://gitter.im/saml-to/assume-aws-role-action https://gitter.im/saml-to/assume-aws-role-action
- johnnypangs 5y agoDoes anyone know the differences between saml and open id connect? https://docs.github.com/en/enterprise-cloud@latest/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services https://docs.github.com/en/enterprise-cloud@latest/actions/d...
- cnuss 5y agoThey're both Identity Protocols, SAML is older and more widely adopted, OIDC is newer. Kinda the XML vs JSON battle at a Protocol level haha! I've found a lot of SaaS providers only support SAML today, so you're stuck if you want to use GitHub identity outside of OIDC.
- zricethezav 5y agoSpeaking of credentials, you can use https://github.com/zricethezav/gitleaks https://github.com/zricethezav/gitleaks to check if your repos contain any secrets
- cnuss 5y agoThis is awesome! thank you!
- orf 5y agoIsn't it just this? https://awsteele.com/blog/2021/09/15/aws-federation-comes-to-github-actions.html https://awsteele.com/blog/2021/09/15/aws-federation-comes-to... (https://github.com/github/roadmap/issues/249 https://github.com/github/roadmap/issues/249) Why does SAML.to need to be used?
- cnuss 5y agoHey orf! You are correct this GitHub action is at its core is very similar! Even though the initial instructions don't prescribe it, the biggest differentiator is that SAML.to supports a centralized permissions configuration across all repositories for a user, project or organization: https://github.com/saml-to/assume-aws-role-action/blob/main/FAQS.md#i-have-many-repositories-that-need-this-action-but-creating-a-saml-provider-in-aws-per-repository-wont-scale-what-should-i-do https://github.com/saml-to/assume-aws-role-action/blob/main/... Also, this action is the tip of the iceberg of what SAML.to aims to provide (check out https://saml.to https://saml.to), for example: - Store Role Assumption and Privileges as Code (the saml-to.yml config file) - A command line interface to login and assume roles - Free (or affordable) for small teams or individuals - Additional Automations, Webhooks, SCIM, etc Let me know if you have any comments on this and thanks for the question!
- zomglings 5y agoWhat is wrong with putting AWS credentials in GitHub secrets?
- sitharus 5y agoNothing in general, there's just a new and more secure way of doing things. There's no reason to change if you're comfortable with the existing way of doing things. Personally I trust GitHub to get the security right more often than I will.
- cnuss 5y agoHey zomglings! I'll echo what I just responded to nodesocket with, but I'd also love your feedback on my comment: https://news.ycombinator.com/item?id=29986209 https://news.ycombinator.com/item?id=29986209
- jackson1442 5y agoSo I've personally started using this: https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect#configuring-the-oidc-trust-with-the-cloud https://docs.github.com/en/actions/deployment/security-harde... (which appears to be rather similar to saml-to, just with OIDC instead of saml.) The reason being that we try to avoid creating long-lived credentials at all where I work. Everyone uses SSO to sign into AWS with a provisioned IAM role, no one has an IAM user, etc. This means there just _aren't_ credentials floating out there, SSO sessions last 12 hours, and Github gets an OIDC token when it needs one. This means there are no credentials to leak (for the most part- there are some edge cases that necessitate creating an access key), they generally are harder to mix up (each aws account is for a separate business purpose, so there are lots of them), and CloudTrail lists _who_ did every action since SSO adds your email to your IAM identity and devs don't have long-lived service credentials. In short, there's nothing _wrong_ with using Secrets to store your tokens, but it's useful in some cases for cohesion. If you're already handing out long-lived tokens to devs or other services, there's not really any reason to stop doing that with github.
- NovemberWhiskey 5y agoI mean, it's much better than putting them in your source code, but why have a long-lived credential at all if you can avoid it?
- nodesocket 5y agoComplexity, the enemy of security. Why is using GitHub secrets insecure exactly?
- cnuss 5y agoTotally agree re: complexity. My goal is that a few config steps in a GitHub repository and AWS makes a GitHub action able to do a wide variety of things (such as accessing multiple accounts) with very little upstart work. Storing Secrets in GitHub isn't technically insecure, and it's awesome it's provided as a free feature, but it's tedious and fragile. Someone (or something has to do various clicks and copy/pastes or API calls) to upload an access key into GitHub Secrets. It gets even worse if you have multiple accounts and then your Action Workflow file gets really gnarly if you simply pull credentials from ${{ secrets.* }}. Also, if you need to rotate your AWS access tokens, you open up a whole new can of worms, so why not remove credentials all together! Thanks for the question nodesocket, let me know if you have more questions or comments!
- hacker_newz 5y agoWhy does a third party need access to your AWS credentials?
- VectorLock 5y agoTo do stuff in your AWS account.
- nodesocket 5y agoOne of many reasons is pushing containers from GitHub Actions automation to AWS ECR (registry).
- hatware 5y agoIt becomes an anti-pattern when there are more SAML-like, short-lived access approaches available. Do you rotate your keys in secrets regularly?
- cnuss 5y ago
- SahAssar 5y agoThe title "Show HN: Stop Putting AWS Credentials in GitHub Secrets" to me sounds like it's exposing some sort of specific vulunerability or similar but I might just be overreacting because of all the recent hacks. A title like "Show HN: A GitHub action to help using AWS credentials" sounds more appropriate to me, saying what it is and what it does instead of saying what not to do.
- cnuss 5y agoThanks for the feedback SahAssar, sorry if the title caused any latent anxiety! I'll heed your advice for the next time I post something on HN, thank you!
- SahAssar 5y agoNo problem, it was more like morbid curiosity. Writing titles that are direct enough for HN but still enthusiastic and marketable can be hard. I can't find the comment right now, but someone said a good rule is to start with "what it is" then "what it does" and last "why you think it's good"
- wanderer_ 5y agoThis, all of this. I was thinking it was a vuln too, but it's no big deal. At this point the Internet has made us sort of desensitized to clickbait, even accidental ones :] Anyway neat idea!
- mdaniel 5y agoSome observations: * it seems your package.json is still from an old iteration: https://github.com/saml-to/assume-aws-role-action/blob/main/package.json#L8 https://github.com/saml-to/assume-aws-role-action/blob/main/... * it was super opaque where this relative import comes from: https://github.com/saml-to/assume-aws-role-action/blob/main/src/action.ts#L9 https://github.com/saml-to/assume-aws-role-action/blob/main/... but after some sniffing around, it seems to be some openapi generation magick https://github.com/saml-to/assume-aws-role-action/blob/main/package.json#L17 https://github.com/saml-to/assume-aws-role-action/blob/main/... against one of your own API endpoints https://github.com/saml-to/assume-aws-role-action/blob/main/.scaffoldly/services.json#L3 https://github.com/saml-to/assume-aws-role-action/blob/main/... which seems to mean that using this toy is not "self contained" in the way that `sts:AssumeRoleWithWebIdentity` is
- cnuss 5y agoThanks mdaniel for your observations! I updated package.json! On the note of the API endpoint. Yes that's correct, I've fashioned a backend API which handles converting of GitHub Repo Tokens to SAML Assertions: https://sso.saml.to/github/swagger.html#/IDP/AssumeRoleForRepo https://sso.saml.to/github/swagger.html#/IDP/AssumeRoleForRe... And providing a static endpoint for SAML Metadata: https://saml.to/metadata https://saml.to/metadata That being said, you're making my brain click a little bit and this could be converted into a "self contained" toy, with some additional work! The biggest piece of the puzzle is a consistent private key and certificate. If that is of interest to you, could you create a GitHub Issue as a feature request? Thanks!
- TheSpiciestDev 5y agoBut then what would happen if the GitHub token leaks? Would someone then be able to retrieve their own credentials as if they were your CI/CD pipeline? I feel like it be hard to audit that because a baddie would then be able to blend in with your CI/CD pipeline's traffic. But you say you find "management of AWS Credentials a pain", so I guess this isn't for security purposes, right? More of just a convenience? Don't get me wrong, I'm all about lessening the amount of environment variables in a pipeline!.. especially with ones that you want to rotate!
- cnuss 5y agoThe GitHub token that is used is a short-lived token that is generated new every time a GitHub action is run. Ref: https://docs.github.com/en/actions/security-guides/automatic-token-authentication https://docs.github.com/en/actions/security-guides/automatic... And the SAML.to backend first checks to make sure the token is valid by invoking: Ref: https://docs.github.com/en/rest/reference/apps#list-repositories-accessible-to-the-app-installation https://docs.github.com/en/rest/reference/apps#list-reposito... I haven't checked, but I assume GitHub invalidates the token when the GitHub Action finishes
- sirwinsley 5y agoI remember receiving a bill for 5K from Amazon once. When inspecting I realized that someone had found my keys in a public GitHub repo I had and was using my account to mine bitcoins. Thankfully AWS support was understanding and forgave me that amount. Other than never exposing keys like that I learned to never hide admin keys and to always create roles specific to the use case. It doesn’t fully protect you but at least it prevents abuse on your behalf.
- amjadtwofaced 5y ago