Skip to content

Use AWS OIDC in prod to push images to ECR#5784

Merged
yau-wd merged 2 commits intoFlowiseAI:mainfrom
natan-hoppe-workday:AWS_OIDC
Feb 24, 2026
Merged

Use AWS OIDC in prod to push images to ECR#5784
yau-wd merged 2 commits intoFlowiseAI:mainfrom
natan-hoppe-workday:AWS_OIDC

Conversation

@natan-hoppe-workday
Copy link
Copy Markdown
Contributor

Overview

Add Production-specific step to the "Docker Image CI - AWS ECR" GitHub workflow enabling use of AWS OIDC IAM role to push to AWS ECR.

The addition of the permission id-token: write is required per documentation, and the action aws-actions/configure-aws-credentials was pinned to version 6 via SHA1 to minimize supply chain attacks.

@gemini-code-assist
Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@harshit-flowise harshit-flowise self-requested a review February 19, 2026 19:30
Copy link
Copy Markdown

@harshit-flowise harshit-flowise left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Solid security improvement. Looks Good to me.

@yau-wd yau-wd self-requested a review February 24, 2026 00:28
@yau-wd yau-wd merged commit 7a3b253 into FlowiseAI:main Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants