AWS static credentials
With static credentials, Stategraph Orchestration reaches AWS with the access keys of an IAM user. It gets a first plan running quickly. For production, OIDC replaces stored keys with short-lived tokens.
Setup has two steps:
- Create the IAM user and its access keys with the AWS CLI.
- Store the keys as GitHub secrets with the GitHub CLI, or as GitLab CI/CD variables in the GitLab UI.
The runner gets the keys as environment variables, and the AWS provider reads them there. See Variables.
Setup steps
- Create a dedicated IAM user for Orchestration:
aws iam create-user --user-name stategraph
- Attach a permissions policy to the user.
PowerUserAccessis a starting point for testing and development. For production, use a custom policy that grants only the permissions that Orchestration needs.
aws iam attach-user-policy \
--policy-arn arn:aws:iam::aws:policy/PowerUserAccess \
--user-name stategraph
- Create access keys for the user:
aws iam create-access-key --user-name stategraph
Output:
{
"AccessKey": {
"UserName": "stategraph",
"AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
"Status": "Active",
"SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
}
}
Copy AccessKeyId and SecretAccessKey. AWS shows the secret access key only one time.
- Store the access keys for your VCS, as below. Then Orchestration can run
stategraph planandstategraph applyagainst your AWS resources.
GitHub
Add the keys as secrets to your GitHub repository. Paste the values from the previous step when the CLI asks for them.
export REPO="your-org/your-repo"
gh secret --repo "$REPO" set AWS_ACCESS_KEY_ID
gh secret --repo "$REPO" set AWS_SECRET_ACCESS_KEY
GitLab
Add the keys as CI/CD variables on your GitLab project:
- Open your GitLab project and go to Settings, then CI/CD, then Variables.
- Click Add variable.
- Enter the Key
AWS_ACCESS_KEY_IDand paste the Value from the previous step. - Mark the variable as masked, and leave Protect variable cleared.
- Click Add variable, then do the same for
AWS_SECRET_ACCESS_KEY.
GitLab passes protected variables only to pipelines on protected branches. Orchestration runs plans on the merge request's source branch, so those runs do not get a protected variable. To share the keys across projects, add the variables to the GitLab group.
Security considerations
Access keys are long-lived secrets:
- Create new access keys periodically, and delete the old ones.
- Use AWS CloudTrail to review what the
stategraphuser does. - Keep hooks and workflow steps from printing the keys.
Next Steps
- Configuration: customize workflows in
.stategraph/config.yml - AWS OIDC: migrate to keyless authentication
- Cloud credentials: credential patterns across providers