AWS static credentials

With static credentials, Stategraph Orchestration reaches AWS with the access keys of an IAM user. It gets a first plan running quickly. For production, OIDC replaces stored keys with short-lived tokens.

Setup has two steps:

  1. Create the IAM user and its access keys with the AWS CLI.
  2. Store the keys as GitHub secrets with the GitHub CLI, or as GitLab CI/CD variables in the GitLab UI.

The runner gets the keys as environment variables, and the AWS provider reads them there. See Variables.

Setup steps

  1. Create a dedicated IAM user for Orchestration:
aws iam create-user --user-name stategraph
  1. Attach a permissions policy to the user. PowerUserAccess is a starting point for testing and development. For production, use a custom policy that grants only the permissions that Orchestration needs.
aws iam attach-user-policy \
--policy-arn arn:aws:iam::aws:policy/PowerUserAccess \
--user-name stategraph
  1. Create access keys for the user:
aws iam create-access-key --user-name stategraph

Output:

{
  "AccessKey": {
    "UserName": "stategraph",
    "AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "Status": "Active",
    "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
  }
}

Copy AccessKeyId and SecretAccessKey. AWS shows the secret access key only one time.

  1. Store the access keys for your VCS, as below. Then Orchestration can run stategraph plan and stategraph apply against your AWS resources.

GitHub

Add the keys as secrets to your GitHub repository. Paste the values from the previous step when the CLI asks for them.

export REPO="your-org/your-repo"

gh secret --repo "$REPO" set AWS_ACCESS_KEY_ID
gh secret --repo "$REPO" set AWS_SECRET_ACCESS_KEY

GitLab

Add the keys as CI/CD variables on your GitLab project:

  1. Open your GitLab project and go to Settings, then CI/CD, then Variables.
  2. Click Add variable.
  3. Enter the Key AWS_ACCESS_KEY_ID and paste the Value from the previous step.
  4. Mark the variable as masked, and leave Protect variable cleared.
  5. Click Add variable, then do the same for AWS_SECRET_ACCESS_KEY.

GitLab passes protected variables only to pipelines on protected branches. Orchestration runs plans on the merge request's source branch, so those runs do not get a protected variable. To share the keys across projects, add the variables to the GitLab group.

Security considerations

Access keys are long-lived secrets:

  • Create new access keys periodically, and delete the old ones.
  • Use AWS CloudTrail to review what the stategraph user does.
  • Keep hooks and workflow steps from printing the keys.

Next Steps