logoalt Hacker News

regularfrytoday at 1:42 PM1 replyview on HN

Technically yes. It depends on whether you consider the account ID to be a secret or not (AWS say "sensitive but not secret" which doesn't help much). But also it can make sense to treat all environment variables as secrets by default just so you don't accidentally end up putting something somewhere that turns out to have been Wrong.


Replies

Kinranytoday at 2:44 PM

GP is saying that GHA would need zero information about AWS if CodeBuild used a Github token and listened for GHA runs.

show 1 reply