Featured image of post A 403 you can't fix in IAM

A 403 you can't fix in IAM

The OIDC post explained the handshake that lets a GitLab pipeline deploy to AWS with no stored key. This is the story of the first time I got it wrong, and spent an afternoon fixing the wrong thing. The error was a flat 403 from AWS, and …

Featured image of post No access keys in CI

No access keys in CI

A long-lived AWS access key, sitting in a CI system, is just about the single credential I’d most like to be rid of. It’s powerful, it never expires unless someone remembers to rotate it (nobody remembers to rotate it), and it lives in one …

(1 - 14)
Enter Press Enter to jump