Skip to content

Validate and productize GitHub Actions federation #34

Description

The repository contains a GitHub OIDC provider, runner infrastructure, provisioning scripts, workflow examples, and RBAC entries, but the path is not currently deployed and its lifecycle remains incomplete.

Acceptance criteria:

  • Make provisioning and rollback idempotent.
  • Define runner group, repository, workflow, and trust boundaries.
  • Verify signed provenance claims used for authorization.
  • Validate deploy.sh --github from a clean environment.
  • Demonstrate the workflow through all enforcement layers.
  • Test revocation, runner replacement, re-attestation, and teardown.

Durable references:

  • GITHUB-FEDERATION-HOWTO.md
  • docs/platform-learnings/GitHub-Actions-Federation.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:federationCross-cloud and GitHub federationarea:identityEntra identity and token exchangearea:spiffeSPIFFE and SPIRE runtimepriority:P2Planned expansion worksecuritySecurity hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions