AWS
supports federation with external identity providers.
Using this, you can allow identities managed by an external identity provider to perform actions in your AWS account.
In this scenario the external identity provider is Concourse and the identities are teams/pipelines/jobs. This means you
are able to grant a specific pipeline or job permission to perform actions in AWS (like deploying something), all
without managing IAM users or dealing with long-lived credentials.
Set url to the external URL of your Concourse server (or the --oidc-issuer-url if you're using a separate OIDC
issuer -
see Configuring a Separate OIDC Issuer).
For client_id_list, you can choose any string you like, but using a value like sts.amazonaws.com is recommended.
Note
You have to use the same string later in the configuration of your idtoken var source.
var_sources:-name:awstokentype:idtokenconfig:audience:-"sts.amazonaws.com"jobs:-name:aws-loginplan:-task:printconfig:platform:linuximage_resource:type:registry-imagesource:repository:amazon/aws-clirun:path:bashargs:--e--c-|aws sts assume-role-with-web-identity \--role-session-name Concourse \--role-arn arn:aws:iam::<your_account>:role/s3_manager \--web-identity-token ((awstoken:token)) > creds.jsonecho "Now do something with the temporary credentials in creds.json"