dry-vegetable-10976
03/31/2025, 1:01 PMAWS_ACCESS_KEY_ID
and AWS_SECRET_ACCESS_KEY
?mammoth-electrician-64525
03/31/2025, 1:09 PMdry-vegetable-10976
03/31/2025, 1:12 PMmammoth-electrician-64525
03/31/2025, 1:13 PMmammoth-electrician-64525
03/31/2025, 1:15 PMdry-vegetable-10976
03/31/2025, 1:16 PMmammoth-electrician-64525
03/31/2025, 1:19 PMmammoth-electrician-64525
03/31/2025, 1:22 PMdry-vegetable-10976
03/31/2025, 1:39 PMmammoth-electrician-64525
03/31/2025, 1:43 PMenvironment:
- your-pulumi-esc-project/your-pulumi-esc-oidc-provider
mammoth-electrician-64525
03/31/2025, 1:45 PMlittle-cartoon-10569
03/31/2025, 8:45 PMmammoth-electrician-64525
04/01/2025, 6:21 AMmammoth-electrician-64525
04/01/2025, 6:26 AMvalues:
SSOroleArn: arn:aws:iam::XXXXX:role/aws-reserved/sso.amazonaws.com/region/AWSReservedSSO_AWSAdministratorAccess_XXXXX
aws:
region: region
roleArn: arn:aws:iam::XXXXX:role/pulumi-esc-oidc-role
login:
fn::open::aws-login:
oidc:
duration: 1h
roleArn: ${aws.roleArn}
sessionName: pulumi-environments-session
environmentVariables:
AWS_ACCESS_KEY_ID: ${aws.login.accessKeyId}
AWS_SECRET_ACCESS_KEY: ${aws.login.secretAccessKey}
AWS_SESSION_TOKEN: ${aws.login.sessionToken}
AWS_REGION: ${aws.region}
pulumiConfig:
project:environment: aws-dev-cluster
aws:region: ${aws.region}
roleArn: ${aws.roleArn}
SSOroleArn: ${SSOroleArn}
little-cartoon-10569
04/01/2025, 7:30 AMaws sso login
to log in, then run Pulumi. It gets its credentials from the AWS session.little-cartoon-10569
04/01/2025, 7:30 AMlittle-cartoon-10569
04/01/2025, 7:31 AMmammoth-electrician-64525
04/01/2025, 7:32 AMmammoth-electrician-64525
04/01/2025, 7:33 AMmammoth-electrician-64525
04/01/2025, 7:35 AMmammoth-electrician-64525
04/01/2025, 7:37 AMaws SSO login
mammoth-electrician-64525
04/01/2025, 7:41 AMlittle-cartoon-10569
04/01/2025, 7:44 AMlittle-cartoon-10569
04/01/2025, 7:45 AMlittle-cartoon-10569
04/01/2025, 7:45 AMmammoth-electrician-64525
04/01/2025, 7:47 AMlittle-cartoon-10569
04/01/2025, 7:49 AMmammoth-electrician-64525
04/01/2025, 7:49 AMdry-vegetable-10976
04/01/2025, 9:22 AMlittle-cartoon-10569
04/01/2025, 7:43 PMlittle-cartoon-10569
04/01/2025, 7:44 PMdry-vegetable-10976
04/01/2025, 7:49 PMlittle-cartoon-10569
04/01/2025, 7:50 PMlittle-cartoon-10569
04/01/2025, 7:51 PMpulumi up
from needs to do that.dry-vegetable-10976
04/01/2025, 9:58 PMCommand failed with exit code 255: pulumi up --yes --skip-preview --message Executed from codebuild --refresh --diff --parallel 1 --client=127.0.0.1:33929 --exec-kind auto.inline --stack platform-iac-bastion-role --non-interactive
621
error: pulumi:providers:aws resource 'default_6_56_0' has a problem: No valid credential sources found.
so what you mean Pulumi does not need to authenticate with AWS? Code Build machine have full access
its not case using Pulumi Deploymentslittle-cartoon-10569
04/01/2025, 10:04 PMlittle-cartoon-10569
04/01/2025, 10:04 PMlittle-cartoon-10569
04/01/2025, 10:05 PMlittle-cartoon-10569
04/01/2025, 10:06 PM