Docs / Guides

GitHub Actions

Let a GitHub Actions workflow call the PastKeys broker with its OIDC token, so CI performs operations with no stored secret.

GitHub Actions can issue every job a short-lived OIDC token. Trust it once, and your workflows call the broker with no secret stored in GitHub.

1. Trust GitHub as an issuer

In Workload identity, add an issuer with the GitHub Actions preset and set the required claim to your organization:

Issuerhttps://token.actions.githubusercontent.com
Audiencehttps://pastkeys.com
Required claimrepository_owner = your-org
Agent ID prefixgithub:

Pin more claims to narrow further, such as repository, ref or environment.

2. Write the policy

The agent ID is github: plus the token subject. For the main branch of your-org/infra:

{"agent": "github:repo:your-org/infra:ref:refs/heads/main",
 "rules": [{"provider": "cloudflare", "resource": "example.com",
            "actions": ["DNS_UPDATE"], "credential_ttl": "2m"}]}

3. Call the broker from the workflow

permissions:
  id-token: write
jobs:
  dns:
    runs-on: ubuntu-latest
    steps:
      - name: Update DNS through PastKeys
        run: |
          TOKEN=$(curl -sS -H "Authorization: bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \
            "$ACTIONS_ID_TOKEN_REQUEST_URL&audience=https://pastkeys.com" | jq -r .value)
          curl -sS -H "Authorization: Bearer $TOKEN" \
            -d '{"provider":"cloudflare","resource":"example.com","action":"DNS_UPDATE",
                 "parameters":{"type":"A","name":"api.example.com","content":"203.0.113.10"}}' \
            https://your-broker.example/v1/actions

The broker must be reachable from the runner (a self-hosted runner on your network, or a broker behind your ingress). Fetch a new token for each call: tokens are single-use at the broker.

Then remove the old secret. Once CI uses workload identity, delete the provider token from GitHub secrets and consider turning on Require workload identity.