Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
GitHub Actions
Let a GitHub Actions workflow call the PastKeys broker with its OIDC token, so CI performs operations with no stored secret.
GitHub Actions can issue every job a short-lived OIDC token. Trust it once, and your workflows call the broker with no secret stored in GitHub.
1. Trust GitHub as an issuer
In Workload identity, add an issuer with the GitHub Actions preset and set the required claim to your organization:
| Issuer | https://token.actions.githubusercontent.com |
| Audience | https://pastkeys.com |
| Required claim | repository_owner = your-org |
| Agent ID prefix | github: |
Pin more claims to narrow further, such as repository, ref or environment.
2. Write the policy
The agent ID is github: plus the token subject. For the main branch of your-org/infra:
{"agent": "github:repo:your-org/infra:ref:refs/heads/main",
"rules": [{"provider": "cloudflare", "resource": "example.com",
"actions": ["DNS_UPDATE"], "credential_ttl": "2m"}]}
3. Call the broker from the workflow
permissions:
id-token: write
jobs:
dns:
runs-on: ubuntu-latest
steps:
- name: Update DNS through PastKeys
run: |
TOKEN=$(curl -sS -H "Authorization: bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \
"$ACTIONS_ID_TOKEN_REQUEST_URL&audience=https://pastkeys.com" | jq -r .value)
curl -sS -H "Authorization: Bearer $TOKEN" \
-d '{"provider":"cloudflare","resource":"example.com","action":"DNS_UPDATE",
"parameters":{"type":"A","name":"api.example.com","content":"203.0.113.10"}}' \
https://your-broker.example/v1/actions
The broker must be reachable from the runner (a self-hosted runner on your network, or a broker behind your ingress). Fetch a new token for each call: tokens are single-use at the broker.
Then remove the old secret. Once CI uses workload identity, delete the provider token from GitHub secrets and consider turning on Require workload identity.