i 'd like to run 'kubectl apply -f xx.yaml' or some other kubectl commands in pipeline , but don't want to config $aws_access_id , $aws_access_key in pipeline. is it possible to realize?I have successfully configured oidc with ecr auth follow this:
https://support.atlassian.com/bitbucket-cloud/docs/deploy-on-aws-using-bitbucket-pipelines-openid-connect/#Using-claims-in-ID-tokens-to-limit-access-to-the-IAM-role-in-AWS
and pipeline works now.
Bitbucket pipelines has a concept of variables and secrets!
You can use it to store the AWS credentials in 2 separate secrets and have the pipeline yml refer to those. We do this with great success.
See: https://support.atlassian.com/bitbucket-cloud/docs/variables-and-secrets/
It looks like you're new here. Sign in or register to get started.