I have multiple AWS accounts for different stages (i.e. One for development, one for staging, and one for production)
In each account, I have created an OpenID Connect Identity Provider, using the URL and audience found in my Organisations BitBucket account, and an associated IAM Role. There are the same in every AWS account, except the name of the IAM Role changes to reflect the stage.
I have a BitBucket pipeline in a repository to deploy the application to AWS. I have set Deployment variables in the repository settings for `CDK_DEFAULT_ACCOUNT` and `AWS_ROLE_ARN` to reflect the different accounts I want to deploy to for each stage.
branches:
staging:
- stage:
name: Build and Deploy Staging
deployment: Staging
steps:
- step: *install_dependencies
- step: *test
- step: *build
- step: *deploy
development:
- stage:
name: Build and Deploy Development
deployment: Development
steps:
- step: *install_dependencies
- step: *test
- step: *build
- step: *deploy
When I run the pipeline on the `development` branch, it runs correctly and deploys to AWS.
When I run the pipeline on the `staging` branch, I get
Building Assets Failed: Error: Need to perform AWS calls for account XXXXXXXXXX, but no credentials have been configured
despite having the same variables defined.
Is there a limitation on OpenID Connect and multiple AWS accounts, or some extra configuration needed? Or simply something set up incorrectly in my pipeline?