I am using OIDC to authenticate with AWS and in other parts of my pipeline the authentication with AWS is successful
I've specified a private ECR image within a Dockerfile and within the pipeline I have set AWS_DEFAULT_REGION and AWS_OIDC_ROLE_ARN using:
variables:
AWS_DEFAULT_REGION: $AWS_DEFAULT_REGION
AWS_OIDC_ROLE_ARN: $AWS_OIDC_ROLE_ARN
I have also tried setting these using:
- export AWS_REGION=$AWS_DEFAULT_REGION
- export AWS_ROLE_ARN=$AWS_OIDC_ROLE_ARN
- export AWS_WEB_IDENTITY_TOKEN_FILE=$(pwd)/web-identity-token
- echo $BITBUCKET_STEP_OIDC_TOKEN > $(pwd)/web-identity-token
The role has `AdministratorAccess` within AWS
But I keep receiving a 401 at the build stage:
#3 ERROR: unexpected status code [manifests latest]: 401 Unauthorized
failed to solve with frontend dockerfile.v0: failed to create LLB definition: unexpected status code [manifests latest]: 401 Unauthorized
Which doesn't make any sense because other parts of my pipeline are using the same method for setting the AWS variables and they have authorisation with AWS
Is there a step i'm missing? I am seeing examples of using aws ecr login but I don't think that applies when using OIDC?