Hello,
I have the following use-case:
I have a self-hosted runner on an EC2. The runner is in docker on that EC2.
In the pipeline I have one step with "runs-on: test" <- the tag from my runner, and all the required stuff (oidc: true etc).
In the OIDC role for the Bitbucket, in trust policy, I have put a condition that will allow sts assume only from a specific CIDR range (the CIDR of my VPC). It seems that each time I run the pipeline I get a access denied error.
My question is this:
If the runner is in docker mode, it will try to leverage the EC2 private IP or it will try to leverage the default docker CIDR (172.17.x.x)?