Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering GitHub Actions

You're reading from  Mastering GitHub Actions

Product type Book
Published in Mar 2024
Publisher Packt
ISBN-13 9781805128625
Pages 490 pages
Edition 1st Edition
Languages
Concepts
Author (1):
Eric Chapman Eric Chapman
Profile icon Eric Chapman

Table of Contents (22) Chapters

Preface 1. Part 1:Centralized Workflows to Assist with Governance
2. Chapter 1: An Overview of GitHub and GitHub Actions 3. Chapter 2: Exploring Workflows 4. Chapter 3: Deep Dive into Reusable Workflows and Composite Actions 5. Chapter 4: Workflow Personalization Using GitHub Apps 6. Chapter 5: Utilizing Starter Workflows in Your Team 7. Part 2: Implementing Advanced Patterns within Actions
8. Chapter 6: Using HashiCorp Vault in GitHub 9. Chapter 7: Deploying to Azure Using OpenID Connect 10. Chapter 8: Working with Checks 11. Chapter 9: Annotating Code with Actions 12. Chapter 10: Advancing with Event-Driven Workflows 13. Chapter 11: Setting Up Self-Hosted Runners 14. Part 3: Best Practices, Patterns, Tricks, and Tips Toolkit
15. Chapter 12: The Crawler Pattern 16. Chapter 13: The Configuration Centralization Pattern 17. Chapter 14: Using Remote Workflows to Kickstart Your Products 18. Chapter 15: Housekeeping Tips for Your Organization 19. Chapter 16: Handy Workflows for Managing Your Software 20. Index 21. Other Books You May Enjoy

Enabling JWT authentication in HashiCorp

Enabling JWT is simple; configuring it is a little trickier. It’s simple to enable using the UI, but you need API or CLI calls to configure it securely. So, we’re going to use each of them in this process so you get a little bit of experience with each of the methods available.

There is also official GitHub documentation for this here: https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-hashicorp-vault. It gives a very basic example, but it’s not up to date nor is it very secure, so we’ll use parts of it and expand on it further.

Let’s just quickly go over what we’re configuring in this section. We will configure our instance to allow JWT to be enabled as a form of authentication and for the authentication to be set up to understand how to verify GitHub tokens.

Enabling JWT for GitHub-produced tokens

In this section, we’re...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}