Skip to content

BoxFetch Original kit

GitHub Actions Exact AWS OIDC Trust

This two-stage kit prepares a bounded GitHub claim probe, stops for human observation and approval, then creates one exact zero-permission AWS IAM role and an immutable manual smoke workflow.

This is one of the first six BoxFetch Originals for bounded cloud work.

Windows, macOS, LinuxFree during beta

What does this kit do?

Prepare an observed-claim checkpoint, then create one zero-permission IAM role with exact GitHub repository, ID, environment, branch, audience, and subject trust.

Who should use it?

  • The target is one exact GitHub.com repository and protected environment.
  • The AWS commercial account already has the GitHub Actions OIDC provider.
  • You want exact observed claims before creating a role.

What will it change?

  • Package-owned claim-probe and smoke-workflow files in the approved repository.
  • One new IAM role with exact trust and no permissions.

What will the human approve?

The human configures the protected environment, observes and approves the bounded claim document, and approves one zero-permission role in the exact AWS account.

What does it verify?

  • Observed issuer, audience, subject, repository IDs, environment, and branch match exactly.
  • The role has one exact trust statement and no attached, inline, boundary, or instance-profile permissions.

What can it remove?

  • Unchanged run-created files and the exact empty-permission role while every evidence and drift check passes.

What does it deliberately not do?

  • The repository, environment, branch, account, or observed claims cannot be identified exactly.
  • You need the role to carry application permissions.
  • The agent would need to create or modify the shared account OIDC provider.
  • GitHub environment policy, a changed role, the shared OIDC provider, or downstream workflow effects.

How does an agent use it?

  1. Open the BoxFetch Original in the BoxFetch app.
  2. Let the kit inspect the target without making changes.
  3. Review the plan, target, and human checkpoint.
  4. Approve only the changes you intend to make.
  5. Read the verification result and run record.

How do I use it?

Create a BoxFetch account and open the app to see current beta availability. The six current Originals are free during the controlled beta, while the application remains the authority for live access.

Technical compatibility

Supported target

One GitHub.com repository and protected environment with an existing AWS GitHub OIDC provider.

Supported systems

Windows, macOS, Linux