This repo includes the the backend cloud infrastructure and dcc-validation-decorator
you have to export the follwing env var
export AWS_PROFILE=coviscan
set the default project env var
export GOOGLE_PROJECT=coviscan-339716
see links:
Add AWS role in IAM with trust relationship like
"Version": "2012-10-17",
"Statement": [
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::161247518108:oidc-provider/"
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringLike": {
"": "repo:coviscan/coviscan-core:*"
In order to initially create all IAM roles that you need to assume in Github actions you need one bootstrap user with AWS credentials that has the following policies attached:
- IAMFullAccess (In order to create the IAM roles)
- AmazonS3FullAccess (In order to initiate the Terraform S3 backend)
- A custom role with all OIDC permissions allowing the following actions
- iam:RemoveClientIDFromOpenIDConnectProvider
- iam:ListOpenIDConnectProviderTags
- iam:UpdateOpenIDConnectProviderThumbprint
- iam:UntagOpenIDConnectProvider
- iam:AddClientIDToOpenIDConnectProvider
- iam:DeleteOpenIDConnectProvider
- iam:GetOpenIDConnectProvider
- iam:TagOpenIDConnectProvider
- iam:CreateOpenIDConnectProvider
After setting up the initial bootstrap user you have to execute the bootstraping script
bash /bin/tf/aws/
We are load testing using k6 from Grafana Labs. For installation instructions see here.