From 6b27a25752f0b733a7f94b0071dc6a1cecd6e313 Mon Sep 17 00:00:00 2001 From: Andreas Braun Date: Fri, 23 May 2025 10:06:48 +0200 Subject: [PATCH] Use assume_role command before accessing secrets --- .evergreen/config/test-task-groups.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.evergreen/config/test-task-groups.yml b/.evergreen/config/test-task-groups.yml index a8edffa41..4a83bac2c 100644 --- a/.evergreen/config/test-task-groups.yml +++ b/.evergreen/config/test-task-groups.yml @@ -8,6 +8,9 @@ task_groups: - func: "locate PHP binaries" - func: "fetch extension" - func: "install composer" + - command: ec2.assume_role + params: + role_arn: ${aws_test_secrets_role} - command: subprocess.exec params: working_dir: src