From 3ddf183fb505f18f503948f08fbaeea590315052 Mon Sep 17 00:00:00 2001
From: Michaela Wheeler <git@michael-wheeler.org>
Date: Wed, 15 Dec 2021 19:48:28 +1100
Subject: [PATCH] testing gha tokens

---
 .github/workflows/main.yml | 4 ++++
 .github/workflows/pr.yml   | 4 ++++
 2 files changed, 8 insertions(+)

diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml
index 4b817ff..2201809 100644
--- a/.github/workflows/main.yml
+++ b/.github/workflows/main.yml
@@ -12,6 +12,10 @@ jobs:
     environment: main
     name: 'Terraform'
     runs-on: ubuntu-latest
+    # These permissions are needed to interact with GitHub's OIDC Token endpoint.
+    permissions:
+      id-token: write
+      contents: read
     steps:
       - name: Configure AWS Credentials
         uses: aws-actions/configure-aws-credentials@v1
diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml
index d1358a2..8c70479 100644
--- a/.github/workflows/pr.yml
+++ b/.github/workflows/pr.yml
@@ -12,6 +12,10 @@ jobs:
     environment: main
     name: 'Terraform'
     runs-on: ubuntu-latest
+    # These permissions are needed to interact with GitHub's OIDC Token endpoint.
+    permissions:
+      id-token: write
+      contents: read
     steps:
       - name: Configure AWS Credentials
         uses: aws-actions/configure-aws-credentials@v1