Buildkite-agent oidc w/ build_creator claim

It would be really useful if I could add the build_creator as a claim to the the OIDC token.

I’m currently working around this by accepting an OIDC and then using the existing claims to read out the build_creator with an API call. But this could be streamlined if the JWT token could just include the build_creator directly.

To expand on WHY I use this. I want to scope credentials based on who created the build; example if I create a build it might be allowed to assume into an AWS role that can perform an administrator action; but it someone outside the SRE team creates a build, they cannot assume into that IAM role.

Thanks, Love BK 4 ever

Hey @ghthorvx

Thanks for using the community forum and raising this feature request with reasoning for it.

One thing we’d like to note about using Build Creator in general is that it is fungible, and we would discourage people from relying on that information that is fungible. Additionally, it is inferred in some cases (e.g., when GitHub doesn’t tell us in the webhook). For instance, the following can happen:

  • Author and committer differ (merge queues)
  • Commit author and Pull Request author differ
  • Author doesn’t exist as a Buildkite User

We can see this was also raised by another user here - OIDC Build Creator Claim - and has already been raised with our Product Team, yet we cannot share any information on if or when it may be implemented. But we will add that you would also like it.

Thanks,

Tom