GitHub Actions Workload Identity
GitHub Actions can issue a short-lived OIDC token for each workflow job. Mixlayer verifies the token’s repository and workflow claims and exchanges it for a short-lived Mixlayer access token, so the repository does not need a long-lived Mixlayer API-key secret.
1. Record stable repository identifiers
Find the repository and owner numeric IDs with the GitHub CLI:
Numeric IDs remain stable across repository and organization renames. Use names such as repository for readability, but use IDs for the main admission boundary.
2. Configure the Mixlayer provider
Create an OIDC provider in Workload Identity:
Map the job and repository identity:
Restrict admission to the exact owner and repository IDs:
For production access, add a more restrictive first authorization rule before the fallback:
The fallback permissions apply to every admitted job. If only the production workflow should authenticate, move its checks into the admission condition instead of relying on the rule above.
GitHub’s default sub format can vary by repository settings and creation
date. Inspect a real token and prefer stable repository_id and
repository_owner_id claims for the trust boundary.
3. Request and exchange the job token
The job needs id-token: write. This permission allows the job to request an OIDC token; it does not grant write access to repository contents.
Store the non-secret Mixlayer provider ID in a GitHub Actions configuration variable named MIXLAYER_IDENTITY_PROVIDER_ID.
No Mixlayer secret is stored in GitHub. The workflow receives a new GitHub OIDC token for the job and exchanges it at runtime.
Tighten production policies
- Use GitHub environments and required reviewers for production deployments.
- Match the exact
job_workflow_refwhen a centrally controlled reusable workflow should be the only caller. - Match immutable repository and owner IDs before mutable names.
- Do not grant access based only on the public GitHub issuer and audience; any GitHub repository can request a token for a caller-selected audience.
- Do not print the GitHub or Mixlayer tokens in workflow logs.