SpyBara
Go Premium

github-actions-cloud-providers.md 2026-08-05 22:02 UTC to 2026-08-06 15:02 UTC

320 added, 0 removed.

2026
Sun 9 04:02 Sat 8 04:59 Fri 7 23:57 Thu 6 15:02 Wed 5 22:02 Tue 4 22:59 Mon 3 20:02 Sun 2 19:00

Use Claude Code GitHub Actions with cloud providers

Run Claude Code GitHub Actions through Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry instead of the Claude API

Claude Code GitHub Actions calls the Claude API by default. To route inference through your own cloud account instead, set the Claude Code GitHub Action's provider input and configure your cloud to trust the workflow's OpenID Connect (OIDC) token. The workflow authenticates with that token, so you store no long-lived cloud credential in your repository.

Choose your provider

The Claude Code GitHub Action supports three providers, and the setup steps below differ only in the cloud-side configuration. Use the one where your organization already has Claude model access. You tell the Claude Code GitHub Action which provider to use with one input in the anthropics/claude-code-action step's with: block:

  • Amazon Bedrock: use_bedrock: "true"
  • Google Cloud's Agent Platform: use_vertex: "true"
  • Microsoft Foundry: use_foundry: "true"

The following snippet shows the input in place for Amazon Bedrock. You don't need to edit a workflow yet, because the complete workflow examples later on this page already include the input for each provider.

- uses: anthropics/claude-code-action@v1
  with:
    use_bedrock: "true"

Prerequisites

Before you start, you need:

  • Admin access to the repository where the Claude Code GitHub Action runs, to install a GitHub App and add secrets
  • Permission to create identity resources in your cloud account: IAM roles and OIDC identity providers on AWS, Workload Identity Federation resources and service accounts on Google Cloud, or Microsoft Entra applications on Azure
  • Claude model access on your provider:

Set up the integration

Beyond the prerequisites, you create four things: a GitHub identity for the Claude Code GitHub Action, the cloud-side trust configuration, the repository secrets, and the workflow file. The steps below walk through each.

1

Choose a GitHub identity

The Claude Code GitHub Action pushes commits and posts comments through a GitHub identity. The quick setup installs the official Claude GitHub App for this. With a cloud provider, you choose the identity yourself:

  • Official Claude GitHub App: install it on the repository, or skip to the next step if it's already installed
  • Custom GitHub App: create your own app, described below, when you want only the three permissions the Claude Code GitHub Action uses rather than the official app's full set
  • GitHub's automatic GITHUB_TOKEN: no app to create or install, but GitHub doesn't trigger your CI workflows on commits made with it

The workflow examples in the fourth step authenticate with a custom app. That step also says what to change for the other two options.

To create a custom app, register a new GitHub App with webhooks disabled, since this integration doesn't use them. Grant it three repository permissions:

  • Contents: read and write
  • Issues: read and write
  • Pull requests: read and write

After registering the app, generate a private key and keep the downloaded .pem file, note the App ID from the app's settings page, and install the app on the repository where the Claude Code GitHub Action runs. You add the key and the ID as secrets in the third step.

2

Configure cloud authentication

Configure your cloud to trust the OIDC token that GitHub issues to the workflow, so each workflow run gets short-lived cloud credentials. The bullets in each tab summarize what to create, and each tab links the cloud vendor's own guide for the console-level steps.

Create the trust configuration in your AWS account, following the AWS guide to creating OIDC identity providers:

  • Add a GitHub OIDC identity provider with provider URL https://token.actions.githubusercontent.com and audience sts.amazonaws.com
  • Create an IAM role trusted by that provider as a web identity, and attach the scoped invocation policy from IAM configuration, which grants bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles, and bedrock:GetInferenceProfile, along with two aws-marketplace subscription actions
  • Limit the role's trust policy to your repository with a subject condition such as repo:your-org/your-repo:*. See GitHub's OIDC hardening guide for the claim format

Note the role's ARN. You add it as a secret in the next step.

3

Add repository secrets

In the repository where the Claude Code GitHub Action runs, add the secrets for your provider, plus the two app secrets if you created a custom GitHub App in the first step. See GitHub's guide to using secrets in GitHub Actions.

Secret Needed for Value
AWS_ROLE_TO_ASSUME Amazon Bedrock The ARN of the IAM role
GCP_WORKLOAD_IDENTITY_PROVIDER Google Cloud's Agent Platform The provider's full resource name
GCP_SERVICE_ACCOUNT Google Cloud's Agent Platform The service account's email address
AZURE_CLIENT_ID Microsoft Foundry The Entra application's client ID
AZURE_TENANT_ID Microsoft Foundry Your Microsoft Entra tenant ID
AZURE_SUBSCRIPTION_ID Microsoft Foundry Your Azure subscription ID
APP_ID Custom GitHub App The GitHub App's ID
APP_PRIVATE_KEY Custom GitHub App The contents of the .pem private key file
4

Create the workflow file

Create a workflow file for your provider, such as .github/workflows/claude.yml. Each example responds to @claude mentions, authenticates to GitHub with a custom app, and includes the id-token: write permission, which GitHub requires to issue the OIDC token that your cloud provider exchanges for credentials.

If you chose a different GitHub identity in the first step, adjust the example:

  • Official Claude GitHub App: delete the Generate GitHub App token step and the github_token line
  • GitHub's automatic token: delete the token-generation step and change the github_token line to github_token: ${{ secrets.GITHUB_TOKEN }}

Replace the aws-region value with your own. The credentials step exports it as AWS_REGION for the rest of the job.

name: Claude PR Action

permissions:
contents: write
pull-requests: write
issues: write
id-token: write

on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
issues:
types: [opened]

jobs:
claude-pr:
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6

- name: Generate GitHub App token
id: app-token
uses: actions/create-github-app-token@v2
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}

- name: Configure AWS Credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
aws-region: us-west-2

- uses: anthropics/claude-code-action@v1
with:
github_token: ${{ steps.app-token.outputs.token }}
use_bedrock: "true"
claude_args: '--model us.anthropic.claude-sonnet-4-6'

With any provider, you can bound run length and cost by adding --max-turns to claude_args. See Manage costs.

5

Test the setup

Mention @claude in an issue or PR comment, then watch the run in the repository's Actions tab. Claude replies in a comment on the same issue or PR.

Troubleshooting

A failing run usually breaks in one of two places:

  • Authentication errors: usually an OIDC misconfiguration. Check that the workflow includes the id-token: write permission, that the trust configuration's repository condition matches your repository exactly, and that the secret names in your workflow match the ones you added
  • Trigger and CI problems: these behave the same as when the Claude Code GitHub Action calls the Claude API. See the main page's troubleshooting section and the Claude Code GitHub Action's FAQ

What's next