A cryptographically secure password generator built to learn AWS and infrastructure as code: a TypeScript Lambda behind API Gateway, provisioned entirely with Terraform (remote state in S3 with DynamoDB locking) and shipped through a GitHub Actions CI/CD pipeline that authenticates to AWS via OIDC, with no long-lived access keys stored anywhere. Tests gate the deploy: a failing suite blocks terraform apply.
Project Architecture
Wiring GitHub Actions to assume an AWS role via OIDC kept failing the trust-policy check. Most tutorials show the sub claim as repo:owner/repo:ref, but GitHub Actions now sends it in an immutable org-ID/repo-ID format instead (repo:org@<org-id>/repo@<repo-id>:*). Found the actual claim by inspecting the AssumeRoleWithWebIdentity call in AWS CloudTrail, then rewrote the IAM role's trust policy condition to match it.

Pick a length and character sets, then generate. This calls the live API Gateway endpoint directly from your browser.