inspired by https://github.com/shrikant0013/gcp-aws-webidentityfederation
- create an AWS Role configured for Web Identity federation using Cognito or any OpenID provider
- select Google as the Identity provider in the wizard
- set the audience to a dummy value and do not add any additional conditions in the setup wizard. We will edit the trust policy after completing the wizard.
- assign any permissions needed to the role
- read up on "Available keys for AWS web identity federation" at