Merge pull request #97 from Sea-Haven-Industries/fix/remove-slack-bot-role-step2

fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
This commit is contained in:
Adam Moussa 2026-07-27 18:06:43 -04:00 • committed by GitHub
commit 0df5ee3955
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1101,49 +1101,6 @@ Resources:
# CDK deploy roles (4 repos)
# ---------------------------------------------------------------------------
# DECOMMISSIONED — being removed from this stack in two steps.
#
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
# that no longer exists. That ghost broke EVERY subsequent stack update: the
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
# IAM read, which 404s. A change-set does not reveal this, because the
# resource itself is unchanged and Outputs are not previewed.
#
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
# and record Retain so that step 2 cannot issue DeleteRole against a role
# that is not there.
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
# CloudFormation simply stops managing it — no IAM call is made.
SeahavenSlackBotDeployRole:
Type: AWS::IAM::Role
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
RoleName: githubdeploy-seahaven-slack-bot
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
ExecAideDeployRole:
Type: AWS::IAM::Role
Properties: