diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index b62fbf9..fe0430c 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1101,49 +1101,6 @@ Resources: # CDK deploy roles (4 repos) # --------------------------------------------------------------------------- - # DECOMMISSIONED — being removed from this stack in two steps. - # - # seahaven-slack-bot was retired (superseded by sh-mcp) and this role was - # deleted directly in IAM on 2026-07-23, leaving the stack holding a resource - # that no longer exists. That ghost broke EVERY subsequent stack update: the - # Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live - # IAM read, which 404s. A change-set does not reveal this, because the - # resource itself is unchanged and Outputs are not previewed. - # - # Step 1 (this change): drop the Output so updates stop resolving the ghost, - # and record Retain so that step 2 cannot issue DeleteRole against a role - # that is not there. - # Step 2 (follow-up): delete the resource block itself. With Retain recorded, - # CloudFormation simply stops managing it — no IAM call is made. - SeahavenSlackBotDeployRole: - Type: AWS::IAM::Role - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - RoleName: githubdeploy-seahaven-slack-bot - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - ExecAideDeployRole: Type: AWS::IAM::Role Properties: