From e009d3c65f0d5140a1b14ec037015dc4021e48f8 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 27 Jul 2026 18:04:47 -0400 Subject: [PATCH] fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2) Removes the SeahavenSlackBotDeployRole resource block. Step 1 recorded DeletionPolicy/UpdateReplacePolicy Retain in the deployed template, so CloudFormation stops managing the resource without issuing DeleteRole against a role that no longer exists -- confirmed from the change set, which reports PolicyAction: Retain on a single Remove entry. seahaven-slack-bot was decommissioned in favour of sh-mcp and the role was deleted directly in IAM on 2026-07-23. The stack is now consistent with reality again, and stack updates no longer fail on it. --- oidc-deploy-roles.yaml | 43 ------------------------------------------ 1 file changed, 43 deletions(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index b62fbf9..fe0430c 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1101,49 +1101,6 @@ Resources: # CDK deploy roles (4 repos) # --------------------------------------------------------------------------- - # DECOMMISSIONED — being removed from this stack in two steps. - # - # seahaven-slack-bot was retired (superseded by sh-mcp) and this role was - # deleted directly in IAM on 2026-07-23, leaving the stack holding a resource - # that no longer exists. That ghost broke EVERY subsequent stack update: the - # Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live - # IAM read, which 404s. A change-set does not reveal this, because the - # resource itself is unchanged and Outputs are not previewed. - # - # Step 1 (this change): drop the Output so updates stop resolving the ghost, - # and record Retain so that step 2 cannot issue DeleteRole against a role - # that is not there. - # Step 2 (follow-up): delete the resource block itself. With Retain recorded, - # CloudFormation simply stops managing it — no IAM call is made. - SeahavenSlackBotDeployRole: - Type: AWS::IAM::Role - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - RoleName: githubdeploy-seahaven-slack-bot - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - ExecAideDeployRole: Type: AWS::IAM::Role Properties: