mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-02 23:53:25 +00:00
Merge pull request #97 from Sea-Haven-Industries/fix/remove-slack-bot-role-step2
fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
This commit is contained in:
commit
0df5ee3955
1 changed files with 0 additions and 43 deletions
|
|
@ -1101,49 +1101,6 @@ Resources:
|
||||||
# CDK deploy roles (4 repos)
|
# CDK deploy roles (4 repos)
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
# DECOMMISSIONED — being removed from this stack in two steps.
|
|
||||||
#
|
|
||||||
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
|
|
||||||
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
|
|
||||||
# that no longer exists. That ghost broke EVERY subsequent stack update: the
|
|
||||||
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
|
|
||||||
# IAM read, which 404s. A change-set does not reveal this, because the
|
|
||||||
# resource itself is unchanged and Outputs are not previewed.
|
|
||||||
#
|
|
||||||
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
|
|
||||||
# and record Retain so that step 2 cannot issue DeleteRole against a role
|
|
||||||
# that is not there.
|
|
||||||
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
|
|
||||||
# CloudFormation simply stops managing it — no IAM call is made.
|
|
||||||
SeahavenSlackBotDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
DeletionPolicy: Retain
|
|
||||||
UpdateReplacePolicy: Retain
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-seahaven-slack-bot
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
ExecAideDeployRole:
|
ExecAideDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue