mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-03 23:43:14 +00:00
Merge pull request #96 from Sea-Haven-Industries/fix/remove-decommissioned-slack-bot-role
fix(iam): stop the decommissioned slack-bot role breaking every stack update (step 1/2)
This commit is contained in:
commit
2ec783052a
1 changed files with 20 additions and 2 deletions
|
|
@ -1101,8 +1101,24 @@ Resources:
|
||||||
# CDK deploy roles (4 repos)
|
# CDK deploy roles (4 repos)
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
# DECOMMISSIONED — being removed from this stack in two steps.
|
||||||
|
#
|
||||||
|
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
|
||||||
|
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
|
||||||
|
# that no longer exists. That ghost broke EVERY subsequent stack update: the
|
||||||
|
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
|
||||||
|
# IAM read, which 404s. A change-set does not reveal this, because the
|
||||||
|
# resource itself is unchanged and Outputs are not previewed.
|
||||||
|
#
|
||||||
|
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
|
||||||
|
# and record Retain so that step 2 cannot issue DeleteRole against a role
|
||||||
|
# that is not there.
|
||||||
|
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
|
||||||
|
# CloudFormation simply stops managing it — no IAM call is made.
|
||||||
SeahavenSlackBotDeployRole:
|
SeahavenSlackBotDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
DeletionPolicy: Retain
|
||||||
|
UpdateReplacePolicy: Retain
|
||||||
Properties:
|
Properties:
|
||||||
RoleName: githubdeploy-seahaven-slack-bot
|
RoleName: githubdeploy-seahaven-slack-bot
|
||||||
AssumeRolePolicyDocument:
|
AssumeRolePolicyDocument:
|
||||||
|
|
@ -1283,8 +1299,10 @@ Outputs:
|
||||||
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
||||||
PaymentsDashboardDeployRoleArn:
|
PaymentsDashboardDeployRoleArn:
|
||||||
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
||||||
SeahavenSlackBotDeployRoleArn:
|
# SeahavenSlackBotDeployRoleArn removed 2026-07-27: the role was deleted
|
||||||
Value: !GetAtt SeahavenSlackBotDeployRole.Arn
|
# out-of-band on 2026-07-23, so this !GetAtt failed as a live IAM read and
|
||||||
|
# broke every stack update. Nothing imported it (the Output had no
|
||||||
|
# ExportName, and no stack imports any export from this stack).
|
||||||
ExecAideDeployRoleArn:
|
ExecAideDeployRoleArn:
|
||||||
Value: !GetAtt ExecAideDeployRole.Arn
|
Value: !GetAtt ExecAideDeployRole.Arn
|
||||||
SeahavenDoorUnlockApiDeployRoleArn:
|
SeahavenDoorUnlockApiDeployRoleArn:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue