From 30c8e22e4fae09fec0d7497b15c3d9e82ce28b62 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 8 May 2026 16:45:35 -0400 Subject: [PATCH] Add reusable CD workflows and OIDC deploy roles template Two reusable deploy workflows (cd-sam.yaml, cd-cdk.yaml) for GitHub Actions OIDC-based deployments. CloudFormation template provisions per-repo deploy roles for all 10 deployable repos. --- .github/workflows/cd-cdk.yaml | 73 +++++ .github/workflows/cd-sam.yaml | 65 ++++ README.md | 78 ++++- oidc-deploy-roles.yaml | 575 ++++++++++++++++++++++++++++++++++ 4 files changed, 790 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/cd-cdk.yaml create mode 100644 .github/workflows/cd-sam.yaml create mode 100644 oidc-deploy-roles.yaml diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml new file mode 100644 index 0000000..b629225 --- /dev/null +++ b/.github/workflows/cd-cdk.yaml @@ -0,0 +1,73 @@ +name: CD — CDK Deploy + +on: + workflow_call: + inputs: + node-version: + description: "Node.js version to use" + type: string + default: "22" + python-version: + description: "Python version for Python CDK repos (leave empty for TypeScript CDK)" + type: string + default: "" + region: + description: "AWS region" + type: string + default: "us-east-1" + cdk-dir: + description: "Directory containing cdk.json" + type: string + default: "." + enable-qemu: + description: "Enable QEMU for cross-platform Docker builds (arm64 on x86 runners)" + type: boolean + default: false + secrets: + deploy-role-arn: + description: "OIDC deploy role ARN" + required: true + +permissions: + id-token: write + contents: read + +jobs: + deploy: + runs-on: ubuntu-latest + timeout-minutes: 20 + steps: + - uses: actions/checkout@v4 + + - uses: docker/setup-qemu-action@v3 + if: ${{ inputs.enable-qemu }} + + - uses: actions/setup-node@v4 + with: + node-version: ${{ inputs.node-version }} + + - uses: actions/setup-python@v5 + if: ${{ inputs.python-version != '' }} + with: + python-version: ${{ inputs.python-version }} + + - name: Install Node dependencies + if: ${{ inputs.python-version == '' }} + run: npm ci + + - name: Install Python dependencies + if: ${{ inputs.python-version != '' }} + working-directory: ${{ inputs.cdk-dir }} + run: | + for req in $(find . -name requirements.txt -not -path '*/node_modules/*'); do + pip install -r "$req" + done + + - uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.deploy-role-arn }} + aws-region: ${{ inputs.region }} + + - name: CDK deploy + working-directory: ${{ inputs.cdk-dir }} + run: npx -y cdk deploy --all --require-approval never diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml new file mode 100644 index 0000000..413bd40 --- /dev/null +++ b/.github/workflows/cd-sam.yaml @@ -0,0 +1,65 @@ +name: CD — SAM Deploy + +on: + workflow_call: + inputs: + python-version: + description: "Python version to use" + type: string + default: "3.12" + stack-name: + description: "CloudFormation stack name" + type: string + required: true + sam-template: + description: "Path to SAM template file" + type: string + default: "template.yaml" + region: + description: "AWS region" + type: string + default: "us-east-1" + cfn-role-arn: + description: "CloudFormation execution role ARN" + type: string + required: true + secrets: + deploy-role-arn: + description: "OIDC deploy role ARN" + required: true + +permissions: + id-token: write + contents: read + +jobs: + deploy: + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-python@v5 + with: + python-version: ${{ inputs.python-version }} + + - uses: aws-actions/setup-sam@v2 + + - uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.deploy-role-arn }} + aws-region: ${{ inputs.region }} + + - name: SAM build + run: sam build --template ${{ inputs.sam-template }} + + - name: SAM deploy + run: | + sam deploy \ + --stack-name ${{ inputs.stack-name }} \ + --template-file .aws-sam/build/template.yaml \ + --resolve-s3 \ + --capabilities CAPABILITY_IAM \ + --no-confirm-changeset \ + --no-fail-on-empty-changeset \ + --role-arn ${{ inputs.cfn-role-arn }} diff --git a/README.md b/README.md index 5748a81..6a35a16 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,10 @@ Organization-level GitHub configuration for Sea Haven Industries. **`.github/workflows/ci-typescript-cdk.yaml`** — Reusable CI workflow for TypeScript / CDK repos. Runs `npm ci` + optional `tsc --noEmit`, optional ESLint, optional Jest, and optional `cdk synth`. Also supports Node.js SAM repos via an optional `sam validate` step. +**`.github/workflows/cd-sam.yaml`** — Reusable CD workflow for SAM repos. Runs `sam build` + `sam deploy` with OIDC credentials and a CloudFormation execution role. Triggers via `workflow_call` from per-repo `deploy.yaml` on push to `main`. + +**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds. + **`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults). **`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`. @@ -117,6 +121,78 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main ``` +### 5. Add CD to a repo + +Create `.github/workflows/deploy.yaml` in the target repo. Requires `AWS_DEPLOY_ROLE_ARN` repo secret. + +**SAM repo** (e.g., afterhours-shift-manager): + +```yaml +name: Deploy +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main + with: + stack-name: afterhours-shift-manager + cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} +``` + +**TypeScript CDK repo** (e.g., seahaven-door-unlock-api): + +```yaml +name: Deploy +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} +``` + +**Python CDK repo** (e.g., po-ingest): + +```yaml +name: Deploy +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main + with: + python-version: "3.12" + cdk-dir: cdk + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} +``` + +**CDK repo with arm64 Docker builds** (e.g., exec-aide): + +```yaml +name: Deploy +on: + push: + branches: [main] + +jobs: + deploy: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main + with: + enable-qemu: true + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} +``` + Enable optional steps as repos adopt them: | Input | Default | Turn on when... | @@ -127,7 +203,7 @@ Enable optional steps as repos adopt them: | `run-cdk-synth` | `true` | Repo is CDK-based | | `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template | -### 5. Roll out PR reviews to repos +### 6. Roll out PR reviews to repos ```bash ./scripts/rollout-review-workflow.sh diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml new file mode 100644 index 0000000..d4be4f0 --- /dev/null +++ b/oidc-deploy-roles.yaml @@ -0,0 +1,575 @@ +AWSTemplateFormatVersion: "2010-09-09" +Description: >- + GitHub Actions OIDC deploy roles for Sea Haven Industries repos. + Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC. + +Parameters: + GitHubOrg: + Type: String + Default: Sea-Haven-Industries + CreateOIDCProvider: + Type: String + Default: "false" + AllowedValues: ["true", "false"] + Description: Set to true only if the GitHub OIDC provider does not already exist in this account + +Conditions: + ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"] + +Resources: + + # --------------------------------------------------------------------------- + # OIDC Provider (conditional — already exists for seahaven-site) + # --------------------------------------------------------------------------- + GitHubOIDCProvider: + Type: AWS::IAM::OIDCProvider + Condition: ShouldCreateOIDCProvider + Properties: + Url: https://token.actions.githubusercontent.com + ClientIdList: + - sts.amazonaws.com + ThumbprintList: + - 6938fd4d98bab03faadb97b34396831e3780aea1 + + # --------------------------------------------------------------------------- + # Shared CloudFormation execution role (SAM stacks) + # --------------------------------------------------------------------------- + SamCfnExecutionRole: + Type: AWS::IAM::Role + Properties: + RoleName: github-cfn-execution-role + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: cloudformation.amazonaws.com + Action: sts:AssumeRole + ManagedPolicyArns: + - arn:aws:iam::aws:policy/AWSLambda_FullAccess + - arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator + - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess + - arn:aws:iam::aws:policy/AmazonS3FullAccess + - arn:aws:iam::aws:policy/CloudWatchLogsFullAccess + - arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess + - arn:aws:iam::aws:policy/AmazonSESFullAccess + - arn:aws:iam::aws:policy/IAMFullAccess + + # --------------------------------------------------------------------------- + # SAM deploy roles (5 repos) + # --------------------------------------------------------------------------- + + AfterhoursShiftManagerDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-afterhours-shift-manager + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + + ExpenseApprovalBotDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-expense-approval-bot + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/expense-approval-bot:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/expense-approval-bot/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + + AfiBackupMonitorDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-afi-backup-monitor + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + + RingScheduler3cxDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-ring-scheduler-3cx + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + + PaymentsDashboardDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-payments-dashboard + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + + # --------------------------------------------------------------------------- + # CDK deploy roles (5 repos) + # --------------------------------------------------------------------------- + + SeahavenSlackBotDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-slack-bot + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main + Policies: + - PolicyName: cdk-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - sts:AssumeRole + Resource: + - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* + + ExecAideDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-exec-aide + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main + Policies: + - PolicyName: cdk-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - sts:AssumeRole + Resource: + - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* + + SeahavenDoorUnlockApiDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-door-unlock-api + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main + Policies: + - PolicyName: cdk-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - sts:AssumeRole + Resource: + - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* + + PoIngestDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-po-ingest + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main + Policies: + - PolicyName: cdk-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - sts:AssumeRole + Resource: + - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* + + WorkorderIngestDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-workorder-ingest + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main + Policies: + - PolicyName: cdk-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - sts:AssumeRole + Resource: + - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* + +Outputs: + SamCfnExecutionRoleArn: + Value: !GetAtt SamCfnExecutionRole.Arn + Export: + Name: github-cfn-execution-role-arn + AfterhoursShiftManagerDeployRoleArn: + Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn + ExpenseApprovalBotDeployRoleArn: + Value: !GetAtt ExpenseApprovalBotDeployRole.Arn + AfiBackupMonitorDeployRoleArn: + Value: !GetAtt AfiBackupMonitorDeployRole.Arn + RingScheduler3cxDeployRoleArn: + Value: !GetAtt RingScheduler3cxDeployRole.Arn + PaymentsDashboardDeployRoleArn: + Value: !GetAtt PaymentsDashboardDeployRole.Arn + SeahavenSlackBotDeployRoleArn: + Value: !GetAtt SeahavenSlackBotDeployRole.Arn + ExecAideDeployRoleArn: + Value: !GetAtt ExecAideDeployRole.Arn + SeahavenDoorUnlockApiDeployRoleArn: + Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn + PoIngestDeployRoleArn: + Value: !GetAtt PoIngestDeployRole.Arn + WorkorderIngestDeployRoleArn: + Value: !GetAtt WorkorderIngestDeployRole.Arn