mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
cd-cdk stacks input + org-baseline rename trust pair (#77)
* Add stacks input to cd-cdk for multi-account apps cdk deploy was hardcoded to --all, which breaks when one CDK app defines stacks for two AWS accounts: whichever role the job assumed fails on the other account's stacks. Callers can now pass per-job stack selectors; default stays --all so existing callers are unaffected. * Trust seahaven-org-baseline sub on account-baseline deploy role Transition pair for the repo rename: OIDC sub claims carry the repo full name, so the renamed repo cannot assume the role until its sub is trusted. Old sub is removed after a post-rename deploy verifies green. * Pass stacks selector via env var, not expression interpolation Defense-in-depth from the security review: expression interpolation into run: is pre-shell text substitution, so metacharacters in the input would execute as script. Env-var expansion never re-parses shell syntax; word-splitting for multiple selectors is preserved.
This commit is contained in:
parent
4505931ad8
commit
3cde673b9d
2 changed files with 16 additions and 2 deletions
11
.github/workflows/cd-cdk.yaml
vendored
11
.github/workflows/cd-cdk.yaml
vendored
|
|
@ -35,6 +35,10 @@ on:
|
|||
description: "CloudFormation stack name (for pre-flight checks)"
|
||||
type: string
|
||||
default: ""
|
||||
stacks:
|
||||
description: "CDK stack selector(s) to deploy (space-separated construct ids/patterns). Default deploys every stack in the app; set per job when a multi-account app splits deploys across roles."
|
||||
type: string
|
||||
default: "--all"
|
||||
post-deploy-script:
|
||||
description: "Optional path to a script to run after CDK deploy (e.g. web build, S3 sync)"
|
||||
type: string
|
||||
|
|
@ -121,7 +125,12 @@ jobs:
|
|||
|
||||
- name: CDK deploy
|
||||
working-directory: ${{ inputs.cdk-dir }}
|
||||
run: npx -y cdk deploy --all --require-approval never
|
||||
# Env-var indirection (not inline expression interpolation) so shell
|
||||
# metacharacters in the input are never parsed as script; unquoted
|
||||
# $STACKS deliberately word-splits multiple selectors.
|
||||
env:
|
||||
STACKS: ${{ inputs.stacks }}
|
||||
run: npx -y cdk deploy $STACKS --require-approval never
|
||||
|
||||
- name: Post-deploy script
|
||||
if: ${{ inputs.post-deploy-script != '' }}
|
||||
|
|
|
|||
|
|
@ -1247,7 +1247,12 @@ Resources:
|
|||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
|
||||
# Transition pair for the seahaven-account-baseline ->
|
||||
# seahaven-org-baseline repo rename (2026-07-14). The old sub is
|
||||
# removed once a post-rename deploy is verified green.
|
||||
token.actions.githubusercontent.com:sub:
|
||||
- !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue