From 3cde673b9d05c0e68aac4d997d582f2543853d20 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 14 Jul 2026 13:47:56 -0400 Subject: [PATCH] cd-cdk stacks input + org-baseline rename trust pair (#77) * Add stacks input to cd-cdk for multi-account apps cdk deploy was hardcoded to --all, which breaks when one CDK app defines stacks for two AWS accounts: whichever role the job assumed fails on the other account's stacks. Callers can now pass per-job stack selectors; default stays --all so existing callers are unaffected. * Trust seahaven-org-baseline sub on account-baseline deploy role Transition pair for the repo rename: OIDC sub claims carry the repo full name, so the renamed repo cannot assume the role until its sub is trusted. Old sub is removed after a post-rename deploy verifies green. * Pass stacks selector via env var, not expression interpolation Defense-in-depth from the security review: expression interpolation into run: is pre-shell text substitution, so metacharacters in the input would execute as script. Env-var expansion never re-parses shell syntax; word-splitting for multiple selectors is preserved. --- .github/workflows/cd-cdk.yaml | 11 ++++++++++- oidc-deploy-roles.yaml | 7 ++++++- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index a25e3ed..82d1d21 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -35,6 +35,10 @@ on: description: "CloudFormation stack name (for pre-flight checks)" type: string default: "" + stacks: + description: "CDK stack selector(s) to deploy (space-separated construct ids/patterns). Default deploys every stack in the app; set per job when a multi-account app splits deploys across roles." + type: string + default: "--all" post-deploy-script: description: "Optional path to a script to run after CDK deploy (e.g. web build, S3 sync)" type: string @@ -121,7 +125,12 @@ jobs: - name: CDK deploy working-directory: ${{ inputs.cdk-dir }} - run: npx -y cdk deploy --all --require-approval never + # Env-var indirection (not inline expression interpolation) so shell + # metacharacters in the input are never parsed as script; unquoted + # $STACKS deliberately word-splits multiple selectors. + env: + STACKS: ${{ inputs.stacks }} + run: npx -y cdk deploy $STACKS --require-approval never - name: Post-deploy script if: ${{ inputs.post-deploy-script != '' }} diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 7ab639f..5e44d24 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1247,7 +1247,12 @@ Resources: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main + # Transition pair for the seahaven-account-baseline -> + # seahaven-org-baseline repo rename (2026-07-14). The old sub is + # removed once a post-rename deploy is verified green. + token.actions.githubusercontent.com:sub: + - !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: