cd-cdk stacks input + org-baseline rename trust pair (#77)

* Add stacks input to cd-cdk for multi-account apps

cdk deploy was hardcoded to --all, which breaks when one CDK app defines
stacks for two AWS accounts: whichever role the job assumed fails on the
other account's stacks. Callers can now pass per-job stack selectors;
default stays --all so existing callers are unaffected.

* Trust seahaven-org-baseline sub on account-baseline deploy role

Transition pair for the repo rename: OIDC sub claims carry the repo full
name, so the renamed repo cannot assume the role until its sub is
trusted. Old sub is removed after a post-rename deploy verifies green.

* Pass stacks selector via env var, not expression interpolation

Defense-in-depth from the security review: expression interpolation
into run: is pre-shell text substitution, so metacharacters in the
input would execute as script. Env-var expansion never re-parses shell
syntax; word-splitting for multiple selectors is preserved.
This commit is contained in:
Adam Moussa 2026-07-14 13:47:56 -04:00 • committed by GitHub
parent 4505931ad8
commit 3cde673b9d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 16 additions and 2 deletions

View file

@ -35,6 +35,10 @@ on:
description: "CloudFormation stack name (for pre-flight checks)" description: "CloudFormation stack name (for pre-flight checks)"
type: string type: string
default: "" default: ""
stacks:
description: "CDK stack selector(s) to deploy (space-separated construct ids/patterns). Default deploys every stack in the app; set per job when a multi-account app splits deploys across roles."
type: string
default: "--all"
post-deploy-script: post-deploy-script:
description: "Optional path to a script to run after CDK deploy (e.g. web build, S3 sync)" description: "Optional path to a script to run after CDK deploy (e.g. web build, S3 sync)"
type: string type: string
@ -121,7 +125,12 @@ jobs:
- name: CDK deploy - name: CDK deploy
working-directory: ${{ inputs.cdk-dir }} working-directory: ${{ inputs.cdk-dir }}
run: npx -y cdk deploy --all --require-approval never # Env-var indirection (not inline expression interpolation) so shell
# metacharacters in the input are never parsed as script; unquoted
# $STACKS deliberately word-splits multiple selectors.
env:
STACKS: ${{ inputs.stacks }}
run: npx -y cdk deploy $STACKS --require-approval never
- name: Post-deploy script - name: Post-deploy script
if: ${{ inputs.post-deploy-script != '' }} if: ${{ inputs.post-deploy-script != '' }}

View file

@ -1247,7 +1247,12 @@ Resources:
StringEquals: StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike: StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main # Transition pair for the seahaven-account-baseline ->
# seahaven-org-baseline repo rename (2026-07-14). The old sub is
# removed once a post-rename deploy is verified green.
token.actions.githubusercontent.com:sub:
- !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
Policies: Policies:
- PolicyName: cdk-deploy - PolicyName: cdk-deploy
PolicyDocument: PolicyDocument: