diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index eec2e7d..522a567 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -145,76 +145,6 @@ Resources: Resource: - !GetAtt SamCfnExecutionRole.Arn - ExpenseApprovalBotDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-expense-approval-bot - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/expense-approval-bot:ref:refs/heads/main - Policies: - - PolicyName: sam-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - cloudformation:CreateChangeSet - - cloudformation:DeleteChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:DescribeStackEvents - - cloudformation:DescribeStacks - - cloudformation:ExecuteChangeSet - - cloudformation:GetTemplate - - cloudformation:ListStackResources - - cloudformation:UpdateStack - - cloudformation:CreateStack - - cloudformation:TagResource - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/expense-approval-bot/* - - Effect: Allow - Action: - - cloudformation:GetTemplateSummary - Resource: "*" - - Effect: Allow - Action: - - cloudformation:DescribeStacks - - cloudformation:CreateChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:ExecuteChangeSet - - cloudformation:CreateStack - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - - Effect: Allow - Action: - - s3:PutObject - - s3:GetObject - - s3:ListBucket - - s3:GetBucketLocation - - s3:CreateBucket - - s3:PutBucketPolicy - - s3:GetBucketPolicy - - s3:PutLifecycleConfiguration - - s3:PutBucketVersioning - - s3:DeleteObject - Resource: - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - - Effect: Allow - Action: - - iam:PassRole - Resource: - - !GetAtt SamCfnExecutionRole.Arn - AfiBackupMonitorDeployRole: Type: AWS::IAM::Role Properties: @@ -571,8 +501,6 @@ Outputs: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn - ExpenseApprovalBotDeployRoleArn: - Value: !GetAtt ExpenseApprovalBotDeployRole.Arn AfiBackupMonitorDeployRoleArn: Value: !GetAtt AfiBackupMonitorDeployRole.Arn RingScheduler3cxDeployRoleArn: