diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 2d43de5..432e9e8 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1380,6 +1380,38 @@ Resources: # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update. + + SeahavenOrgBaselinePolicyCheckRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-org-baseline-policy-check + Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions. + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:pull_request + Policies: + - PolicyName: access-analyzer-policy-check + PolicyDocument: + Version: "2012-10-17" + Statement: + - Sid: AccessAnalyzerPolicyCheck + Effect: Allow + Action: + - access-analyzer:ValidatePolicy + - access-analyzer:CheckNoNewAccess + Resource: "*" + Outputs: LambdaExecutionBoundaryArn: Value: !Ref LambdaExecutionBoundary @@ -1414,4 +1446,6 @@ Outputs: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn + SeahavenOrgBaselinePolicyCheckRoleArn: + Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.