From 4f68b535f004493f394599ed47823ab6f147b2b1 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Mon, 28 Sep 2026 00:57:42 +0000 Subject: [PATCH] feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) Adds githubdeploy-seahaven-org-baseline-policy-check with only ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request. The deploy role stays limited to main and CDK assume. Co-authored-by: Adam Moussa --- oidc-deploy-roles.yaml | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 2d43de5..432e9e8 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1380,6 +1380,38 @@ Resources: # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update. + + SeahavenOrgBaselinePolicyCheckRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-org-baseline-policy-check + Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions. + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:pull_request + Policies: + - PolicyName: access-analyzer-policy-check + PolicyDocument: + Version: "2012-10-17" + Statement: + - Sid: AccessAnalyzerPolicyCheck + Effect: Allow + Action: + - access-analyzer:ValidatePolicy + - access-analyzer:CheckNoNewAccess + Resource: "*" + Outputs: LambdaExecutionBoundaryArn: Value: !Ref LambdaExecutionBoundary @@ -1414,4 +1446,6 @@ Outputs: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn + SeahavenOrgBaselinePolicyCheckRoleArn: + Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.