mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-04 10:12:06 +00:00
feat(iam): add org-baseline Access Analyzer CI role (PLAT-234)
Adds githubdeploy-seahaven-org-baseline-policy-check with only ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request. The deploy role stays limited to main and CDK assume. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
0a1010e632
commit
4f68b535f0
1 changed files with 34 additions and 0 deletions
|
|
@ -1380,6 +1380,38 @@ Resources:
|
||||||
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
|
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
SeahavenOrgBaselinePolicyCheckRole:
|
||||||
|
Type: AWS::IAM::Role
|
||||||
|
Properties:
|
||||||
|
RoleName: githubdeploy-seahaven-org-baseline-policy-check
|
||||||
|
Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions.
|
||||||
|
AssumeRolePolicyDocument:
|
||||||
|
Version: "2012-10-17"
|
||||||
|
Statement:
|
||||||
|
- Effect: Allow
|
||||||
|
Principal:
|
||||||
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||||
|
Action: sts:AssumeRoleWithWebIdentity
|
||||||
|
Condition:
|
||||||
|
StringEquals:
|
||||||
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||||
|
StringLike:
|
||||||
|
token.actions.githubusercontent.com:sub:
|
||||||
|
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
|
||||||
|
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:pull_request
|
||||||
|
Policies:
|
||||||
|
- PolicyName: access-analyzer-policy-check
|
||||||
|
PolicyDocument:
|
||||||
|
Version: "2012-10-17"
|
||||||
|
Statement:
|
||||||
|
- Sid: AccessAnalyzerPolicyCheck
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- access-analyzer:ValidatePolicy
|
||||||
|
- access-analyzer:CheckNoNewAccess
|
||||||
|
Resource: "*"
|
||||||
|
|
||||||
Outputs:
|
Outputs:
|
||||||
LambdaExecutionBoundaryArn:
|
LambdaExecutionBoundaryArn:
|
||||||
Value: !Ref LambdaExecutionBoundary
|
Value: !Ref LambdaExecutionBoundary
|
||||||
|
|
@ -1414,4 +1446,6 @@ Outputs:
|
||||||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||||
SeahavenAccountBaselineDeployRoleArn:
|
SeahavenAccountBaselineDeployRoleArn:
|
||||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||||
|
SeahavenOrgBaselinePolicyCheckRoleArn:
|
||||||
|
Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn
|
||||||
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue