mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 14:03:11 +00:00
Add SQS/EC2/SNS to CFN execution role and parameter overrides to cd-sam
- SQS/EC2/SNS as inline policy (managed policy quota is 10) - cd-sam.yaml now accepts optional parameter-overrides input for SAM templates with required parameters
This commit is contained in:
parent
b273e5cd5c
commit
50a0ff53d7
2 changed files with 17 additions and 2 deletions
11
.github/workflows/cd-sam.yaml
vendored
11
.github/workflows/cd-sam.yaml
vendored
|
|
@ -23,6 +23,10 @@ on:
|
|||
description: "CloudFormation execution role ARN"
|
||||
type: string
|
||||
required: true
|
||||
parameter-overrides:
|
||||
description: "SAM parameter overrides (e.g. 'Key1=Value1 Key2=Value2')"
|
||||
type: string
|
||||
default: ""
|
||||
secrets:
|
||||
deploy-role-arn:
|
||||
description: "OIDC deploy role ARN"
|
||||
|
|
@ -55,6 +59,10 @@ jobs:
|
|||
|
||||
- name: SAM deploy
|
||||
run: |
|
||||
PARAMS=""
|
||||
if [ -n "${{ inputs.parameter-overrides }}" ]; then
|
||||
PARAMS="--parameter-overrides ${{ inputs.parameter-overrides }}"
|
||||
fi
|
||||
sam deploy \
|
||||
--stack-name ${{ inputs.stack-name }} \
|
||||
--template-file .aws-sam/build/template.yaml \
|
||||
|
|
@ -62,4 +70,5 @@ jobs:
|
|||
--capabilities CAPABILITY_IAM \
|
||||
--no-confirm-changeset \
|
||||
--no-fail-on-empty-changeset \
|
||||
--role-arn ${{ inputs.cfn-role-arn }}
|
||||
--role-arn ${{ inputs.cfn-role-arn }} \
|
||||
$PARAMS
|
||||
|
|
|
|||
|
|
@ -55,7 +55,7 @@ Resources:
|
|||
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
||||
- arn:aws:iam::aws:policy/IAMFullAccess
|
||||
Policies:
|
||||
- PolicyName: cloudformation-transforms
|
||||
- PolicyName: additional-service-permissions
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
|
|
@ -64,6 +64,12 @@ Resources:
|
|||
- cloudformation:CreateChangeSet
|
||||
Resource:
|
||||
- arn:aws:cloudformation:us-east-1:aws:transform/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sqs:*
|
||||
- sns:*
|
||||
- ec2:*
|
||||
Resource: "*"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# SAM deploy roles (5 repos)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue