Add SQS/EC2/SNS to CFN execution role and parameter overrides to cd-sam

- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
  SAM templates with required parameters
This commit is contained in:
Adam Moussa 2026-05-08 17:18:32 -04:00
parent b273e5cd5c
commit 50a0ff53d7
2 changed files with 17 additions and 2 deletions

View file

@ -23,6 +23,10 @@ on:
description: "CloudFormation execution role ARN"
type: string
required: true
parameter-overrides:
description: "SAM parameter overrides (e.g. 'Key1=Value1 Key2=Value2')"
type: string
default: ""
secrets:
deploy-role-arn:
description: "OIDC deploy role ARN"
@ -55,6 +59,10 @@ jobs:
- name: SAM deploy
run: |
PARAMS=""
if [ -n "${{ inputs.parameter-overrides }}" ]; then
PARAMS="--parameter-overrides ${{ inputs.parameter-overrides }}"
fi
sam deploy \
--stack-name ${{ inputs.stack-name }} \
--template-file .aws-sam/build/template.yaml \
@ -62,4 +70,5 @@ jobs:
--capabilities CAPABILITY_IAM \
--no-confirm-changeset \
--no-fail-on-empty-changeset \
--role-arn ${{ inputs.cfn-role-arn }}
--role-arn ${{ inputs.cfn-role-arn }} \
$PARAMS

View file

@ -55,7 +55,7 @@ Resources:
- arn:aws:iam::aws:policy/AmazonSESFullAccess
- arn:aws:iam::aws:policy/IAMFullAccess
Policies:
- PolicyName: cloudformation-transforms
- PolicyName: additional-service-permissions
PolicyDocument:
Version: "2012-10-17"
Statement:
@ -64,6 +64,12 @@ Resources:
- cloudformation:CreateChangeSet
Resource:
- arn:aws:cloudformation:us-east-1:aws:transform/*
- Effect: Allow
Action:
- sqs:*
- sns:*
- ec2:*
Resource: "*"
# ---------------------------------------------------------------------------
# SAM deploy roles (5 repos)