mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
chore(iam): remove mgmt meal-order weekly-menu OIDC role (#123)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
Weekly-menu publish now assumes the prod HCP role; drop the orphaned mgmt github-meal-order-manager-weekly-menu role from this stack.
This commit is contained in:
parent
d37ca73ffa
commit
59c7b1f9a3
1 changed files with 7 additions and 78 deletions
|
|
@ -1353,82 +1353,12 @@ Resources:
|
|||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
||||
# repo's deploy role: the scheduled job reads Terraform-written deploy
|
||||
# parameters and app config, invokes the IAM-authenticated publication API,
|
||||
# writes the published form, and invalidates the form's CloudFront path. It
|
||||
# deploys nothing, so it gets no CloudFormation write actions, no PassRole,
|
||||
# and no DynamoDB access.
|
||||
MealOrderManagerWeeklyMenuRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: github-meal-order-manager-weekly-menu
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
# StringEquals (not the sibling roles' StringLike): no wildcard is
|
||||
# intended, and job_workflow_ref pins this runtime role to the ONE
|
||||
# workflow it serves — unlike the deploy roles, any main-branch
|
||||
# workflow must NOT be able to mint these credentials.
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/meal-order-manager:ref:refs/heads/main
|
||||
token.actions.githubusercontent.com:job_workflow_ref: !Sub ${GitHubOrg}/meal-order-manager/.github/workflows/weekly-menu.yml@refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: weekly-menu-publish
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
# Secrets Manager appends a random 6-char suffix to every secret
|
||||
# ARN, so a name-based match needs a glob — but exactly six '?'
|
||||
# (one char each), NOT '-*', which would also match any future
|
||||
# secret extending the name (e.g. form-api-key-backup).
|
||||
Resource:
|
||||
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/form-api-key-??????
|
||||
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/slack-bot-token-??????
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- ssm:GetParameter
|
||||
# Deploy targets are written by Terraform (meal-order-manager
|
||||
# terraform/ssm.tf). App config params remain named grants only.
|
||||
Resource:
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
||||
# Publication routes on the meal-order-manager HttpApi (API id
|
||||
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
|
||||
# writes go through these IAM-authenticated routes, not DynamoDB.
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- execute-api:Invoke
|
||||
Resource:
|
||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
|
||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
Resource:
|
||||
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/index.html
|
||||
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/archive/*.html
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudfront:CreateInvalidation
|
||||
# Distribution ID = the meal-order-manager stack's DistributionId
|
||||
# output (stable for the life of the distribution).
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudfront::${AWS::AccountId}:distribution/E314J1CJJ9ZTRA
|
||||
# MealOrderManagerWeeklyMenuRole removed 2026-08-20 (PLAT-70):
|
||||
# weekly-menu OIDC role now lives in seahaven-prod as
|
||||
# /tf-managed/githubdeploy-meal-order-manager-weekly-menu (HCP TF).
|
||||
# GitHub secret AWS_WEEKLY_MENU_ROLE_ARN already points at the prod role.
|
||||
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
|
||||
|
||||
|
||||
Outputs:
|
||||
LambdaExecutionBoundaryArn:
|
||||
|
|
@ -1464,5 +1394,4 @@ Outputs:
|
|||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||
SeahavenAccountBaselineDeployRoleArn:
|
||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||
MealOrderManagerWeeklyMenuRoleArn:
|
||||
Value: !GetAtt MealOrderManagerWeeklyMenuRole.Arn
|
||||
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue