mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
chore(iam): remove mgmt meal-order weekly-menu OIDC role (#123)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
Weekly-menu publish now assumes the prod HCP role; drop the orphaned mgmt github-meal-order-manager-weekly-menu role from this stack.
This commit is contained in:
parent
d37ca73ffa
commit
59c7b1f9a3
1 changed files with 7 additions and 78 deletions
|
|
@ -1353,82 +1353,12 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||||
|
|
||||||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
# MealOrderManagerWeeklyMenuRole removed 2026-08-20 (PLAT-70):
|
||||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
# weekly-menu OIDC role now lives in seahaven-prod as
|
||||||
# repo's deploy role: the scheduled job reads Terraform-written deploy
|
# /tf-managed/githubdeploy-meal-order-manager-weekly-menu (HCP TF).
|
||||||
# parameters and app config, invokes the IAM-authenticated publication API,
|
# GitHub secret AWS_WEEKLY_MENU_ROLE_ARN already points at the prod role.
|
||||||
# writes the published form, and invalidates the form's CloudFront path. It
|
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
|
||||||
# deploys nothing, so it gets no CloudFormation write actions, no PassRole,
|
|
||||||
# and no DynamoDB access.
|
|
||||||
MealOrderManagerWeeklyMenuRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: github-meal-order-manager-weekly-menu
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
# StringEquals (not the sibling roles' StringLike): no wildcard is
|
|
||||||
# intended, and job_workflow_ref pins this runtime role to the ONE
|
|
||||||
# workflow it serves — unlike the deploy roles, any main-branch
|
|
||||||
# workflow must NOT be able to mint these credentials.
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/meal-order-manager:ref:refs/heads/main
|
|
||||||
token.actions.githubusercontent.com:job_workflow_ref: !Sub ${GitHubOrg}/meal-order-manager/.github/workflows/weekly-menu.yml@refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: weekly-menu-publish
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- secretsmanager:GetSecretValue
|
|
||||||
# Secrets Manager appends a random 6-char suffix to every secret
|
|
||||||
# ARN, so a name-based match needs a glob — but exactly six '?'
|
|
||||||
# (one char each), NOT '-*', which would also match any future
|
|
||||||
# secret extending the name (e.g. form-api-key-backup).
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/form-api-key-??????
|
|
||||||
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/slack-bot-token-??????
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- ssm:GetParameter
|
|
||||||
# Deploy targets are written by Terraform (meal-order-manager
|
|
||||||
# terraform/ssm.tf). App config params remain named grants only.
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
|
||||||
# Publication routes on the meal-order-manager HttpApi (API id
|
|
||||||
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
|
|
||||||
# writes go through these IAM-authenticated routes, not DynamoDB.
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- execute-api:Invoke
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
|
|
||||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:PutObject
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/index.html
|
|
||||||
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/archive/*.html
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudfront:CreateInvalidation
|
|
||||||
# Distribution ID = the meal-order-manager stack's DistributionId
|
|
||||||
# output (stable for the life of the distribution).
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudfront::${AWS::AccountId}:distribution/E314J1CJJ9ZTRA
|
|
||||||
|
|
||||||
Outputs:
|
Outputs:
|
||||||
LambdaExecutionBoundaryArn:
|
LambdaExecutionBoundaryArn:
|
||||||
|
|
@ -1464,5 +1394,4 @@ Outputs:
|
||||||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||||
SeahavenAccountBaselineDeployRoleArn:
|
SeahavenAccountBaselineDeployRoleArn:
|
||||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||||
MealOrderManagerWeeklyMenuRoleArn:
|
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
||||||
Value: !GetAtt MealOrderManagerWeeklyMenuRole.Arn
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue