chore(iam): remove mgmt meal-order weekly-menu OIDC role (#123)
Some checks are pending
ci / ci / ci (push) Waiting to run

Weekly-menu publish now assumes the prod HCP role; drop the orphaned
mgmt github-meal-order-manager-weekly-menu role from this stack.
This commit is contained in:
Adam Moussa 2026-08-20 13:21:59 -04:00 • committed by GitHub
parent d37ca73ffa
commit 59c7b1f9a3
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1353,82 +1353,12 @@ Resources:
Resource: Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
# Scoped runtime role for the meal-order-manager weekly-menu workflow # MealOrderManagerWeeklyMenuRole removed 2026-08-20 (PLAT-70):
# (Monday scrape + order-form publish). Deliberately narrower than the # weekly-menu OIDC role now lives in seahaven-prod as
# repo's deploy role: the scheduled job reads Terraform-written deploy # /tf-managed/githubdeploy-meal-order-manager-weekly-menu (HCP TF).
# parameters and app config, invokes the IAM-authenticated publication API, # GitHub secret AWS_WEEKLY_MENU_ROLE_ARN already points at the prod role.
# writes the published form, and invalidates the form's CloudFront path. It # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
# deploys nothing, so it gets no CloudFormation write actions, no PassRole,
# and no DynamoDB access.
MealOrderManagerWeeklyMenuRole:
Type: AWS::IAM::Role
Properties:
RoleName: github-meal-order-manager-weekly-menu
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
# StringEquals (not the sibling roles' StringLike): no wildcard is
# intended, and job_workflow_ref pins this runtime role to the ONE
# workflow it serves — unlike the deploy roles, any main-branch
# workflow must NOT be able to mint these credentials.
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/meal-order-manager:ref:refs/heads/main
token.actions.githubusercontent.com:job_workflow_ref: !Sub ${GitHubOrg}/meal-order-manager/.github/workflows/weekly-menu.yml@refs/heads/main
Policies:
- PolicyName: weekly-menu-publish
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
# Secrets Manager appends a random 6-char suffix to every secret
# ARN, so a name-based match needs a glob — but exactly six '?'
# (one char each), NOT '-*', which would also match any future
# secret extending the name (e.g. form-api-key-backup).
Resource:
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/form-api-key-??????
- !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/slack-bot-token-??????
- Effect: Allow
Action:
- ssm:GetParameter
# Deploy targets are written by Terraform (meal-order-manager
# terraform/ssm.tf). App config params remain named grants only.
Resource:
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
# Publication routes on the meal-order-manager HttpApi (API id
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
# writes go through these IAM-authenticated routes, not DynamoDB.
- Effect: Allow
Action:
- execute-api:Invoke
Resource:
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
- Effect: Allow
Action:
- s3:PutObject
Resource:
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/index.html
- !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/archive/*.html
- Effect: Allow
Action:
- cloudfront:CreateInvalidation
# Distribution ID = the meal-order-manager stack's DistributionId
# output (stable for the life of the distribution).
Resource:
- !Sub arn:aws:cloudfront::${AWS::AccountId}:distribution/E314J1CJJ9ZTRA
Outputs: Outputs:
LambdaExecutionBoundaryArn: LambdaExecutionBoundaryArn:
@ -1464,5 +1394,4 @@ Outputs:
Value: !GetAtt ApmWoAnalysisDeployRole.Arn Value: !GetAtt ApmWoAnalysisDeployRole.Arn
SeahavenAccountBaselineDeployRoleArn: SeahavenAccountBaselineDeployRoleArn:
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
MealOrderManagerWeeklyMenuRoleArn: # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
Value: !GetAtt MealOrderManagerWeeklyMenuRole.Arn