diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index f83201d..f2835a2 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -11,7 +11,10 @@ jobs: # NOTE: this is a literal placeholder on purpose — starter-workflow variables # like $default-branch substitute to the BRANCH name ("main"), not the repo name. stack-name: REPLACE-ME-stack-name - # Required: the CloudFormation execution role ARN for this stack. - cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role + # Required: the CloudFormation execution role ARN for this stack — the + # github-cfn-execution-role in the repo's TARGET account (part of the + # per-account deploy substrate; the account must have it provisioned + # before first deploy). Do not point new repos at the management account. + cfn-role-arn: REPLACE-ME-cfn-role-arn secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}