From 5a5ab684f6dc93a0ebe1021b3ab10964b5202128 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 27 Jul 2026 16:03:25 -0400 Subject: [PATCH] ci(templates): replace hardcoded management-account role ARN with placeholder The sam-deploy starter template pointed every new repo's cfn-role-arn at the management account's execution role, silently landing new workloads in an account frozen for workloads. The ARN is now a REPLACE-ME placeholder with guidance to use the github-cfn-execution-role in the repo's target account. --- workflow-templates/sam-deploy.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index f83201d..f2835a2 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -11,7 +11,10 @@ jobs: # NOTE: this is a literal placeholder on purpose — starter-workflow variables # like $default-branch substitute to the BRANCH name ("main"), not the repo name. stack-name: REPLACE-ME-stack-name - # Required: the CloudFormation execution role ARN for this stack. - cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role + # Required: the CloudFormation execution role ARN for this stack — the + # github-cfn-execution-role in the repo's TARGET account (part of the + # per-account deploy substrate; the account must have it provisioned + # before first deploy). Do not point new repos at the management account. + cfn-role-arn: REPLACE-ME-cfn-role-arn secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}