mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 05:53:12 +00:00
ci(templates): replace hardcoded management-account role ARN with placeholder
The sam-deploy starter template pointed every new repo's cfn-role-arn at the management account's execution role, silently landing new workloads in an account frozen for workloads. The ARN is now a REPLACE-ME placeholder with guidance to use the github-cfn-execution-role in the repo's target account.
This commit is contained in:
parent
786dcfe8d9
commit
5a5ab684f6
1 changed files with 5 additions and 2 deletions
|
|
@ -11,7 +11,10 @@ jobs:
|
|||
# NOTE: this is a literal placeholder on purpose — starter-workflow variables
|
||||
# like $default-branch substitute to the BRANCH name ("main"), not the repo name.
|
||||
stack-name: REPLACE-ME-stack-name
|
||||
# Required: the CloudFormation execution role ARN for this stack.
|
||||
cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role
|
||||
# Required: the CloudFormation execution role ARN for this stack — the
|
||||
# github-cfn-execution-role in the repo's TARGET account (part of the
|
||||
# per-account deploy substrate; the account must have it provisioned
|
||||
# before first deploy). Do not point new repos at the management account.
|
||||
cfn-role-arn: REPLACE-ME-cfn-role-arn
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue