diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 8d2146a..d1e8782 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1162,6 +1162,46 @@ Resources: # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update. + + # PLAT-234 principal only. The checks are seahaven-org-baseline pull request + # 160: .github/workflows/ci.yaml job iam-policy-check and + # scripts/check_iam_policies.py. That job assumes this role. It asserts + # StringEquals on the bootstrap trust templates, no lambda write on the + # plan template, then ValidatePolicy and CheckNoNewAccess when this role + # can be assumed. + SeahavenOrgBaselinePolicyCheckRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-org-baseline-policy-check + Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions. + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main + # use_immutable_subject is false, so pull_request tokens use + # repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge. + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/* + Policies: + - PolicyName: access-analyzer-policy-check + PolicyDocument: + Version: "2012-10-17" + Statement: + - Sid: AccessAnalyzerPolicyCheck + Effect: Allow + Action: + - access-analyzer:ValidatePolicy + - access-analyzer:CheckNoNewAccess + Resource: "*" + Outputs: LambdaExecutionBoundaryArn: Value: !Ref LambdaExecutionBoundary @@ -1190,4 +1230,6 @@ Outputs: # deleted only when this stack is deployed. That deploy is not this change. SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn + SeahavenOrgBaselinePolicyCheckRoleArn: + Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.