Add githubdeploy-apm-wo-analysis OIDC deploy role

Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
This commit is contained in:
Adam Moussa 2026-05-29 13:35:25 -04:00
parent 333a9613b5
commit 6db9f44a47

View file

@ -467,6 +467,33 @@ Resources:
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
ApmWoAnalysisDeployRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-apm-wo-analysis
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
Outputs:
SamCfnExecutionRoleArn:
Value: !GetAtt SamCfnExecutionRole.Arn
@ -488,3 +515,5 @@ Outputs:
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
ProcurementIngestDeployRoleArn:
Value: !GetAtt ProcurementIngestDeployRole.Arn
ApmWoAnalysisDeployRoleArn:
Value: !GetAtt ApmWoAnalysisDeployRole.Arn