diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 432e9e8..b096864 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1381,6 +1381,12 @@ Resources: + # PLAT-234 principal only. The checks are seahaven-org-baseline pull request + # 160: .github/workflows/ci.yaml job iam-policy-check and + # scripts/check_iam_policies.py. That job assumes this role. It asserts + # StringEquals on the bootstrap trust templates, no lambda write on the + # plan template, then ValidatePolicy and CheckNoNewAccess when this role + # can be assumed. SeahavenOrgBaselinePolicyCheckRole: Type: AWS::IAM::Role Properties: