mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) (#153)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
* feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) Adds githubdeploy-seahaven-org-baseline-policy-check with only ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request. The deploy role stays limited to main and CDK assume. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * docs(iam): point the policy-check role at its CI job (PLAT-234) The Access Analyzer checks live in seahaven-org-baseline pull request 160. This role is only the principal that job assumes. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(iam): match the default pull request OIDC subject (PLAT-234) Trust refs/pull/* so seahaven-org-baseline pull request tokens can assume the policy-check role. The immutable subject claim is not enabled. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
0a1010e632
commit
8e6b8e8665
1 changed files with 42 additions and 0 deletions
|
|
@ -1380,6 +1380,46 @@ Resources:
|
|||
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
|
||||
|
||||
|
||||
|
||||
# PLAT-234 principal only. The checks are seahaven-org-baseline pull request
|
||||
# 160: .github/workflows/ci.yaml job iam-policy-check and
|
||||
# scripts/check_iam_policies.py. That job assumes this role. It asserts
|
||||
# StringEquals on the bootstrap trust templates, no lambda write on the
|
||||
# plan template, then ValidatePolicy and CheckNoNewAccess when this role
|
||||
# can be assumed.
|
||||
SeahavenOrgBaselinePolicyCheckRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-seahaven-org-baseline-policy-check
|
||||
Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions.
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub:
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
|
||||
# use_immutable_subject is false, so pull_request tokens use
|
||||
# repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge.
|
||||
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/*
|
||||
Policies:
|
||||
- PolicyName: access-analyzer-policy-check
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: AccessAnalyzerPolicyCheck
|
||||
Effect: Allow
|
||||
Action:
|
||||
- access-analyzer:ValidatePolicy
|
||||
- access-analyzer:CheckNoNewAccess
|
||||
Resource: "*"
|
||||
|
||||
Outputs:
|
||||
LambdaExecutionBoundaryArn:
|
||||
Value: !Ref LambdaExecutionBoundary
|
||||
|
|
@ -1414,4 +1454,6 @@ Outputs:
|
|||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||
SeahavenAccountBaselineDeployRoleArn:
|
||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||
SeahavenOrgBaselinePolicyCheckRoleArn:
|
||||
Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn
|
||||
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue