From 8e6b8e866593c8798d105030462220baeee3bd54 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 28 Sep 2026 16:23:57 +0000 Subject: [PATCH] feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) (#153) * feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) Adds githubdeploy-seahaven-org-baseline-policy-check with only ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request. The deploy role stays limited to main and CDK assume. Co-authored-by: Adam Moussa * docs(iam): point the policy-check role at its CI job (PLAT-234) The Access Analyzer checks live in seahaven-org-baseline pull request 160. This role is only the principal that job assumes. Co-authored-by: Adam Moussa * fix(iam): match the default pull request OIDC subject (PLAT-234) Trust refs/pull/* so seahaven-org-baseline pull request tokens can assume the policy-check role. The immutable subject claim is not enabled. Co-authored-by: Adam Moussa --------- Co-authored-by: Cursor Agent Co-authored-by: Adam Moussa --- oidc-deploy-roles.yaml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 2d43de5..c210ed0 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1380,6 +1380,46 @@ Resources: # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update. + + # PLAT-234 principal only. The checks are seahaven-org-baseline pull request + # 160: .github/workflows/ci.yaml job iam-policy-check and + # scripts/check_iam_policies.py. That job assumes this role. It asserts + # StringEquals on the bootstrap trust templates, no lambda write on the + # plan template, then ValidatePolicy and CheckNoNewAccess when this role + # can be assumed. + SeahavenOrgBaselinePolicyCheckRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-seahaven-org-baseline-policy-check + Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions. + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main + # use_immutable_subject is false, so pull_request tokens use + # repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge. + - !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/* + Policies: + - PolicyName: access-analyzer-policy-check + PolicyDocument: + Version: "2012-10-17" + Statement: + - Sid: AccessAnalyzerPolicyCheck + Effect: Allow + Action: + - access-analyzer:ValidatePolicy + - access-analyzer:CheckNoNewAccess + Resource: "*" + Outputs: LambdaExecutionBoundaryArn: Value: !Ref LambdaExecutionBoundary @@ -1414,4 +1454,6 @@ Outputs: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn + SeahavenOrgBaselinePolicyCheckRoleArn: + Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.