mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 03:43:10 +00:00
Add reusable CD workflows and OIDC deploy roles template (#11)
Two reusable deploy workflows (cd-sam.yaml, cd-cdk.yaml) for GitHub Actions OIDC-based deployments. CloudFormation template provisions per-repo deploy roles for all 10 deployable repos.
This commit is contained in:
parent
f92ac07ce6
commit
9a8d1f7736
4 changed files with 790 additions and 1 deletions
73
.github/workflows/cd-cdk.yaml
vendored
Normal file
73
.github/workflows/cd-cdk.yaml
vendored
Normal file
|
|
@ -0,0 +1,73 @@
|
|||
name: CD — CDK Deploy
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
node-version:
|
||||
description: "Node.js version to use"
|
||||
type: string
|
||||
default: "22"
|
||||
python-version:
|
||||
description: "Python version for Python CDK repos (leave empty for TypeScript CDK)"
|
||||
type: string
|
||||
default: ""
|
||||
region:
|
||||
description: "AWS region"
|
||||
type: string
|
||||
default: "us-east-1"
|
||||
cdk-dir:
|
||||
description: "Directory containing cdk.json"
|
||||
type: string
|
||||
default: "."
|
||||
enable-qemu:
|
||||
description: "Enable QEMU for cross-platform Docker builds (arm64 on x86 runners)"
|
||||
type: boolean
|
||||
default: false
|
||||
secrets:
|
||||
deploy-role-arn:
|
||||
description: "OIDC deploy role ARN"
|
||||
required: true
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 20
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: docker/setup-qemu-action@v3
|
||||
if: ${{ inputs.enable-qemu }}
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: ${{ inputs.node-version }}
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
if: ${{ inputs.python-version != '' }}
|
||||
with:
|
||||
python-version: ${{ inputs.python-version }}
|
||||
|
||||
- name: Install Node dependencies
|
||||
if: ${{ inputs.python-version == '' }}
|
||||
run: npm ci
|
||||
|
||||
- name: Install Python dependencies
|
||||
if: ${{ inputs.python-version != '' }}
|
||||
working-directory: ${{ inputs.cdk-dir }}
|
||||
run: |
|
||||
for req in $(find . -name requirements.txt -not -path '*/node_modules/*'); do
|
||||
pip install -r "$req"
|
||||
done
|
||||
|
||||
- uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.deploy-role-arn }}
|
||||
aws-region: ${{ inputs.region }}
|
||||
|
||||
- name: CDK deploy
|
||||
working-directory: ${{ inputs.cdk-dir }}
|
||||
run: npx -y cdk deploy --all --require-approval never
|
||||
65
.github/workflows/cd-sam.yaml
vendored
Normal file
65
.github/workflows/cd-sam.yaml
vendored
Normal file
|
|
@ -0,0 +1,65 @@
|
|||
name: CD — SAM Deploy
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
python-version:
|
||||
description: "Python version to use"
|
||||
type: string
|
||||
default: "3.12"
|
||||
stack-name:
|
||||
description: "CloudFormation stack name"
|
||||
type: string
|
||||
required: true
|
||||
sam-template:
|
||||
description: "Path to SAM template file"
|
||||
type: string
|
||||
default: "template.yaml"
|
||||
region:
|
||||
description: "AWS region"
|
||||
type: string
|
||||
default: "us-east-1"
|
||||
cfn-role-arn:
|
||||
description: "CloudFormation execution role ARN"
|
||||
type: string
|
||||
required: true
|
||||
secrets:
|
||||
deploy-role-arn:
|
||||
description: "OIDC deploy role ARN"
|
||||
required: true
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: ${{ inputs.python-version }}
|
||||
|
||||
- uses: aws-actions/setup-sam@v2
|
||||
|
||||
- uses: aws-actions/configure-aws-credentials@v4
|
||||
with:
|
||||
role-to-assume: ${{ secrets.deploy-role-arn }}
|
||||
aws-region: ${{ inputs.region }}
|
||||
|
||||
- name: SAM build
|
||||
run: sam build --template ${{ inputs.sam-template }}
|
||||
|
||||
- name: SAM deploy
|
||||
run: |
|
||||
sam deploy \
|
||||
--stack-name ${{ inputs.stack-name }} \
|
||||
--template-file .aws-sam/build/template.yaml \
|
||||
--resolve-s3 \
|
||||
--capabilities CAPABILITY_IAM \
|
||||
--no-confirm-changeset \
|
||||
--no-fail-on-empty-changeset \
|
||||
--role-arn ${{ inputs.cfn-role-arn }}
|
||||
78
README.md
78
README.md
|
|
@ -10,6 +10,10 @@ Organization-level GitHub configuration for Sea Haven Industries.
|
|||
|
||||
**`.github/workflows/ci-typescript-cdk.yaml`** — Reusable CI workflow for TypeScript / CDK repos. Runs `npm ci` + optional `tsc --noEmit`, optional ESLint, optional Jest, and optional `cdk synth`. Also supports Node.js SAM repos via an optional `sam validate` step.
|
||||
|
||||
**`.github/workflows/cd-sam.yaml`** — Reusable CD workflow for SAM repos. Runs `sam build` + `sam deploy` with OIDC credentials and a CloudFormation execution role. Triggers via `workflow_call` from per-repo `deploy.yaml` on push to `main`.
|
||||
|
||||
**`.github/workflows/cd-cdk.yaml`** — Reusable CD workflow for CDK repos (TypeScript and Python). Runs `cdk deploy --all` with OIDC credentials. Supports optional Python setup for Python CDK repos and QEMU emulation for cross-platform Docker builds.
|
||||
|
||||
**`.github/workflows/claude-code-review.yaml`** — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
|
||||
|
||||
**`.github/workflows/compliance-audit.yaml`** — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via `workflow_dispatch`.
|
||||
|
|
@ -117,6 +121,78 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
||||
```
|
||||
|
||||
### 5. Add CD to a repo
|
||||
|
||||
Create `.github/workflows/deploy.yaml` in the target repo. Requires `AWS_DEPLOY_ROLE_ARN` repo secret.
|
||||
|
||||
**SAM repo** (e.g., afterhours-shift-manager):
|
||||
|
||||
```yaml
|
||||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
|
||||
with:
|
||||
stack-name: afterhours-shift-manager
|
||||
cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
```
|
||||
|
||||
**TypeScript CDK repo** (e.g., seahaven-door-unlock-api):
|
||||
|
||||
```yaml
|
||||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
```
|
||||
|
||||
**Python CDK repo** (e.g., po-ingest):
|
||||
|
||||
```yaml
|
||||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||
with:
|
||||
python-version: "3.12"
|
||||
cdk-dir: cdk
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
```
|
||||
|
||||
**CDK repo with arm64 Docker builds** (e.g., exec-aide):
|
||||
|
||||
```yaml
|
||||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
||||
with:
|
||||
enable-qemu: true
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
```
|
||||
|
||||
Enable optional steps as repos adopt them:
|
||||
|
||||
| Input | Default | Turn on when... |
|
||||
|
|
@ -127,7 +203,7 @@ Enable optional steps as repos adopt them:
|
|||
| `run-cdk-synth` | `true` | Repo is CDK-based |
|
||||
| `run-sam-validate` | `true` (Python) / `false` (TS) | Repo has a SAM template |
|
||||
|
||||
### 5. Roll out PR reviews to repos
|
||||
### 6. Roll out PR reviews to repos
|
||||
|
||||
```bash
|
||||
./scripts/rollout-review-workflow.sh
|
||||
|
|
|
|||
575
oidc-deploy-roles.yaml
Normal file
575
oidc-deploy-roles.yaml
Normal file
|
|
@ -0,0 +1,575 @@
|
|||
AWSTemplateFormatVersion: "2010-09-09"
|
||||
Description: >-
|
||||
GitHub Actions OIDC deploy roles for Sea Haven Industries repos.
|
||||
Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC.
|
||||
|
||||
Parameters:
|
||||
GitHubOrg:
|
||||
Type: String
|
||||
Default: Sea-Haven-Industries
|
||||
CreateOIDCProvider:
|
||||
Type: String
|
||||
Default: "false"
|
||||
AllowedValues: ["true", "false"]
|
||||
Description: Set to true only if the GitHub OIDC provider does not already exist in this account
|
||||
|
||||
Conditions:
|
||||
ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"]
|
||||
|
||||
Resources:
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# OIDC Provider (conditional — already exists for seahaven-site)
|
||||
# ---------------------------------------------------------------------------
|
||||
GitHubOIDCProvider:
|
||||
Type: AWS::IAM::OIDCProvider
|
||||
Condition: ShouldCreateOIDCProvider
|
||||
Properties:
|
||||
Url: https://token.actions.githubusercontent.com
|
||||
ClientIdList:
|
||||
- sts.amazonaws.com
|
||||
ThumbprintList:
|
||||
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Shared CloudFormation execution role (SAM stacks)
|
||||
# ---------------------------------------------------------------------------
|
||||
SamCfnExecutionRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: github-cfn-execution-role
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Service: cloudformation.amazonaws.com
|
||||
Action: sts:AssumeRole
|
||||
ManagedPolicyArns:
|
||||
- arn:aws:iam::aws:policy/AWSLambda_FullAccess
|
||||
- arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator
|
||||
- arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
|
||||
- arn:aws:iam::aws:policy/AmazonS3FullAccess
|
||||
- arn:aws:iam::aws:policy/CloudWatchLogsFullAccess
|
||||
- arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
|
||||
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
||||
- arn:aws:iam::aws:policy/IAMFullAccess
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# SAM deploy roles (5 repos)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
AfterhoursShiftManagerDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-afterhours-shift-manager
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: sam-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DeleteChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:DescribeStackEvents
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:GetTemplate
|
||||
- cloudformation:ListStackResources
|
||||
- cloudformation:UpdateStack
|
||||
- cloudformation:CreateStack
|
||||
- cloudformation:TagResource
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:GetTemplateSummary
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:CreateStack
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
- s3:GetObject
|
||||
- s3:ListBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketPolicy
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutLifecycleConfiguration
|
||||
- s3:PutBucketVersioning
|
||||
- s3:DeleteObject
|
||||
Resource:
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- iam:PassRole
|
||||
Resource:
|
||||
- !GetAtt SamCfnExecutionRole.Arn
|
||||
|
||||
ExpenseApprovalBotDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-expense-approval-bot
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/expense-approval-bot:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: sam-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DeleteChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:DescribeStackEvents
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:GetTemplate
|
||||
- cloudformation:ListStackResources
|
||||
- cloudformation:UpdateStack
|
||||
- cloudformation:CreateStack
|
||||
- cloudformation:TagResource
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/expense-approval-bot/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:GetTemplateSummary
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:CreateStack
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
- s3:GetObject
|
||||
- s3:ListBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketPolicy
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutLifecycleConfiguration
|
||||
- s3:PutBucketVersioning
|
||||
- s3:DeleteObject
|
||||
Resource:
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- iam:PassRole
|
||||
Resource:
|
||||
- !GetAtt SamCfnExecutionRole.Arn
|
||||
|
||||
AfiBackupMonitorDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-afi-backup-monitor
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: sam-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DeleteChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:DescribeStackEvents
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:GetTemplate
|
||||
- cloudformation:ListStackResources
|
||||
- cloudformation:UpdateStack
|
||||
- cloudformation:CreateStack
|
||||
- cloudformation:TagResource
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:GetTemplateSummary
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:CreateStack
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
- s3:GetObject
|
||||
- s3:ListBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketPolicy
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutLifecycleConfiguration
|
||||
- s3:PutBucketVersioning
|
||||
- s3:DeleteObject
|
||||
Resource:
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- iam:PassRole
|
||||
Resource:
|
||||
- !GetAtt SamCfnExecutionRole.Arn
|
||||
|
||||
RingScheduler3cxDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-ring-scheduler-3cx
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: sam-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DeleteChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:DescribeStackEvents
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:GetTemplate
|
||||
- cloudformation:ListStackResources
|
||||
- cloudformation:UpdateStack
|
||||
- cloudformation:CreateStack
|
||||
- cloudformation:TagResource
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:GetTemplateSummary
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:CreateStack
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
- s3:GetObject
|
||||
- s3:ListBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketPolicy
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutLifecycleConfiguration
|
||||
- s3:PutBucketVersioning
|
||||
- s3:DeleteObject
|
||||
Resource:
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- iam:PassRole
|
||||
Resource:
|
||||
- !GetAtt SamCfnExecutionRole.Arn
|
||||
|
||||
PaymentsDashboardDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-payments-dashboard
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: sam-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DeleteChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:DescribeStackEvents
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:GetTemplate
|
||||
- cloudformation:ListStackResources
|
||||
- cloudformation:UpdateStack
|
||||
- cloudformation:CreateStack
|
||||
- cloudformation:TagResource
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:GetTemplateSummary
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
- cloudformation:CreateChangeSet
|
||||
- cloudformation:DescribeChangeSet
|
||||
- cloudformation:ExecuteChangeSet
|
||||
- cloudformation:CreateStack
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
- s3:GetObject
|
||||
- s3:ListBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketPolicy
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutLifecycleConfiguration
|
||||
- s3:PutBucketVersioning
|
||||
- s3:DeleteObject
|
||||
Resource:
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- iam:PassRole
|
||||
Resource:
|
||||
- !GetAtt SamCfnExecutionRole.Arn
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# CDK deploy roles (5 repos)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
SeahavenSlackBotDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-seahaven-slack-bot
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
ExecAideDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-exec-aide
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
SeahavenDoorUnlockApiDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-seahaven-door-unlock-api
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
PoIngestDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-po-ingest
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
WorkorderIngestDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-workorder-ingest
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
Outputs:
|
||||
SamCfnExecutionRoleArn:
|
||||
Value: !GetAtt SamCfnExecutionRole.Arn
|
||||
Export:
|
||||
Name: github-cfn-execution-role-arn
|
||||
AfterhoursShiftManagerDeployRoleArn:
|
||||
Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn
|
||||
ExpenseApprovalBotDeployRoleArn:
|
||||
Value: !GetAtt ExpenseApprovalBotDeployRole.Arn
|
||||
AfiBackupMonitorDeployRoleArn:
|
||||
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
||||
RingScheduler3cxDeployRoleArn:
|
||||
Value: !GetAtt RingScheduler3cxDeployRole.Arn
|
||||
PaymentsDashboardDeployRoleArn:
|
||||
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
||||
SeahavenSlackBotDeployRoleArn:
|
||||
Value: !GetAtt SeahavenSlackBotDeployRole.Arn
|
||||
ExecAideDeployRoleArn:
|
||||
Value: !GetAtt ExecAideDeployRole.Arn
|
||||
SeahavenDoorUnlockApiDeployRoleArn:
|
||||
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
||||
PoIngestDeployRoleArn:
|
||||
Value: !GetAtt PoIngestDeployRole.Arn
|
||||
WorkorderIngestDeployRoleArn:
|
||||
Value: !GetAtt WorkorderIngestDeployRole.Arn
|
||||
Loading…
Add table
Reference in a new issue