diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index e273cf1..a068911 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1299,33 +1299,6 @@ Resources: Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - ProcurementIngestDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-procurement-ingest - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - ApmWoAnalysisDeployRole: Type: AWS::IAM::Role Properties: @@ -1483,8 +1456,8 @@ Outputs: Value: !GetAtt ExecAideDeployRole.Arn SeahavenDoorUnlockApiDeployRoleArn: Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn - ProcurementIngestDeployRoleArn: - Value: !GetAtt ProcurementIngestDeployRole.Arn + # ProcurementIngestDeployRoleArn removed 2026-08-07 (PLAT-88): HCP sole + # mutate path; prod githubdeploy role deleted; mgmt twin already gone. ApmWoAnalysisDeployRoleArn: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: