Remove stale OIDC roles and add procurement-ingest role

Deleted roles for archived repos (ring-scheduler-3cx,
workorder-ingest) and renamed po-ingest role to match
the current procurement-ingest repo name.
This commit is contained in:
Adam Moussa 2026-05-13 14:01:37 -04:00
parent 565058ce7a
commit aaec3fa1bd

View file

@ -72,7 +72,7 @@ Resources:
Resource: "*"
# ---------------------------------------------------------------------------
# SAM deploy roles (6 repos)
# SAM deploy roles (4 repos)
# ---------------------------------------------------------------------------
AfterhoursShiftManagerDeployRole:
@ -285,76 +285,6 @@ Resources:
Resource:
- !GetAtt SamCfnExecutionRole.Arn
RingScheduler3cxDeployRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-ring-scheduler-3cx
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main
Policies:
- PolicyName: sam-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- cloudformation:CreateChangeSet
- cloudformation:DeleteChangeSet
- cloudformation:DescribeChangeSet
- cloudformation:DescribeStackEvents
- cloudformation:DescribeStacks
- cloudformation:ExecuteChangeSet
- cloudformation:GetTemplate
- cloudformation:ListStackResources
- cloudformation:UpdateStack
- cloudformation:CreateStack
- cloudformation:TagResource
Resource:
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/*
- Effect: Allow
Action:
- cloudformation:GetTemplateSummary
Resource: "*"
- Effect: Allow
Action:
- cloudformation:DescribeStacks
- cloudformation:CreateChangeSet
- cloudformation:DescribeChangeSet
- cloudformation:ExecuteChangeSet
- cloudformation:CreateStack
Resource:
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
- Effect: Allow
Action:
- s3:PutObject
- s3:GetObject
- s3:ListBucket
- s3:GetBucketLocation
- s3:CreateBucket
- s3:PutBucketPolicy
- s3:GetBucketPolicy
- s3:PutLifecycleConfiguration
- s3:PutBucketVersioning
- s3:DeleteObject
Resource:
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
- Effect: Allow
Action:
- iam:PassRole
Resource:
- !GetAtt SamCfnExecutionRole.Arn
PaymentsDashboardDeployRole:
Type: AWS::IAM::Role
Properties:
@ -426,7 +356,7 @@ Resources:
- !GetAtt SamCfnExecutionRole.Arn
# ---------------------------------------------------------------------------
# CDK deploy roles (5 repos)
# CDK deploy roles (4 repos)
# ---------------------------------------------------------------------------
SeahavenSlackBotDeployRole:
@ -510,10 +440,10 @@ Resources:
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
PoIngestDeployRole:
ProcurementIngestDeployRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-po-ingest
RoleName: githubdeploy-procurement-ingest
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
@ -525,34 +455,7 @@ Resources:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
WorkorderIngestDeployRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-workorder-ingest
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
@ -575,8 +478,6 @@ Outputs:
Value: !GetAtt FrontIntegrationsDeployRole.Arn
AfiBackupMonitorDeployRoleArn:
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
RingScheduler3cxDeployRoleArn:
Value: !GetAtt RingScheduler3cxDeployRole.Arn
PaymentsDashboardDeployRoleArn:
Value: !GetAtt PaymentsDashboardDeployRole.Arn
SeahavenSlackBotDeployRoleArn:
@ -585,7 +486,5 @@ Outputs:
Value: !GetAtt ExecAideDeployRole.Arn
SeahavenDoorUnlockApiDeployRoleArn:
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
PoIngestDeployRoleArn:
Value: !GetAtt PoIngestDeployRole.Arn
WorkorderIngestDeployRoleArn:
Value: !GetAtt WorkorderIngestDeployRole.Arn
ProcurementIngestDeployRoleArn:
Value: !GetAtt ProcurementIngestDeployRole.Arn