mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-01 17:53:18 +00:00
Remove stale OIDC roles and add procurement-ingest role
Deleted roles for archived repos (ring-scheduler-3cx, workorder-ingest) and renamed po-ingest role to match the current procurement-ingest repo name.
This commit is contained in:
parent
565058ce7a
commit
aaec3fa1bd
1 changed files with 7 additions and 108 deletions
|
|
@ -72,7 +72,7 @@ Resources:
|
||||||
Resource: "*"
|
Resource: "*"
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# SAM deploy roles (6 repos)
|
# SAM deploy roles (4 repos)
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
AfterhoursShiftManagerDeployRole:
|
AfterhoursShiftManagerDeployRole:
|
||||||
|
|
@ -285,76 +285,6 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
- !GetAtt SamCfnExecutionRole.Arn
|
||||||
|
|
||||||
RingScheduler3cxDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-ring-scheduler-3cx
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: sam-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DeleteChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:DescribeStackEvents
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:GetTemplate
|
|
||||||
- cloudformation:ListStackResources
|
|
||||||
- cloudformation:UpdateStack
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
- cloudformation:TagResource
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:GetTemplateSummary
|
|
||||||
Resource: "*"
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:PutObject
|
|
||||||
- s3:GetObject
|
|
||||||
- s3:ListBucket
|
|
||||||
- s3:GetBucketLocation
|
|
||||||
- s3:CreateBucket
|
|
||||||
- s3:PutBucketPolicy
|
|
||||||
- s3:GetBucketPolicy
|
|
||||||
- s3:PutLifecycleConfiguration
|
|
||||||
- s3:PutBucketVersioning
|
|
||||||
- s3:DeleteObject
|
|
||||||
Resource:
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- iam:PassRole
|
|
||||||
Resource:
|
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
|
||||||
|
|
||||||
PaymentsDashboardDeployRole:
|
PaymentsDashboardDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -426,7 +356,7 @@ Resources:
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
- !GetAtt SamCfnExecutionRole.Arn
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# CDK deploy roles (5 repos)
|
# CDK deploy roles (4 repos)
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
SeahavenSlackBotDeployRole:
|
SeahavenSlackBotDeployRole:
|
||||||
|
|
@ -510,10 +440,10 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||||
|
|
||||||
PoIngestDeployRole:
|
ProcurementIngestDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
RoleName: githubdeploy-po-ingest
|
RoleName: githubdeploy-procurement-ingest
|
||||||
AssumeRolePolicyDocument:
|
AssumeRolePolicyDocument:
|
||||||
Version: "2012-10-17"
|
Version: "2012-10-17"
|
||||||
Statement:
|
Statement:
|
||||||
|
|
@ -525,34 +455,7 @@ Resources:
|
||||||
StringEquals:
|
StringEquals:
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||||
StringLike:
|
StringLike:
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
WorkorderIngestDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-workorder-ingest
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main
|
|
||||||
Policies:
|
Policies:
|
||||||
- PolicyName: cdk-deploy
|
- PolicyName: cdk-deploy
|
||||||
PolicyDocument:
|
PolicyDocument:
|
||||||
|
|
@ -575,8 +478,6 @@ Outputs:
|
||||||
Value: !GetAtt FrontIntegrationsDeployRole.Arn
|
Value: !GetAtt FrontIntegrationsDeployRole.Arn
|
||||||
AfiBackupMonitorDeployRoleArn:
|
AfiBackupMonitorDeployRoleArn:
|
||||||
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
||||||
RingScheduler3cxDeployRoleArn:
|
|
||||||
Value: !GetAtt RingScheduler3cxDeployRole.Arn
|
|
||||||
PaymentsDashboardDeployRoleArn:
|
PaymentsDashboardDeployRoleArn:
|
||||||
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
||||||
SeahavenSlackBotDeployRoleArn:
|
SeahavenSlackBotDeployRoleArn:
|
||||||
|
|
@ -585,7 +486,5 @@ Outputs:
|
||||||
Value: !GetAtt ExecAideDeployRole.Arn
|
Value: !GetAtt ExecAideDeployRole.Arn
|
||||||
SeahavenDoorUnlockApiDeployRoleArn:
|
SeahavenDoorUnlockApiDeployRoleArn:
|
||||||
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
||||||
PoIngestDeployRoleArn:
|
ProcurementIngestDeployRoleArn:
|
||||||
Value: !GetAtt PoIngestDeployRole.Arn
|
Value: !GetAtt ProcurementIngestDeployRole.Arn
|
||||||
WorkorderIngestDeployRoleArn:
|
|
||||||
Value: !GetAtt WorkorderIngestDeployRole.Arn
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue