From b1b341afe5b7afd0407e80a1ad4da3bfa0c9104e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 13 May 2026 14:06:09 -0400 Subject: [PATCH] Remove stale OIDC roles and add procurement-ingest role (#24) Deleted roles for archived repos (ring-scheduler-3cx, workorder-ingest) and renamed po-ingest role to match the current procurement-ingest repo name. --- oidc-deploy-roles.yaml | 115 +++-------------------------------------- 1 file changed, 7 insertions(+), 108 deletions(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index b42325d..48539a5 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -72,7 +72,7 @@ Resources: Resource: "*" # --------------------------------------------------------------------------- - # SAM deploy roles (6 repos) + # SAM deploy roles (4 repos) # --------------------------------------------------------------------------- AfterhoursShiftManagerDeployRole: @@ -285,76 +285,6 @@ Resources: Resource: - !GetAtt SamCfnExecutionRole.Arn - RingScheduler3cxDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-ring-scheduler-3cx - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main - Policies: - - PolicyName: sam-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - cloudformation:CreateChangeSet - - cloudformation:DeleteChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:DescribeStackEvents - - cloudformation:DescribeStacks - - cloudformation:ExecuteChangeSet - - cloudformation:GetTemplate - - cloudformation:ListStackResources - - cloudformation:UpdateStack - - cloudformation:CreateStack - - cloudformation:TagResource - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/* - - Effect: Allow - Action: - - cloudformation:GetTemplateSummary - Resource: "*" - - Effect: Allow - Action: - - cloudformation:DescribeStacks - - cloudformation:CreateChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:ExecuteChangeSet - - cloudformation:CreateStack - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - - Effect: Allow - Action: - - s3:PutObject - - s3:GetObject - - s3:ListBucket - - s3:GetBucketLocation - - s3:CreateBucket - - s3:PutBucketPolicy - - s3:GetBucketPolicy - - s3:PutLifecycleConfiguration - - s3:PutBucketVersioning - - s3:DeleteObject - Resource: - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - - Effect: Allow - Action: - - iam:PassRole - Resource: - - !GetAtt SamCfnExecutionRole.Arn - PaymentsDashboardDeployRole: Type: AWS::IAM::Role Properties: @@ -426,7 +356,7 @@ Resources: - !GetAtt SamCfnExecutionRole.Arn # --------------------------------------------------------------------------- - # CDK deploy roles (5 repos) + # CDK deploy roles (4 repos) # --------------------------------------------------------------------------- SeahavenSlackBotDeployRole: @@ -510,10 +440,10 @@ Resources: Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - PoIngestDeployRole: + ProcurementIngestDeployRole: Type: AWS::IAM::Role Properties: - RoleName: githubdeploy-po-ingest + RoleName: githubdeploy-procurement-ingest AssumeRolePolicyDocument: Version: "2012-10-17" Statement: @@ -525,34 +455,7 @@ Resources: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - - WorkorderIngestDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-workorder-ingest - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: @@ -575,8 +478,6 @@ Outputs: Value: !GetAtt FrontIntegrationsDeployRole.Arn AfiBackupMonitorDeployRoleArn: Value: !GetAtt AfiBackupMonitorDeployRole.Arn - RingScheduler3cxDeployRoleArn: - Value: !GetAtt RingScheduler3cxDeployRole.Arn PaymentsDashboardDeployRoleArn: Value: !GetAtt PaymentsDashboardDeployRole.Arn SeahavenSlackBotDeployRoleArn: @@ -585,7 +486,5 @@ Outputs: Value: !GetAtt ExecAideDeployRole.Arn SeahavenDoorUnlockApiDeployRoleArn: Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn - PoIngestDeployRoleArn: - Value: !GetAtt PoIngestDeployRole.Arn - WorkorderIngestDeployRoleArn: - Value: !GetAtt WorkorderIngestDeployRole.Arn + ProcurementIngestDeployRoleArn: + Value: !GetAtt ProcurementIngestDeployRole.Arn