From b273e5cd5c2c288cdc2449c72a96940f24cd888c Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 8 May 2026 17:12:03 -0400 Subject: [PATCH] Fix CFN execution role transform permission and pip install path (#12) - Add cloudformation:CreateChangeSet on aws:transform/* to the shared CFN execution role (required for SAM's Serverless transform) - Remove working-directory from pip install step so it finds requirements.txt at repo root (not just cdk-dir) --- .github/workflows/cd-cdk.yaml | 1 - oidc-deploy-roles.yaml | 10 ++++++++++ 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index b629225..ecc1cbb 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -57,7 +57,6 @@ jobs: - name: Install Python dependencies if: ${{ inputs.python-version != '' }} - working-directory: ${{ inputs.cdk-dir }} run: | for req in $(find . -name requirements.txt -not -path '*/node_modules/*'); do pip install -r "$req" diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index d4be4f0..1064656 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -54,6 +54,16 @@ Resources: - arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess - arn:aws:iam::aws:policy/AmazonSESFullAccess - arn:aws:iam::aws:policy/IAMFullAccess + Policies: + - PolicyName: cloudformation-transforms + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + Resource: + - arn:aws:cloudformation:us-east-1:aws:transform/* # --------------------------------------------------------------------------- # SAM deploy roles (5 repos)