diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 522a567..b42325d 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -72,7 +72,7 @@ Resources: Resource: "*" # --------------------------------------------------------------------------- - # SAM deploy roles (5 repos) + # SAM deploy roles (6 repos) # --------------------------------------------------------------------------- AfterhoursShiftManagerDeployRole: @@ -145,6 +145,76 @@ Resources: Resource: - !GetAtt SamCfnExecutionRole.Arn + FrontIntegrationsDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-front-integrations + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + AfiBackupMonitorDeployRole: Type: AWS::IAM::Role Properties: @@ -501,6 +571,8 @@ Outputs: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn + FrontIntegrationsDeployRoleArn: + Value: !GetAtt FrontIntegrationsDeployRole.Arn AfiBackupMonitorDeployRoleArn: Value: !GetAtt AfiBackupMonitorDeployRole.Arn RingScheduler3cxDeployRoleArn: