From bcbfd8ebfa57d64ebee94a348151b27ea052a233 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 12 May 2026 13:37:04 -0400 Subject: [PATCH] Add OIDC deploy role for front-integrations (#22) Consolidates front-sla-monitor and google-user-sync into a single SAM deploy role for the new front-integrations repo. --- oidc-deploy-roles.yaml | 74 +++++++++++++++++++++++++++++++++++++++++- 1 file changed, 73 insertions(+), 1 deletion(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index eec2e7d..24e9a9e 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -72,7 +72,7 @@ Resources: Resource: "*" # --------------------------------------------------------------------------- - # SAM deploy roles (5 repos) + # SAM deploy roles (6 repos) # --------------------------------------------------------------------------- AfterhoursShiftManagerDeployRole: @@ -145,6 +145,76 @@ Resources: Resource: - !GetAtt SamCfnExecutionRole.Arn + FrontIntegrationsDeployRole: + Type: AWS::IAM::Role + Properties: + RoleName: githubdeploy-front-integrations + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com + Action: sts:AssumeRoleWithWebIdentity + Condition: + StringEquals: + token.actions.githubusercontent.com:aud: sts.amazonaws.com + StringLike: + token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main + Policies: + - PolicyName: sam-deploy + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:DescribeStackEvents + - cloudformation:DescribeStacks + - cloudformation:ExecuteChangeSet + - cloudformation:GetTemplate + - cloudformation:ListStackResources + - cloudformation:UpdateStack + - cloudformation:CreateStack + - cloudformation:TagResource + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/* + - Effect: Allow + Action: + - cloudformation:GetTemplateSummary + Resource: "*" + - Effect: Allow + Action: + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:CreateStack + Resource: + - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* + - Effect: Allow + Action: + - s3:PutObject + - s3:GetObject + - s3:ListBucket + - s3:GetBucketLocation + - s3:CreateBucket + - s3:PutBucketPolicy + - s3:GetBucketPolicy + - s3:PutLifecycleConfiguration + - s3:PutBucketVersioning + - s3:DeleteObject + Resource: + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* + - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* + - Effect: Allow + Action: + - iam:PassRole + Resource: + - !GetAtt SamCfnExecutionRole.Arn + ExpenseApprovalBotDeployRole: Type: AWS::IAM::Role Properties: @@ -571,6 +641,8 @@ Outputs: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn + FrontIntegrationsDeployRoleArn: + Value: !GetAtt FrontIntegrationsDeployRole.Arn ExpenseApprovalBotDeployRoleArn: Value: !GetAtt ExpenseApprovalBotDeployRole.Arn AfiBackupMonitorDeployRoleArn: