From b6e52556ec77535d7df7a53df24dc18b15762476 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 20 Aug 2026 13:11:14 -0400 Subject: [PATCH] chore(iam): remove mgmt meal-order weekly-menu OIDC role Weekly-menu publish now assumes the prod HCP role; drop the orphaned mgmt github-meal-order-manager-weekly-menu role from this stack. --- oidc-deploy-roles.yaml | 85 ++++-------------------------------------- 1 file changed, 7 insertions(+), 78 deletions(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 4ea8b24..94154d7 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1353,82 +1353,12 @@ Resources: Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - # Scoped runtime role for the meal-order-manager weekly-menu workflow - # (Monday scrape + order-form publish). Deliberately narrower than the - # repo's deploy role: the scheduled job reads Terraform-written deploy - # parameters and app config, invokes the IAM-authenticated publication API, - # writes the published form, and invalidates the form's CloudFront path. It - # deploys nothing, so it gets no CloudFormation write actions, no PassRole, - # and no DynamoDB access. - MealOrderManagerWeeklyMenuRole: - Type: AWS::IAM::Role - Properties: - RoleName: github-meal-order-manager-weekly-menu - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - # StringEquals (not the sibling roles' StringLike): no wildcard is - # intended, and job_workflow_ref pins this runtime role to the ONE - # workflow it serves — unlike the deploy roles, any main-branch - # workflow must NOT be able to mint these credentials. - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/meal-order-manager:ref:refs/heads/main - token.actions.githubusercontent.com:job_workflow_ref: !Sub ${GitHubOrg}/meal-order-manager/.github/workflows/weekly-menu.yml@refs/heads/main - Policies: - - PolicyName: weekly-menu-publish - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - secretsmanager:GetSecretValue - # Secrets Manager appends a random 6-char suffix to every secret - # ARN, so a name-based match needs a glob — but exactly six '?' - # (one char each), NOT '-*', which would also match any future - # secret extending the name (e.g. form-api-key-backup). - Resource: - - !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/form-api-key-?????? - - !Sub arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:meal-order-manager/slack-bot-token-?????? - - Effect: Allow - Action: - - ssm:GetParameter - # Deploy targets are written by Terraform (meal-order-manager - # terraform/ssm.tf). App config params remain named grants only. - Resource: - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id - - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id - # Publication routes on the meal-order-manager HttpApi (API id - # b5mli7qgp3 is stable for the life of the stack). Menu/settings - # writes go through these IAM-authenticated routes, not DynamoDB. - - Effect: Allow - Action: - - execute-api:Invoke - Resource: - - !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings - - !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu - - Effect: Allow - Action: - - s3:PutObject - Resource: - - !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/index.html - - !Sub arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/archive/*.html - - Effect: Allow - Action: - - cloudfront:CreateInvalidation - # Distribution ID = the meal-order-manager stack's DistributionId - # output (stable for the life of the distribution). - Resource: - - !Sub arn:aws:cloudfront::${AWS::AccountId}:distribution/E314J1CJJ9ZTRA + # MealOrderManagerWeeklyMenuRole removed 2026-08-20 (PLAT-70): + # weekly-menu OIDC role now lives in seahaven-prod as + # /tf-managed/githubdeploy-meal-order-manager-weekly-menu (HCP TF). + # GitHub secret AWS_WEEKLY_MENU_ROLE_ARN already points at the prod role. + # Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update. + Outputs: LambdaExecutionBoundaryArn: @@ -1464,5 +1394,4 @@ Outputs: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn - MealOrderManagerWeeklyMenuRoleArn: - Value: !GetAtt MealOrderManagerWeeklyMenuRole.Arn + # MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.