diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index c210ed0..d1e8782 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1051,146 +1051,6 @@ Resources: Resource: - !GetAtt SamCfnExecutionRole.Arn - FrontIntegrationsDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-front-integrations - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main - Policies: - - PolicyName: sam-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - cloudformation:CreateChangeSet - - cloudformation:DeleteChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:DescribeStackEvents - - cloudformation:DescribeStacks - - cloudformation:ExecuteChangeSet - - cloudformation:GetTemplate - - cloudformation:ListStackResources - - cloudformation:UpdateStack - - cloudformation:CreateStack - - cloudformation:TagResource - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/* - - Effect: Allow - Action: - - cloudformation:GetTemplateSummary - Resource: "*" - - Effect: Allow - Action: - - cloudformation:DescribeStacks - - cloudformation:CreateChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:ExecuteChangeSet - - cloudformation:CreateStack - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - - Effect: Allow - Action: - - s3:PutObject - - s3:GetObject - - s3:ListBucket - - s3:GetBucketLocation - - s3:CreateBucket - - s3:PutBucketPolicy - - s3:GetBucketPolicy - - s3:PutLifecycleConfiguration - - s3:PutBucketVersioning - - s3:DeleteObject - Resource: - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - - Effect: Allow - Action: - - iam:PassRole - Resource: - - !GetAtt SamCfnExecutionRole.Arn - - AfiBackupMonitorDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-afi-backup-monitor - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main - Policies: - - PolicyName: sam-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - cloudformation:CreateChangeSet - - cloudformation:DeleteChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:DescribeStackEvents - - cloudformation:DescribeStacks - - cloudformation:ExecuteChangeSet - - cloudformation:GetTemplate - - cloudformation:ListStackResources - - cloudformation:UpdateStack - - cloudformation:CreateStack - - cloudformation:TagResource - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/* - - Effect: Allow - Action: - - cloudformation:GetTemplateSummary - Resource: "*" - - Effect: Allow - Action: - - cloudformation:DescribeStacks - - cloudformation:CreateChangeSet - - cloudformation:DescribeChangeSet - - cloudformation:ExecuteChangeSet - - cloudformation:CreateStack - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - - Effect: Allow - Action: - - s3:PutObject - - s3:GetObject - - s3:ListBucket - - s3:GetBucketLocation - - s3:CreateBucket - - s3:PutBucketPolicy - - s3:GetBucketPolicy - - s3:PutLifecycleConfiguration - - s3:PutBucketVersioning - - s3:DeleteObject - Resource: - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - - Effect: Allow - Action: - - iam:PassRole - Resource: - - !GetAtt SamCfnExecutionRole.Arn - PaymentsDashboardDeployRole: Type: AWS::IAM::Role Properties: @@ -1262,90 +1122,12 @@ Resources: - !GetAtt SamCfnExecutionRole.Arn # --------------------------------------------------------------------------- - # CDK deploy roles (4 repos) + # CDK deploy role for seahaven-org-baseline. + # Soaked githubdeploy roles for front-integrations, afi-backup-monitor, + # exec-aide, seahaven-door-unlock-api, and apm-wo-analysis are removed + # here (PLAT-232). Deploying this stack deletes those roles. # --------------------------------------------------------------------------- - ExecAideDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-exec-aide - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - - SeahavenDoorUnlockApiDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-seahaven-door-unlock-api - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - - ApmWoAnalysisDeployRole: - Type: AWS::IAM::Role - Properties: - RoleName: githubdeploy-apm-wo-analysis - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - token.actions.githubusercontent.com:aud: sts.amazonaws.com - StringLike: - token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main - Policies: - - PolicyName: cdk-deploy - PolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Action: - - sts:AssumeRole - Resource: - - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* - SeahavenAccountBaselineDeployRole: Type: AWS::IAM::Role Properties: @@ -1434,24 +1216,18 @@ Outputs: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn - FrontIntegrationsDeployRoleArn: - Value: !GetAtt FrontIntegrationsDeployRole.Arn - AfiBackupMonitorDeployRoleArn: - Value: !GetAtt AfiBackupMonitorDeployRole.Arn PaymentsDashboardDeployRoleArn: Value: !GetAtt PaymentsDashboardDeployRole.Arn # SeahavenSlackBotDeployRoleArn removed 2026-07-27: the role was deleted # out-of-band on 2026-07-23, so this !GetAtt failed as a live IAM read and # broke every stack update. Nothing imported it (the Output had no # ExportName, and no stack imports any export from this stack). - ExecAideDeployRoleArn: - Value: !GetAtt ExecAideDeployRole.Arn - SeahavenDoorUnlockApiDeployRoleArn: - Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn # ProcurementIngestDeployRoleArn removed 2026-08-07 (PLAT-88): HCP sole # mutate path; prod githubdeploy role deleted; mgmt twin already gone. - ApmWoAnalysisDeployRoleArn: - Value: !GetAtt ApmWoAnalysisDeployRole.Arn + # FrontIntegrations, AfiBackupMonitor, ExecAide, SeahavenDoorUnlockApi, + # and ApmWoAnalysis deploy role outputs removed 2026-09-28 (PLAT-232). + # CloudTrail showed no successful mutation for 14 days. The roles are + # deleted only when this stack is deployed. That deploy is not this change. SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn SeahavenOrgBaselinePolicyCheckRoleArn: