mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
Removes the SeahavenSlackBotDeployRole resource block. Step 1 recorded DeletionPolicy/UpdateReplacePolicy Retain in the deployed template, so CloudFormation stops managing the resource without issuing DeleteRole against a role that no longer exists -- confirmed from the change set, which reports PolicyAction: Retain on a single Remove entry. seahaven-slack-bot was decommissioned in favour of sh-mcp and the role was deleted directly in IAM on 2026-07-23. The stack is now consistent with reality again, and stack updates no longer fail on it.
This commit is contained in:
parent
2ec783052a
commit
e009d3c65f
1 changed files with 0 additions and 43 deletions
|
|
@ -1101,49 +1101,6 @@ Resources:
|
|||
# CDK deploy roles (4 repos)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
# DECOMMISSIONED — being removed from this stack in two steps.
|
||||
#
|
||||
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
|
||||
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
|
||||
# that no longer exists. That ghost broke EVERY subsequent stack update: the
|
||||
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
|
||||
# IAM read, which 404s. A change-set does not reveal this, because the
|
||||
# resource itself is unchanged and Outputs are not previewed.
|
||||
#
|
||||
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
|
||||
# and record Retain so that step 2 cannot issue DeleteRole against a role
|
||||
# that is not there.
|
||||
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
|
||||
# CloudFormation simply stops managing it — no IAM call is made.
|
||||
SeahavenSlackBotDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
DeletionPolicy: Retain
|
||||
UpdateReplacePolicy: Retain
|
||||
Properties:
|
||||
RoleName: githubdeploy-seahaven-slack-bot
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
ExecAideDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue