fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)

Removes the SeahavenSlackBotDeployRole resource block. Step 1 recorded
DeletionPolicy/UpdateReplacePolicy Retain in the deployed template, so
CloudFormation stops managing the resource without issuing DeleteRole
against a role that no longer exists -- confirmed from the change set,
which reports PolicyAction: Retain on a single Remove entry.

seahaven-slack-bot was decommissioned in favour of sh-mcp and the role
was deleted directly in IAM on 2026-07-23. The stack is now consistent
with reality again, and stack updates no longer fail on it.
This commit is contained in:
Adam Moussa 2026-07-27 18:04:47 -04:00
parent 2ec783052a
commit e009d3c65f
No known key found for this signature in database

View file

@ -1101,49 +1101,6 @@ Resources:
# CDK deploy roles (4 repos)
# ---------------------------------------------------------------------------
# DECOMMISSIONED — being removed from this stack in two steps.
#
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
# that no longer exists. That ghost broke EVERY subsequent stack update: the
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
# IAM read, which 404s. A change-set does not reveal this, because the
# resource itself is unchanged and Outputs are not previewed.
#
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
# and record Retain so that step 2 cannot issue DeleteRole against a role
# that is not there.
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
# CloudFormation simply stops managing it — no IAM call is made.
SeahavenSlackBotDeployRole:
Type: AWS::IAM::Role
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
RoleName: githubdeploy-seahaven-slack-bot
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
ExecAideDeployRole:
Type: AWS::IAM::Role
Properties: