mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-04 11:22:05 +00:00
fix(iam): drop the decommissioned slack-bot deploy role from the stack (step 2/2)
Removes the SeahavenSlackBotDeployRole resource block. Step 1 recorded DeletionPolicy/UpdateReplacePolicy Retain in the deployed template, so CloudFormation stops managing the resource without issuing DeleteRole against a role that no longer exists -- confirmed from the change set, which reports PolicyAction: Retain on a single Remove entry. seahaven-slack-bot was decommissioned in favour of sh-mcp and the role was deleted directly in IAM on 2026-07-23. The stack is now consistent with reality again, and stack updates no longer fail on it.
This commit is contained in:
parent
2ec783052a
commit
e009d3c65f
1 changed files with 0 additions and 43 deletions
|
|
@ -1101,49 +1101,6 @@ Resources:
|
||||||
# CDK deploy roles (4 repos)
|
# CDK deploy roles (4 repos)
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
# DECOMMISSIONED — being removed from this stack in two steps.
|
|
||||||
#
|
|
||||||
# seahaven-slack-bot was retired (superseded by sh-mcp) and this role was
|
|
||||||
# deleted directly in IAM on 2026-07-23, leaving the stack holding a resource
|
|
||||||
# that no longer exists. That ghost broke EVERY subsequent stack update: the
|
|
||||||
# Outputs section resolved !GetAtt SeahavenSlackBotDeployRole.Arn as a live
|
|
||||||
# IAM read, which 404s. A change-set does not reveal this, because the
|
|
||||||
# resource itself is unchanged and Outputs are not previewed.
|
|
||||||
#
|
|
||||||
# Step 1 (this change): drop the Output so updates stop resolving the ghost,
|
|
||||||
# and record Retain so that step 2 cannot issue DeleteRole against a role
|
|
||||||
# that is not there.
|
|
||||||
# Step 2 (follow-up): delete the resource block itself. With Retain recorded,
|
|
||||||
# CloudFormation simply stops managing it — no IAM call is made.
|
|
||||||
SeahavenSlackBotDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
DeletionPolicy: Retain
|
|
||||||
UpdateReplacePolicy: Retain
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-seahaven-slack-bot
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
ExecAideDeployRole:
|
ExecAideDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue