mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-01 06:23:12 +00:00
Add SQS/EC2/SNS to CFN execution role and parameter overrides to cd-sam (#13)
- SQS/EC2/SNS as inline policy (managed policy quota is 10) - cd-sam.yaml now accepts optional parameter-overrides input for SAM templates with required parameters
This commit is contained in:
parent
b273e5cd5c
commit
e00a7c567e
2 changed files with 17 additions and 2 deletions
11
.github/workflows/cd-sam.yaml
vendored
11
.github/workflows/cd-sam.yaml
vendored
|
|
@ -23,6 +23,10 @@ on:
|
||||||
description: "CloudFormation execution role ARN"
|
description: "CloudFormation execution role ARN"
|
||||||
type: string
|
type: string
|
||||||
required: true
|
required: true
|
||||||
|
parameter-overrides:
|
||||||
|
description: "SAM parameter overrides (e.g. 'Key1=Value1 Key2=Value2')"
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
secrets:
|
secrets:
|
||||||
deploy-role-arn:
|
deploy-role-arn:
|
||||||
description: "OIDC deploy role ARN"
|
description: "OIDC deploy role ARN"
|
||||||
|
|
@ -55,6 +59,10 @@ jobs:
|
||||||
|
|
||||||
- name: SAM deploy
|
- name: SAM deploy
|
||||||
run: |
|
run: |
|
||||||
|
PARAMS=""
|
||||||
|
if [ -n "${{ inputs.parameter-overrides }}" ]; then
|
||||||
|
PARAMS="--parameter-overrides ${{ inputs.parameter-overrides }}"
|
||||||
|
fi
|
||||||
sam deploy \
|
sam deploy \
|
||||||
--stack-name ${{ inputs.stack-name }} \
|
--stack-name ${{ inputs.stack-name }} \
|
||||||
--template-file .aws-sam/build/template.yaml \
|
--template-file .aws-sam/build/template.yaml \
|
||||||
|
|
@ -62,4 +70,5 @@ jobs:
|
||||||
--capabilities CAPABILITY_IAM \
|
--capabilities CAPABILITY_IAM \
|
||||||
--no-confirm-changeset \
|
--no-confirm-changeset \
|
||||||
--no-fail-on-empty-changeset \
|
--no-fail-on-empty-changeset \
|
||||||
--role-arn ${{ inputs.cfn-role-arn }}
|
--role-arn ${{ inputs.cfn-role-arn }} \
|
||||||
|
$PARAMS
|
||||||
|
|
|
||||||
|
|
@ -55,7 +55,7 @@ Resources:
|
||||||
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
||||||
- arn:aws:iam::aws:policy/IAMFullAccess
|
- arn:aws:iam::aws:policy/IAMFullAccess
|
||||||
Policies:
|
Policies:
|
||||||
- PolicyName: cloudformation-transforms
|
- PolicyName: additional-service-permissions
|
||||||
PolicyDocument:
|
PolicyDocument:
|
||||||
Version: "2012-10-17"
|
Version: "2012-10-17"
|
||||||
Statement:
|
Statement:
|
||||||
|
|
@ -64,6 +64,12 @@ Resources:
|
||||||
- cloudformation:CreateChangeSet
|
- cloudformation:CreateChangeSet
|
||||||
Resource:
|
Resource:
|
||||||
- arn:aws:cloudformation:us-east-1:aws:transform/*
|
- arn:aws:cloudformation:us-east-1:aws:transform/*
|
||||||
|
- Effect: Allow
|
||||||
|
Action:
|
||||||
|
- sqs:*
|
||||||
|
- sns:*
|
||||||
|
- ec2:*
|
||||||
|
Resource: "*"
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# SAM deploy roles (5 repos)
|
# SAM deploy roles (5 repos)
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue